service

CNA Auth

Authentication and identity provider for the CNA platform (accounts, tokens, OTP/2FA, per-application access grants). Consumes the Application and Employee topics and publishes nothing.

Service

Overview

cna-auth is the identity provider behind every CNA application. On the Kafka bus it is a pure consumer: it keeps accounts in sync with employees created and updated in CNA OneCNA OneServicev1.0.0Franchise operating system (franchises and employees, pricing, products and learning books, school operations). Publishe...PublishesGrantApplicationAccess, EmployeeCreated +6SubscribesInviteUser, FranchiseCreated +9Ownercna-platformMapRepoView docs, and grants or revokes application access when asked to. It exposes a GraphQL API to the front ends and does not publish any message.

Consumers subscribe by topic (aggregateRoot) and dispatch on metadata.event. There is no schema registry: the TypeScript payload type in the event class is the contract.

Messages

Messages for this service

Sends messages (0)

Quickly find the message you need by searching for the name, type, or summary.
NameVersionTypeSummaryChannels
No messages found

Receives messages (4)

Quickly find the message you need by searching for the name, type, or summary.
NameVersionTypeSummaryChannels
Grant Application Access
v1.0.0commandAsks CNA Auth to give a person access to an application, provisioning the account and user when they are new. Published by cna-one when an invited user is mirrored into a person; handled by cna-auth.
-
Revoke Application Access
v1.0.0commandAsks CNA Auth to take a person's access to an application away and drop the sessions it holds. Handled by cna-auth; no application publishes it today.
-
Employee Created
v1.0.0eventAn employee was created in CNA One, with the person it points at. Consumed by cna-auth to provision the account and the login user.
-
Employee Updated
v1.0.0eventAn employee or the person it points at changed in CNA One. Consumed by cna-auth to update the account and the user, including blocking or unblocking the login.
-

Kafka consumers

Consumers run as a separate process from the API, started by api/scripts/events/consume.ts.

Consumer groupTopicsHandler
auth-user-eventsEmployee, Applicationapi/app/domains/external/consumers/accountConsumer.ts

Custom properties

PropertyValue
Runtimex-runtimeExpress 5 + GraphQL Yoga + TypeORM/Postgres + kafkajs
Events Pathx-events-pathapi/app/events/<owner>/<aggregateRoot>/<EventName>.ts
Driftx-driftShips an unused copy of InviteUser.ts (owner AUTH) that is never produced nor consumed here.