CodamAIDocs
Topicdone

Set the password

CIAS never sees a password. How the person sets their password at Keycloak after verification, and what happens without a password setup link.

Variants
with password setup link in the welcome emailwithout link (“Forgot password”)link later via admin

What this is about

Nobody enters a password during registration. CIAS does not accept passwords, does not store them, and does not see them. The person sets the password at Keycloak, on a Keycloak page.

To make this go smoothly after registration, CIAS requires the account to set a password when it enables the account. If possible, it sends a direct link for this in the welcome email.

sequenceDiagram
    participant C as CIAS
    participant K as Keycloak
    participant X as Keycloak extension
    participant M as Email
    participant B as User
    C->>K: Enable account
    C->>K: Required action “Set password” (UPDATE_PASSWORD)
    C->>X: POST /admin/realms/{realm}/cias-action-links
    X-->>C: Link and expiry time
    C->>M: Welcome email with link
    M-->>B: Email
    B->>K: opens the link
    K-->>B: Page “New password”
    B->>K: Enter password twice
    K-->>B: back to the application's sign-in page

The Keycloak extension is a small add-on module that runs inside Keycloak (cias-iam-keycloak-provider). It creates the same one-time link that Keycloak would send by email itself, but returns it to CIAS. This way, CIAS sends the email in its own style and with its own templates. The link works only once and only for this address.

The variants

How the person gets their password

When: The installation has configured a password client (codamai.cias.registration.password-setup.client-id), and the Keycloak extension is installed.

The welcome email contains the link. It leads directly to the Keycloak page for setting the password and then back to the application's sign-in page. How long it is valid is set by password-setup.valid-for, at most 72 hours; if not set, the realm setting applies, likewise at most 72 hours.

Result: One click, set the password, done.

When: No password client is configured, or the extension is missing or refuses.

The registration is still completed. The welcome email then contains the link to sign in and a note to set a password via “Forgot password”. Keycloak then sends its own reset email.

Result: Two more steps, but no failure.

When: The person lost the email, or the link has expired.

  1. 1
    Admin→CIAS
    POST /cias/admin/users/{id}/password-setup-link
  2. 2
    CIAS→Keycloak
    fetches a new link, the account stays unchanged
  3. 3
    CIAS→Email
    Email PASSWORD_SETUP with the link

Result: Only for platform administrators. The response names the recipient and the expiry time, never the link itself. Requires that the installation has set up delivery and that the account is active. See Resend the password setup link.

Next

Sources in the code and the knowledge base
  • CIAS/cias-registration – RegistrationService (provision: requirePasswordSetup, passwordSetupContext), PasswordSetupPolicy, RegistrationLinks
  • CIAS/cias-iam-keycloak-provider – ActionLinkResourceProviderFactory, ActionLinkResource (cias-action-links)
  • CIAS/cias-iam-keycloak – KeycloakIdentityAdapter (requirePasswordSetup, createPasswordSetupLink)
  • CIAS/cias-spring-boot-starter – CiasProperties (registration.password-setup, keycloak.password-setup-actions)
  • CIAS/cias-user – UserAdminController (password-setup-link), UserService, PasswordSetupDelivery
  • CIAS/cias-notification – WELCOME, PASSWORD_SETUP
Search