CodamAIDocs
Topicdone

Resend the password setup link

How an administrator sends a person a new link to set their password.

Variants
send linkaccount not activedelivery not configuredKeycloak extension missing

What this is about

After registration, a person gets a link in the welcome email to set their password in Keycloak. Sometimes this email gets lost, or the link has expired. Then a platform administrator can send a new link.

The flow

POST /cias/admin/users/{id}/password-setup-link
  1. 1
    Admin→CIAS
    requests the link, without a body
  2. 2
    CIAS
    Platform administrator? Person known?
    otherwise 403 or 404
  3. 3
    CIAS
    Delivery configured? Account active?
    otherwise 501 or 409
  4. 4
    CIAS→Keycloak
    fetches a one-time link through the Keycloak extension
    The link carries the action "set password" itself. Keycloak only demands it once the person opens the link.
  5. 5
    CIAS→Email
    Email PASSWORD_SETUP with the link to the person's address
    in the language Keycloak holds for the person (attribute locale), otherwise German
  6. 6
    CIAS
    Event PasswordSetupLinkSent
    Result: 200 { "recipient": "anna@nordbau.example", "expiresAt": "…" }

The variants

When the link arrives

When: The installation has configured the delivery, and the account is active.

The person gets the email, clicks the link, sets a password in Keycloak, and then lands on the configured return address. The email may have its own template per tenant.

Result: New password set. Until then the old one stays valid.

When: The account is not yet enabled (PENDING), suspended (SUSPENDED) or closed (CLOSED).

CIAS refuses before Keycloak does anything. An account that is not yet enabled cannot sign in at Keycloak, a suspended or closed one is meant to stay out.

Result: 409 cias.user.invalid-state, no email.

When: The installation has not set a client for this link.

CIAS refuses, the account stays unchanged. The person can request a new password themselves through "Forgot password" on the login page.

Result: 501 cias.user.password-setup-unavailable, no email.

When: The add-on module cias-iam-keycloak-provider is not installed in Keycloak.

Keycloak does not know the endpoint for the link. CIAS refuses, the account stays unchanged.

Result: 501 cias.user.password-setup-unavailable, no email. See The Keycloak extension for the password link.

Settings

SettingMeaning
codamai.cias.user.password-setup.client-idthe browser client of the user interface Keycloak issues the link for. Empty means: feature off, response 501
codamai.cias.user.password-setup.return-urlwhere the person lands after setting the password. Must be a permitted redirect address of that client. If a client is set and the address is missing, the application does not start
codamai.cias.user.password-setup.valid-forhow long the link is valid, default 24 hours, at most 72 hours

The settings are separate from those of registration. A registration knows which application it ran for, an administrator’s link does not. That is why it needs its own return address.

Next

Sources in the code and the knowledge base
  • CIAS/cias-user – UserAdminController (password-setup-link), UserService (sendPasswordSetupLink), PasswordSetupDelivery, PasswordSetupDispatch, PasswordSetupUnavailableException, UserExceptionHandler, UserEvent.PasswordSetupLinkSent
  • CIAS/cias-spring-boot-starter – CiasAutoConfiguration (passwordSetupDelivery), CiasProperties (user.password-setup)
  • CIAS/cias-iam-keycloak – KeycloakIdentityAdapter (createPasswordSetupLink)
  • CIAS/cias-iam-keycloak-provider – ActionLinkResource
  • CIAS/cias-notification – PASSWORD_SETUP
Search