domain

Auth

Identity and access bounded context. Owns the AUTH message contracts (application access grants, user invitations) and the cna-auth service.

Domain

Overview

Auth is the bounded context for identity and access across CNA applications: accounts, tokens, second factor, and which person may use which application. It owns the message contracts declared with static owner = 'AUTH' and the CNA AuthCNA AuthServicev1.0.0Authentication and identity provider for the CNA platform (accounts, tokens, OTP/2FA, per-application access grants). Co...SubscribesGrantApplicationAccess, RevokeApplicationAccess +2Ownercna-platformMapRepoView docs service that implements them.

Owning a contract is not the same as producing it. The AUTH contracts are mostly published by other applications and handled by cna-auth: CNA OneCNA OneServicev1.0.0Franchise operating system (franchises and employees, pricing, products and learning books, school operations). Publishe...PublishesGrantApplicationAccess, EmployeeCreated +6SubscribesInviteUser, FranchiseCreated +9Ownercna-platformMapRepoView docs asks for application access to be granted or revoked, and CNA NexusCNA NexusServicev1.0.0Franchise network back-office (franchises, economic groups, partners, contracts and amendments, document storage, AI doc...PublishesInviteUser, ContractActivationRequested +13SubscribesContractActivationRequested, AmendmentApplyRequested +4Ownercna-platformMapRepoView docs and CNA Placement TestCNA Placement TestServicev1.0.0English placement test application (candidates, tests, attempts, admin users). Publishes InviteUser and consumes nothing...PublishesInviteUserOwnercna-platformMapRepoView docs invite users. Read the message pages for the exact producers and consumers.

Contracts owned by this domain

Every message declared with static owner = 'AUTH', whichever application publishes or handles it.

Resources

Resources (3)

Browse resources in this group or search by name, type, or description.
NameVersionTypeDescription
Grant Application Access
v1.0.0commandAsks CNA Auth to give a person access to an application, provisioning the account and user when they are new. Published by cna-one when an invited user is mirrored into a person; handled by cna-auth.
Revoke Application Access
v1.0.0commandAsks CNA Auth to take a person's access to an application away and drop the sessions it holds. Handled by cna-auth; no application publishes it today.
Invite User
v1.0.0commandInvites a person into the CNA platform. Published by cna-nexus and cna-placement when a user is created or re-invited; handled by cna-one, which creates the person and employee and then requests application access from cna-auth.

Messages flowing through this domain’s services

Messages for this domain

Sends messages (0)

Quickly find the message you need by searching for the name, type, or summary.
NameVersionTypeSummaryChannels
No messages found

Receives messages (4)

Quickly find the message you need by searching for the name, type, or summary.
NameVersionTypeSummaryChannels
Grant Application Access
v1.0.0commandAsks CNA Auth to give a person access to an application, provisioning the account and user when they are new. Published by cna-one when an invited user is mirrored into a person; handled by cna-auth.
-
Revoke Application Access
v1.0.0commandAsks CNA Auth to take a person's access to an application away and drop the sessions it holds. Handled by cna-auth; no application publishes it today.
-
Employee Created
v1.0.0eventAn employee was created in CNA One, with the person it points at. Consumed by cna-auth to provision the account and the login user.
-
Employee Updated
v1.0.0eventAn employee or the person it points at changed in CNA One. Consumed by cna-auth to update the account and the user, including blocking or unblocking the login.
-

Entities

Outside the model

The Subscription Kafka topic used by cna-auth to fan out GraphQL subscriptions between pods is infrastructure, not a contract. It is intentionally not documented as a channel or message. See “Topics outside the model” in docs/modelling/02-mapping.md.