Keycloak : refuse authentication based on group attribute

I’m trying to refuse authentication to a user based on a group attribute.

I thought I’d try to override the default ‘Browser’ flow in the Authentication menu, but I’m not even sure I’m on the right track.

I don’t really see what interface I’m supposed to implement to be able to insert my own logic in the authentication flow.

Am I even supposed to change the browser flow ?