What this is about
Not every registration is finished. Some emails land in spam, some people change their mind. What is left is a registration that waits forever and a disabled account in Keycloak. The cleanup removes both.
Four ways to EXPIRED
When: The cleanup is switched on, and a registration has been waiting longer than configured.
-
1CIASfinds registrations in
PENDING_VERIFICATIONorPENDING_APPROVALthat are older than the deadline -
2CIAS→Keycloakdeletes the account if it was a new account and is still disabled and unverified
-
3CIASregistration →
EXPIRED, eventExpired
Result: The address is free again.
When: The same address registers again.
Open registrations of this address that wait for the click or for approval go to EXPIRED right away. The account in Keycloak stays, because the new attempt takes it over.
Result: Only the newest link is valid. See The email is the account.
When: A platform administrator calls discard.
Like the cleanup, but for a single registration, and also for failed ones (FAILED). For a failed registration CIAS takes back what it created: first every hook undoes its part (initial roles, groups, user record), then CIAS closes its own tenant (the database stays) and deletes its own organization. CIAS deletes the account only if the registration created it and it is a member nowhere else. The response says whether the address is free again.
Result: See Approval by an administrator.
When: The installation sets purge-after.
Registrations in a final state (COMPLETED, REJECTED, EXPIRED) that are older than the deadline are deleted from the database completely. After that, an old link leads to 404.
The settings
The cleanup is a job that runs at a fixed interval. It is off by default, and each deadline can be switched off on its own.
Setting under codamai.cias.registration.cleanup | Default | Meaning |
|---|---|---|
enabled | false | run the cleanup at all |
interval | 1 hour | time between two runs |
unverified-after | off | deadline for registrations waiting for the click |
pending-approval-after | off | deadline for registrations waiting for approval |
purge-after | off | deadline after which registrations in a final state are deleted |
The deadlines are durations in ISO format, for example P7D for seven days. The hub switches the cleanup on and sets unverified-after: P7D.
codamai:
cias:
registration:
cleanup:
enabled: true
interval: PT1H
unverified-after: P7D
pending-approval-after: P30D
purge-after: P180DWhat the run reports
After each run that did something, CIAS writes one line to the log: how many registrations expired, how many accounts were deleted, how many old registrations were removed, and how many had errors. An error in one registration does not stop the run; that registration is handled again in the next run.