Skip to content

Adopt scim2-models ScimProvider and follow the service configuration - #21

Merged
azmeuk merged 16 commits into
mainfrom
overhaul
Sep 25, 2026
Merged

azmeuk merged 16 commits into
mainfrom
overhaul

Conversation

@azmeuk

@azmeuk azmeuk commented Sep 25, 2026

Copy link
Copy Markdown
Member

scim2-server now describes the service with the ScimProvider of scim2-models instead of its own registry, and derives its behaviour from the ServiceProviderConfig it publishes.

  • PUT replaces the resource (RFC 7644 §3.5.1); an omitted password is kept.
  • The page size is filter.maxResults (1000 by default) instead of a hardcoded 50.
  • PATCH, filtering and sorting answer 501 when the configuration does not support them;
  • /Bulk answers 501 instead of 500.
  • etag.supported drives the ETag header, meta.version and the conditional headers, which follow the evaluation order of RFC 7232.
  • Uniqueness holds among the resources sharing a schema (RFC 7643 erratum 8279), so several resource types can serve one schema, such as /Users and /Admins.
  • The CLI takes --service-provider-config.

The in-memory backend derived them from the registered schemas. It now reads
the Uniqueness annotations of the model, extensions included. A missing unique
value no longer crashes the check nor clashes, and case-insensitive values are
compared with Unicode case folding.
meta.resourceType carries the name of the resource type, per RFC 7643 §3.1,
while the in-memory backend compared it with the resource type id. With an id
differing from the name, created resources could not be read, searched or
deleted, and their uniqueness was never checked.
The sort moves to scim2-models, which reads the sort key the way the filters
do: case exactness from the schema, extension attributes, the primary entry of
a multi-valued attribute, and missing values last.
scim2-models now provides ScimProvider, the description of a SCIM service.
The WSGI application takes another name to avoid confusing the two.
The backend no longer knows the ScimProvider: its methods take the
ResourceType instead of its id, and SCIMApplication holds the provider.
If-Match is evaluated first and its failure answers 412 whatever the method,
a GET no longer answers 304 to it. A failed If-None-Match answers 304 to a GET
and 412 otherwise. DELETE now honours both headers, and a 304 carries the ETag.
RFC 7643 erratum 8279 makes a server-unique value unique among the resources
using the schema that declares the attribute, whatever their resource type.
Two resource types serving the same schema, such as /Users and /Admins, keep
disjoint resources but can no longer hold the same userName.
@azmeuk
azmeuk merged commit 47187d5 into main Sep 25, 2026
8 checks passed
@azmeuk
azmeuk deleted the overhaul branch September 25, 2026 21:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant