Table of Contents

CzechIdM - extras

CzechIdM - extras contains various features, which are not suited to be in any other module. List of the currently supported features is below.

Currently supported CzechIdM version : 10.4.9

https://github.com/bcvsolutions/czechidm-extras

Table of compatible versions

Extras version Min dependency versions Max dependency versions Note
2.5.0 idm-core-10.3.3 UNKNOWN
2.6.0 idm-core-10.4.4 UNKNOWN
2.6.1 idm-core-10.4.8 UNKNOWN This version is needed for Automatic roles on tree nodes - import data from CSV
2.7.0 idm-core-10.4.9 UNKNOWN

Developing and releasing

How to develop a new feature in extras:

Rules for code review:

If your code does not meet the requirements mentioned above, it may be rejected.

Virtual system import LRT

Documentation is available here: Systems - Import of data from CSV

Automatic role definitions - Import of data from CSV LRT

Documentation is available here: Automatic role definitions - Import of data from CSV

Automatic role definitions - Import all rules LRT

Since module version 1.9.0. Documentation is available here: Automatic role definitions - Import all rules

Assign roles to contract EAV - Import of data from CSV LRT

Documentation is available here: Assign roles to contract EAV - Import of data from CSV

Roles - Import of data from CSV LRT

Documentation is available here: Roles - Import of data from CSV

Automatic roles - adding role by node in structure

Documentation is available here: Automatic roles - adding role by node in structure

Status task

Documentation is available here: Status task - How to prepare the task Information about content is here: status_task_content

SSO authenticate

Documentation is available here: sso_authentificate

Role force provisioning to particular system

The tutorial is available here: Provisioning - how to force provisioning for roles

Guarantees of roles can assign their roles to everybody

This feature enable that if you are guarantee at least for one role then you will see all users and you can assign/delete/edit roles for which you are guarantee. You can see all user's roles but you can't change the others for which you are not guarantee

For correct behavior you need to configure three new evaluators to userRole:

Other thing you need to do is to enable service ExtrasIdmConceptRoleRequestService. This service is by default turned off in extras module. Go to your project modul and create new service which will inherit from ExtrasIdmConceptRoleRequestService and add annotation Primary and Service.

Update IdmConceptRoleRequestDto is allowed everybody that will change only audited fields or systemState field (this is for update state of whole request after retry mechanism or approving virtual request).

Report Compare values in IdM with values in system

Report will compare value of attributes with connected system. Connected system does not need to be in read only. More information is available here: Report - Compare values in IdM to system

Notification about the end of identity's last contract

A notification about the end of identity's last contract will be sent to those who have a specified role assigned and optionally the manager of the user. A different notification can be sent before the contract ends and when it ends. More information is available here: Notification - the end of identity's last contract

Edit: full IdmIdentityDto was added for use in a template in 1.7.0

Edit: Support for technical identities added for use in version 1.9.0

Get titles before and after

Almost every project receive all titles in one string and IdM allow separates titles before and after. For this case was created in ExtrasUtils two methods getTitlesAfter and getTitlesBefore. And transformation scripts extrasGetTitlesBefore and extrasGetTitlesAfter, transformation scripts calls method from utils.

Dictionary with titles can be setup by configuration properties. Default values exists in BE

idm.sec.extras.configuration.titlesAfter=Ph.D.,Th.D.,CSc.,DrSc.,dr. h. c.,DiS.,MBA,LL.M.,FESC,MHA,FEBO,FESO,FEBU,FACC
idm.sec.extras.configuration.titlesBefore=Bc.,BcA.,Ing.,Ing. arch.,MUDr.,MVDr.,MgA.,Mgr.,JUDr.,PhDr.,RNDr.,PharmDr.,ThLic.,ThDr.,prof.,doc.,PaedDr.,Dr.,PhMr.,MDDr.

Import automatic roles on tree nodes

You can use this tool to create automatic roles which are assigned based on the position within the organization structure using a CSV file as a source. More information is available here: Automatic roles on tree nodes - import data from CSV

Groups synchronization workflow

Since module version 1.4.0 was exists better workflow for groups synchronization than in core. This workflow has same features as product. In product will be available same feature as this workflow but with configuration from GUI.

Documentation for configuration is available Systems - Groups synchronization workflow.

Workflow to disable contract on MISSING_ACCOUNT

Setting this workflow (extrasDisableMissingContract) as workflow for action in contract reconciliation will disable contract, when its being synchronized. It can be used for example, in situations when contracts are being deleted from source data after expiration and they keep being stuck in MISSING_ACCOUNT state.

Note: When using this workflow, please consider the possibility that the contracts may "reappear" in the source data. In such case, it would make sense to enable the contracts again, e.g. by mapping the attribute "state" and filling it by value null (= active contract).

Groups membership in multi domain (cross domain) AD environment

Since module version 1.8.0

Documentation is available Systems - Manage groups membership in multi domain (cross domain) AD environment

Evaluator (permissions) for identities that has relationship on defined organization unit

Since module version 1.9.0. Available only on LTS version!

Documentation is available there

Evaluator (permissions) for roles that is inside defined role catalogue

Since module version 1.9.0. Available only on LTS version!

Documentation is available there.

Import code list and it's items

Since module version 1.9.0 and 2.4.0

Documentation is available there

Evaluators (permissions) for Identities and Contracts which are both subordinate and have given projection

Since module version 2.4.0.

Documentation is available there.

Workflows for approval of role assignment

Since module version 2.3.0

Documentation is available there