lahirujayathilake opened a new pull request, #475:
URL: https://github.com/apache/airavata-custos/pull/475
The upcoming ACCESS-AMIE connector integration needs core models for
external identity bindings, certificate identities, lifecycle status, and user
merges. This PR adds those records and their REST endpoints so the connector
can read and write against them directly.
Addresses Issue #466
## What's added
- **External identities.** - A user can be linked to their identifier in
an external system (ACCESS, NAIRR, CILogon, etc.). Each binding stores the
source, the source's native ID, optional OIDC subject, and a JSON metadata blob
for source-specific attributes. A user can hold multiple external identities.
- **User DNs.** - X.509 distinguished names (mTLS client cert subjects,
grid certificates) can be bound to a user as append only credentials. DNs are
globally unique across the system.
- **User merges.** - When two records turn out to be the same person, one
can be consolidated into the other. Identity-forward state (external
identities, DNs, cluster accounts, project PI assignments, allocation
memberships) moves to the surviving user whereas historical truth (who made
which change request, who consumed which usage) stays with the original user.
The retiring user is flipped to a merged state and the consolidation is
recorded in an audit table.
- **Lifecycle status on users, projects, and cluster users.** - Each
entity now carries a status field so we can mark them active, inactive,
suspended, or merged without deleting them. Status flips are exposed as
dedicated REST endpoints.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]