What this is about
In CIAS every registration is its own record with a state. The state tells you where the registration stands right now: Is it waiting for the click in the email? For an approval? Is it done?
The state diagram
stateDiagram-v2
direction LR
[*] --> PENDING_VERIFICATION: request accepted,<br/>email with link sent
PENDING_VERIFICATION --> VERIFIED: link clicked<br/>or admin confirms
VERIFIED --> PENDING_APPROVAL: approval needed
VERIFIED --> PROVISIONING: no approval needed
PENDING_APPROVAL --> APPROVED: approved
APPROVED --> PROVISIONING
PROVISIONING --> COMPLETED: everything provisioned
PROVISIONING --> FAILED: error
FAILED --> PROVISIONING: retry
PENDING_VERIFICATION --> EXPIRED: expired, replaced<br/>or discarded
PENDING_APPROVAL --> EXPIRED: expired, replaced<br/>or discarded
FAILED --> EXPIRED: discarded
PENDING_VERIFICATION --> REJECTED: rejected
PENDING_APPROVAL --> REJECTED: rejected
COMPLETED --> [*]
REJECTED --> [*]
EXPIRED --> [*]
You can reject from any state that has not ended yet. The diagram shows only the two most common paths.
Each state
| State | Meaning | What happens next |
|---|---|---|
INITIATED | The request is being processed. This state exists only briefly in memory; the registration is already stored as PENDING_VERIFICATION. | moves on right away |
PENDING_VERIFICATION | The email with the link has been sent. CIAS waits for the click. | click, admin confirms, expires, is replaced, discarded or rejected |
VERIFIED | The address is verified. | moves on right away to approval or to provisioning |
PENDING_APPROVAL | A platform administrator must agree. | approve, reject, expires, discard |
APPROVED | approved | moves on right away to provisioning |
PROVISIONING | CIAS enables the account, assigns the tenant, grants roles. | COMPLETED or FAILED |
COMPLETED | done. The person can sign in. | final state |
FAILED | Provisioning has failed. | an administrator repeats it (retry) or discards the registration |
REJECTED | rejected | final state |
EXPIRED | expired, replaced by a newer attempt, or discarded | final state |
Who triggers which transition
When: They click the link in the email.
POST /cias/registration/verify moves the registration from PENDING_VERIFICATION to VERIFIED. After that it continues without anyone doing anything: to approval if the flow requires one, otherwise straight to provisioning.
Result: See Verify the email.
When: Through the endpoints under /cias/admin/registrations/{id}/…
activate verifies the address by hand, approve approves, reject rejects, retry repeats a failed provisioning, discard discards the registration.
Result: See Approval by an administrator.
When: The same address registers again.
All open registrations of this address that still wait for the click or the approval move to EXPIRED. Only the newest link is valid.
Result: See The email is the account.
When: When the installation has turned on the cleanup.
A regular run sets registrations that wait too long to EXPIRED.
Result: See Clean up abandoned registrations.