Grant roles and permissions
The role catalog, the levels of a role, how modules register their roles, who may grant roles, time-limited grants, and how a role gets into the token.
Topics in this subject area
- 1.The role catalog
What CIAS keeps for every role: key and client, owner module, scope, delegation, display group, retirement.
- 2.Realm role, client role, organization role
The three levels at which a role is granted, where it ends up in the token, and who reads it.
- 3.Modules register their roles
Every module declares its roles and attributes itself. How CIAS takes in the declaration, embedded as a bean or standalone via
/cias/fetch, and what happens with a rejected declaration. - 4.Reconciliation with Keycloak
At startup and at the push of a button, CIAS brings roles, profile attributes and claim mappers in Keycloak up to date. Why Keycloak first and then the catalog, and why nothing is ever deleted but retired instead.
- 5.How a role gets from the code into the token
The whole path: declaration in the module, catalog, creation in Keycloak, grant, claim in the token.
- 6.Grant a role
Who may grant? The platform administrator always, everyone else only with delegation, within the ceiling and in the same tenant. The flow with all rejections.
- 7.Time-limited roles
Grants with a start and an end: SCHEDULED, ACTIVE, EXPIRED, REVOKED, and how a timer adds and removes them in Keycloak.
- 8.Revoke a role
What happens when you revoke a role, in which order, and when it reaches the token.
- 9.The platform's realm roles
platform-admin, user, mail-template-admin, allowed-tenant-context-switch, allowed-user-context-switch, declaration-reader: what each one is for and who may grant it.