CodamAIDocs
Topicdone

A person leaves the company

Suspend, revoke roles, close the account: what takes effect immediately, what only when the token expires, and what happens to her data and the audit.

Variants
revoke rolessuspend the accountclose the accountit has to stop nowthe person comes back

What this is about

Ben works for the customer nordbau and leaves on 30 September. His access should end, his work should stay. There are three handles for this, and they do different things:

HandleWhoTakes away
revoke a rolea tenant administrator or a platform administratora single permission
suspend the accounta platform administratorall access, reversible
close the accounta platform administratorall access, final

The process on 30 September

From the farewell to the closed account
  1. 1
    Admin→CIAS
    lists Ben's role assignments: GET /cias/admin/role-assignments?userId=…
  2. 2
    Admin→CIAS
    revokes each one of them: POST /cias/admin/role-assignments/{id}/revoke with a reason
  3. 3
    CIAS→Keycloak
    removes the role, and only then is the assignment REVOKED
    What takes access away comes first. If the second step fails, Ben still does not hold the role.
  4. 4
    Admin→CIAS
    suspends the account: POST /cias/admin/users/{id}/suspend with a reason
  5. 5
    CIAS→Keycloak
    disables the account, and only then does the record become SUSPENDED
  6. 6
    Admin→CIAS
    later, when nothing is open any more: POST /cias/admin/users/{id}/close with a reason
    Result: Record CLOSED, account disabled in Keycloak. Nothing is deleted, and there is no way back out of CLOSED.

Why in this order? Suspending alone leaves every role in place: if the account is ever reactivated, Ben has exactly the rights he had before. And closing is final, so it comes last, once it is certain that nobody needs to do anything with the account any more.

What takes effect when

gantt
    title Revoked and suspended at 00:00 (access token 5 minutes)
    dateFormat mm:ss
    axisFormat %M:%S
    section Keycloak
    role removed, account disabled :milestone, k1, 00:00, 0s
    section Login
    no login, no refresh any more :done, a1, 00:00, 5m
    section Old token
    role still in the token, requests run :crit, t1, 00:00, 3m
    section Afterwards
    token expired, no new one :active, n1, 03:00, 2m
What you changeEffect on new tokensEffect on the token the person already holds
role revokedimmediately, the role is missing from the next tokenonly with the next token, that is at the latest when the access token expires
time-limited assignment expiresafter the next run of the timer, by default every 5 minutesthen as above
attribute value per tenant revoked–at most 30 seconds, because that value is not in the token
account suspended or closedimmediately: Keycloak issues no token for a disabled account, not even on a refreshnot at all, it expires normally
the whole tenant suspended–at most 30 seconds, after which every request is refused at the tenant gate

Why this is so is explained under Why revoking permissions takes effect with a delay: on every request CIAS only checks the signature and the expiry of the token and does not ask Keycloak whether the roles still hold.

Which handle for which case

What do you want to achieve?
OccasionHandle and effect
Ben changes department and no longer needs a permissionrevoke the role. Takes effect with the next token
Ben is on parental leave and will come backsuspend the account. Reactivate it later, the rights are back
Ben leaves the companyrevoke the roles, suspend the account, later close it
Suspected misuse, it has to stop nowsuspend the account. No new token at once; you wait out the running one
The whole customer stopssuspend the tenant, see A customer cancels

What happens to the person’s data

After closing
Stays
everywhere
  • the user record in CIAS, with status CLOSED
  • the account in Keycloak, disabled, including membership in the organization and in groups
  • role assignments nobody revoked
  • every row in CDMS Ben created or changed
  • the history: every revision with name, IP address and browser
  • the CIAS audit: Revoked, Suspended, Closed, each with its reason
Goes
only the access
  • new login: impossible
  • refreshing the token: fails
  • every request, as soon as the last token has expired

Nothing is deleted, and there is no endpoint for it either: neither for users nor for tenants. The reason lies in the data itself. In CDMS rows hang on the person, and the history names her; a deleted account would leave those references pointing nowhere, and later an auditor could no longer say who did what.

User models are models in which every person only sees her own rows. Ben’s rows there stay assigned to him and are invisible to everybody else, because the owner filter works with your own id. Whoever has to look at them once more needs a user switch. It only succeeds as long as CIAS still finds Ben as a person, he still belongs to the tenant nordbau, through the organization or his attributes tenant or allowedTenants, and a valid consent from Ben exists. Otherwise CIAS answers with 403. Ben cannot give a new consent after he has left. Whoever wants to hand them to another person creates them there anew.

What the audit records

HandleEntryContains
role revokedAuthorizationEvent.Revokedassignment, person, role, tenant, reason
time-limited role expiredAuthorizationEvent.Expiredassignment, person, role, tenant
account suspendedUserEvent.Suspendeduser id, reason
account closedUserEvent.Closeduser id, reason

The reason is mandatory for all three. It is not stored on the record but in the event and therefore in the audit. Who acted is added by the audit from the token of the request. No entry is created for a group membership somebody ends, or for roles that exist only in the Keycloak console. See Which events are logged.

Traps

Next

Sources in the code and the knowledge base
  • CIAS/cias-user – UserAdminController (suspend, reactivate, close; no DELETE), UserService (suspend, close: disable the account first, then the record), User (suspend, close), UserStatus, UserEvent (Suspended, Closed)
  • CIAS/cias-iam-keycloak – KeycloakIdentityAdapter (enable, disable)
  • CIAS/cias-authorization – RoleAssignmentService.revoke (Keycloak first, then REVOKED), RoleAdminController (POST /cias/admin/role-assignments/{id}/revoke), AuthorizationEvent.Revoked, RoleSynchronizationScheduler (PT5M)
  • CIAS/cias-authentication – JwtDecoderUtil (signature and expiry only), TenantGateProperties (ttl 30s), AttributeLookupProperties (ttl 30s)
  • CIAS/cias-audit – DomainEventAuditListener, AuditEntry
  • CDMS/cdms-persistence-database – AuditRevisionListener, AuditHistoryReader (no deletion of revisions); CDMS/cdms-system-layer – AbstractLayer (owner filter via getUserId)
Search