diff --git a/crates/common/src/cache/invalidate.rs b/crates/common/src/cache/invalidate.rs index 94772fd..0b47bc4 100644 --- a/crates/common/src/cache/invalidate.rs +++ b/crates/common/src/cache/invalidate.rs @@ -119,6 +119,10 @@ impl CacheInvalidationBuilder { || (current.sub_addressing != new.sub_addressing) || (current.allow_relaying != new.allow_relaying) || (current.is_enabled != new.is_enabled) + // inbuxa: SCIM-60, the flag is cached as DOMAIN_FLAG_SCIM, + // so turning SCIM's authority on or off has to take effect + // without a restart + || (current.allow_scim_provisioning != new.allow_scim_provisioning) { self.invalidate(CacheInvalidation::Domain(id)); } diff --git a/docs/spec/features/scim.md b/docs/spec/features/scim.md index 0cf1468..1ace14f 100644 --- a/docs/spec/features/scim.md +++ b/docs/spec/features/scim.md @@ -888,6 +888,12 @@ with errors only for its generated non-address `userName`. `lastModified`): scim2-client builds its models from it. - The five `scim.*` events (SCIM-54) have ids 637 to 641, the fork's own, and are in the packaged schema's event list. + - `allowScimProvisioning` is cached with the domain, so it joins the + fields whose change drops that cache entry + (`crates/common/src/cache/invalidate.rs`); without that, SCIM-60's + "takes effect without a restart" held only until something else + evicted the domain. Found on 2026-09-19 by the two acceptance checks + below. - **Known limits, not requirements of this spec:** - Ending open sessions on suspension (SCIM-52) covers subscriptions to changes (IMAP IDLE, JMAP event streams and WebSockets), and only on the diff --git a/tests/src/scim/acceptance.rs b/tests/src/scim/acceptance.rs index 29379e2..73e95a8 100644 --- a/tests/src/scim/acceptance.rs +++ b/tests/src/scim/acceptance.rs @@ -65,6 +65,8 @@ pub async fn test(test: &TestServer, scim: &ScimTest) { deletion(test, scim).await; adoption(test, scim).await; tenants(test, scim).await; + authority(test, scim, closed_id).await; + rate_limits(test, scim).await; admin .registry_destroy(ObjectType::Domain, [closed_id])