command

Revoke Application Access

Asks CNA Auth to take a person's access to an application away and drop the sessions it holds. Handled by cna-auth; no application publishes it today.

Command Topic: ApplicationKey: documentNo producer

Overview

Intent to remove a person’s access to an application. It is the counterpart of Grant Application AccessGrant Application AccessCommandv1.0.0Asks CNA Auth to give a person access to an application, provisioning the account and user when they are new. Published ...Ownercna-platformSchemaMapView docs and carries the same payload.

Who publishes it. Nobody today. CNA OneCNA OneServicev1.0.0Franchise operating system (franchises and employees, pricing, products and learning books, school operations). Publishe...PublishesGrantApplicationAccess, EmployeeCreated +6SubscribesInviteUser, FranchiseCreated +9Ownercna-platformMapRepoView docs defines revokeApplicationAccessProducer, but no code path calls it. The command is documented because CNA AuthCNA AuthServicev1.0.0Authentication and identity provider for the CNA platform (accounts, tokens, OTP/2FA, per-application access grants). Co...SubscribesGrantApplicationAccess, RevokeApplicationAccess +2Ownercna-platformMapRepoView docs handles it and because the producer is ready to be wired.

What the consumer does. cna-auth (accountConsumer, handler revokeApplicationAccess):

  1. Looks the application up by payload.application. Unknown application: logged and dropped.
  2. Checks payload.origin against the application’s allowedOrigins. Origin not allowed: logged and dropped.
  3. Looks the Account up by document. A revoke never provisions identity: unknown account is logged and dropped.
  4. Removes the ApplicationGrant and kills the sessions the account had on that application. An inactive application keeps its grants, which still have to be revocable.

Every failure is a log and a return; the offset is committed either way.

Kafka

Topic (aggregateRoot)Application
Message key (routingKey)payload.document
Contract ownerAUTH
metadata.eventRevokeApplicationAccess
Consumer groupauth-user-events

Payload schema

Same payload type as GrantApplicationAccess (ApplicationAccessPayload).

Source of truth

import { ApplicationAccessPayload } from "events/auth/application/GrantApplicationAccess";
class RevokeApplicationAccess extends Event<ApplicationAccessPayload> {
public static owner = "AUTH";
public static aggregateRoot = "Application";
public static routingKey = "document";
}

Known drift

  • No producer. cna-one api/app/domains/franchise/employee/producers/revokeApplicationAccessProducer.ts exists but is never called (only its unit tests reference it). Nothing publishes this command.
  • File name. cna-auth stores the class in RevokeApplication.ts; the convention in api/docs/EVENTS.md is file name = class name. cna-one names it correctly.

Custom properties

PropertyValue
Contract Ownerx-contract-ownerAUTH
Kafka Topicx-kafka-topicApplication
Message Keyx-message-keydocument
Sourcex-sourcecna-auth api/app/events/auth/application/RevokeApplication.ts
Driftx-driftcna-one has a producer (revokeApplicationAccessProducer.ts) that nothing calls, so no application publishes this command today. In cna-auth the class lives in RevokeApplication.ts, a file name that differs from the class name.
7 properties
idstring
required

Id of the person in the publishing application (cna-one Person.id). Stored on the account as its person id.

namestring
required

Full name of the person (name and surname joined).

emailstring
required

E-mail the login is provisioned on. Taken from the invite, not from what the publisher stores.

documentstring
required

Person document (CPF). Kafka message key and the field both systems correlate the person by.

employeeIdstring
required

CNA One employee id the access is keyed by. Stored on the account.

applicationstring
required

Identifier of the application in cna-auth (applications.identifier), e.g. cna-one.

originstring
required

System requesting the access: ONE, NEXUS or PLACEMENT. Must be one of the application's allowed origins; compared uppercase.