CodamAIDocs
Subject area

Grant roles and permissions

The role catalog, the levels of a role, how modules register their roles, who may grant roles, time-limited grants, and how a role gets into the token.

Topics in this subject area

  1. 1.The role catalog

    What CIAS keeps for every role: key and client, owner module, scope, delegation, display group, retirement.

  2. 2.Realm role, client role, organization role

    The three levels at which a role is granted, where it ends up in the token, and who reads it.

  3. 3.Modules register their roles

    Every module declares its roles and attributes itself. How CIAS takes in the declaration, embedded as a bean or standalone via /cias/fetch, and what happens with a rejected declaration.

  4. 4.Reconciliation with Keycloak

    At startup and at the push of a button, CIAS brings roles, profile attributes and claim mappers in Keycloak up to date. Why Keycloak first and then the catalog, and why nothing is ever deleted but retired instead.

  5. 5.How a role gets from the code into the token

    The whole path: declaration in the module, catalog, creation in Keycloak, grant, claim in the token.

  6. 6.Grant a role

    Who may grant? The platform administrator always, everyone else only with delegation, within the ceiling and in the same tenant. The flow with all rejections.

  7. 7.Time-limited roles

    Grants with a start and an end: SCHEDULED, ACTIVE, EXPIRED, REVOKED, and how a timer adds and removes them in Keycloak.

  8. 8.Revoke a role

    What happens when you revoke a role, in which order, and when it reaches the token.

  9. 9.The platform's realm roles

    platform-admin, user, mail-template-admin, allowed-tenant-context-switch, allowed-user-context-switch, declaration-reader: what each one is for and who may grant it.

Search