GSSO — Functional and Non-Functional Requirements
Acest conținut nu este încă disponibil în limba selectată.
| Document code | SPEC-GSSO-2026 / Report 02 |
| Version | 0.1-draft (EN source, governing) |
| Date | 2026-10-05 |
| Status | Draft |
| Companion reports | 00 RFP · 01 ADR · 03 Consumers & contract · 04 Technical documentation · 05 Roadmap |
This report is the single source of truth for GSSO requirements. Report 00 only summarises them.
Revision history
Section titled “Revision history”| Version | Date | Changes |
|---|---|---|
| 0.1-draft | 2026-10-05 | Initial matrix: GSSO-FR-001..116, 44 GSSO-NFR-, traceability to CAP-GSSO-01..07, CU-, NFRQ |
Columns
Section titled “Columns”- Pri:
[M]: mandatory for the MVP or GA.[REC]: recommended; never blocks a gate.[OPT]: optional or later.
- Source:
CAP-GSSO-nn: capability requested by a consumer (CRM report 03 §4.1 and the gDocFlow, gTenders, gFlow and gInsight packages).CU-*: universal gStack requirement.NFRQnn: caiet-de-sarcini code.DES: required by the designGSSO.dc.html.NEW: found during platform analysis.- A consumer tag (
crm,interdictii,glog…) marks a need derived from that app (report 03).
- Component:
kc: Keycloak extensions, themes, realm baselines.server: thegssomicroservice.gateway:gsso-gateway.web:gsso-web.starter:gsso-spring-boot-starter.ng:@gstack/gsso-angular.ops: compose, Helm, runbooks.
- Phase (report 05):
S0: Foundation.S1: Console & catalog MVP.S2: Governance (grants, events, policies).S3: Integration kit & pilot.S4: Migration of existing apps.S5: Extensions.
Summary
Section titled “Summary”| Group | IDs | [M] | [REC] | [OPT] |
|---|---|---|---|---|
| FR-RLM Realms and tenants | 001..010 | 7 | 2 | 1 |
| FR-CAT Service catalog | 011..022 | 10 | 2 | 0 |
| FR-USR Users and sessions | 023..036 | 11 | 3 | 0 |
| FR-GRT Roles and grants | 037..052 | 13 | 2 | 1 |
| FR-ORG Organisational units | 053..056 | 3 | 1 | 0 |
| FR-AUT Authentication and federation | 057..070 | 9 | 3 | 2 |
| FR-SYN Reconciliation | 071..080 | 9 | 1 | 0 |
| FR-EVT Events and audit | 081..090 | 9 | 1 | 0 |
| FR-RPT Dashboard and reports | 091..096 | 4 | 2 | 0 |
| FR-API App API and integration kit | 097..108 | 10 | 2 | 0 |
| FR-UI Console | 109..116 | 8 | 0 | 0 |
| Functional total | 116 | 93 | 19 | 4 |
| NFR (PERF 5, CAP 4, AVL 6, SEC 10, TEN 3, OBS 4, OPS 5, CMP 4, DATA 3) | 44 |
I. Functional requirements
Section titled “I. Functional requirements”1. Realms and tenants — FR-RLM
Section titled “1. Realms and tenants — FR-RLM”| ID | Requirement | Pri | Source | Component | Phase |
|---|---|---|---|---|---|
| GSSO-FR-001 | Realm registry: a GSSO_ADMIN registers a realm with name, display name, type (STAFF, CETATEAN, TENANT, SERVICE), owner, drift policy and status; the realm is created in Keycloak by the reconciler | [M] | DES, CAP-GSSO-01 | server, web | S1 |
| GSSO-FR-002 | Realm creation from a versioned template (tenant-template) applying baseline flows, client scopes, mappers, password policy, themes and the gsso-kafka event listener | [M] | NEW | kc, server | S1 |
| GSSO-FR-003 | Enable/disable a realm; a disabled realm refuses logins; the action requires confirmation and is audited | [M] | DES | server, web | S1 |
| GSSO-FR-004 | Realm list shows display name, name, user count, client count, federation (broker) and status, as in the design screen “Realms” | [M] | DES | web | S1 |
| GSSO-FR-005 | Realm switcher in the side bar scopes all screens to the selected realm; the choice persists per admin | [M] | DES | web | S1 |
| GSSO-FR-006 | Realm-scoped administration: GSSO_REALM_ADMIN with attribute gsso.realm=<name> sees and changes only that realm | [M] | NEW | server, gateway | S1 |
| GSSO-FR-007 | Realm adoption: import an existing realm (e.g. interdictii) into the catalog read-only, with drift policy IGNORE until the owner switches it | [M] | NEW, interdictii | server, web | S1 |
| GSSO-FR-008 | Realm branding: display name, logo, accent colour and default locale applied to the GDS login theme through realm attributes | [REC] | NEW | kc, web | S2 |
| GSSO-FR-009 | Realm export (configuration, no secrets, no users) as JSON for backup and review | [REC] | NEW | server, web | S2 |
| GSSO-FR-010 | Keycloak Organizations support inside a realm as an alternative to org-unit attributes | [OPT] | NEW | server | S5 |
2. Service catalog — FR-CAT
Section titled “2. Service catalog — FR-CAT”| ID | Requirement | Pri | Source | Component | Phase |
|---|---|---|---|---|---|
| GSSO-FR-011 | Platform registry (Platforma): code (lower-case, unique), name, type (SAAS, PAAS), description RO/RU/EN, owner(s), base URL, accent, status, realm(s) | [M] | CAP-GSSO-06 | server, web | S1 |
| GSSO-FR-012 | Clients per platform (ClientAplicatie): clientId, protocol (OIDC, SAML), access type (PUBLIC_PKCE, CONFIDENTIAL, BEARER_ONLY, SERVICE_ACCOUNT), redirect URIs, web origins, post-logout URIs, back-channel logout URL, audience, status | [M] | DES, CAP-GSSO-01 | server, web | S1 |
| GSSO-FR-013 | Client templates per access type apply secure defaults: PKCE S256 for public clients, no implicit flow, no direct access grants, exact redirect URIs, consent off for internal apps | [M] | NFRQ56, NEW | server | S1 |
| GSSO-FR-014 | Client secret rotation for confidential clients: generate, show once, keep the previous secret valid for a grace period (Keycloak client secret rotation policy) | [M] | NFRQ60 | server, web | S2 |
| GSSO-FR-015 | Service-account clients receive client roles or scopes (e.g. audit:write, storage:read) declared on the client, not through grants | [M] | glog, gstorage | server, web | S1 |
| GSSO-FR-016 | Platform roles (RolPlatforma): code automatically prefixed <PLATFORMA>_, descriptions RO/RU/EN, composite (with child roles of the same platform), sensitive flag, default validity | [M] | DES, GSSO-ADR-005 | server, web | S1 |
| GSSO-FR-017 | Role bundles (groups): named sets of platform roles (e.g. “Operator Cancelaria”) grantable in one request | [M] | NEW, cancelarie | server, web | S2 |
| GSSO-FR-018 | Audience mapper per platform: each client’s tokens carry its platform audience; resource servers validate it | [M] | CAP-GSSO-01, gregistry | kc, server | S1 |
| GSSO-FR-019 | Token-exchange permissions per client: list of target audiences a client may exchange for (GSSO-ADR-012) | [M] | CAP-GSSO-07 | server, web | S3 |
| GSSO-FR-020 | One service client per microservice of a platform (e.g. crm-core, crm-clienti…), creatable in bulk from a list | [M] | CAP-GSSO-01 | server, web | S1 |
| GSSO-FR-021 | Platform deactivation: disables all its clients and suspends its active grants (not deleted), reversible | [REC] | NEW | server | S2 |
| GSSO-FR-022 | Platform card shows clients, roles, grant count, owners, sync status and onboarding checklist progress | [REC] | NEW | web | S2 |
3. Users and sessions — FR-USR
Section titled “3. Users and sessions — FR-USR”| ID | Requirement | Pri | Source | Component | Phase |
|---|---|---|---|---|---|
| GSSO-FR-023 | User list per realm with search by name, username, e-mail, IDNP (authorised roles only), filters by status, MFA, platform role, org unit; columns as in the design (user, e-mail, 2FA, status, last login) | [M] | DES | server, web | S1 |
| GSSO-FR-024 | Create user: username, first/last name, e-mail, IDNP, org unit, locale; send an invitation e-mail with required actions (verify e-mail, set password, configure OTP if a sensitive role is granted) | [M] | DES, CAP-GSSO-01 | server, web | S1 |
| GSSO-FR-025 | Edit user attributes; enable/disable user (disable terminates sessions) | [M] | DES | server, web | S1 |
| GSSO-FR-026 | User drawer with tabs Details, Credentials, Roles, Sessions as in the design | [M] | DES | web | S1 |
| GSSO-FR-027 | Credentials tab: password set/last changed, OTP devices, WebAuthn keys; actions reset password (e-mail), remove an OTP/WebAuthn credential, force required actions | [M] | DES | server, web | S1 |
| GSSO-FR-028 | Roles tab: effective platform roles with their source (grant id, bundle, composite) and grant validity | [M] | DES | server, web | S2 |
| GSSO-FR-029 | Sessions tab: active sessions with client, IP, device (user agent), start and last access; terminate one or all | [M] | DES, CAP-GSSO-03 | server, web | S1 |
| GSSO-FR-030 | Unlock a user temporarily locked by brute-force protection | [M] | NEW | server, web | S1 |
| GSSO-FR-031 | User projection (ProiectieUtilizator) refreshed by events, nightly full sync and on open; shows “refreshed at” | [M] | GSSO-ADR-008 | server | S1 |
| GSSO-FR-032 | sub is a UUID and stable; username and e-mail changes never change sub | [M] | CAP-GSSO-01 | kc | S0 |
| GSSO-FR-033 | User attribute locale (ro, ru, en) editable by user and admin; emitted in the token | [M] | CAP-GSSO-01 | kc, server | S1 |
| GSSO-FR-034 | Bulk import of users from CSV (validated, dry-run report first) | [REC] | cancelarie | server, web | S2 |
| GSSO-FR-035 | Self-service through the Keycloak account console in GDS theme: profile, password, MFA, sessions, linked accounts | [REC] | NEW | kc | S2 |
| GSSO-FR-036 | Last-login and last-failure shown per user from the event stream | [REC] | DES, CRM REQ-PLT | server, web | S2 |
4. Roles and grants — FR-GRT
Section titled “4. Roles and grants — FR-GRT”| ID | Requirement | Pri | Source | Component | Phase |
|---|---|---|---|---|---|
| GSSO-FR-037 | Realm-roles and client-roles screen as in the design: role, description, composite/simple, members; client roles grouped per client | [M] | DES | web | S1 |
| GSSO-FR-038 | Grant request (AtribuireAcces): user, platform role or bundle, optional org unit, validDe, validPana, mandatory reason; requester recorded | [M] | NEW, NFRQ56 | server, web | S2 |
| GSSO-FR-039 | Grant lifecycle SOLICITATA → APROBATA → ACTIVA → REVOCATA/EXPIRATA, SOLICITATA → RESPINSA enforced in the service layer; illegal transitions rejected with RFC 7807 invalid-transition | [M] | GSSO-ADR-006 | server | S2 |
| GSSO-FR-040 | Approval by a platform owner or realm admin; for sensitive roles a second distinct approver with GSSO_APPROVER | [M] | NFRQ56, GSSO-ADR-006 | server, web | S2 |
| GSSO-FR-041 | Nobody approves a request they created or a grant for themselves | [M] | NFRQ56 | server | S2 |
| GSSO-FR-042 | ACTIVA only after the reconciler confirms the role mapping in Keycloak; failure leaves APROBATA with a sync error shown | [M] | GSSO-ADR-004 | server | S2 |
| GSSO-FR-043 | Revocation with mandatory reason removes the mapping and triggers session termination and gsso.access-revoked.v1 | [M] | CAP-GSSO-04 | server | S2 |
| GSSO-FR-044 | Expiry scheduler (hourly) expires grants past validPana and removes mappings | [M] | NEW | server | S2 |
| GSSO-FR-045 | Expiry warnings to the user and platform owner 14 days and 1 day before, through GNotify | [M] | NEW | server | S2 |
| GSSO-FR-046 | Direct grant by an admin for non-sensitive roles (request + approval in one step), audited as ACORDARE_DIRECTA | [M] | NEW | server, web | S2 |
| GSSO-FR-047 | Grants inbox per approver: pending requests with requester, user, role, reason, age; approve/reject in bulk | [M] | NEW | web | S2 |
| GSSO-FR-048 | Grant history per user and per role, filterable, exportable (CSV) | [M] | NFRQ65 | server, web | S2 |
| GSSO-FR-049 | Role mappings created directly in Keycloak (not through a grant) are reported as drift (MAPARE_NEGUVERNATA) | [M] | GSSO-ADR-004 | server | S2 |
| GSSO-FR-050 | Access review campaign: per platform, owners confirm or revoke each active grant before a deadline; unconfirmed grants are flagged | [REC] | NFRQ56 | server, web | S5 |
| GSSO-FR-051 | Grant request by an app on behalf of a user through api/v1/app (e.g. onboarding in cancelarie) | [REC] | cancelarie, crm | server | S3 |
| GSSO-FR-052 | Segregation-of-duties rules: pairs of roles that must not be held together (e.g. INTERDICTII_EMITENT + INTERDICTII_APROBATOR); conflicting requests rejected or flagged | [OPT] | NEW | server | S5 |
5. Organisational units — FR-ORG
Section titled “5. Organisational units — FR-ORG”| ID | Requirement | Pri | Source | Component | Phase |
|---|---|---|---|---|---|
| GSSO-FR-053 | Org-unit tree per realm (UnitateOrganizationala): code, name RO/RU/EN, parent, head(s) | [M] | CAP-GSSO-04 | server, web | S2 |
| GSSO-FR-054 | User attribute org_unit (code) and claim org_unit; optional org_unit_path claim (codes from root) | [M] | CAP-GSSO-04, ginsight | kc, server | S2 |
| GSSO-FR-055 | Grants may be scoped to an org unit; the scope is emitted as roles_scoped claim {"<ROLE>": ["<ou>"…]} when present | [M] | NEW | kc, server | S2 |
| GSSO-FR-056 | Import of org units from CSV/JSON | [REC] | NEW | server | S2 |
6. Authentication and federation — FR-AUT
Section titled “6. Authentication and federation — FR-AUT”| ID | Requirement | Pri | Source | Component | Phase |
|---|---|---|---|---|---|
| GSSO-FR-057 | Authentication policy per realm (PoliticaAutentificare): method toggles password, OTP, WebAuthn, QR, client credentials, broker, magic link, as in the design screen “Authentication” | [M] | DES | server, web | S2 |
| GSSO-FR-058 | Browser flow shown as ordered steps (cookie, broker, username+password, conditional second factor) with requirement (alternative/required/conditional) | [M] | DES | server, web | S2 |
| GSSO-FR-059 | Conditional MFA: OTP or WebAuthn required when the user holds any sensitive role (custom conditional authenticator or “condition – user role” on a composite GSSO_MFA_REQUIRED) | [M] | CAP-GSSO-02, NFRQ58 | kc, server | S2 |
| GSSO-FR-060 | Password policy per realm: length ≥ 12, complexity, history 5, not username/e-mail, max age optional | [M] | NFRQ58 | kc, server | S0 |
| GSSO-FR-061 | Brute-force protection on (lockout after 5 failures, incremental wait) | [M] | NFRQ58 | kc | S0 |
| GSSO-FR-062 | Session lifetimes per realm and per client: SSO idle 30 min / max 10 h for staff; admin console client 15 min idle | [M] | NFRQ60 | kc, server | S0 |
| GSSO-FR-063 | MPass/eID identity provider (SAML) in realm cetatean; first-broker-login links or creates the user by IDNP; mock IdP for tests | [M] | NEW, drumuri | kc, server | S2 |
| GSSO-FR-064 | AD/LDAP user federation per realm (read-only by default), with attribute and group mappers | [M] | CAP-GSSO-02 | kc, server, web | S2 |
| GSSO-FR-065 | WebAuthn / passkeys (two-factor and passwordless policies) | [M] | DES | kc | S2 |
| GSSO-FR-066 | GDS login, account and e-mail themes in RO/RU/EN; IBM Plex; realm accent | [REC] | NFRQ38/40 | kc | S0 |
| GSSO-FR-067 | Magic link login (e-mail) for low-assurance clients only | [OPT] | DES | kc | S5 |
| GSSO-FR-068 | QR cross-device login with the gsso_mob app as a Keycloak authenticator (replaces the per-site approve endpoint) | [OPT] | gsso_mob, Q-GSSO-9 | kc | S5 |
| GSSO-FR-069 | Required actions configurable per realm: verify e-mail, update password, configure OTP, terms and conditions | [REC] | NEW | kc, server | S2 |
| GSSO-FR-070 | Level-of-assurance claim acr (1 password, 2 MFA, 3 MPass high) and step-up via acr_values for sensitive operations | [REC] | NEW | kc | S3 |
7. Reconciliation — FR-SYN
Section titled “7. Reconciliation — FR-SYN”| ID | Requirement | Pri | Source | Component | Phase |
|---|---|---|---|---|---|
| GSSO-FR-071 | Every catalog, user or grant change creates a JobSincronizare in the same transaction (outbox) | [M] | GSSO-ADR-004 | server | S1 |
| GSSO-FR-072 | Reconciler worker applies jobs idempotently through the Keycloak Admin REST API with the gsso-reconciler service account | [M] | GSSO-ADR-004 | server | S1 |
| GSSO-FR-073 | Retry with exponential backoff (1 s → 5 min, 10 attempts), then FAILED with GNotify alert | [M] | NEW | server | S1 |
| GSSO-FR-074 | Full reconcile per realm every 15 min (configurable) and on demand; diff of managed object types | [M] | GSSO-ADR-004 | server | S1 |
| GSSO-FR-075 | Drift findings stored with a JSON diff; policy per realm REPORT, ENFORCE, IGNORE | [M] | NEW | server | S1 |
| GSSO-FR-076 | Managed objects carry gsso.managed=true; unmanaged objects are never deleted, only reported | [M] | NEW | server | S1 |
| GSSO-FR-077 | Sync screen: jobs (pending, running, OK, failed, drift) with filters, retry, and “accept drift” (adopt the Keycloak value) | [M] | NEW | web | S1 |
| GSSO-FR-078 | Each catalog object shows its stareSync (in sync, pending, failed, drift) in lists | [M] | NEW | web | S1 |
| GSSO-FR-079 | Only one reconciler instance applies jobs per realm at a time (advisory lock), so ordering per realm is preserved | [M] | NEW | server | S1 |
| GSSO-FR-080 | Dry-run mode for reconcile and adoption producing a report without writes | [REC] | NEW | server, web | S1 |
8. Events and audit — FR-EVT
Section titled “8. Events and audit — FR-EVT”| ID | Requirement | Pri | Source | Component | Phase |
|---|---|---|---|---|---|
| GSSO-FR-081 | Keycloak event listener gsso-kafka publishes user and admin events to gsso.kc-events.v1 (CloudEvents, async, non-blocking) | [M] | GSSO-ADR-007 | kc | S2 |
| GSSO-FR-082 | Idempotent consumer stores events in EvenimentGsso and updates the projection and aggregates | [M] | GSSO-ADR-007 | server | S2 |
| GSSO-FR-083 | GSSO’s own events (catalog, grant, sync, admin console actions) written in the same transaction as the change | [M] | CU-AUDIT | server | S1 |
| GSSO-FR-084 | EvenimentGsso is append-only: no update/delete in repository; database trigger rejects UPDATE/DELETE | [M] | CU-AUDIT, NFRQ65 | server | S1 |
| GSSO-FR-085 | Hash chain per realm (hashPrecedent, hash SHA-256) and a verification endpoint | [M] | NEW | server | S2 |
| GSSO-FR-086 | Forwarding of every event to GLog with retry and receipt id | [M] | CU-AUDIT | server | S2 |
| GSSO-FR-087 | Back-fill from the Keycloak events API when the stream had a gap | [M] | NEW | server | S2 |
| GSSO-FR-088 | Event list with filters (type, actor, realm, client, IP, time range) and detail view | [M] | DES | web | S2 |
| GSSO-FR-089 | Publication of gsso.access-revoked.v1 and gsso.user-changed.v1 for consumers | [M] | CAP-GSSO-04 | server | S2 |
| GSSO-FR-090 | Security alerts through GNotify: brute-force lockout of an admin, login from new country for admins, grant of a GSSO_* role, reconciler failure | [REC] | NFRQ65 | server | S2 |
9. Dashboard and reports — FR-RPT
Section titled “9. Dashboard and reports — FR-RPT”| ID | Requirement | Pri | Source | Component | Phase |
|---|---|---|---|---|---|
| GSSO-FR-091 | Dashboard KPIs: realms, clients (OIDC/SAML), users (delta today), active sessions | [M] | DES | server, web | S2 |
| GSSO-FR-092 | Logins over 24 h in 2-hour buckets, success vs failure | [M] | DES | server, web | S2 |
| GSSO-FR-093 | Recent security events (last 20) with actor, text, realm, IP, time | [M] | DES | web | S2 |
| GSSO-FR-094 | Authentication-method mix over 24 h (password, OTP, WebAuthn, MPass/eID, app-to-app) | [M] | DES | server, web | S2 |
| GSSO-FR-095 | Access report: who holds which role on which platform (filter by platform, org unit), CSV/PDF | [REC] | NFRQ56 | server, web | S2 |
| GSSO-FR-096 | Dormant-account report: users with no login in N days and holding roles | [REC] | NEW | server, web | S5 |
10. App API and integration kit — FR-API
Section titled “10. App API and integration kit — FR-API”| ID | Requirement | Pri | Source | Component | Phase |
|---|---|---|---|---|---|
| GSSO-FR-097 | admin zone API covering every console function; OpenAPI published | [M] | CU-API-003 | server | S1 |
| GSSO-FR-098 | app zone API with client credentials and scope gsso:app; each app sees only its own platform | [M] | CAP-GSSO-06 | server | S3 |
| GSSO-FR-099 | App self-registration: create/update its platform, clients and roles (when the app’s client is flagged) | [M] | CAP-GSSO-06 | server | S3 |
| GSSO-FR-100 | User lookup by sub, username, e-mail or IDNP (IDNP only for clients allowed by the DPO) | [M] | CAP-GSSO-03, crm | server | S3 |
| GSSO-FR-101 | User status and platform roles query (GET /api/v1/app/utilizatori/{sub}/roluri) | [M] | CAP-GSSO-03 | server | S3 |
| GSSO-FR-102 | Terminate a user’s sessions (DELETE /api/v1/app/utilizatori/{sub}/sesiuni) | [M] | CAP-GSSO-03 | server | S3 |
| GSSO-FR-103 | Users holding a role (GET /api/v1/app/roluri/{cod}/utilizatori), paged; used e.g. by gFlow candidate resolution | [M] | gflow | server | S3 |
| GSSO-FR-104 | gsso-spring-boot-starter: resource-server validation (issuer, JWKS, audience), roles → authorities with alias map, GssoPrincipal, client-credentials and token-exchange clients, revocation deny-list, Keycloak health indicator, Testcontainers helper | [M] | GSSO-ADR-009 | starter | S3 |
| GSSO-FR-105 | @gstack/gsso-angular: PKCE or BFF mode, role guard and directive, silent refresh, single logout, locale sync | [M] | GSSO-ADR-009 | ng | S3 |
| GSSO-FR-106 | Onboarding runbook and checklist (report 03 §8) and a sample app | [M] | NEW | ops | S3 |
| GSSO-FR-107 | Kafka SASL OAUTHBEARER configuration helper for service clients | [REC] | CAP-GSSO-01 | starter | S3 |
| GSSO-FR-108 | Terraform/OpenTofu or CLI (gsso-cli) for platform onboarding from CI | [REC] | CAP-GSSO-06 | ops | S5 |
11. Console (UI) — FR-UI
Section titled “11. Console (UI) — FR-UI”| ID | Requirement | Pri | Source | Component | Phase |
|---|---|---|---|---|---|
| GSSO-FR-109 | GDS layout as in the design: side bar with sections Identity (Dashboard, Realms, Applications) and Access (Users, Roles, Authentication), plus Governance (Platforms, Grants, Sync, Events) | [M] | DES | web | S1 |
| GSSO-FR-110 | Language switch RO/RU/EN in the header; all labels translated; domain terms Romanian | [M] | NFRQ38 | web | S1 |
| GSSO-FR-111 | Context-aware “Create” action per screen (realm, client, user, role, grant) opening a form drawer | [M] | DES | web | S1 |
| GSSO-FR-112 | Responsive layout down to 360 px with the collapsible side bar (as the design breakpoints 880/480 px) | [M] | DES, NFRQ39 | web | S1 |
| GSSO-FR-113 | Tables with filter, sort, pagination and empty states; destructive actions require confirmation with the object name | [M] | NEW | web | S1 |
| GSSO-FR-114 | Screens and actions hidden or disabled according to the admin’s GSSO role and realm scope; the backend enforces the same | [M] | NFRQ56 | web, server | S1 |
| GSSO-FR-115 | Toast feedback and sync-status badges after every change (pending → in sync) | [M] | DES | web | S1 |
| GSSO-FR-116 | Accessibility WCAG 2.1 AA (keyboard, focus, contrast, labels) | [M] | NFRQ39 | web | S1 |
II. Non-functional requirements
Section titled “II. Non-functional requirements”12. Performance — NFR-PERF
Section titled “12. Performance — NFR-PERF”| ID | Requirement | Target | Verification |
|---|---|---|---|
| GSSO-NFR-PERF-001 | Login (password, existing user) end-to-end at the Keycloak | p95 < 500 ms at 50 logins/s | load test |
| GSSO-NFR-PERF-002 | Console list endpoints (users, grants, events; 50 rows) | p95 < 800 ms with 100 000 users, 1 M events | load test (NFRQ20) |
| GSSO-NFR-PERF-003 | Catalog change → in Keycloak | p95 < 2 s, p99 < 10 s | IT timing |
| GSSO-NFR-PERF-004 | Kafka event → visible in console | p95 < 5 s | IT timing |
| GSSO-NFR-PERF-005 | Token validation overhead in the starter (cached JWKS) | < 2 ms per request | microbenchmark |
13. Capacity — NFR-CAP
Section titled “13. Capacity — NFR-CAP”| ID | Requirement | Target |
|---|---|---|
| GSSO-NFR-CAP-001 | Staff users in gstack | 20 000 |
| GSSO-NFR-CAP-002 | Citizen users in cetatean | 1 000 000 |
| GSSO-NFR-CAP-003 | Concurrent SSO sessions | 10 000 |
| GSSO-NFR-CAP-004 | Platforms / clients / roles / active grants | 100 / 1 000 / 2 000 / 200 000 |
14. Availability and continuity — NFR-AVL
Section titled “14. Availability and continuity — NFR-AVL”| ID | Requirement | Target |
|---|---|---|
| GSSO-NFR-AVL-001 | Keycloak (login, token, JWKS) availability | 99.9 % monthly (NFRQ availability) |
| GSSO-NFR-AVL-002 | GSSO console and API availability | 99.5 % monthly |
| GSSO-NFR-AVL-003 | Logins and token issuance do not depend on gsso, Kafka or GLog being up | verified by chaos test |
| GSSO-NFR-AVL-004 | RPO / RTO Keycloak database | 15 min / 1 h |
| GSSO-NFR-AVL-005 | RPO / RTO GSSO database | 1 h / 4 h; catalog rebuildable by adoption |
| GSSO-NFR-AVL-006 | TLS certificate expiry monitored with alert 21 days before | alert test |
15. Security — NFR-SEC
Section titled “15. Security — NFR-SEC”| ID | Requirement |
|---|---|
| GSSO-NFR-SEC-001 | OWASP ASVS L2 for console, gateway and API; OWASP Top 10 (NFRQ56/57) |
| GSSO-NFR-SEC-002 | Tokens signed RS256 (or ES256); key rotation every 90 days with overlap; HS* not allowed |
| GSSO-NFR-SEC-003 | The SPA never holds tokens (BFF); session cookie HttpOnly, Secure, SameSite=Lax; CSRF protection |
| GSSO-NFR-SEC-004 | gsso-reconciler credentials only in the secret store; its permissions limited to manage-realm, manage-users, manage-clients, view-events of managed realms (no master admin) |
| GSSO-NFR-SEC-005 | No secret in git; client secrets shown once; secrets encrypted at rest in GSSO DB if stored at all (prefer not stored) |
| GSSO-NFR-SEC-006 | IDNP encrypted at rest in the projection, masked in UI unless role GSSO_IDNP_VIEW |
| GSSO-NFR-SEC-007 | Security headers (CSP, HSTS, X-Frame-Options, Referrer-Policy) on gateway and Keycloak themes (NFRQ56) |
| GSSO-NFR-SEC-008 | Admin console client: MFA mandatory, session idle 15 min |
| GSSO-NFR-SEC-009 | SAST, SCA, secrets scanning and SBOM in CI (/gsast), DAST baseline (/gtest) — NFRQ90/91 |
| GSSO-NFR-SEC-010 | Rate limiting on app API (per client) and on login endpoints at the ingress |
16. Tenancy isolation — NFR-TEN
Section titled “16. Tenancy isolation — NFR-TEN”| ID | Requirement |
|---|---|
| GSSO-NFR-TEN-001 | Every GSSO table row carries realm; every query from a realm-scoped admin is filtered server-side |
| GSSO-NFR-TEN-002 | An app’s gsso:app client can read and change only its own platform’s objects |
| GSSO-NFR-TEN-003 | Tests prove that no endpoint leaks another realm’s or platform’s data (authorization matrix probe) |
17. Observability — NFR-OBS
Section titled “17. Observability — NFR-OBS”| ID | Requirement |
|---|---|
| GSSO-NFR-OBS-001 | /health/live, /health/ready (DB, Kafka, Keycloak), /metrics (Prometheus), /info on gsso and gsso-gateway; Keycloak /health and /metrics enabled |
| GSSO-NFR-OBS-002 | Metrics: sync jobs by state, reconcile duration, drift count, event lag, GLog forwarding lag, logins/failures per realm |
| GSSO-NFR-OBS-003 | Structured JSON logs with trace id; no tokens, secrets or IDNP in logs (NFRQ35/50) |
| GSSO-NFR-OBS-004 | Alerts: reconciler failed, event lag > 5 min, Keycloak down, certificate expiry, error rate |
18. Operability — NFR-OPS
Section titled “18. Operability — NFR-OPS”| ID | Requirement |
|---|---|
| GSSO-NFR-OPS-001 | One-command local stack (docker compose up) and documented demo-host deployment |
| GSSO-NFR-OPS-002 | Helm chart for the Kubernetes target |
| GSSO-NFR-OPS-003 | Keycloak database backup daily + before every upgrade; restore tested quarterly |
| GSSO-NFR-OPS-004 | Keycloak upgrade gated by the realm baseline + reconciler integration test suite against the new version |
| GSSO-NFR-OPS-005 | Runbooks: takeover, upgrade, key rotation, certificate renewal, break-glass, restore |
19. Compatibility and standards — NFR-CMP
Section titled “19. Compatibility and standards — NFR-CMP”| ID | Requirement |
|---|---|
| GSSO-NFR-CMP-001 | OpenID Connect Core 1.0, OAuth 2.1 practices (PKCE, no implicit), RFC 8693, RFC 7807, SAML 2.0 |
| GSSO-NFR-CMP-002 | GovStack API standard: api/v1 zones, health endpoints, OpenAPI, Idempotency-Key on POST (checked by api_audit.py) |
| GSSO-NFR-CMP-003 | DEV-PLAYBOOK §2 stack, versions as generated by JHipster 9.1.0 |
| GSSO-NFR-CMP-004 | Keycloak 26.6.x; extensions built against the same SPI version |
20. Data protection and retention — NFR-DATA
Section titled “20. Data protection and retention — NFR-DATA”| ID | Requirement |
|---|---|
| GSSO-NFR-DATA-001 | Personal data minimised to: username, name, e-mail, IDNP (optional), org unit, locale |
| GSSO-NFR-DATA-002 | Events retained 90 days in GSSO, then purged (partition drop); GLog keeps the trail per its policy |
| GSSO-NFR-DATA-003 | User deletion propagates: projection purged, actor references replaced by sub |
III. Traceability
Section titled “III. Traceability”21. Consumer capability requests → requirements
Section titled “21. Consumer capability requests → requirements”| CAP | Request | GSSO requirements | Phase |
|---|---|---|---|
| CAP-GSSO-01 | Corporate realm; confidential crm-gateway; one service client per microservice; Kafka OAUTHBEARER; GDocs/GLog clients; locale; UUID sub | FR-001, 012, 018, 020, 032, 033, 107 | S1–S3 |
| CAP-GSSO-02 | AD/LDAP federation, TOTP MFA per role | FR-059, 064 | S2 |
| CAP-GSSO-03 | Session list and forced termination via admin API; user status and roles | FR-029, 100, 101, 102 | S1, S3 |
| CAP-GSSO-04 | Revocation ≤ 60 s; org-unit claims | FR-043, 053..055, 089; GSSO-ADR-013 | S2 |
| CAP-GSSO-06 | Automatable client provisioning | FR-011, 098, 099, 108 | S3, S5 |
| CAP-GSSO-07 | Token exchange RFC 8693 | FR-019; GSSO-ADR-012 | S3 |
22. Universal requirements (CU-*) → requirements
Section titled “22. Universal requirements (CU-*) → requirements”| CU | Status for GSSO | Requirements |
|---|---|---|
| CU-AUTH-001 (authentication) | Provided by GSSO to all apps; console uses it | FR-057..070; NFR-SEC-002, 003, 008 |
| CU-AUTH-002 (signature) | N/A — MSign / gsso_mob | — |
| CU-AUTH-003 (sessions) | Applicable | FR-029, 062, 102; GSSO-ADR-013 |
| CU-RBAC-001..003 | Applicable — GSSO is the RBAC source for all apps | FR-016, 037..052, 114 |
| CU-AUDIT-001..003 | Applicable, through GLog | FR-081..090 |
| CU-OBS-001..004 | Applicable | NFR-OBS-001..004 |
| CU-API-003..006 | Applicable — mandatory | FR-097, 098; NFR-CMP-002 |
| CU-MSG-001 | Applicable (Kafka, idempotent consumers) | FR-081, 082, 089 |
| CU-DATA-001..003 | Applicable | NFR-DATA-001..003, NFR-AVL-004/005 |
| CU-DEPLOY | Applicable | NFR-OPS-001..005 |
23. NFRQ (caiet de sarcini) → requirements
Section titled “23. NFRQ (caiet de sarcini) → requirements”| NFRQ | GSSO |
|---|---|
| NFRQ20–22 performance | NFR-PERF-001..005 |
| NFRQ35/50/51 logging | FR-081..090, NFR-OBS-003 |
| NFRQ38 multilingual | FR-066, 110 |
| NFRQ39 accessibility | FR-112, 116 |
| NFRQ40 unified design (GDS) | FR-066, 109 |
| NFRQ56–66 security | FR-013, 014, 040, 041, 059..062, NFR-SEC-* |
| NFRQ90–93 testing and acceptance | NFR-SEC-009, report 04 §12, test-scenarios.md |