What this is about
Everything so far in this chapter is work for platform administrators. But there are three endpoints that every signed-in person may call for themselves. They live under /cias/me.
The three endpoints
When: The UI wants to show which tenant the person is currently working in.
GET /cias/me/tenant returns the tenant of this request, as CIAS determined it from the token, plus its type and whether the installation requires a tenant. The response also comes when the person has no tenant; then it contains null. This way a UI can explain why nothing works.
Result: { "tenantKey": "nordbau", "type": "DYNAMIC", "required": true }
When: The UI wants to show texts and emails in the right language.
GET /cias/me/locale returns the person's stored language and all languages the installation offers. If the person has none stored, you get the first offered language.
Result: { "locale": "de", "supported": ["de", "en"] }
When: The person picks a different language.
PUT /cias/me/locale with { "locale": "en" }. CIAS stores the language as the attribute locale on the account in Keycloak. The Keycloak login pages use the same attribute.
Result: Language not offered: 400 cias.user.unsupported-locale, the message names the offered ones.
When: Everything else
A person can neither read nor change name, address, attributes, or status through /cias/me. The address is the sign-in and cannot be changed; a platform administrator maintains everything else.
Settings and errors
The offered languages are set in codamai.cias.locale.supported, default de,en.
| Case | Response |
|---|---|
| not signed in | 403 from the filter chain |
| token without user ID | 403 cias.user.caller-not-identified |
| language empty | 400 cias.user.invalid-request |
| language not offered | 400 cias.user.unsupported-locale |
| Keycloak not reachable (language) | 503 cias.iam.unavailable |