CodamAIDocs
Topicdone

Approval by an administrator

When a registration needs approval: approve, reject, retry, discard.

Variants
approvereject (email REJECTED)retry provisioningdiscard (unused account is deleted)list of registrations

What this is about

Some registrations should not go through automatically. Self-registration, for example, creates a new tenant, and a human should decide about that. This is what approval is for: after the click on the link, the registration waits until a platform administrator agrees.

Whether a flow needs approval is set in its configuration: approval-required: true.

The excerpt

stateDiagram-v2
    direction LR
    VERIFIED --> PENDING_APPROVAL: approval needed
    PENDING_APPROVAL --> APPROVED: approve
    APPROVED --> PROVISIONING
    PENDING_APPROVAL --> REJECTED: reject
    PROVISIONING --> FAILED: error
    FAILED --> PROVISIONING: retry
    PENDING_APPROVAL --> EXPIRED: discard
    FAILED --> EXPIRED: discard

The actions

All actions are under /cias/admin/registrations/{id}/… and are POST calls.

What a platform administrator can do

When: Registration in PENDING_APPROVAL

approve sets the registration to APPROVED and starts provisioning in the same call. There is no separate email for the approval; the person gets the welcome email after provisioning.

Result: COMPLETED, or FAILED if provisioning fails.

When: Registration in a state that is not yet final

reject with an optional reason ({ "reason": "…" }, at most 255 characters). The registration moves to REJECTED, and the person gets the email REJECTED with the reason.

Result: Final state. The person can register again later.

When: Provisioning has failed (FAILED).

retry starts provisioning again from the beginning. This is useful once the cause is fixed, for example when Keycloak is reachable again or a missing role was created.

Result: COMPLETED or FAILED again.

When: Registration is waiting for the click or for approval, or has failed.

discard sets the registration to EXPIRED. If it was a registration with a new account and the account was never enabled, CIAS deletes it in Keycloak. The address is then free again. No email is sent.

Result: Response { "identityRemoved": true } or false.

When: Registration is waiting for the click.

activate verifies the address without a click. See Verify the email.

If the state does not fit the action, for example approve on a registration that is still waiting for the click, the action is rejected.

The list of registrations

GET /cias/admin/registrations shows all registrations, oldest first, page by page.

ParameterMeaning
stateFilter by state, also several times, e.g. ?state=PENDING_APPROVAL&state=FAILED
pagePage, starting at 0
sizeEntries per page, default 50, at most 500

Each entry contains ID, address, flow, kind, state, tenant assignment, tenant key, the given fields, and timestamps. Links and tokens are never in the list.

Next

Sources in the code and the knowledge base
  • CIAS/cias-registration – RegistrationAdminController, RegistrationService (approve, reject, retry, activate, page, requireAdministrator), RegistrationMaintenanceService (discard, close)
  • CIAS/cias-registration – RegistrationPage, RegistrationRestDtos (RegistrationSummary)
  • CIAS/cias-runtime – application.yml (approval-required), hub-backend – application.yaml
Search