Tree:
471c96536b
cached-config-operations
main
revert-7033-patch-1
test_dylint
various_fixes
0.10.0
0.11.0
0.12.0
0.13.0
0.9.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.14
1.14.1
1.14.2
1.15.0
1.15.1
1.16.0
1.16.1
1.16.2
1.16.3
1.17.0
1.18.0
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.23.0
1.23.1
1.24.0
1.25.0
1.25.1
1.25.2
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.29.2
1.3.0
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.31.0
1.32.0
1.32.1
1.32.2
1.32.3
1.32.4
1.32.5
1.32.6
1.32.7
1.33.0
1.33.1
1.33.2
1.34.0
1.34.1
1.34.2
1.34.3
1.35.0
1.35.1
1.35.2
1.35.3
1.35.4
1.35.5
1.35.6
1.35.7
1.35.8
1.36.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.8.0
1.9.0
1.9.1
${ noResults }
2 Commits (471c96536be213d65d639b1a13eca0d64e2bb436)
| Author | SHA1 | Message | Date |
|---|---|---|---|
|
|
471c96536b |
docs(scim): document reinstatement exposure and add TODOS backlog
Note in README and design that lossless restore makes revocation IdP-authoritative: a member revoked in the vault is re-activated on the next sync if the IdP still shows them active, and a leaked token can reinstate any previously-confirmed member. Document token-management audit events and the omitted-vs-empty members and externalId-uniqueness semantics. Add TODOS.md tracking the deferred follow-ups (config-gated denial tests, live Entra validation, coverage edges, perf backlog, upstream ip_constant lints). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
3 days ago |
|
|
f67e7641e3 |
Make useScim dynamic and add SCIM documentation
Phase 4 of the SCIM v2 implementation: - The two hardcoded 'useScim: false' sites in organization.rs now report CONFIG.scim_enabled(), so clients see the truthful capability flag. manageScim stays false: management is via the /api endpoints, not the web vault's enterprise UI. - docs/scim/README.md: operator setup, token generation/rotation, the full Entra ID enterprise-app walkthrough with attribute mappings, and the documented deviations (DELETE=revoke, no role sync, no post-create rename sync). - docs/scim/design.md: architecture and security model with four mermaid diagrams (provision/deprovision sequence, membership state machine including the -128/-127/-126 revocation offsets, the guard decision flow with uniform-401 sinks, and the module map), the sha256-vs-argon2 rationale, and the E2EE constraint analysis explaining why confirm cannot be server-side. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
4 days ago |