CodamAIDocs
Subject area

Login and token

How a person or a service gets a token, how it is renewed and ended, and what happens with the token on every request.

Topics in this subject area

  1. 1.Sign in in the browser

    The path from “open page” to “signed in” via Keycloak with authorization code, with all variants of the login page.

  2. 2.Sign in as a service (client credentials)

    How a server gets a token without a person, what this is meant for, and why user-owned models usually return nothing with it.

  3. 3.Session in the BFF and cookies

    Why the token lives in the frontend's server and not in the browser, what the session cookie looks like, and why every portal has its own cookie prefix.

  4. 4.Renew the token

    When and how the token is renewed before it expires, and what happens when a refresh is rejected or fails.

  5. 5.Sign out

    How signing out deletes cookies, how Keycloak ends the session, and why the login page does not sign you in again right away.

  6. 6.What happens with the token on every request

    The filter chain step by step: read the header, validate, exchange, read the identity, resolve the tenant, admit the tenant, build the roles, perform the switch, clean up.

  7. 7.Token exchange

    Why CIAS exchanges every user token for one for its own client, how long the result is cached, and what happens with a misconfigured realm.

  8. 8.What is read from the token

    Which claim goes where in the RequestContext: user, name, realm roles, business roles, organization, tenant, allowed tenants, attributes.

  9. 9.Effective roles: global or in the tenant

    How CIAS builds the valid roles from global roles and roles of the organization, and why globally granted roles can drop away under a dynamic tenant.

  10. 10.Why revoking permissions takes effect with a delay

    Revoked permissions stay in the token until it expires or the exchange cache runs out. How long this takes and how to block someone immediately.

Search