What this is about
When you revoke a role from someone in CIAS, CIAS writes this to Keycloak right away. Still, the person can keep working as before for a few more minutes. This is not a bug. It follows from the way tokens work.
The reason for this approach: if every request had to ask Keycloak, every request would be slower, and every short outage of Keycloak would be an outage of all applications.
The caches
Three places hold on to an answer for a while:
| What | How long at most | Setting |
|---|---|---|
| the access token itself | its lifetime, 5 minutes by default in Keycloak | realm setting in Keycloak |
| the exchanged token in the cache | until 10 seconds before it expires, at most 5 minutes | codamai.cias.token-exchange.ttl |
| the tenant gate (“is this tenant served?”) | 30 seconds | codamai.cias.tenant-gate.ttl |
| attribute values per tenant | 30 seconds | codamai.cias.attribute-lookup.ttl |
The exchanged token cannot live longer than the token the client sends: if that one has expired, the request already ends with 401 before. In practice, revoking a role takes effect at the latest when the current access token expires and the BFF gets a new one.
The timeline
gantt
title Role revoked at 00:00 (access token 5 minutes)
dateFormat mm:ss
axisFormat %M:%S
section Keycloak
Role removed from the account :milestone, k1, 00:00, 0s
section Old token
Role is still in the token :crit, a1, 00:00, 3m
section BFF
Refresh, new token without role :milestone, r1, 03:00, 0s
section Requests
Role no longer takes effect :done, n1, 03:00, 2m
In the example, the old token was still valid for just under 4.5 minutes. The BFF renews 90 seconds before expiry, so after 3 minutes. From then on, the role is missing.
The variants
When: A role grant is revoked in CIAS or expires.
-
1CIAS→Keycloakremoves the role in Keycloak first, then in its own record
-
2Client→CIASrequests with the old token still carry the role
-
3BFF→Keycloakgets a new token on the next refresh, without the role
Result: Takes effect at the latest when the current access token expires, with the default values after at most 5 minutes.
When: A value like projects is changed for a person in a tenant.
These values are not in the token. CIAS asks for them on every request. The answer is remembered for 30 seconds. Attributes that are in the profile in Keycloak, on the other hand, only take effect with the next token, like roles.
Result: Takes effect after at most 30 seconds.
When: A tenant is suspended, closed, or its validity ends.
The tenant gate remembers its answer for 30 seconds. After that it asks again and refuses every request in this tenant with 403 cias.authentication.tenant-not-served, no matter which roles are in the token.
Result: Takes effect after at most 30 seconds, for all persons in the tenant.
When: A person is suspended in CIAS.
CIAS disables the account in Keycloak. Keycloak issues no new tokens to a disabled account, the next refresh fails, and the person has to log in again, which also fails. The access token they have right now stays valid until it expires.
Result: Takes effect at the latest when the current access token expires.
When it has to be fast
| What should stop? | Lever and effect |
|---|---|
| a single permission of a person | Revoke the role. Takes effect with the next token, at most a few minutes |
| all access of a person | Suspend the account. No new token anymore, the current one still runs out |
| all access of a whole customer | Suspend the tenant. Takes effect after at most 30 seconds |