User attributes
Details on the account that become claims in the token and filter rows in CDMS: where they come from, how modules declare them, who may write them and which tenants a value applies to.
Topics in this subject area
- 1.Two origins of attributes
Platform attributes (e.g.
tenant) and project attributes from the model. The difference and why it matters. - 2.Registering attributes
How a module declares an attribute, why a required attribute needs a default value, and how the attribute catalog comes about.
- 3.The path into the token
Profile in Keycloak, claim mapper, claim in the token, attribute in the RequestContext.
- 4.Who may write an attribute
Delegation per attribute and ceiling for values: an administrator can only grant values they hold themselves.
*means unrestricted. - 5.One value per person or per tenant
An attribute applies either to the person in all tenants (USER) or separately per tenant (USER_IN_TENANT). How the right value gets into the token and the attribute filter when a person belongs to several tenants.
- 6.How an attribute goes away again
An attribute that no module declares any more is retired, not deleted.