What this is about
A tenant administrator wants to bring a colleague into their tenant. For this there is the variant TENANT_ADMIN: they send the address and name, CIAS sends an email with a link, and when the colleague redeems the link, they are a member.
The flow
sequenceDiagram
participant A as Admin (tenant nordbau)
participant C as CIAS
participant K as Keycloak
participant M as Email
participant B as User
A->>C: POST /cias/tenant/registrations<br/>email, firstName, lastName
C->>C: role tenant-admin? Tenant from the token: nordbau
C->>K: create account disabled (only for a new address)
C->>M: email with link
C-->>A: 202
M-->>B: email
B->>C: redeems the link
C->>K: enable, member of nordbau, member roles
C->>M: welcome email
The variants
- account is created disabled
- email
VERIFY_EMAILwith link - after the click: enable, set the password in Keycloak
- member of
nordbauwith the member roles
- no new account
- email
MEMBERSHIP_INVITATIONwith link - password and account stay untouched
- after the click: member of
nordbau, in addition to the previous tenants
When: The call contains "tenantKey": "suedlogistik".
CIAS drops the field without checking it. The invitation is for the tenant from the inviting person's token.
Result: The person becomes a member of nordbau, not of suedlogistik.
When: The calling person's token carries no tenant.
Without a tenant, CIAS does not know where to invite the person.
Result: 403 cias.registration.not-authorized
When: The calling person does not have all roles from required-caller-roles (as shipped: tenant-admin).
Result: 403 cias.registration.not-authorized
What the inviting person must provide
The flow’s configuration sets the fields. In cias-runtime only email is required; firstName and lastName are optional. What the inviting person leaves open, the link later shows as an open field, see Redeem an invitation.
How long the link is valid is also in the configuration (token-ttl). In cias-runtime it is 14 days.
Next
- Redeem an invitation
- The email is the account
- Initial roles as a rule set: which roles members get