CodamAIDocs
Topicdone

Group roles under dynamic tenants

Why client roles granted globally, including those from groups, do not apply under a dynamic tenant that has roles of its own, and how to plan groups accordingly.

Variants
tenant without roles of its owntenant with roles of its ownrealm roles from groups

What this is about

A group applies platform wide. That is why its roles end up in the token in the global place:

  • realm roles under realm_access.roles,
  • client roles under resource_access.<client>.roles.

If a request runs in a dynamic tenant, and the person has roles of their own there, CIAS replaces the global client roles with the roles in the tenant. This is described in detail in Effective roles: global or in the tenant. For groups this means:

Why is that? Nobody granted a group role for this one tenant. If it applied anyway, a permission would leak into a tenant that decides for itself which business roles apply in it. CIAS does not fix this but shows it: every role of a group carries the field effectiveInEveryTenant.

Before and after

Anna is a member of the group support. In her dynamic tenant nordbau she also has a role of her own, hr-employee-edit.

flowchart LR
    subgraph T["In Anna's token"]
      direction TB
      G["global, from the group support:<br/>cdms-backend: customer-read<br/>crms-backend: ticket-edit"]
      R["realm, from the group support:<br/>user"]
      O["in the tenant nordbau:<br/>cdms-backend: hr-employee-edit"]
    end
    subgraph E["Effective in nordbau, in the CDMS deployment"]
      direction TB
      E1["business roles:<br/>hr-employee-edit"]
      E2["realm roles:<br/>user"]
    end
    O --> E1
    R --> E2
    G -. "drop out" .-> E

customer-read from the group drops out because Anna has roles of her own in nordbau. The realm role user from the same group stays.

The three variants

What arrives from a group

When: Static tenant, or a dynamic tenant in which the person has no roles.

The global client roles apply, so all roles from groups apply too. An installation whose tenants are all static does not notice this limit at all.

Result: all roles of the group apply

When: Dynamic tenant, and the person has at least one role there, for whatever client.

The roles in the tenant replace the global client roles. Client roles from groups are not there for this request.

Result: only the realm roles of the group apply

When: always

Realm roles are under realm_access.roles and are never replaced. In the group view they show effectiveInEveryTenant: true.

Result: apply in every tenant

The decision

Does a role from a group apply to this request?
Level of the roleTenant of the request dynamic?Person has roles of their own there?Result
realm role––applies
client roleno–applies
client roleyesnoapplies
client roleyesyesdoes not apply, even though it is in the token

The field effectiveInEveryTenant

Every role in the response of GET /cias/admin/groups/{key} carries this field:

RoleeffectiveInEveryTenantWhat the interface should show
realm roletruenothing special
client rolefalsea hint: “does not apply in tenants with roles of their own”

The field says what the mechanism is, not what your installation happens to do with it. Even if all your tenants are static, client roles show false.

The scope of a role in the catalog does not change this. A group may also carry roles with scope TENANT; it still grants them globally, without a tenant. You grant a role for one tenant only with a grant in the tenant, not through a group.

Plan your groups

Where does this role belong?
Does every person need it in every tenant?Are there dynamic tenants with roles of their own?Plan
yes–as a realm role in a group
nonoas a client role in a group
noyesas a grant in the tenant, per person and tenant

In short: in installations with dynamic tenants, groups are good for realm roles and for people without roles of their own in the tenant. Business roles that should apply in a tenant that already has roles of its own belong in the tenant.

Pitfalls

Next

Sources in the code and the knowledge base
  • CIAS/cias-authentication – EffectiveRoles.resolve, KeycloakOrganizationClaimReader
  • CIAS/cias-authorization – Group (class comment), GroupRoleView.effectiveInEveryTenant, AuthorizationRestDtos.GroupRoleResponse, GroupService.requireCatalogued
  • CIAS/cias-authorization – ConferralCeiling.heldBy (group roles count towards the ceiling)
  • CIAS/cias-iam-api – GroupManagementPort (class comment)
  • CIAS/cias-authorization/docs/adr – ADR-023, ADR-031, ADR-034
Search