Revoke Application Access
Asks CNA Auth to take a person's access to an application away and drop the sessions it holds. Handled by cna-auth; no application publishes it today.
Overview
Intent to remove a person’s access to an application. It is the counterpart of Grant Application AccessGrant Application AccessCommandv1.0.0Asks CNA Auth to give a person access to an application, provisioning the account and user when they are new. Published ...Ownercna-platformSchemaMapView docs and carries the same payload.
Who publishes it. Nobody today. CNA OneCNA OneServicev1.0.0Franchise operating system (franchises and employees, pricing, products and learning books, school operations). Publishe...PublishesGrantApplicationAccess, EmployeeCreated +6SubscribesInviteUser, FranchiseCreated +9Ownercna-platformMapRepoView docs defines revokeApplicationAccessProducer, but no code path calls it. The command is documented because CNA AuthCNA AuthServicev1.0.0Authentication and identity provider for the CNA platform (accounts, tokens, OTP/2FA, per-application access grants). Co...SubscribesGrantApplicationAccess, RevokeApplicationAccess +2Ownercna-platformMapRepoView docs handles it and because the producer is ready to be wired.
What the consumer does. cna-auth (accountConsumer, handler revokeApplicationAccess):
- Looks the application up by
payload.application. Unknown application: logged and dropped. - Checks
payload.originagainst the application’sallowedOrigins. Origin not allowed: logged and dropped. - Looks the
Accountup bydocument. A revoke never provisions identity: unknown account is logged and dropped. - Removes the
ApplicationGrantand kills the sessions the account had on that application. An inactive application keeps its grants, which still have to be revocable.
Every failure is a log and a return; the offset is committed either way.
Kafka
Topic (aggregateRoot) | Application |
Message key (routingKey) | payload.document |
| Contract owner | AUTH |
metadata.event | RevokeApplicationAccess |
| Consumer group | auth-user-events |
Payload schema
Same payload type as GrantApplicationAccess (ApplicationAccessPayload).
Source of truth
import { ApplicationAccessPayload } from "events/auth/application/GrantApplicationAccess";
class RevokeApplicationAccess extends Event<ApplicationAccessPayload> { public static owner = "AUTH"; public static aggregateRoot = "Application"; public static routingKey = "document";}Known drift
- No producer. cna-one
api/app/domains/franchise/employee/producers/revokeApplicationAccessProducer.tsexists but is never called (only its unit tests reference it). Nothing publishes this command. - File name. cna-auth stores the class in
RevokeApplication.ts; the convention inapi/docs/EVENTS.mdis file name = class name. cna-one names it correctly.
Custom properties
| Property | Value |
|---|---|
| Contract Ownerx-contract-owner | AUTH |
| Kafka Topicx-kafka-topic | Application |
| Message Keyx-message-key | document |
| Sourcex-source | cna-auth api/app/events/auth/application/RevokeApplication.ts |
| Driftx-drift | cna-one has a producer (revokeApplicationAccessProducer.ts) that nothing calls, so no application publishes this command today. In cna-auth the class lives in RevokeApplication.ts, a file name that differs from the class name. |
Id of the person in the publishing application (cna-one Person.id). Stored on the account as its person id.
Full name of the person (name and surname joined).
E-mail the login is provisioned on. Taken from the invite, not from what the publisher stores.
Person document (CPF). Kafka message key and the field both systems correlate the person by.
CNA One employee id the access is keyed by. Stored on the account.
Identifier of the application in cna-auth (applications.identifier), e.g. cna-one.
System requesting the access: ONE, NEXUS or PLACEMENT. Must be one of the application's allowed origins; compared uppercase.