CodamAIDocs
Topicdone

Redeem an invitation

What the invited person sees and does: fetch the open fields, redeem the link, membership.

Variants
fetch the open fieldsacceptalready accepted (same response)link unknown or expired → 404

What this is about

The invited person got an email with a link, see Invitation by the tenant administrator. The link contains a token: a long random string that matches only this one registration. With the token, the UI can do two things:

  1. show which details the inviter left open,
  2. accept the invitation.

The flow

From the link to the membership
  1. 1
    User→Frontend
    opens the link from the email
  2. 2
    Frontend→CIAS
    GET /cias/registration/invitations/{token}/form
  3. 3
    CIAS→Frontend
    List of the flow's fields that have no value yet, for example firstName
  4. 4
    User→Frontend
    clicks “Accept invitation”
  5. 5
    Frontend→CIAS
    POST /cias/registration/invitations/accept with { "token": "…" }
  6. 6
    CIAS
    Does the token exist, and is it not expired?
    no: 404 cias.registration.not-found
  7. 7
    CIAS
    Registration → VERIFIED, then approval or provisioning
  8. 8
    CIAS→Keycloak
    Membership in the tenant, member roles. For a new address, also enable the account
  9. 9
    CIAS→Email
    Welcome email
    Result: 202 { "status": "accepted" }, the person is a member

Accepting takes only the token.

The variants

What can happen when you redeem the link

When: The UI wants to show what is still missing.

The response contains all fields of the flow for which the inviter gave no value, both required and optional fields. If the token is unknown, CIAS responds with 404.

When: The token is valid, and the registration is waiting for the click.

The registration moves to VERIFIED and continues like any registration: approval, if the flow requires one, otherwise provisioning right away.

Result: 202, then the welcome email.

When: The token was already redeemed, for example because the email program opened the link in advance, or the person clicks twice.

CIAS does nothing and responds with 202, just like the first time. This is on purpose: a second click must not lead to an error.

Result: 202, no change.

When: The token does not exist, or it expired while the registration is still waiting for the click.

Both cases look the same. This way, nobody can find out by trial and error which links exist.

Result: 404 { "error": "cias.registration.not-found", "message": "no open registration for this link" }

Next

Sources in the code and the knowledge base
  • CIAS/cias-registration – RegistrationController (GET /invitations/{token}/form, POST /invitations/accept), RegistrationService (invitationForm, verify, provision)
  • CIAS/cias-registration – Registration.verify, RegistrationToken, RegistrationExceptionHandler
  • CIAS/cias-registration/docs/adr – ADR-011, ADR-012
Search