User Context Schema
The user object in the x-cwms-auth-context header contains identity and attributes retrieved from the CWMS database and the user’s JWT token.
Schema Reference
Field |
Type |
Required |
Description |
|---|---|---|---|
|
string |
yes |
Unique user identifier, typically matches username |
|
string |
yes |
CWMS username from at_sec_cwms_users table |
|
string |
no |
Email address from JWT claims |
|
string[] |
yes |
User groups from av_sec_users view |
|
string[] |
yes |
Office IDs the user belongs to |
|
string |
no |
Default office for the user |
|
string |
no |
User persona for role-based behavior |
|
string |
no |
Geographic region assignment |
|
string |
no |
User’s preferred timezone |
|
number |
no |
Shift start hour (0-23) for time-based access |
|
number |
no |
Shift end hour (0-23) for time-based access |
|
boolean |
no |
Whether the user provided valid credentials |
|
string |
no |
Authentication method used (jwt, api_key, etc.) |
|
string[] |
no |
Specific parameter IDs the user can access |
|
string |
no |
ISO 8601 date when partnership access expires |
|
TsGroupPrivilege[] |
no |
Time series group access privileges |
|
object |
no |
Additional custom attributes |
TsGroupPrivilege Schema
The ts_privileges array contains per-group access settings.
Field |
Type |
Description |
|---|---|---|
|
number |
Numeric code for the time series group |
|
string |
String identifier for the time series group |
|
string |
Access level: “read”, “write”, “read-write”, or “none” |
|
number |
Hours of embargo restriction for this group |
Persona Values
The persona field controls behavior-specific access patterns.
Persona |
Description |
|---|---|
|
Restricted to recent data (time_window applies) |
|
Full access to office data, embargo exempt |
|
Administrative access, embargo exempt |
|
System access to all offices |
|
Full system access |
Example: Authenticated User
{
"id": "m5hectest",
"username": "m5hectest",
"email": "m5hectest@example.com",
"roles": ["cwms_user", "ts_id_creator", "all_users"],
"offices": ["SWT"],
"primary_office": "SWT",
"persona": "water_manager",
"authenticated": true,
"auth_method": "jwt",
"ts_privileges": [
{
"ts_group_code": 1,
"ts_group_id": "Default",
"privilege": "read-write",
"embargo_hours": 0
},
{
"ts_group_code": 2,
"ts_group_id": "Sensitive",
"privilege": "read",
"embargo_hours": 168
}
]
}
Example: Anonymous User
{
"id": "anonymous",
"username": "anonymous",
"email": "anonymous@example.com",
"roles": [],
"offices": [],
"authenticated": false
}
Example: Dam Operator with Shift Hours
{
"id": "operator123",
"username": "operator123",
"roles": ["cwms_user", "dam_operator"],
"offices": ["SWT"],
"primary_office": "SWT",
"persona": "dam_operator",
"timezone": "America/Chicago",
"shift_start": 6,
"shift_end": 18,
"authenticated": true
}
Data Sources
User context fields are populated from multiple sources:
Source |
Fields |
|---|---|
CWMS at_sec_cwms_users |
username, offices, primary_office |
CWMS av_sec_users |
roles |
JWT token claims |
id (sub), email, preferred_username |
OPA policy decision |
persona (may be assigned by policy) |
User configuration |
timezone, shift_start, shift_end, region |