What this is about
A group applies platform wide. That is why its roles end up in the token in the global place:
- realm roles under
realm_access.roles, - client roles under
resource_access.<client>.roles.
If a request runs in a dynamic tenant, and the person has roles of their own there, CIAS replaces the global client roles with the roles in the tenant. This is described in detail in Effective roles: global or in the tenant. For groups this means:
Why is that? Nobody granted a group role for this one tenant. If it applied anyway, a permission would leak into a tenant that decides for itself which business roles apply in it. CIAS does not fix this but shows it: every role of a group carries the field effectiveInEveryTenant.
Before and after
Anna is a member of the group support. In her dynamic tenant nordbau she also has a role of her own, hr-employee-edit.
flowchart LR
subgraph T["In Anna's token"]
direction TB
G["global, from the group support:<br/>cdms-backend: customer-read<br/>crms-backend: ticket-edit"]
R["realm, from the group support:<br/>user"]
O["in the tenant nordbau:<br/>cdms-backend: hr-employee-edit"]
end
subgraph E["Effective in nordbau, in the CDMS deployment"]
direction TB
E1["business roles:<br/>hr-employee-edit"]
E2["realm roles:<br/>user"]
end
O --> E1
R --> E2
G -. "drop out" .-> E
customer-read from the group drops out because Anna has roles of her own in nordbau. The realm role user from the same group stays.
The three variants
When: Static tenant, or a dynamic tenant in which the person has no roles.
The global client roles apply, so all roles from groups apply too. An installation whose tenants are all static does not notice this limit at all.
Result: all roles of the group apply
When: Dynamic tenant, and the person has at least one role there, for whatever client.
The roles in the tenant replace the global client roles. Client roles from groups are not there for this request.
Result: only the realm roles of the group apply
When: always
Realm roles are under realm_access.roles and are never replaced. In the group view they show effectiveInEveryTenant: true.
Result: apply in every tenant
The decision
| Level of the role | Tenant of the request dynamic? | Person has roles of their own there? | Result |
|---|---|---|---|
| realm role | – | – | applies |
| client role | no | – | applies |
| client role | yes | no | applies |
| client role | yes | yes | does not apply, even though it is in the token |
The field effectiveInEveryTenant
Every role in the response of GET /cias/admin/groups/{key} carries this field:
| Role | effectiveInEveryTenant | What the interface should show |
|---|---|---|
| realm role | true | nothing special |
| client role | false | a hint: “does not apply in tenants with roles of their own” |
The field says what the mechanism is, not what your installation happens to do with it. Even if all your tenants are static, client roles show false.
The scope of a role in the catalog does not change this. A group may also carry roles with scope TENANT; it still grants them globally, without a tenant. You grant a role for one tenant only with a grant in the tenant, not through a group.
Plan your groups
| Does every person need it in every tenant? | Are there dynamic tenants with roles of their own? | Plan |
|---|---|---|
| yes | – | as a realm role in a group |
| no | no | as a client role in a group |
| no | yes | as a grant in the tenant, per person and tenant |
In short: in installations with dynamic tenants, groups are good for realm roles and for people without roles of their own in the tenant. Business roles that should apply in a tenant that already has roles of its own belong in the tenant.