Sari la conținut

GSSO — Functional and Non-Functional Requirements

Acest conținut nu este încă disponibil în limba selectată.

Document codeSPEC-GSSO-2026 / Report 02
Version0.1-draft (EN source, governing)
Date2026-10-05
StatusDraft
Companion reports00 RFP · 01 ADR · 03 Consumers & contract · 04 Technical documentation · 05 Roadmap

This report is the single source of truth for GSSO requirements. Report 00 only summarises them.

VersionDateChanges
0.1-draft2026-10-05Initial matrix: GSSO-FR-001..116, 44 GSSO-NFR-, traceability to CAP-GSSO-01..07, CU-, NFRQ
  • Pri:
    • [M]: mandatory for the MVP or GA.
    • [REC]: recommended; never blocks a gate.
    • [OPT]: optional or later.
  • Source:
    • CAP-GSSO-nn: capability requested by a consumer (CRM report 03 §4.1 and the gDocFlow, gTenders, gFlow and gInsight packages).
    • CU-*: universal gStack requirement.
    • NFRQnn: caiet-de-sarcini code.
    • DES: required by the design GSSO.dc.html.
    • NEW: found during platform analysis.
    • A consumer tag (crm, interdictii, glog…) marks a need derived from that app (report 03).
  • Component:
    • kc: Keycloak extensions, themes, realm baselines.
    • server: the gsso microservice.
    • gateway: gsso-gateway.
    • web: gsso-web.
    • starter: gsso-spring-boot-starter.
    • ng: @gstack/gsso-angular.
    • ops: compose, Helm, runbooks.
  • Phase (report 05):
    • S0: Foundation.
    • S1: Console & catalog MVP.
    • S2: Governance (grants, events, policies).
    • S3: Integration kit & pilot.
    • S4: Migration of existing apps.
    • S5: Extensions.
GroupIDs[M][REC][OPT]
FR-RLM Realms and tenants001..010721
FR-CAT Service catalog011..0221020
FR-USR Users and sessions023..0361130
FR-GRT Roles and grants037..0521321
FR-ORG Organisational units053..056310
FR-AUT Authentication and federation057..070932
FR-SYN Reconciliation071..080910
FR-EVT Events and audit081..090910
FR-RPT Dashboard and reports091..096420
FR-API App API and integration kit097..1081020
FR-UI Console109..116800
Functional total11693194
NFR (PERF 5, CAP 4, AVL 6, SEC 10, TEN 3, OBS 4, OPS 5, CMP 4, DATA 3)44
IDRequirementPriSourceComponentPhase
GSSO-FR-001Realm registry: a GSSO_ADMIN registers a realm with name, display name, type (STAFF, CETATEAN, TENANT, SERVICE), owner, drift policy and status; the realm is created in Keycloak by the reconciler[M]DES, CAP-GSSO-01server, webS1
GSSO-FR-002Realm creation from a versioned template (tenant-template) applying baseline flows, client scopes, mappers, password policy, themes and the gsso-kafka event listener[M]NEWkc, serverS1
GSSO-FR-003Enable/disable a realm; a disabled realm refuses logins; the action requires confirmation and is audited[M]DESserver, webS1
GSSO-FR-004Realm list shows display name, name, user count, client count, federation (broker) and status, as in the design screen “Realms”[M]DESwebS1
GSSO-FR-005Realm switcher in the side bar scopes all screens to the selected realm; the choice persists per admin[M]DESwebS1
GSSO-FR-006Realm-scoped administration: GSSO_REALM_ADMIN with attribute gsso.realm=<name> sees and changes only that realm[M]NEWserver, gatewayS1
GSSO-FR-007Realm adoption: import an existing realm (e.g. interdictii) into the catalog read-only, with drift policy IGNORE until the owner switches it[M]NEW, interdictiiserver, webS1
GSSO-FR-008Realm branding: display name, logo, accent colour and default locale applied to the GDS login theme through realm attributes[REC]NEWkc, webS2
GSSO-FR-009Realm export (configuration, no secrets, no users) as JSON for backup and review[REC]NEWserver, webS2
GSSO-FR-010Keycloak Organizations support inside a realm as an alternative to org-unit attributes[OPT]NEWserverS5
IDRequirementPriSourceComponentPhase
GSSO-FR-011Platform registry (Platforma): code (lower-case, unique), name, type (SAAS, PAAS), description RO/RU/EN, owner(s), base URL, accent, status, realm(s)[M]CAP-GSSO-06server, webS1
GSSO-FR-012Clients per platform (ClientAplicatie): clientId, protocol (OIDC, SAML), access type (PUBLIC_PKCE, CONFIDENTIAL, BEARER_ONLY, SERVICE_ACCOUNT), redirect URIs, web origins, post-logout URIs, back-channel logout URL, audience, status[M]DES, CAP-GSSO-01server, webS1
GSSO-FR-013Client templates per access type apply secure defaults: PKCE S256 for public clients, no implicit flow, no direct access grants, exact redirect URIs, consent off for internal apps[M]NFRQ56, NEWserverS1
GSSO-FR-014Client secret rotation for confidential clients: generate, show once, keep the previous secret valid for a grace period (Keycloak client secret rotation policy)[M]NFRQ60server, webS2
GSSO-FR-015Service-account clients receive client roles or scopes (e.g. audit:write, storage:read) declared on the client, not through grants[M]glog, gstorageserver, webS1
GSSO-FR-016Platform roles (RolPlatforma): code automatically prefixed <PLATFORMA>_, descriptions RO/RU/EN, composite (with child roles of the same platform), sensitive flag, default validity[M]DES, GSSO-ADR-005server, webS1
GSSO-FR-017Role bundles (groups): named sets of platform roles (e.g. “Operator Cancelaria”) grantable in one request[M]NEW, cancelarieserver, webS2
GSSO-FR-018Audience mapper per platform: each client’s tokens carry its platform audience; resource servers validate it[M]CAP-GSSO-01, gregistrykc, serverS1
GSSO-FR-019Token-exchange permissions per client: list of target audiences a client may exchange for (GSSO-ADR-012)[M]CAP-GSSO-07server, webS3
GSSO-FR-020One service client per microservice of a platform (e.g. crm-core, crm-clienti…), creatable in bulk from a list[M]CAP-GSSO-01server, webS1
GSSO-FR-021Platform deactivation: disables all its clients and suspends its active grants (not deleted), reversible[REC]NEWserverS2
GSSO-FR-022Platform card shows clients, roles, grant count, owners, sync status and onboarding checklist progress[REC]NEWwebS2
IDRequirementPriSourceComponentPhase
GSSO-FR-023User list per realm with search by name, username, e-mail, IDNP (authorised roles only), filters by status, MFA, platform role, org unit; columns as in the design (user, e-mail, 2FA, status, last login)[M]DESserver, webS1
GSSO-FR-024Create user: username, first/last name, e-mail, IDNP, org unit, locale; send an invitation e-mail with required actions (verify e-mail, set password, configure OTP if a sensitive role is granted)[M]DES, CAP-GSSO-01server, webS1
GSSO-FR-025Edit user attributes; enable/disable user (disable terminates sessions)[M]DESserver, webS1
GSSO-FR-026User drawer with tabs Details, Credentials, Roles, Sessions as in the design[M]DESwebS1
GSSO-FR-027Credentials tab: password set/last changed, OTP devices, WebAuthn keys; actions reset password (e-mail), remove an OTP/WebAuthn credential, force required actions[M]DESserver, webS1
GSSO-FR-028Roles tab: effective platform roles with their source (grant id, bundle, composite) and grant validity[M]DESserver, webS2
GSSO-FR-029Sessions tab: active sessions with client, IP, device (user agent), start and last access; terminate one or all[M]DES, CAP-GSSO-03server, webS1
GSSO-FR-030Unlock a user temporarily locked by brute-force protection[M]NEWserver, webS1
GSSO-FR-031User projection (ProiectieUtilizator) refreshed by events, nightly full sync and on open; shows “refreshed at”[M]GSSO-ADR-008serverS1
GSSO-FR-032sub is a UUID and stable; username and e-mail changes never change sub[M]CAP-GSSO-01kcS0
GSSO-FR-033User attribute locale (ro, ru, en) editable by user and admin; emitted in the token[M]CAP-GSSO-01kc, serverS1
GSSO-FR-034Bulk import of users from CSV (validated, dry-run report first)[REC]cancelarieserver, webS2
GSSO-FR-035Self-service through the Keycloak account console in GDS theme: profile, password, MFA, sessions, linked accounts[REC]NEWkcS2
GSSO-FR-036Last-login and last-failure shown per user from the event stream[REC]DES, CRM REQ-PLTserver, webS2
IDRequirementPriSourceComponentPhase
GSSO-FR-037Realm-roles and client-roles screen as in the design: role, description, composite/simple, members; client roles grouped per client[M]DESwebS1
GSSO-FR-038Grant request (AtribuireAcces): user, platform role or bundle, optional org unit, validDe, validPana, mandatory reason; requester recorded[M]NEW, NFRQ56server, webS2
GSSO-FR-039Grant lifecycle SOLICITATA → APROBATA → ACTIVA → REVOCATA/EXPIRATA, SOLICITATA → RESPINSA enforced in the service layer; illegal transitions rejected with RFC 7807 invalid-transition[M]GSSO-ADR-006serverS2
GSSO-FR-040Approval by a platform owner or realm admin; for sensitive roles a second distinct approver with GSSO_APPROVER[M]NFRQ56, GSSO-ADR-006server, webS2
GSSO-FR-041Nobody approves a request they created or a grant for themselves[M]NFRQ56serverS2
GSSO-FR-042ACTIVA only after the reconciler confirms the role mapping in Keycloak; failure leaves APROBATA with a sync error shown[M]GSSO-ADR-004serverS2
GSSO-FR-043Revocation with mandatory reason removes the mapping and triggers session termination and gsso.access-revoked.v1[M]CAP-GSSO-04serverS2
GSSO-FR-044Expiry scheduler (hourly) expires grants past validPana and removes mappings[M]NEWserverS2
GSSO-FR-045Expiry warnings to the user and platform owner 14 days and 1 day before, through GNotify[M]NEWserverS2
GSSO-FR-046Direct grant by an admin for non-sensitive roles (request + approval in one step), audited as ACORDARE_DIRECTA[M]NEWserver, webS2
GSSO-FR-047Grants inbox per approver: pending requests with requester, user, role, reason, age; approve/reject in bulk[M]NEWwebS2
GSSO-FR-048Grant history per user and per role, filterable, exportable (CSV)[M]NFRQ65server, webS2
GSSO-FR-049Role mappings created directly in Keycloak (not through a grant) are reported as drift (MAPARE_NEGUVERNATA)[M]GSSO-ADR-004serverS2
GSSO-FR-050Access review campaign: per platform, owners confirm or revoke each active grant before a deadline; unconfirmed grants are flagged[REC]NFRQ56server, webS5
GSSO-FR-051Grant request by an app on behalf of a user through api/v1/app (e.g. onboarding in cancelarie)[REC]cancelarie, crmserverS3
GSSO-FR-052Segregation-of-duties rules: pairs of roles that must not be held together (e.g. INTERDICTII_EMITENT + INTERDICTII_APROBATOR); conflicting requests rejected or flagged[OPT]NEWserverS5
IDRequirementPriSourceComponentPhase
GSSO-FR-053Org-unit tree per realm (UnitateOrganizationala): code, name RO/RU/EN, parent, head(s)[M]CAP-GSSO-04server, webS2
GSSO-FR-054User attribute org_unit (code) and claim org_unit; optional org_unit_path claim (codes from root)[M]CAP-GSSO-04, ginsightkc, serverS2
GSSO-FR-055Grants may be scoped to an org unit; the scope is emitted as roles_scoped claim {"<ROLE>": ["<ou>"…]} when present[M]NEWkc, serverS2
GSSO-FR-056Import of org units from CSV/JSON[REC]NEWserverS2

6. Authentication and federation — FR-AUT

Section titled “6. Authentication and federation — FR-AUT”
IDRequirementPriSourceComponentPhase
GSSO-FR-057Authentication policy per realm (PoliticaAutentificare): method toggles password, OTP, WebAuthn, QR, client credentials, broker, magic link, as in the design screen “Authentication”[M]DESserver, webS2
GSSO-FR-058Browser flow shown as ordered steps (cookie, broker, username+password, conditional second factor) with requirement (alternative/required/conditional)[M]DESserver, webS2
GSSO-FR-059Conditional MFA: OTP or WebAuthn required when the user holds any sensitive role (custom conditional authenticator or “condition – user role” on a composite GSSO_MFA_REQUIRED)[M]CAP-GSSO-02, NFRQ58kc, serverS2
GSSO-FR-060Password policy per realm: length ≥ 12, complexity, history 5, not username/e-mail, max age optional[M]NFRQ58kc, serverS0
GSSO-FR-061Brute-force protection on (lockout after 5 failures, incremental wait)[M]NFRQ58kcS0
GSSO-FR-062Session lifetimes per realm and per client: SSO idle 30 min / max 10 h for staff; admin console client 15 min idle[M]NFRQ60kc, serverS0
GSSO-FR-063MPass/eID identity provider (SAML) in realm cetatean; first-broker-login links or creates the user by IDNP; mock IdP for tests[M]NEW, drumurikc, serverS2
GSSO-FR-064AD/LDAP user federation per realm (read-only by default), with attribute and group mappers[M]CAP-GSSO-02kc, server, webS2
GSSO-FR-065WebAuthn / passkeys (two-factor and passwordless policies)[M]DESkcS2
GSSO-FR-066GDS login, account and e-mail themes in RO/RU/EN; IBM Plex; realm accent[REC]NFRQ38/40kcS0
GSSO-FR-067Magic link login (e-mail) for low-assurance clients only[OPT]DESkcS5
GSSO-FR-068QR cross-device login with the gsso_mob app as a Keycloak authenticator (replaces the per-site approve endpoint)[OPT]gsso_mob, Q-GSSO-9kcS5
GSSO-FR-069Required actions configurable per realm: verify e-mail, update password, configure OTP, terms and conditions[REC]NEWkc, serverS2
GSSO-FR-070Level-of-assurance claim acr (1 password, 2 MFA, 3 MPass high) and step-up via acr_values for sensitive operations[REC]NEWkcS3
IDRequirementPriSourceComponentPhase
GSSO-FR-071Every catalog, user or grant change creates a JobSincronizare in the same transaction (outbox)[M]GSSO-ADR-004serverS1
GSSO-FR-072Reconciler worker applies jobs idempotently through the Keycloak Admin REST API with the gsso-reconciler service account[M]GSSO-ADR-004serverS1
GSSO-FR-073Retry with exponential backoff (1 s → 5 min, 10 attempts), then FAILED with GNotify alert[M]NEWserverS1
GSSO-FR-074Full reconcile per realm every 15 min (configurable) and on demand; diff of managed object types[M]GSSO-ADR-004serverS1
GSSO-FR-075Drift findings stored with a JSON diff; policy per realm REPORT, ENFORCE, IGNORE[M]NEWserverS1
GSSO-FR-076Managed objects carry gsso.managed=true; unmanaged objects are never deleted, only reported[M]NEWserverS1
GSSO-FR-077Sync screen: jobs (pending, running, OK, failed, drift) with filters, retry, and “accept drift” (adopt the Keycloak value)[M]NEWwebS1
GSSO-FR-078Each catalog object shows its stareSync (in sync, pending, failed, drift) in lists[M]NEWwebS1
GSSO-FR-079Only one reconciler instance applies jobs per realm at a time (advisory lock), so ordering per realm is preserved[M]NEWserverS1
GSSO-FR-080Dry-run mode for reconcile and adoption producing a report without writes[REC]NEWserver, webS1
IDRequirementPriSourceComponentPhase
GSSO-FR-081Keycloak event listener gsso-kafka publishes user and admin events to gsso.kc-events.v1 (CloudEvents, async, non-blocking)[M]GSSO-ADR-007kcS2
GSSO-FR-082Idempotent consumer stores events in EvenimentGsso and updates the projection and aggregates[M]GSSO-ADR-007serverS2
GSSO-FR-083GSSO’s own events (catalog, grant, sync, admin console actions) written in the same transaction as the change[M]CU-AUDITserverS1
GSSO-FR-084EvenimentGsso is append-only: no update/delete in repository; database trigger rejects UPDATE/DELETE[M]CU-AUDIT, NFRQ65serverS1
GSSO-FR-085Hash chain per realm (hashPrecedent, hash SHA-256) and a verification endpoint[M]NEWserverS2
GSSO-FR-086Forwarding of every event to GLog with retry and receipt id[M]CU-AUDITserverS2
GSSO-FR-087Back-fill from the Keycloak events API when the stream had a gap[M]NEWserverS2
GSSO-FR-088Event list with filters (type, actor, realm, client, IP, time range) and detail view[M]DESwebS2
GSSO-FR-089Publication of gsso.access-revoked.v1 and gsso.user-changed.v1 for consumers[M]CAP-GSSO-04serverS2
GSSO-FR-090Security alerts through GNotify: brute-force lockout of an admin, login from new country for admins, grant of a GSSO_* role, reconciler failure[REC]NFRQ65serverS2
IDRequirementPriSourceComponentPhase
GSSO-FR-091Dashboard KPIs: realms, clients (OIDC/SAML), users (delta today), active sessions[M]DESserver, webS2
GSSO-FR-092Logins over 24 h in 2-hour buckets, success vs failure[M]DESserver, webS2
GSSO-FR-093Recent security events (last 20) with actor, text, realm, IP, time[M]DESwebS2
GSSO-FR-094Authentication-method mix over 24 h (password, OTP, WebAuthn, MPass/eID, app-to-app)[M]DESserver, webS2
GSSO-FR-095Access report: who holds which role on which platform (filter by platform, org unit), CSV/PDF[REC]NFRQ56server, webS2
GSSO-FR-096Dormant-account report: users with no login in N days and holding roles[REC]NEWserver, webS5

10. App API and integration kit — FR-API

Section titled “10. App API and integration kit — FR-API”
IDRequirementPriSourceComponentPhase
GSSO-FR-097admin zone API covering every console function; OpenAPI published[M]CU-API-003serverS1
GSSO-FR-098app zone API with client credentials and scope gsso:app; each app sees only its own platform[M]CAP-GSSO-06serverS3
GSSO-FR-099App self-registration: create/update its platform, clients and roles (when the app’s client is flagged)[M]CAP-GSSO-06serverS3
GSSO-FR-100User lookup by sub, username, e-mail or IDNP (IDNP only for clients allowed by the DPO)[M]CAP-GSSO-03, crmserverS3
GSSO-FR-101User status and platform roles query (GET /api/v1/app/utilizatori/{sub}/roluri)[M]CAP-GSSO-03serverS3
GSSO-FR-102Terminate a user’s sessions (DELETE /api/v1/app/utilizatori/{sub}/sesiuni)[M]CAP-GSSO-03serverS3
GSSO-FR-103Users holding a role (GET /api/v1/app/roluri/{cod}/utilizatori), paged; used e.g. by gFlow candidate resolution[M]gflowserverS3
GSSO-FR-104gsso-spring-boot-starter: resource-server validation (issuer, JWKS, audience), roles → authorities with alias map, GssoPrincipal, client-credentials and token-exchange clients, revocation deny-list, Keycloak health indicator, Testcontainers helper[M]GSSO-ADR-009starterS3
GSSO-FR-105@gstack/gsso-angular: PKCE or BFF mode, role guard and directive, silent refresh, single logout, locale sync[M]GSSO-ADR-009ngS3
GSSO-FR-106Onboarding runbook and checklist (report 03 §8) and a sample app[M]NEWopsS3
GSSO-FR-107Kafka SASL OAUTHBEARER configuration helper for service clients[REC]CAP-GSSO-01starterS3
GSSO-FR-108Terraform/OpenTofu or CLI (gsso-cli) for platform onboarding from CI[REC]CAP-GSSO-06opsS5
IDRequirementPriSourceComponentPhase
GSSO-FR-109GDS layout as in the design: side bar with sections Identity (Dashboard, Realms, Applications) and Access (Users, Roles, Authentication), plus Governance (Platforms, Grants, Sync, Events)[M]DESwebS1
GSSO-FR-110Language switch RO/RU/EN in the header; all labels translated; domain terms Romanian[M]NFRQ38webS1
GSSO-FR-111Context-aware “Create” action per screen (realm, client, user, role, grant) opening a form drawer[M]DESwebS1
GSSO-FR-112Responsive layout down to 360 px with the collapsible side bar (as the design breakpoints 880/480 px)[M]DES, NFRQ39webS1
GSSO-FR-113Tables with filter, sort, pagination and empty states; destructive actions require confirmation with the object name[M]NEWwebS1
GSSO-FR-114Screens and actions hidden or disabled according to the admin’s GSSO role and realm scope; the backend enforces the same[M]NFRQ56web, serverS1
GSSO-FR-115Toast feedback and sync-status badges after every change (pending → in sync)[M]DESwebS1
GSSO-FR-116Accessibility WCAG 2.1 AA (keyboard, focus, contrast, labels)[M]NFRQ39webS1
IDRequirementTargetVerification
GSSO-NFR-PERF-001Login (password, existing user) end-to-end at the Keycloakp95 < 500 ms at 50 logins/sload test
GSSO-NFR-PERF-002Console list endpoints (users, grants, events; 50 rows)p95 < 800 ms with 100 000 users, 1 M eventsload test (NFRQ20)
GSSO-NFR-PERF-003Catalog change → in Keycloakp95 < 2 s, p99 < 10 sIT timing
GSSO-NFR-PERF-004Kafka event → visible in consolep95 < 5 sIT timing
GSSO-NFR-PERF-005Token validation overhead in the starter (cached JWKS)< 2 ms per requestmicrobenchmark
IDRequirementTarget
GSSO-NFR-CAP-001Staff users in gstack20 000
GSSO-NFR-CAP-002Citizen users in cetatean1 000 000
GSSO-NFR-CAP-003Concurrent SSO sessions10 000
GSSO-NFR-CAP-004Platforms / clients / roles / active grants100 / 1 000 / 2 000 / 200 000

14. Availability and continuity — NFR-AVL

Section titled “14. Availability and continuity — NFR-AVL”
IDRequirementTarget
GSSO-NFR-AVL-001Keycloak (login, token, JWKS) availability99.9 % monthly (NFRQ availability)
GSSO-NFR-AVL-002GSSO console and API availability99.5 % monthly
GSSO-NFR-AVL-003Logins and token issuance do not depend on gsso, Kafka or GLog being upverified by chaos test
GSSO-NFR-AVL-004RPO / RTO Keycloak database15 min / 1 h
GSSO-NFR-AVL-005RPO / RTO GSSO database1 h / 4 h; catalog rebuildable by adoption
GSSO-NFR-AVL-006TLS certificate expiry monitored with alert 21 days beforealert test
IDRequirement
GSSO-NFR-SEC-001OWASP ASVS L2 for console, gateway and API; OWASP Top 10 (NFRQ56/57)
GSSO-NFR-SEC-002Tokens signed RS256 (or ES256); key rotation every 90 days with overlap; HS* not allowed
GSSO-NFR-SEC-003The SPA never holds tokens (BFF); session cookie HttpOnly, Secure, SameSite=Lax; CSRF protection
GSSO-NFR-SEC-004gsso-reconciler credentials only in the secret store; its permissions limited to manage-realm, manage-users, manage-clients, view-events of managed realms (no master admin)
GSSO-NFR-SEC-005No secret in git; client secrets shown once; secrets encrypted at rest in GSSO DB if stored at all (prefer not stored)
GSSO-NFR-SEC-006IDNP encrypted at rest in the projection, masked in UI unless role GSSO_IDNP_VIEW
GSSO-NFR-SEC-007Security headers (CSP, HSTS, X-Frame-Options, Referrer-Policy) on gateway and Keycloak themes (NFRQ56)
GSSO-NFR-SEC-008Admin console client: MFA mandatory, session idle 15 min
GSSO-NFR-SEC-009SAST, SCA, secrets scanning and SBOM in CI (/gsast), DAST baseline (/gtest) — NFRQ90/91
GSSO-NFR-SEC-010Rate limiting on app API (per client) and on login endpoints at the ingress
IDRequirement
GSSO-NFR-TEN-001Every GSSO table row carries realm; every query from a realm-scoped admin is filtered server-side
GSSO-NFR-TEN-002An app’s gsso:app client can read and change only its own platform’s objects
GSSO-NFR-TEN-003Tests prove that no endpoint leaks another realm’s or platform’s data (authorization matrix probe)
IDRequirement
GSSO-NFR-OBS-001/health/live, /health/ready (DB, Kafka, Keycloak), /metrics (Prometheus), /info on gsso and gsso-gateway; Keycloak /health and /metrics enabled
GSSO-NFR-OBS-002Metrics: sync jobs by state, reconcile duration, drift count, event lag, GLog forwarding lag, logins/failures per realm
GSSO-NFR-OBS-003Structured JSON logs with trace id; no tokens, secrets or IDNP in logs (NFRQ35/50)
GSSO-NFR-OBS-004Alerts: reconciler failed, event lag > 5 min, Keycloak down, certificate expiry, error rate
IDRequirement
GSSO-NFR-OPS-001One-command local stack (docker compose up) and documented demo-host deployment
GSSO-NFR-OPS-002Helm chart for the Kubernetes target
GSSO-NFR-OPS-003Keycloak database backup daily + before every upgrade; restore tested quarterly
GSSO-NFR-OPS-004Keycloak upgrade gated by the realm baseline + reconciler integration test suite against the new version
GSSO-NFR-OPS-005Runbooks: takeover, upgrade, key rotation, certificate renewal, break-glass, restore

19. Compatibility and standards — NFR-CMP

Section titled “19. Compatibility and standards — NFR-CMP”
IDRequirement
GSSO-NFR-CMP-001OpenID Connect Core 1.0, OAuth 2.1 practices (PKCE, no implicit), RFC 8693, RFC 7807, SAML 2.0
GSSO-NFR-CMP-002GovStack API standard: api/v1 zones, health endpoints, OpenAPI, Idempotency-Key on POST (checked by api_audit.py)
GSSO-NFR-CMP-003DEV-PLAYBOOK §2 stack, versions as generated by JHipster 9.1.0
GSSO-NFR-CMP-004Keycloak 26.6.x; extensions built against the same SPI version

20. Data protection and retention — NFR-DATA

Section titled “20. Data protection and retention — NFR-DATA”
IDRequirement
GSSO-NFR-DATA-001Personal data minimised to: username, name, e-mail, IDNP (optional), org unit, locale
GSSO-NFR-DATA-002Events retained 90 days in GSSO, then purged (partition drop); GLog keeps the trail per its policy
GSSO-NFR-DATA-003User deletion propagates: projection purged, actor references replaced by sub

21. Consumer capability requests → requirements

Section titled “21. Consumer capability requests → requirements”
CAPRequestGSSO requirementsPhase
CAP-GSSO-01Corporate realm; confidential crm-gateway; one service client per microservice; Kafka OAUTHBEARER; GDocs/GLog clients; locale; UUID subFR-001, 012, 018, 020, 032, 033, 107S1–S3
CAP-GSSO-02AD/LDAP federation, TOTP MFA per roleFR-059, 064S2
CAP-GSSO-03Session list and forced termination via admin API; user status and rolesFR-029, 100, 101, 102S1, S3
CAP-GSSO-04Revocation ≤ 60 s; org-unit claimsFR-043, 053..055, 089; GSSO-ADR-013S2
CAP-GSSO-06Automatable client provisioningFR-011, 098, 099, 108S3, S5
CAP-GSSO-07Token exchange RFC 8693FR-019; GSSO-ADR-012S3

22. Universal requirements (CU-*) → requirements

Section titled “22. Universal requirements (CU-*) → requirements”
CUStatus for GSSORequirements
CU-AUTH-001 (authentication)Provided by GSSO to all apps; console uses itFR-057..070; NFR-SEC-002, 003, 008
CU-AUTH-002 (signature)N/A — MSign / gsso_mob—
CU-AUTH-003 (sessions)ApplicableFR-029, 062, 102; GSSO-ADR-013
CU-RBAC-001..003Applicable — GSSO is the RBAC source for all appsFR-016, 037..052, 114
CU-AUDIT-001..003Applicable, through GLogFR-081..090
CU-OBS-001..004ApplicableNFR-OBS-001..004
CU-API-003..006Applicable — mandatoryFR-097, 098; NFR-CMP-002
CU-MSG-001Applicable (Kafka, idempotent consumers)FR-081, 082, 089
CU-DATA-001..003ApplicableNFR-DATA-001..003, NFR-AVL-004/005
CU-DEPLOYApplicableNFR-OPS-001..005

23. NFRQ (caiet de sarcini) → requirements

Section titled “23. NFRQ (caiet de sarcini) → requirements”
NFRQGSSO
NFRQ20–22 performanceNFR-PERF-001..005
NFRQ35/50/51 loggingFR-081..090, NFR-OBS-003
NFRQ38 multilingualFR-066, 110
NFRQ39 accessibilityFR-112, 116
NFRQ40 unified design (GDS)FR-066, 109
NFRQ56–66 securityFR-013, 014, 040, 041, 059..062, NFR-SEC-*
NFRQ90–93 testing and acceptanceNFR-SEC-009, report 04 §12, test-scenarios.md