# Client Mapper Type: Javascript Mapper

**URL:** <https://forum.keycloak.org/t/client-mapper-type-javascript-mapper/19592>\
**Category:** Getting advice\
**Created:** [January 13, 2023, 2:07am UTC](https://forum.keycloak.org/t/client-mapper-type-javascript-mapper/19592 "2023-01-13T02:07:34Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![melancholia](https://avatars.discourse-cdn.com/v4/letter/m/dbc845/32.png) [@melancholia](https://forum.keycloak.org/u/melancholia)\
**Post date:** [January 13, 2023, 2:07am UTC](https://forum.keycloak.org/t/client-mapper-type-javascript-mapper/19592/1 "2023-01-13T02:07:34Z")

</div>

Hi All:

2 hopefully quick questions:

1. Is the Client Protocol Mapper Type ‘Javascript Mapper’ on deprecation path?

2. Is the Client Protocol Mapper Type ‘Javascript Mapper’ available for both client protocols SAML and OpenID-Connect?

Thank you.

---

<div class="post-metadata">

**Author:** ![xgp](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/xgp/32/2589_2.png) [@xgp](https://forum.keycloak.org/u/xgp)\
**Post date:** [January 13, 2023, 9:23am UTC](https://forum.keycloak.org/t/client-mapper-type-javascript-mapper/19592/2 "2023-01-13T09:23:24Z")

</div>

I don’t know for sure, but I’m operating on the assumption that javascript mappers are NOT deprecated. in KC18, they deprecated the `upload-scripts` feature, but made no mention of a long-term plan to deprecate scripts altogether. Here’s the relevant snippet in the release notes: [Keycloak 18.0.0 released - Keycloak](https://www.keycloak.org/2022/04/keycloak-1800-released#_removal_of_the_upload_scripts_feature)

For this question, I think it’s probably better to ask on the Keycloak Github Discussions, as the maintainers sometimes answer questions there, but rarely here.

Regarding #2, they work with both types.

---

<div class="post-metadata">

**Author:** ![melancholia](https://avatars.discourse-cdn.com/v4/letter/m/dbc845/32.png) [@melancholia](https://forum.keycloak.org/u/melancholia)\
**Post date:** [February 16, 2023, 6:28pm UTC](https://forum.keycloak.org/t/client-mapper-type-javascript-mapper/19592/3 "2023-02-16T18:28:58Z")

</div>

Hi @xgp

FYI - upgraded to v20.0.3 – the JavaScript Mapper for the Client is no longer available. I had read elsewhere that it was deprecated and option is to write code (will like here when I re-find the article).

---

<div class="post-metadata">

**Author:** ![xgp](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/xgp/32/2589_2.png) [@xgp](https://forum.keycloak.org/u/xgp)\
**Post date:** [February 16, 2023, 6:34pm UTC](https://forum.keycloak.org/t/client-mapper-type-javascript-mapper/19592/4 "2023-02-16T18:34:12Z")

</div>

> [@melancholia](#):
>
> I had read elsewhere that it was deprecated

Thanks. Please post when you find the article. Have you included the nashorn jar in your providers dir? I haven’t tested it yet, but I’m assuming you can probably keep this functionality by including the nashorn jar, and maybe the deprecated mapper code.

---

<div class="post-metadata">

**Author:** ![melancholia](https://avatars.discourse-cdn.com/v4/letter/m/dbc845/32.png) [@melancholia](https://forum.keycloak.org/u/melancholia)\
**Post date:** [February 16, 2023, 6:51pm UTC](https://forum.keycloak.org/t/client-mapper-type-javascript-mapper/19592/5 "2023-02-16T18:51:01Z")

</div>

Will do – w.r.t the article.

Meanwhile thje following could be reason why the JavaScript Mapper deprecated:

> <https://github.com/keycloak/keycloak/issues/9945>
>
> \### Describe the bug
> 
> Hitting this below exception when I run the \`org.keycloak.…testsuite.authz.\*\` module tests 
> 
> and here is the reference for the deprecation notice in openjdk - https://openjdk.java.net/jeps/372
> 
> I was able to confirm the same runs just fine with JDK11 runtime for the authserver. This would be a blocker for the Java 17 certification tests.
> 
> \`\`\`Caused by: java.lang.IllegalStateException: Could not find ScriptEngine for script: Script{id='null', realmId='0cfba609-5d40-404f-a3eb-769cf46dcff8', name='Grant Policy', type='text/javascript', code='$evaluation.grant();', description='null'}\`\`\`
> 
> This is also was previously discussed in \[KEYCLOAK-12755\](https://issues.redhat.com/browse/KEYCLOAK-12755)
> 
> \### Version
> 
> 17.0.0-SNAPSHOT, OpenJDK17
> 
> \### Expected behavior
> 
> We would like the javascript engine to initialize and not fail on the authorization work flows
> 
> \### Actual behavior
> 
> The suspicion is that because of the deprecated Nashorn js engine in jdk17, we are getting a \`Could not find ScriptEngine for script\` IllegalStateExceptions.
> 
> I think we also want a proper exception to bubble up the stack trace, as currently we get a generic exception which is 
> \`Unexpected error while evaluating permissions: java.lang.RuntimeException: Failed to evaluate permissions\` even though we get the actual problem the stack trace down the line.
> 
> \### How to Reproduce?
> 
> run the authz module testsuite using the below mvn command
> 
> set the right binary path for the JDK17\_HOME and MVN\_SETTINGS\_PATH before you run it.
> 
> \`\`\`
> mvn -f testsuite/integration-arquillian/tests/base/pom.xml clean install -Dauth.server.java.home=${JDK17\_HOME} -Dauth.server.memory.settings="-Xms128m -Xmx512m -XX:MetaspaceSize=96m -XX:MaxMetaspaceSize=256m" -Dapp.server.memory.settings="-Xms128m -Xmx512m -XX:MetaspaceSize=96m -XX:MaxMetaspaceSize=256m" -B -s ${MVN\_SETTINGS\_PATH} -Dsettings.path=${MVN\_SETTINGS\_PATH} -Dsurefire.memory.Xms=512m -Dsurefire.memory.Xmx=1536m -Dinsecure.repositories=WARN -Pauth-server-wildfly -Pjava11-auth-server -Dtest=org.keycloak.testsuite.authz.AuthorizationTest
> 
> \`\`\`
> 
> \### Anything else?
> 
> Issue full stack trace:
> 
> \`\`\`
> 2022-02-01 20:07:38,427 ERROR \[org.keycloak.authorization.authorization.AuthorizationTokenService\] (default task-1) Unexpected error while evaluating permissions: java.lang.RuntimeException: Failed to evaluate permissions
> at org.keycloak.keycloak-server-spi-private@17.0.0-SNAPSHOT//org.keycloak.authorization.policy.evaluation.DecisionPermissionCollector.onError(DecisionPermissionCollector.java:182)
> at org.keycloak.keycloak-server-spi-private@17.0.0-SNAPSHOT//org.keycloak.authorization.permission.evaluator.IterablePermissionEvaluator.evaluate(IterablePermissionEvaluator.java:71)
> at org.keycloak.keycloak-server-spi-private@17.0.0-SNAPSHOT//org.keycloak.authorization.permission.evaluator.IterablePermissionEvaluator.evaluate(IterablePermissionEvaluator.java:87)
> at org.keycloak.keycloak-services@17.0.0-SNAPSHOT//org.keycloak.authorization.authorization.AuthorizationTokenService.evaluatePermissions(AuthorizationTokenService.java:285)
> at org.keycloak.keycloak-services@17.0.0-SNAPSHOT//org.keycloak.authorization.authorization.AuthorizationTokenService.authorize(AuthorizationTokenService.java:222)
> .
> .
> .
> .
> Caused by: java.lang.IllegalStateException: Could not find ScriptEngine for script: Script{id='null', realmId='0cfba609-5d40-404f-a3eb-769cf46dcff8', name='Grant Policy', type='text/javascript', code='$evaluation.grant();', description='null'}
> at org.keycloak.keycloak-services@17.0.0-SNAPSHOT//org.keycloak.scripting.DefaultScriptingProvider.createPreparedScriptEngine(DefaultScriptingProvider.java:106)
> at org.keycloak.keycloak-services@17.0.0-SNAPSHOT//org.keycloak.scripting.DefaultScriptingProvider.prepareEvaluatableScript(DefaultScriptingProvider.java:72)
> at org.keycloak.keycloak-services@17.0.0-SNAPSHOT//org.keycloak.scripting.DefaultScriptingProvider.prepareEvaluatableScript(DefaultScriptingProvider.java:33)
> at org.keycloak.keycloak-authz-policy-common@17.0.0-SNAPSHOT//org.keycloak.authorization.policy.provider.js.JSPolicyProviderFactory.lambda$getEvaluatableScript$0(JSPolicyProviderFactory.java:109)
> at org.keycloak.keycloak-authz-policy-common@17.0.0-SNAPSHOT//org.keycloak.authorization.policy.provider.js.ScriptCache.lambda$computeIfAbsent$0(ScriptCache.java:80)
> at java.base/java.util.HashMap.computeIfAbsent(HashMap.java:1220)
> at org.keycloak.keycloak-authz-policy-common@17.0.0-SNAPSHOT//org.keycloak.authorization.policy.provider.js.ScriptCache.computeIfAbsent(ScriptCache.java:80)
> at org.keycloak.keycloak-authz-policy-common@17.0.0-SNAPSHOT//org.keycloak.authorization.policy.provider.js.JSPolicyProviderFactory.getEvaluatableScript(JSPolicyProviderFactory.java:106)
> at org.keycloak.keycloak-authz-policy-common@17.0.0-SNAPSHOT//org.keycloak.authorization.policy.provider.js.JSPolicyProvider.evaluate(JSPolicyProvider.java:46)
> at org.keycloak.keycloak-authz-policy-common@17.0.0-SNAPSHOT//org.keycloak.authorization.policy.provider.permission.AbstractPermissionProvider.evaluate(AbstractPermissionProvider.java:56)
> at org.keycloak.keycloak-authz-policy-common@17.0.0-SNAPSHOT//org.keycloak.authorization.policy.provider.permission.ResourcePolicyProvider.evaluate(ResourcePolicyProvider.java:47)
> at org.keycloak.keycloak-server-spi-private@17.0.0-SNAPSHOT//org.keycloak.authorization.policy.evaluation.DefaultPolicyEvaluator.lambda$createPolicyEvaluator$0(DefaultPolicyEvaluator.java:116)
> 
> \`\`\`

---

<div class="post-metadata">

**Author:** ![melancholia](https://avatars.discourse-cdn.com/v4/letter/m/dbc845/32.png) [@melancholia](https://forum.keycloak.org/u/melancholia)\
**Post date:** [February 16, 2023, 7:09pm UTC](https://forum.keycloak.org/t/client-mapper-type-javascript-mapper/19592/6 "2023-02-16T19:09:32Z")

</div>

@xgp[https://github.com/keycloak/keycloak/pull/11322](https://github.com/keycloak/keycloak/pull/11322) seems to point that was added to the release – however can’t find any release notes on it or why was removed.

---

<div class="post-metadata">

**Author:** ![melancholia](https://avatars.discourse-cdn.com/v4/letter/m/dbc845/32.png) [@melancholia](https://forum.keycloak.org/u/melancholia)\
**Post date:** [February 17, 2023, 3:31pm UTC](https://forum.keycloak.org/t/client-mapper-type-javascript-mapper/19592/7 "2023-02-17T15:31:41Z")

</div>

@xgp FYI - a kind poster provided the link on the GitHub forum: [Server Developer Guide](https://www.keycloak.org/docs/latest/server_development/index.html#_script_providers)
