CNA Auth
Authentication and identity provider for the CNA platform (accounts, tokens, OTP/2FA, per-application access grants). Consumes the Application and Employee topics and publishes nothing.
Overview
cna-auth is the identity provider behind every CNA application. On the Kafka bus it is a pure consumer: it keeps accounts in sync with employees created and updated in CNA OneCNA OneServicev1.0.0Franchise operating system (franchises and employees, pricing, products and learning books, school operations). Publishe...PublishesGrantApplicationAccess, EmployeeCreated +6SubscribesInviteUser, FranchiseCreated +9Ownercna-platformMapRepoView docs, and grants or revokes application access when asked to. It exposes a GraphQL API to the front ends and does not publish any message.
Consumers subscribe by topic (aggregateRoot) and dispatch on metadata.event. There is no schema registry: the TypeScript payload type in the event class is the contract.
Messages
Messages for this service
Sends messages (0)
Quickly find the message you need by searching for the name, type, or summary.| Name | Version | Type | Summary | Channels |
|---|---|---|---|---|
| No messages found | ||||
Receives messages (4)
Quickly find the message you need by searching for the name, type, or summary.Kafka consumers
Consumers run as a separate process from the API, started by api/scripts/events/consume.ts.
| Consumer group | Topics | Handler |
|---|---|---|
auth-user-events | Employee, Application | api/app/domains/external/consumers/accountConsumer.ts |
Custom properties
| Property | Value |
|---|---|
| Runtimex-runtime | Express 5 + GraphQL Yoga + TypeORM/Postgres + kafkajs |
| Events Pathx-events-path | api/app/events/<owner>/<aggregateRoot>/<EventName>.ts |
| Driftx-drift | Ships an unused copy of InviteUser.ts (owner AUTH) that is never produced nor consumed here. |