CodamAIDocs
Topicdone

Invitation by the tenant administrator

A tenant administrator invites a person into their own tenant. The tenant always comes from their token, never from the payload.

Variants
new personperson already has an account (joining)tenant in the payload (is ignored)caller without tenant → 403

What this is about

A tenant administrator wants to bring a colleague into their tenant. For this there is the variant TENANT_ADMIN: they send the address and name, CIAS sends an email with a link, and when the colleague redeems the link, they are a member.

The flow

sequenceDiagram
    participant A as Admin (tenant nordbau)
    participant C as CIAS
    participant K as Keycloak
    participant M as Email
    participant B as User
    A->>C: POST /cias/tenant/registrations<br/>email, firstName, lastName
    C->>C: role tenant-admin? Tenant from the token: nordbau
    C->>K: create account disabled (only for a new address)
    C->>M: email with link
    C-->>A: 202
    M-->>B: email
    B->>C: redeems the link
    C->>K: enable, member of nordbau, member roles
    C->>M: welcome email

The variants

New or known person
new person
address without an account
  • account is created disabled
  • email VERIFY_EMAIL with link
  • after the click: enable, set the password in Keycloak
  • member of nordbau with the member roles
person already has an account
joining another tenant
  • no new account
  • email MEMBERSHIP_INVITATION with link
  • password and account stay untouched
  • after the click: member of nordbau, in addition to the previous tenants
Other cases

When: The call contains "tenantKey": "suedlogistik".

CIAS drops the field without checking it. The invitation is for the tenant from the inviting person's token.

Result: The person becomes a member of nordbau, not of suedlogistik.

When: The calling person's token carries no tenant.

Without a tenant, CIAS does not know where to invite the person.

Result: 403 cias.registration.not-authorized

When: The calling person does not have all roles from required-caller-roles (as shipped: tenant-admin).

Result: 403 cias.registration.not-authorized

What the inviting person must provide

The flow’s configuration sets the fields. In cias-runtime only email is required; firstName and lastName are optional. What the inviting person leaves open, the link later shows as an open field, see Redeem an invitation.

How long the link is valid is also in the configuration (token-ttl). In cias-runtime it is 14 days.

Next

Sources in the code and the knowledge base
  • CIAS/cias-registration – RegistrationAdminController (POST /cias/tenant/registrations), RegistrationService (register, authorize, resolveTenant, mailPurpose)
  • CIAS/cias-registration – RegistrationRestTest (tenantAdminCannotNameATenant), RegistrationServiceTest
  • CIAS/cias-runtime – application.yml (flows.TENANT_ADMIN)
  • CIAS/cias-registration/docs/adr – ADR-011, ADR-014
Search