What this is about
Nobody enters a password during registration. CIAS does not accept passwords, does not store them, and does not see them. The person sets the password at Keycloak, on a Keycloak page.
To make this go smoothly after registration, CIAS requires the account to set a password when it enables the account. If possible, it sends a direct link for this in the welcome email.
The flow with a password setup link
sequenceDiagram
participant C as CIAS
participant K as Keycloak
participant X as Keycloak extension
participant M as Email
participant B as User
C->>K: Enable account
C->>K: Required action “Set password” (UPDATE_PASSWORD)
C->>X: POST /admin/realms/{realm}/cias-action-links
X-->>C: Link and expiry time
C->>M: Welcome email with link
M-->>B: Email
B->>K: opens the link
K-->>B: Page “New password”
B->>K: Enter password twice
K-->>B: back to the application's sign-in page
The Keycloak extension is a small add-on module that runs inside Keycloak (cias-iam-keycloak-provider). It creates the same one-time link that Keycloak would send by email itself, but returns it to CIAS. This way, CIAS sends the email in its own style and with its own templates. The link works only once and only for this address.
The variants
When: The installation has configured a password client (codamai.cias.registration.password-setup.client-id), and the Keycloak extension is installed.
The welcome email contains the link. It leads directly to the Keycloak page for setting the password and then back to the application's sign-in page. How long it is valid is set by password-setup.valid-for, at most 72 hours; if not set, the realm setting applies, likewise at most 72 hours.
Result: One click, set the password, done.
When: No password client is configured, or the extension is missing or refuses.
The registration is still completed. The welcome email then contains the link to sign in and a note to set a password via “Forgot password”. Keycloak then sends its own reset email.
Result: Two more steps, but no failure.
When: The person lost the email, or the link has expired.
-
1Admin→CIAS
POST /cias/admin/users/{id}/password-setup-link -
2CIAS→Keycloakfetches a new link, the account stays unchanged
-
3CIAS→EmailEmail
PASSWORD_SETUPwith the link
Result: Only for platform administrators. The response names the recipient and the expiry time, never the link itself. Requires that the installation has set up delivery and that the account is active. See Resend the password setup link.