What this is about
Sometimes support creates an access by hand, for example for a customer who should not register themselves. For this there is the variant PLATFORM_ADMIN: a registration that a signed-in administrator starts for another person.
The person still gets an email with a link and verifies their address themselves. So the administrator does not create a finished account. They start the registration.
Turning on the variant
PLATFORM_ADMIN is available only when the installation configures the flow. An example:
codamai:
cias:
registration:
flows:
PLATFORM_ADMIN:
enabled: true
tenant-assignment: FROM_PAYLOAD
required-caller-roles: [platform-admin]
token-ttl: P7D
fields:
- { key: email, type: EMAIL, required: true }
- { key: firstName }
- { key: lastName }required-caller-roles sets which roles the caller must have. Without this entry, being signed in is enough. So for this variant, always put platform-admin in it.
The flow
-
1Admin→CIASsends email, fields and optionally
tenantKey -
2CIASIs the flow turned on?no: rejected,
cias.registration.misconfigured -
3CIASDoes the caller have all roles from
required-caller-roles?no: 403cias.registration.not-authorized -
4CIASdetermines the tenant by the setting
tenant-assignment -
5CIASchecks the fieldsa required field is missing: 422
-
6CIAS→Keycloakcreates the account disabled if the address is new
-
7CIAS→Emailemail with link to the person
-
8User→CIASclicks the link, then provisioning as always
This variant is not throttled. Throttling exists only for the public form.
With or without a tenant
What happens to the tenantKey in the payload is decided only by the flow’s setting tenant-assignment:
| tenant-assignment | tenantKey sent? | Result |
|---|---|---|
FROM_PAYLOAD | yes | The person becomes a member of this tenant |
FROM_PAYLOAD | no | 400 cias.registration.invalid-request: the tenant is missing |
NONE | – | The person gets no tenant. A key that was sent is ignored |
JOIN_EXISTING | yes | The person joins this existing tenant |
CIAS checks whether the named tenant exists during provisioning. If it is missing there, the registration ends in FAILED. See What happens on completion.