lahirujayathilake opened a new pull request, #475:
URL: https://github.com/apache/airavata-custos/pull/475

   The upcoming ACCESS-AMIE connector integration needs core models for 
external identity bindings, certificate identities, lifecycle status, and user 
merges. This PR adds those records and their REST endpoints so the connector 
can read and write against them directly.
   
   Addresses Issue #466
   
   ## What's added
   
     - **External identities.** - A user can be linked to their identifier in 
an external system (ACCESS, NAIRR, CILogon, etc.). Each binding stores the 
source, the source's native ID, optional OIDC subject, and a JSON metadata blob 
for source-specific attributes. A user can hold multiple external identities.
     - **User DNs.** - X.509 distinguished names (mTLS client cert subjects, 
grid certificates) can be bound to a user as append only credentials. DNs are 
globally unique across the system.
     - **User merges.** - When two records turn out to be the same person, one 
can be consolidated into the other. Identity-forward state (external 
identities, DNs, cluster accounts, project PI assignments, allocation 
memberships) moves to the surviving user whereas historical truth (who made 
which change request, who consumed which usage) stays with the original user. 
The retiring user is flipped to a merged state and the consolidation is 
recorded in an audit table.
     - **Lifecycle status on users, projects, and cluster users.** - Each 
entity now carries a status field so we can mark them active, inactive, 
suspended, or merged without deleting them. Status flips are exposed as 
dedicated REST endpoints.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to