# Require Reauthentication for Update Profile

**URL:** <https://forum.keycloak.org/t/require-reauthentication-for-update-profile/29053>\
**Category:** Extending the server\
**Tags:** authentication\
**Created:** [December 3, 2024, 10:03am UTC](https://forum.keycloak.org/t/require-reauthentication-for-update-profile/29053 "2024-12-03T10:03:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![CertainPassenger](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/certainpassenger/32/11725_2.png) [@CertainPassenger](https://forum.keycloak.org/u/CertainPassenger)\
**Post date:** [December 3, 2024, 10:03am UTC](https://forum.keycloak.org/t/require-reauthentication-for-update-profile/29053/1 "2024-12-03T10:03:36Z")

</div>

Hello together,

I have a question regarding the Update Profile action and how to enforce reauthentication for it. I’m using Keycloak to secure my SPA. To let a user update their password or profile or delete their account, I want to redirect users to the different login actions. For instance for updating the password to `http://localhost:8080/realms/myrealm/protocol/openid-connect/auth?client_id=myclient&redirect_uri=https://link-to-my-spa&response_type=code&scope=openid&kc_action=UPDATE_PASSWORD` or their profile `http://localhost:8080/realms/myrealm/protocol/openid-connect/auth?client_id=myclient&redirect_uri=https://link-to-my-spa&response_type=code&scope=openid&kc_action=UPDATE_PROFILE`. For UPDATE\_PASSWORD I can set the Maximum Authentication Age to 0 in the Keycloak settings, so a user has to reauthenticate before changing their password. This is also the case for the delete account action. However, how can I also enforce this for UPDATE\_PROFILE? I’ve thought about creating a SPI for this, such as:

```auto
@AutoService(org.keycloak.authentication.requiredactions.UpdateProfile.class)
class UserEventsProvider extends UpdateProfile {
  @Override
  public int getMaxAuthAge() {
    return 0;
  }

  @Override
  public int order() {
    return 100;
  }

  @Override
  public String getId() {
    return "RESTRICTED_UPDATE_PROFILE";
  }
}

```

but I cant find out how to use this RESTRICTED\_UPDATE\_PROFILE instead of UPDATE\_PROFILE. Additionally, I don’t even know if this would be the right approach to force reauthentication for profile updates. Any help would be greatly appreciated! Thank you!

---

<div class="post-metadata">

**Author:** ![dasniko](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/dasniko/32/2969_2.png) [@dasniko](https://forum.keycloak.org/u/dasniko)\
**Post date:** [December 3, 2024, 10:45am UTC](https://forum.keycloak.org/t/require-reauthentication-for-update-profile/29053/2 "2024-12-03T10:45:36Z")

</div>

You are on a good way.  
Remove your custom `getId()` method and deploy it to Keycloak. Then your custom class overloads the built-in one (UpdateProfile), no need to configure anything else.  
This is, because your class uses the same `ID` as the extended one, but a higher order.

---

<div class="post-metadata">

**Author:** ![CertainPassenger](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/certainpassenger/32/11725_2.png) [@CertainPassenger](https://forum.keycloak.org/u/CertainPassenger)\
**Post date:** [December 3, 2024, 12:02pm UTC](https://forum.keycloak.org/t/require-reauthentication-for-update-profile/29053/3 "2024-12-03T12:02:03Z")

</div>

Perfect, thank you very much! With your information I got it to work. In addition I also had to change the class in `@AutoService` from

```auto
@AutoService(org.keycloak.authentication.requiredactions.UpdateProfile.class)

```

to

```auto
@AutoService(org.keycloak.authentication.RequiredActionFactory.class)

```

Afterwards I’ve mapped the jar file into my Keycloak Docker container

```auto
-v "./restrict-update-profile-1.0-SNAPSHOT.jar":"/opt/keycloak/providers/restrict-update-profile-1.0-SNAPSHOT.jar"

```

And now the user has to reauthenticate before they are able to update their profile. Thanks!
