Documentation
¶
Overview ¶
Package scim is the SCIM 2.0 wire format (RFC 7643, RFC 7644) AuthKit speaks both ways: the User resource, list and error messages, bulk requests, discovery documents, the filter subset its service provider answers, and the client its provisioning pushes with.
Index ¶
- Constants
- Variables
- func IsStatus(err error, status int) bool
- func LocationID(location string) string
- type Attribute
- type AuthScheme
- type BulkOperation
- type BulkRequest
- type BulkResponse
- type BulkResult
- type BulkSupport
- type Client
- func (c *Client) Bulk(ctx context.Context, ops []BulkOperation) (BulkResponse, error)
- func (c *Client) Create(ctx context.Context, u User) (User, error)
- func (c *Client) Delete(ctx context.Context, id string) error
- func (c *Client) FindByExternalID(ctx context.Context, id string) (User, bool, error)
- func (c *Client) Get(ctx context.Context, id string) (User, error)
- func (c *Client) List(ctx context.Context, startIndex, count int) (ListResponse[User], error)
- func (c *Client) Replace(ctx context.Context, id string, u User) error
- func (c *Client) ServiceProviderConfig(ctx context.Context) (ServiceProviderConfig, error)
- type Email
- type Error
- type Filter
- type FilterSupport
- type ListResponse
- type Meta
- type Name
- type ResourceType
- type SchemaDoc
- type ServiceProviderConfig
- type Status
- type StatusError
- type Supported
- type User
Constants ¶
const ( SchemaUser = "urn:ietf:params:scim:schemas:core:2.0:User" SchemaListResponse = "urn:ietf:params:scim:api:messages:2.0:ListResponse" SchemaError = "urn:ietf:params:scim:api:messages:2.0:Error" SchemaBulkRequest = "urn:ietf:params:scim:api:messages:2.0:BulkRequest" SchemaBulkResponse = "urn:ietf:params:scim:api:messages:2.0:BulkResponse" SchemaServiceProviderConfig = "urn:ietf:params:scim:schemas:core:2.0:ServiceProviderConfig" SchemaResourceType = "urn:ietf:params:scim:schemas:core:2.0:ResourceType" SchemaSchema = "urn:ietf:params:scim:schemas:core:2.0:Schema" )
Schema URNs.
const MaxResults = 200
MaxResults caps one page of AuthKit's GET /Users.
const MediaType = "application/scim+json"
MediaType is SCIM's content type.
Variables ¶
var ErrInvalidFilter = errors.New("scim: invalid filter")
ErrInvalidFilter is a filter outside the subset; its message is the response's detail.
Functions ¶
func LocationID ¶
LocationID is the last path segment of a resource location.
Types ¶
type Attribute ¶
type Attribute struct {
Name string `json:"name"`
Type string `json:"type"`
MultiValued bool `json:"multiValued"`
Description string `json:"description,omitempty"`
Required bool `json:"required"`
CaseExact bool `json:"caseExact"`
Mutability string `json:"mutability"`
Returned string `json:"returned"`
Uniqueness string `json:"uniqueness"`
SubAttributes []Attribute `json:"subAttributes,omitempty"`
}
Attribute describes one attribute of a schema.
type AuthScheme ¶
type AuthScheme struct {
Type string `json:"type"`
Name string `json:"name"`
Description string `json:"description"`
SpecURI string `json:"specUri,omitempty"`
Primary bool `json:"primary,omitempty"`
}
AuthScheme is how a client authenticates.
type BulkOperation ¶
type BulkOperation struct {
Method string `json:"method"`
BulkID string `json:"bulkId,omitempty"`
Path string `json:"path"`
Data any `json:"data,omitempty"`
}
BulkOperation is one operation of a bulk request.
type BulkRequest ¶
type BulkRequest struct {
Schemas []string `json:"schemas"`
FailOnErrors *int `json:"failOnErrors,omitempty"`
Operations []BulkOperation `json:"Operations"`
}
BulkRequest is a bulk request (RFC 7644 §3.7).
type BulkResponse ¶
type BulkResponse struct {
Schemas []string `json:"schemas"`
Operations []BulkResult `json:"Operations"`
}
BulkResponse answers a bulk request.
type BulkResult ¶
type BulkResult struct {
Location string `json:"location,omitempty"`
Method string `json:"method,omitempty"`
BulkID string `json:"bulkId,omitempty"`
Status Status `json:"status"`
Response json.RawMessage `json:"response,omitempty"`
}
BulkResult is one operation's outcome. Response holds an error's detail.
type BulkSupport ¶
type BulkSupport struct {
Supported bool `json:"supported"`
MaxOperations int `json:"maxOperations"`
MaxPayloadSize int `json:"maxPayloadSize"`
}
BulkSupport is the bulk feature and its limits.
type Client ¶
Client calls a SCIM service provider at Base (".../scim/v2") through HTTP, which carries the credential.
func (*Client) Bulk ¶
func (c *Client) Bulk(ctx context.Context, ops []BulkOperation) (BulkResponse, error)
Bulk sends one bulk request; per-operation failures are in the response.
func (*Client) FindByExternalID ¶
FindByExternalID returns the provider's user whose externalId is id.
func (*Client) ServiceProviderConfig ¶
func (c *Client) ServiceProviderConfig(ctx context.Context) (ServiceProviderConfig, error)
ServiceProviderConfig reads the provider's features and limits.
type Error ¶
type Error struct {
Schemas []string `json:"schemas"`
Status string `json:"status"`
ScimType string `json:"scimType,omitempty"`
Detail string `json:"detail,omitempty"`
}
Error is an error response (RFC 7644 §3.12). Status is the HTTP status as a string, as the RFC's examples send it.
type Filter ¶
type Filter struct {
IDs, UserNames, Emails []string
}
Filter is the filter subset AuthKit's service provider answers: equality on id, userName or emails.value, joined by "or". A user matches when it matches any term.
type FilterSupport ¶
FilterSupport is the filter feature and its result cap.
type ListResponse ¶
type ListResponse[T any] struct { Schemas []string `json:"schemas"` TotalResults int `json:"totalResults"` StartIndex int `json:"startIndex"` ItemsPerPage int `json:"itemsPerPage"` Resources []T `json:"Resources"` }
ListResponse is a query's page (RFC 7644 §3.4.2).
type Meta ¶
type Meta struct {
ResourceType string `json:"resourceType,omitempty"`
Created *time.Time `json:"created,omitempty"`
LastModified *time.Time `json:"lastModified,omitempty"`
Location string `json:"location,omitempty"`
}
Meta is a resource's metadata.
type Name ¶
type Name struct {
Formatted string `json:"formatted,omitempty"`
}
Name is the User's name; AuthKit keeps only the display form.
type ResourceType ¶
type ResourceType struct {
Schemas []string `json:"schemas"`
ID string `json:"id"`
Name string `json:"name"`
Endpoint string `json:"endpoint"`
Description string `json:"description,omitempty"`
Schema string `json:"schema"`
Meta *Meta `json:"meta,omitempty"`
}
ResourceType describes one resource endpoint (RFC 7643 §6).
type SchemaDoc ¶
type SchemaDoc struct {
Schemas []string `json:"schemas,omitempty"`
ID string `json:"id"`
Name string `json:"name"`
Description string `json:"description,omitempty"`
Attributes []Attribute `json:"attributes"`
Meta *Meta `json:"meta,omitempty"`
}
SchemaDoc describes a schema's attributes (RFC 7643 §7).
func UserSchema ¶
func UserSchema() SchemaDoc
UserSchema is the part of the core User schema AuthKit serves.
type ServiceProviderConfig ¶
type ServiceProviderConfig struct {
Schemas []string `json:"schemas"`
DocumentationURI string `json:"documentationUri,omitempty"`
Patch Supported `json:"patch"`
Bulk BulkSupport `json:"bulk"`
Filter FilterSupport `json:"filter"`
ChangePassword Supported `json:"changePassword"`
Sort Supported `json:"sort"`
ETag Supported `json:"etag"`
AuthenticationSchemes []AuthScheme `json:"authenticationSchemes"`
Meta *Meta `json:"meta,omitempty"`
}
ServiceProviderConfig is the discovery document of RFC 7643 §5.
type Status ¶
type Status int
Status is an HTTP status a SCIM peer sent as a JSON string or number.
func (*Status) UnmarshalJSON ¶
type StatusError ¶
StatusError is a response with a status the call did not expect.
func ErrorOf ¶
func ErrorOf(status int, response []byte) *StatusError
ErrorOf is the StatusError a failed operation's status and response describe.
func (*StatusError) Error ¶
func (e *StatusError) Error() string
type Supported ¶
type Supported struct {
Supported bool `json:"supported"`
}
Supported is a feature a service provider has or lacks.
type User ¶
type User struct {
Schemas []string `json:"schemas"`
ID string `json:"id,omitempty"`
ExternalID string `json:"externalId,omitempty"`
UserName string `json:"userName"`
Name *Name `json:"name,omitempty"`
DisplayName string `json:"displayName,omitempty"`
Emails []Email `json:"emails,omitempty"`
Active *bool `json:"active,omitempty"`
Meta *Meta `json:"meta,omitempty"`
}
User is the core User resource, as much of it as AuthKit sends and reads.
func (User) PrimaryEmail ¶
PrimaryEmail is the primary address, else the first; "" without one.