CodamAIDocs
Topicdone

Creation by the platform administrator

The platform administrator creates a person and is the only one allowed to name the tenant in the payload.

Variants
with tenant from the payload (FROM_PAYLOAD)without tenant (NONE)flow not configured → rejected

What this is about

Sometimes support creates an access by hand, for example for a customer who should not register themselves. For this there is the variant PLATFORM_ADMIN: a registration that a signed-in administrator starts for another person.

The person still gets an email with a link and verifies their address themselves. So the administrator does not create a finished account. They start the registration.

Turning on the variant

PLATFORM_ADMIN is available only when the installation configures the flow. An example:

application.yml
codamai:
  cias:
    registration:
      flows:
        PLATFORM_ADMIN:
          enabled: true
          tenant-assignment: FROM_PAYLOAD
          required-caller-roles: [platform-admin]
          token-ttl: P7D
          fields:
            - { key: email, type: EMAIL, required: true }
            - { key: firstName }
            - { key: lastName }

required-caller-roles sets which roles the caller must have. Without this entry, being signed in is enough. So for this variant, always put platform-admin in it.

The flow

POST /cias/admin/registrations
  1. 1
    Admin→CIAS
    sends email, fields and optionally tenantKey
  2. 2
    CIAS
    Is the flow turned on?
    no: rejected, cias.registration.misconfigured
  3. 3
    CIAS
    Does the caller have all roles from required-caller-roles?
    no: 403 cias.registration.not-authorized
  4. 4
    CIAS
    determines the tenant by the setting tenant-assignment
  5. 5
    CIAS
    checks the fields
    a required field is missing: 422
  6. 6
    CIAS→Keycloak
    creates the account disabled if the address is new
  7. 7
    CIAS→Email
    email with link to the person
  8. 8
    User→CIAS
    clicks the link, then provisioning as always

This variant is not throttled. Throttling exists only for the public form.

With or without a tenant

What happens to the tenantKey in the payload is decided only by the flow’s setting tenant-assignment:

tenantKey in the payload
tenant-assignmenttenantKey sent?Result
FROM_PAYLOADyesThe person becomes a member of this tenant
FROM_PAYLOADno400 cias.registration.invalid-request: the tenant is missing
NONE–The person gets no tenant. A key that was sent is ignored
JOIN_EXISTINGyesThe person joins this existing tenant

CIAS checks whether the named tenant exists during provisioning. If it is missing there, the registration ends in FAILED. See What happens on completion.

Next

Sources in the code and the knowledge base
  • CIAS/cias-registration – RegistrationAdminController (POST /cias/admin/registrations), RegistrationService (register, authorize, resolveTenant), RegistrationPolicy, TenantDecision
  • CIAS/cias-spring-boot-starter – ConfigurableRegistrationPolicyProvider, CiasProperties (flows.*)
  • CIAS/cias-registration/docs/adr – ADR-011
Search