scim

package
v1.15.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 10, 2026 License: MIT Imports: 11 Imported by: 0

Documentation

Overview

Package scim is the SCIM 2.0 wire format (RFC 7643, RFC 7644) AuthKit speaks both ways: the User resource, list and error messages, bulk requests, discovery documents, the filter subset its service provider answers, and the client its provisioning pushes with.

Index

Constants

View Source
const (
	SchemaUser                  = "urn:ietf:params:scim:schemas:core:2.0:User"
	SchemaListResponse          = "urn:ietf:params:scim:api:messages:2.0:ListResponse"
	SchemaError                 = "urn:ietf:params:scim:api:messages:2.0:Error"
	SchemaBulkRequest           = "urn:ietf:params:scim:api:messages:2.0:BulkRequest"
	SchemaBulkResponse          = "urn:ietf:params:scim:api:messages:2.0:BulkResponse"
	SchemaServiceProviderConfig = "urn:ietf:params:scim:schemas:core:2.0:ServiceProviderConfig"
	SchemaResourceType          = "urn:ietf:params:scim:schemas:core:2.0:ResourceType"
	SchemaSchema                = "urn:ietf:params:scim:schemas:core:2.0:Schema"
)

Schema URNs.

View Source
const MaxResults = 200

MaxResults caps one page of AuthKit's GET /Users.

View Source
const MediaType = "application/scim+json"

MediaType is SCIM's content type.

Variables

View Source
var ErrInvalidFilter = errors.New("scim: invalid filter")

ErrInvalidFilter is a filter outside the subset; its message is the response's detail.

Functions

func IsStatus

func IsStatus(err error, status int) bool

IsStatus reports whether err is a StatusError with status.

func LocationID

func LocationID(location string) string

LocationID is the last path segment of a resource location.

Types

type Attribute

type Attribute struct {
	Name          string      `json:"name"`
	Type          string      `json:"type"`
	MultiValued   bool        `json:"multiValued"`
	Description   string      `json:"description,omitempty"`
	Required      bool        `json:"required"`
	CaseExact     bool        `json:"caseExact"`
	Mutability    string      `json:"mutability"`
	Returned      string      `json:"returned"`
	Uniqueness    string      `json:"uniqueness"`
	SubAttributes []Attribute `json:"subAttributes,omitempty"`
}

Attribute describes one attribute of a schema.

type AuthScheme

type AuthScheme struct {
	Type        string `json:"type"`
	Name        string `json:"name"`
	Description string `json:"description"`
	SpecURI     string `json:"specUri,omitempty"`
	Primary     bool   `json:"primary,omitempty"`
}

AuthScheme is how a client authenticates.

type BulkOperation

type BulkOperation struct {
	Method string `json:"method"`
	BulkID string `json:"bulkId,omitempty"`
	Path   string `json:"path"`
	Data   any    `json:"data,omitempty"`
}

BulkOperation is one operation of a bulk request.

type BulkRequest

type BulkRequest struct {
	Schemas      []string        `json:"schemas"`
	FailOnErrors *int            `json:"failOnErrors,omitempty"`
	Operations   []BulkOperation `json:"Operations"`
}

BulkRequest is a bulk request (RFC 7644 §3.7).

type BulkResponse

type BulkResponse struct {
	Schemas    []string     `json:"schemas"`
	Operations []BulkResult `json:"Operations"`
}

BulkResponse answers a bulk request.

type BulkResult

type BulkResult struct {
	Location string          `json:"location,omitempty"`
	Method   string          `json:"method,omitempty"`
	BulkID   string          `json:"bulkId,omitempty"`
	Status   Status          `json:"status"`
	Response json.RawMessage `json:"response,omitempty"`
}

BulkResult is one operation's outcome. Response holds an error's detail.

type BulkSupport

type BulkSupport struct {
	Supported      bool `json:"supported"`
	MaxOperations  int  `json:"maxOperations"`
	MaxPayloadSize int  `json:"maxPayloadSize"`
}

BulkSupport is the bulk feature and its limits.

type Client

type Client struct {
	Base string
	HTTP *http.Client
}

Client calls a SCIM service provider at Base (".../scim/v2") through HTTP, which carries the credential.

func (*Client) Bulk

func (c *Client) Bulk(ctx context.Context, ops []BulkOperation) (BulkResponse, error)

Bulk sends one bulk request; per-operation failures are in the response.

func (*Client) Create

func (c *Client) Create(ctx context.Context, u User) (User, error)

Create creates a user and returns it as stored, with the provider's id.

func (*Client) Delete

func (c *Client) Delete(ctx context.Context, id string) error

Delete deletes the user id; one already gone is no error.

func (*Client) FindByExternalID

func (c *Client) FindByExternalID(ctx context.Context, id string) (User, bool, error)

FindByExternalID returns the provider's user whose externalId is id.

func (*Client) Get

func (c *Client) Get(ctx context.Context, id string) (User, error)

Get reads the user id.

func (*Client) List

func (c *Client) List(ctx context.Context, startIndex, count int) (ListResponse[User], error)

List reads one page of users, startIndex 1-based.

func (*Client) Replace

func (c *Client) Replace(ctx context.Context, id string, u User) error

Replace replaces the user id.

func (*Client) ServiceProviderConfig

func (c *Client) ServiceProviderConfig(ctx context.Context) (ServiceProviderConfig, error)

ServiceProviderConfig reads the provider's features and limits.

type Email

type Email struct {
	Value   string `json:"value"`
	Primary bool   `json:"primary,omitempty"`
}

Email is one of the User's addresses.

type Error

type Error struct {
	Schemas  []string `json:"schemas"`
	Status   string   `json:"status"`
	ScimType string   `json:"scimType,omitempty"`
	Detail   string   `json:"detail,omitempty"`
}

Error is an error response (RFC 7644 §3.12). Status is the HTTP status as a string, as the RFC's examples send it.

func NewError

func NewError(status int, scimType, detail string) Error

NewError is an error response for status.

type Filter

type Filter struct {
	IDs, UserNames, Emails []string
}

Filter is the filter subset AuthKit's service provider answers: equality on id, userName or emails.value, joined by "or". A user matches when it matches any term.

func ParseFilter

func ParseFilter(expr string) (Filter, error)

ParseFilter parses expr: `attr eq "value"` terms joined by "or", attribute names and operators matched without regard to case (RFC 7644 §3.4.2.2).

type FilterSupport

type FilterSupport struct {
	Supported  bool `json:"supported"`
	MaxResults int  `json:"maxResults"`
}

FilterSupport is the filter feature and its result cap.

type ListResponse

type ListResponse[T any] struct {
	Schemas      []string `json:"schemas"`
	TotalResults int      `json:"totalResults"`
	StartIndex   int      `json:"startIndex"`
	ItemsPerPage int      `json:"itemsPerPage"`
	Resources    []T      `json:"Resources"`
}

ListResponse is a query's page (RFC 7644 §3.4.2).

type Meta

type Meta struct {
	ResourceType string     `json:"resourceType,omitempty"`
	Created      *time.Time `json:"created,omitempty"`
	LastModified *time.Time `json:"lastModified,omitempty"`
	Location     string     `json:"location,omitempty"`
}

Meta is a resource's metadata.

type Name

type Name struct {
	Formatted string `json:"formatted,omitempty"`
}

Name is the User's name; AuthKit keeps only the display form.

type ResourceType

type ResourceType struct {
	Schemas     []string `json:"schemas"`
	ID          string   `json:"id"`
	Name        string   `json:"name"`
	Endpoint    string   `json:"endpoint"`
	Description string   `json:"description,omitempty"`
	Schema      string   `json:"schema"`
	Meta        *Meta    `json:"meta,omitempty"`
}

ResourceType describes one resource endpoint (RFC 7643 §6).

type SchemaDoc

type SchemaDoc struct {
	Schemas     []string    `json:"schemas,omitempty"`
	ID          string      `json:"id"`
	Name        string      `json:"name"`
	Description string      `json:"description,omitempty"`
	Attributes  []Attribute `json:"attributes"`
	Meta        *Meta       `json:"meta,omitempty"`
}

SchemaDoc describes a schema's attributes (RFC 7643 §7).

func UserSchema

func UserSchema() SchemaDoc

UserSchema is the part of the core User schema AuthKit serves.

type ServiceProviderConfig

type ServiceProviderConfig struct {
	Schemas               []string      `json:"schemas"`
	DocumentationURI      string        `json:"documentationUri,omitempty"`
	Patch                 Supported     `json:"patch"`
	Bulk                  BulkSupport   `json:"bulk"`
	Filter                FilterSupport `json:"filter"`
	ChangePassword        Supported     `json:"changePassword"`
	Sort                  Supported     `json:"sort"`
	ETag                  Supported     `json:"etag"`
	AuthenticationSchemes []AuthScheme  `json:"authenticationSchemes"`
	Meta                  *Meta         `json:"meta,omitempty"`
}

ServiceProviderConfig is the discovery document of RFC 7643 §5.

type Status

type Status int

Status is an HTTP status a SCIM peer sent as a JSON string or number.

func (*Status) UnmarshalJSON

func (s *Status) UnmarshalJSON(b []byte) error

type StatusError

type StatusError struct {
	Status   int
	ScimType string
	Detail   string
}

StatusError is a response with a status the call did not expect.

func ErrorOf

func ErrorOf(status int, response []byte) *StatusError

ErrorOf is the StatusError a failed operation's status and response describe.

func (*StatusError) Error

func (e *StatusError) Error() string

type Supported

type Supported struct {
	Supported bool `json:"supported"`
}

Supported is a feature a service provider has or lacks.

type User

type User struct {
	Schemas     []string `json:"schemas"`
	ID          string   `json:"id,omitempty"`
	ExternalID  string   `json:"externalId,omitempty"`
	UserName    string   `json:"userName"`
	Name        *Name    `json:"name,omitempty"`
	DisplayName string   `json:"displayName,omitempty"`
	Emails      []Email  `json:"emails,omitempty"`
	Active      *bool    `json:"active,omitempty"`
	Meta        *Meta    `json:"meta,omitempty"`
}

User is the core User resource, as much of it as AuthKit sends and reads.

func (User) PrimaryEmail

func (u User) PrimaryEmail() string

PrimaryEmail is the primary address, else the first; "" without one.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL