CodamAIDocs
Topicdone

CIAS audit and CDMS history

Two different records: CIAS records events around people and permissions, CDMS records data states. When to look where.

Variants
question about permissions and people → CIAS auditquestion about data → CDMS historyquestion about both

What this is about

In CodamAI there are two records, and they answer different questions:

  • The CIAS audit records what happened to people, tenants and permissions: who gave whom which role and when? When was the tenant suspended?
  • The CDMS history records what data looked like: what state did this order have yesterday, and who changed it? See Audit, history, rollback.

Side by side

CIAS audit
what happened to people and permissions
  • one entry per event, such as AuthorizationEvent.Granted
  • one table cias_audit_entry in the system database, for the whole platform
  • actor: sub and tenant from the token
  • append only, no rollback
  • read only by a platform administrator, via AuditQueryUseCase
CDMS history
what data looked like
  • one revision per change, with the whole state of the object
  • a separate revision log per database, so per tenant
  • actor: name, IP address, browser; in the database also the user ID (sub)
  • an old state can be brought back (rollback)
  • read by whoever has the model's history role, via POST /{id}/history

Where to look?

Where is the answer to my question?
What is it about?Look in
Who gave this person the role, and when?CIAS audit, AuthorizationEvent.Granted
Since when has the tenant been suspended, and who did it?CIAS audit, TenantEvent.Suspended
When did this person register?CIAS audit, RegistrationEvent.Initiated and Completed
Who changed the price of this order, and what was in it before?CDMS history of the order
What did the customer look like a week ago?CDMS history, possibly rollback
Was the person who changed the order allowed to do so back then?both: time and name from the CDMS history, then in the CIAS audit this person's role grants up to that time

Connecting both

Was Ben allowed to change the order on 22.09.?
  1. 1
    Admin→CDMS
    reads the history of the order: revision 57 on 22.09. at 10:02, username Ben Beispiel
  2. 2
    Admin→CIAS
    looks up Ben's user record and reads the audit: entries AuthorizationEvent.Granted, Revoked, Expired with Ben's userId up to 10:02
  3. 3
    Admin
    order-edit was granted on 20.09. and only revoked on 25.09.
    Result: Ben had the permission at the time of the change

Watch the names and IDs: the CDMS history returns the name from the token (username); the user ID (sub) is only in the table revinfo of the database. After a user switch, username is the person acted on behalf of, and actingUsername the person who actually acted. As actor in the CIAS audit there is the Keycloak ID (sub). In the role events, userId is the ID of the user record in CIAS. You find the link in the user record, which holds Keycloak ID, name and CIAS ID, see The user record.

Pitfalls

Next

Sources in the code and the knowledge base
  • CIAS/cias-audit – DomainEventAuditListener, AuditEntry, V1__cias_audit_entry.sql, AuditService
  • CDMS/cdms-persistence-database – auditing/AuditRevisionEntity (revinfo), AuditRevisionListener, AuditHistoryReader
  • CIAS/cias-authentication – JwtSessionFilter, TokenParser (userId from sub)
  • CIAS/cias-audit/docs/adr – ADR-033
Search