CodamAIDocs
Topicdone

Initial roles as a rule set

Which roles a new person gets is decided by a rule set per situation (founder, member, without tenant). Who may write rules and why the tenant rule replaces instead of adds.

Variants
TENANT_FOUNDERTENANT_MEMBERTENANTLESSDefault of the installation (bean)Installation ruleTenant rule (replaces)Delegation checked again when applied

What this is about

A person who registers needs a few roles from the start, otherwise they cannot do anything after the first sign-in. Which roles these are is not fixed in code but set by a rule set. It knows three situations:

Situationapplies whenDefault
TENANT_FOUNDERthe registration founds a new tenant (CREATE_NEW)tenant-owner, tenant-admin, tenant-user (client roles)
TENANT_MEMBERthe person joins an existing tenanttenant-user (client role)
TENANTLESSthe registration has no tenant (NONE)user (realm role)

The situation depends only on the tenant assignment, not on the variant. So an invitation by a tenant administrator is TENANT_MEMBER, and a self-registration with CREATE_NEW is TENANT_FOUNDER.

Where the roles come from

rolesFor(situation, tenant)
  1. CIAS
    Tenant rule
    Is there a rule for this tenant and this situation? Then only that rule applies
  2. CIAS
    Installation rule
    Otherwise: is there a rule without a tenant for this situation?
  3. CIAS
    Default
    Otherwise: the RegistrationRoles bean
  4. The initial roles are fixed. After that, hooks may still change them

The three levels

Default, installation rule, tenant rule

When: No stored rule matches.

The RegistrationRoles bean in the application's code. cias-runtime and the hub ship it: founder tenant-owner, tenant-admin and tenant-user, member tenant-user, without tenant user. The founder gets all three so that she can run her tenant without a platform administrator: inviting requires tenant-admin, and she can only pass on what she holds herself. If registration is switched on and the bean is missing, the application does not start. There is no built-in standard set.

When: A platform administrator writes a rule without a tenant.

PUT /cias/admin/registration-rules/{situation} with { "roles": [ { "key": "…", "level": "MODULE" } ] }. Each role must be in the role catalog and must not be retired. The rule applies to all tenants that have no rule of their own.

When: A tenant administrator wants different initial roles for their tenant.

The same endpoint, called with a token that carries a tenant. The rule applies only to this tenant. Each role must be tenant-scoped, and all roles must be delegated through one role that the author holds themselves. They must also hold each role themselves (ceiling). CIAS remembers through which role the rule was written.

Result: The rule replaces the installation rule for this tenant.

level is MODULE for a client role of your own client or REALM for a realm role. It is required.

Why replace instead of add?

If the tenant rule only added to the installation rule, a tenant could only ever grant more, never less. “New members first get read access only” would then not be possible. That is why: if the tenant has a rule, only that rule counts.

Rules
Installation, TENANT_MEMBER:  tenant-user, report-read
Tenant nordbau, TENANT_MEMBER: report-read
Initial roles
New member in nordbau:       report-read
New member in suedlogistik:  tenant-user, report-read

Two authorities

Installation ruleTenant rule
Who writes itplatform administratortenant administration, as delegated
Who it applies toall tenants without their own ruleonly this tenant
Which rolesall from the catalogonly tenant-scoped, delegated, held by the author
Checked when appliednoyes, the delegation

Delegation when applied

A tenant rule is checked not only when it is written, but on every registration that applies it. CIAS then asks the catalog: may the role through which the rule was written still pass on these roles?

If the installation has withdrawn the delegation in the meantime, CIAS does not apply the rule and does not grant a reduced set either. The registration is not completed, and the log says which rule is no longer covered. The tenant administration then rewrites the rule or deletes it.

Hooks and ceiling

After the rule set, a hook with onAssignInitialRoles may still change the set. CIAS then only checks that each role exists. What the rule set grants is granted by the installation, not by a single person. That is why the ceiling applies when a rule is written, not when roles are granted.

Next

Sources in the code and the knowledge base
  • CIAS/cias-registration – RegistrationSituation, RegistrationRoles, RegistrationRoleRule, RegistrationRoleRuleService (rolesFor, qualifyingRole, requireStillDelegated), RegistrationRoleRuleController, GrantedRole
  • CIAS/cias-registration – V2__cias_registration_role_rule.sql, ConferralCeilingPort
  • CIAS/cias-runtime – CiasRegistrationRoleConfiguration; hub-backend – CiasRegistrationSupportConfiguration
  • CIAS/cias-registration/docs/adr – ADR-029; CIAS/cias-authorization/docs/adr – ADR-043
Search