CodamAIDocs
Topicdone

Clean up abandoned registrations

How waiting registrations are set to EXPIRED after their deadline, unused accounts are deleted, and old registrations are removed.

Variants
waiting, expiredreplaced by a newer attemptdiscarded by handdelete old registrations

What this is about

Not every registration is finished. Some emails land in spam, some people change their mind. What is left is a registration that waits forever and a disabled account in Keycloak. The cleanup removes both.

Four ways to EXPIRED

How a registration expires

When: The cleanup is switched on, and a registration has been waiting longer than configured.

  1. 1
    CIAS
    finds registrations in PENDING_VERIFICATION or PENDING_APPROVAL that are older than the deadline
  2. 2
    CIAS→Keycloak
    deletes the account if it was a new account and is still disabled and unverified
  3. 3
    CIAS
    registration → EXPIRED, event Expired

Result: The address is free again.

When: The same address registers again.

Open registrations of this address that wait for the click or for approval go to EXPIRED right away. The account in Keycloak stays, because the new attempt takes it over.

Result: Only the newest link is valid. See The email is the account.

When: A platform administrator calls discard.

Like the cleanup, but for a single registration, and also for failed ones (FAILED). For a failed registration CIAS takes back what it created: first every hook undoes its part (initial roles, groups, user record), then CIAS closes its own tenant (the database stays) and deletes its own organization. CIAS deletes the account only if the registration created it and it is a member nowhere else. The response says whether the address is free again.

Result: See Approval by an administrator.

When: The installation sets purge-after.

Registrations in a final state (COMPLETED, REJECTED, EXPIRED) that are older than the deadline are deleted from the database completely. After that, an old link leads to 404.

The settings

The cleanup is a job that runs at a fixed interval. It is off by default, and each deadline can be switched off on its own.

Setting under codamai.cias.registration.cleanupDefaultMeaning
enabledfalserun the cleanup at all
interval1 hourtime between two runs
unverified-afteroffdeadline for registrations waiting for the click
pending-approval-afteroffdeadline for registrations waiting for approval
purge-afteroffdeadline after which registrations in a final state are deleted

The deadlines are durations in ISO format, for example P7D for seven days. The hub switches the cleanup on and sets unverified-after: P7D.

application.yml
codamai:
  cias:
    registration:
      cleanup:
        enabled: true
        interval: PT1H
        unverified-after: P7D
        pending-approval-after: P30D
        purge-after: P180D

What the run reports

After each run that did something, CIAS writes one line to the log: how many registrations expired, how many accounts were deleted, how many old registrations were removed, and how many had errors. An error in one registration does not stop the run; that registration is handled again in the next run.

Next

Sources in the code and the knowledge base
  • CIAS/cias-registration – RegistrationMaintenanceService (sweep, close, removeOrphanedIdentity, purge, discard), RegistrationRetention, RegistrationSweepReport
  • CIAS/cias-registration – CiasRegistrationConfiguration (schedule cleanup.interval)
  • CIAS/cias-registration – RegistrationService (supersedeOpenAttempts)
  • hub-backend – application.yaml (cleanup)
Search