Tree:
b1d0261800
cached-config-operations
main
revert-7033-patch-1
test_dylint
various_fixes
0.10.0
0.11.0
0.12.0
0.13.0
0.9.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.14
1.14.1
1.14.2
1.15.0
1.15.1
1.16.0
1.16.1
1.16.2
1.16.3
1.17.0
1.18.0
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.23.0
1.23.1
1.24.0
1.25.0
1.25.1
1.25.2
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.29.2
1.3.0
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.31.0
1.32.0
1.32.1
1.32.2
1.32.3
1.32.4
1.32.5
1.32.6
1.32.7
1.33.0
1.33.1
1.33.2
1.34.0
1.34.1
1.34.2
1.34.3
1.35.0
1.35.1
1.35.2
1.35.3
1.35.4
1.35.5
1.35.6
1.35.7
1.35.8
1.36.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.8.0
1.9.0
1.9.1
${ noResults }
1 Commits (b1d026180040fae94b01bea0bcd542c0170ed1d3)
| Author | SHA1 | Message | Date |
|---|---|---|---|
|
|
b1d0261800 |
Add SCIM v2 scaffolding: per-org api key, auth guard, discovery endpoints
Groundwork for SCIM v2 provisioning (RFC 7643/7644), targeting Entra ID: - New scim_api_key table (sqlite/mysql/postgresql migrations) storing a sha256 digest of a per-organization static bearer secret. An active row doubles as per-org SCIM enablement; org deletion cleans it up. - ScimToken request guard modeled on PublicToken: pre-auth rate limiting, scim_enabled gate, token format scim_v1.<org>.<secret>, token-org vs path-org check before any DB work, constant-time digest compare with a dummy compare on miss. All failure causes log server-side and surface as one uniform SCIM-enveloped 401. - SCIM error envelope + catchers so every response under /scim (400/401/ 404/429/500) is application/scim+json. - Discovery endpoints (ServiceProviderConfig, ResourceTypes, Schemas). - Admin-session management endpoints under /api: generate/rotate (plaintext shown once), delete, and status; guarded by AdminHeaders plus password or OTP re-auth, mirroring rotate_api_key. - Config: scim_enabled (default off) and SCIM rate limiter settings. - Test infrastructure: hermetic pre-main env bootstrap (test-support crate, keeps CONFIG away from the developer's .env and data), Rocket local-client harness on temp sqlite, authz matrix asserting byte-identical 401 bodies, rate limiter drain test. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
5 days ago |