Employee Created
An employee was created in CNA One, with the person it points at. Consumed by cna-auth to provision the account and the login user.
Overview
Fact: an employee now exists in CNA One. The payload is a snapshot of the employee and of the person it points at, enough for CNA AuthCNA AuthServicev1.0.0Authentication and identity provider for the CNA platform (accounts, tokens, OTP/2FA, per-application access grants). Co...SubscribesGrantApplicationAccess, RevokeApplicationAccess +2Ownercna-platformMapRepoView docs to provision identity without calling back.
When it is published. CNA OneCNA OneServicev1.0.0Franchise operating system (franchises and employees, pricing, products and learning books, school operations). Publishe...PublishesGrantApplicationAccess, EmployeeCreated +6SubscribesInviteUser, FranchiseCreated +9Ownercna-platformMapRepoView docs publishes it after the write completes, not inside afterCommit:
createEmployee, when a franchise manager creates an employee: after e-mail validation,findOrCreatePersonand the transaction that saves the employee and its inactive staff link.syncFranchisePartners, while handling aFranchiseCreatedfrom Nexus: one message per partner that did not yet exist as an employee (partners that already existed getEmployeeUpdatedinstead).
It is deliberately not published for the employee created by InviteUser: that flow provisions the login through GrantApplicationAccess instead.
What the consumer does. cna-auth (accountConsumer, handler syncEmployeeEvent, shared with EmployeeUpdated):
- Rejects the message when
person.typeis notCPF(logged, reported to Sentry, dropped). - Finds or creates the
Accountbyperson.document, settingname(name and surname joined),employeeId(the payloadid) andpersonId. A new account gets an OTP authentication method when it has none. - Finds the
Userin that account byemployeeId, falling back toemail; creates it when missing and sends the first-access e-mail for applicationcna-one. Existing users are updated:name,email,employeeId, andblockedAtset whenisActiveis false, cleared when true.
Failures are logged and reported to Sentry, never rethrown; the offset is committed either way.
Kafka
Topic (aggregateRoot) | Employee |
Message key (routingKey) | payload.id |
| Contract owner | ONE |
metadata.event | EmployeeCreated |
| Consumer group | auth-user-events |
Payload schema
Source of truth
export type EmployeePayload = { id: string; email: string; isActive: boolean; person: { id: string; name: string; surname: string; birthdate?: string | null; document: string; type: string; email?: string | null; phone?: string | null; };};
class EmployeeCreated extends Event<EmployeePayload> { public static owner = "ONE"; public static aggregateRoot = "Employee"; public static routingKey = "id";}Known drift
- cna-auth
api/app/events/one/employee/EmployeeCreated.tsnames the typeEmployeeEventPayload, extracts the nested object asEmployeePersonData, and typesbirthdateasDate | null. On the wire it is theYYYY-MM-DDstring TypeORM returns for adatecolumn. - cna-auth’s handler passes the literal
cna-oneas the application of the first-access e-mail although its docstring says it usesmetadata.owner.
Custom properties
| Property | Value |
|---|---|
| Contract Ownerx-contract-owner | ONE |
| Kafka Topicx-kafka-topic | Employee |
| Message Keyx-message-key | id |
| Sourcex-source | cna-one api/app/events/one/employee/EmployeeCreated.ts |
| Driftx-drift | cna-auth's copy names the type EmployeeEventPayload and types person.birthdate as Date, while the wire carries a YYYY-MM-DD string. |
Employee id (UUID) in cna-one franchise.employees. Kafka message key; stored as employeeId on the cna-auth account and user.
Employee work e-mail, unique across employees. Becomes the cna-auth user e-mail.
Whether the employee is active. cna-auth sets blockedAt on the user when false and clears it when true.
Snapshot of the Person the employee points at (cna-one common.persons).