What this is about
The invited person got an email with a link, see Invitation by the tenant administrator. The link contains a token: a long random string that matches only this one registration. With the token, the UI can do two things:
- show which details the inviter left open,
- accept the invitation.
The flow
-
1User→Frontendopens the link from the email
-
2Frontend→CIAS
GET /cias/registration/invitations/{token}/form -
3CIAS→FrontendList of the flow's fields that have no value yet, for example
firstName -
4User→Frontendclicks “Accept invitation”
-
5Frontend→CIAS
POST /cias/registration/invitations/acceptwith{ "token": "…" } -
6CIASDoes the token exist, and is it not expired?no: 404
cias.registration.not-found -
7CIASRegistration →
VERIFIED, then approval or provisioning -
8CIAS→KeycloakMembership in the tenant, member roles. For a new address, also enable the account
-
9CIAS→EmailWelcome emailResult:
202 { "status": "accepted" }, the person is a member
Accepting takes only the token.
The variants
When: The UI wants to show what is still missing.
The response contains all fields of the flow for which the inviter gave no value, both required and optional fields. If the token is unknown, CIAS responds with 404.
When: The token is valid, and the registration is waiting for the click.
The registration moves to VERIFIED and continues like any registration: approval, if the flow requires one, otherwise provisioning right away.
Result: 202, then the welcome email.
When: The token was already redeemed, for example because the email program opened the link in advance, or the person clicks twice.
CIAS does nothing and responds with 202, just like the first time. This is on purpose: a second click must not lead to an error.
Result: 202, no change.
When: The token does not exist, or it expired while the registration is still waiting for the click.
Both cases look the same. This way, nobody can find out by trial and error which links exist.
Result: 404 { "error": "cias.registration.not-found", "message": "no open registration for this link" }
Next
- Verify the email: the same rules for the token
- What happens on completion