cmind/users/v1/user_management_service.proto
Package: cmind.users.v1
Messages
PlatformUser
PlatformUser is a user known to the identity provider, with their tenant memberships. Admin-gated — computing memberships is a Keycloak round-trip per user.
| Field | Type | Number | Description |
|---|---|---|---|
userId | string | 1 | |
username | string | 2 | |
email | string | 3 | |
tenants | repeated UserTenantMembership | 4 | Tenants the user belongs to, each with their role. Empty for a user who holds no tenant membership. |
enabled | bool | 5 | |
systemAccount | bool | 6 | Internal service accounts are read-only in user management. |
UserTenantMembership
| Field | Type | Number | Description |
|---|---|---|---|
tenantId | string | 1 | |
tenantName | string | 2 | |
role | cmind.tenants.v1.TenantRole | 3 |
ListPlatformUsersRequest
| Field | Type | Number | Description |
|---|---|---|---|
page | cmind.common.v1.PageRequest | 1 | |
search | string | 2 | Optional: return only users whose username or email contains this substring (case-insensitive, Keycloak's native search). |
ListPlatformUsersResponse
| Field | Type | Number | Description |
|---|---|---|---|
users | repeated PlatformUser | 1 | |
page | cmind.common.v1.PageInfo | 2 |
CreatePlatformUserRequest
The password is always temporary. The user must replace it at first login. Creating a user does not send email or change an existing account.
| Field | Type | Number | Description |
|---|---|---|---|
username | string | 1 | |
password | string | 2 | |
email | optional string | 3 |
CreatePlatformUserResponse
| Field | Type | Number | Description |
|---|---|---|---|
userId | string | 1 |
GetPlatformUserRequest
| Field | Type | Number | Description |
|---|---|---|---|
userId | string | 1 |
GetPlatformUserResponse
| Field | Type | Number | Description |
|---|---|---|---|
user | PlatformUser | 1 |
UpdatePlatformUserRequest
| Field | Type | Number | Description |
|---|---|---|---|
userId | string | 1 | |
email | optional string | 2 | Omit to keep the current value; an empty email clears it. |
enabled | optional bool | 3 |
UpdatePlatformUserResponse
SetPlatformUserPasswordRequest
| Field | Type | Number | Description |
|---|---|---|---|
userId | string | 1 | |
password | string | 2 | Always temporary; the user must replace it at their next login. |
SetPlatformUserPasswordResponse
DeletePlatformUserRequest
| Field | Type | Number | Description |
|---|---|---|---|
userId | string | 1 |
DeletePlatformUserResponse
Services
UserManagementService
UserManagementService administers user accounts at platform scope. User self-service operations belong in a separate service in this package.
ListPlatformUsers
Lists every user in the identity provider realm, with their tenant memberships. Platform-admin operation.
Request: ListPlatformUsersRequest
Response: ListPlatformUsersResponse
CreatePlatformUser
Creates an enabled account with a temporary password. Tenant memberships are managed separately. Existing accounts are never modified.
Request: CreatePlatformUserRequest
Response: CreatePlatformUserResponse
GetPlatformUser
Request: GetPlatformUserRequest
Response: GetPlatformUserResponse
UpdatePlatformUser
Request: UpdatePlatformUserRequest
Response: UpdatePlatformUserResponse
SetPlatformUserPassword
Request: SetPlatformUserPasswordRequest
Response: SetPlatformUserPasswordResponse
DeletePlatformUser
Removes a user account. The caller and internal service accounts are protected.
Request: DeletePlatformUserRequest
Response: DeletePlatformUserResponse