CodamAIDocs
Topicdone

Who decides what?

Keycloak logs you in, CIAS gives meaning and writes permissions, the token carries them, CDMS enforces them. Which question each part answers.

Variants
Keycloak: login and tokenCIAS: meaning, grants, filter chain, tenant gateToken: carries the permissionsCDMS: enforcement on the dataHook: the project's own business logic

What this is about

Several parts take part in every request, and each answers different questions. If you know which part is responsible for what, you look for a bug in the right place and put a rule where it belongs.

The chain

flowchart LR
    K["Keycloak<br/>logs in,<br/>issues token"] --> T(["Token<br/>carries tenant,<br/>roles, attributes"])
    C["CIAS<br/>manages tenants, roles,<br/>groups, attributes"] -- "writes permissions" --> K
    T --> F["CIAS filter chain<br/>checks token and tenant"]
    F --> D["CDMS<br/>role → operation,<br/>attribute → rows"]

Read it like this: CIAS writes roles, groups and attributes to Keycloak. Keycloak puts them into the token at login. On every request the CIAS filter chain checks the token and the tenant. After that CDMS decides what the roles allow on the data.

The filter chain is CIAS code, but it runs in front of CDMS in the same program, even when CIAS itself runs as a separate service. See Embedded and standalone compared.

The four parts

Who does what?
Keycloak
login
  • shows the login page
  • checks password and MFA
  • holds the session
  • issues and signs tokens
CIAS
meaning and grants
  • manages users, tenants, roles, groups, attributes
  • decides who may grant a permission
  • is the only one that writes permissions into Keycloak
  • checks token and tenant on every request
Token
carrier
  • carries person, tenant, roles, attributes
  • is valid until it expires
  • its roles are not re-checked with Keycloak on a request
CDMS
enforcement
  • checks whether a role allows an operation on a model
  • filters rows by attributes and owner
  • picks the tenant's database
  • calls the project's hooks

What a role allows in CDMS is defined in the model. You set it in the hub, and the build generates the code from it. CIAS deliberately does not know this table. See The two permission matrices.

Which question each part answers

Logging in

QuestionResponsibleMore
Is the password right, is MFA satisfied?KeycloakLogging in with the browser
Who issues and signs the token?KeycloakLogging in with the browser
Is the token genuine and not expired?CIAS filter chain, without asking KeycloakWhat happens to the token on every request
Does the account exist, is it enabled?Keycloak, CIAS aligns with itCIAS as the bridge to the identity provider
Who is the person in business terms, which tenant do they belong to?CIASThe user record

Tenant

QuestionResponsibleMore
Which tenants exist, and what state are they in?CIASThe life of a tenant
Which tenant does this request run in?CIAS filter chain, from the tokenDetermining the tenant of a request
Is this tenant currently being served?tenant gate in the filter chain, CIAS gives the answerAdmitting the tenant (tenant gate)
May the person switch to another tenant by header?CIAS filter chain checks the realm role, CDMS checks the target against the allowed tenantsTenant switch by header
Which database does the access go to?CDMS, from model level and tenantWhich database? The persistence target

Permissions

QuestionResponsibleMore
Which roles and attributes exist?the module declares them, CIAS keeps the catalogModules declare their roles
Who may grant a role?CIAS: delegation and ceilingGranting a role
Who writes roles, groups and attributes into Keycloak?only CIAS, through its adapterCIAS as the bridge to the identity provider
Which roles apply to exactly this request?CIAS filter chain builds the effective roles from the tokenEffective roles: global or in the tenant
Which value does an attribute have in this tenant?token for USER, CIAS for USER_IN_TENANTOne value per person or per tenant
When does a revoked permission take effect?the token: with the next new tokenWhy revoking a permission takes effect with a delay

Data

QuestionResponsibleMore
Which role does an operation on a model require?the model in the hub, and the code generated from itHow role names are built
May this role read, create, change, delete the model?CDMS, model roleModel roles
May the person go through this field into another model?CDMS, role of the target model or field rolePermissions on relations (field roles)
Which rows does the person see?CDMS: owner filter, attribute filter, custom filtersThe three levels at a glance
What else should happen in business terms when saving?the hook of your projectHooks: kinds and points in time

Tracing back

QuestionResponsibleMore
Who gave whom which role and when, who suspended the tenant?CIAS, auditOne trail for everything
What did an object look like earlier, and who changed it?CDMS, historyReading the history

One request, station by station

The same split shows up along the path of a read request. Each station shows which part decides:

POST /hr/employee/query with token
  1. Filter chain
    Check token
    Is Keycloak's signature genuine, is the token not expired?
    ↳ no 401
  2. Filter chain
    Resolve tenant
    Which tenant is in the token, is it unambiguous?
    ↳ no 403 cias.authentication.tenant-unresolved
  3. CIAS
    Tenant gate
    Is this tenant being served?
    ↳ no 403 cias.authentication.tenant-not-served
  4. Filter chain
    Effective roles and attributes
    Which roles and attribute values apply in this tenant?
  5. CDMS
    Model role
    Does one of the roles allow reading employee?
    ↳ no 403 missing-permission|<role>
  6. CDMS
    Row filter
    Which rows pass the owner filter, attribute filter and custom filters?
    ↳ no row is missing from the list
  7. Hook
    Hook
    after hook with operation READ, before the response
  8. The allowed rows come back

Keycloak itself appears only once on this path: the filter chain exchanges the token at Keycloak for one for the CIAS client, or takes it from its cache. It does not ask again whether password and roles are right.

Pitfalls

Next

Sources in the code and the knowledge base
  • CIAS/cias-authentication – JwtSessionFilter, TokenParser, EffectiveRoles, EffectiveAttributes, TenantGate, ContextSwitch
  • CIAS/cias-authorization – RoleAssignmentService (delegation, ceiling), role catalog, groups
  • CIAS/cias-iam-keycloak – adapter, the only write path to Keycloak
  • CIAS/cias-audit – DomainEventAuditListener
  • commons – session/RequestContextHolder, interfaces/HookServiceInterface
  • CDMS/cdms-authorization – AbstractAuthorizationLayer (effectiveUserRoles), AbstractAttributeFilter
  • CDMS/cdms-system-layer – AbstractLayer (filters), HookManagementSystem
  • CDMS/cdms-persistence-database – persistence target, auditing/AuditRevisionEntity
  • Finished pages cias/grundlagen/bruecke, cias/grundlagen/zwei-matrizen, cdms/sicherheit/drei-ebenen
Search