SCIM: users, groups, queries, PATCH, Bulk and cursors at /scim/v2, over x:Account (SCIM-1 to SCIM-57)
Every SCIM operation becomes the x:Account get, query or set JMAP makes, as the service principal, so permissions, tenant scope and limits, address uniqueness and account destruction are enforced in one place. Discovery is anonymous; everything else takes an API key as a bearer token and nothing else. Domains open to SCIM carry a flag in the domain cache. Filters take eq and and, answered from the account indexes, with unindexed attributes checked on at most 200 candidates. Cursors are stateless, HMAC-sealed under the server key. PATCH applies to the resource in memory and saves it as a PUT, so it is all or nothing. Groups get an address from their display name on the principal's domain; membership is written on each user. Every write emits one of five new scim.* events (ids 637 to 641), also added to the packaged schema. The helpers the surviving SCIM suites import are rebuilt from the spec; scim_tests runs the new acceptance suite and the surviving tenant isolation suite, and both pass.
This commit is contained in:
Generated
+5
@@ -3337,6 +3337,7 @@ dependencies = [
|
||||
"registry",
|
||||
"rkyv",
|
||||
"scim",
|
||||
"scim-proto",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"services",
|
||||
@@ -7417,8 +7418,11 @@ dependencies = [
|
||||
name = "scim"
|
||||
version = "0.16.22"
|
||||
dependencies = [
|
||||
"ahash",
|
||||
"base64 0.23.1",
|
||||
"common",
|
||||
"directory",
|
||||
"hmac 0.13.0",
|
||||
"http_proto",
|
||||
"hyper",
|
||||
"icu_locale",
|
||||
@@ -7428,6 +7432,7 @@ dependencies = [
|
||||
"scim-proto",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"sha2 0.11.0",
|
||||
"store",
|
||||
"trc",
|
||||
"types",
|
||||
|
||||
Reference in New Issue
Block a user