mirror of
https://github.com/zitadel/zitadel.git
synced 2025-08-12 00:57:33 +00:00
fix(scim): add type attribute to ScimEmail (#9690)
# Which Problems Are Solved - SCIM PATCH operations for users from Entra ID for the `emails` attribute fails due to missing `type` subattribute # How the Problems Are Solved - Adds the `type` attribute to the `ScimUser` struct and sets the default value to `"work"` in the `mapWriteModelToScimUser()` method. # Additional Changes # Additional Context The SCIM handlers for POST and PUT ignore multiple emails and only uses the primary email for a given user, or falls back to the first email if none are marked as primary. PATCH operations however, will attempt to resolve the provided filter in `operations[].path`. Some services, such as Entra ID, only support patching emails by filtering for `emails[type eq "(work|home|other)"].value`, which fails with Zitadel as the ScimUser struct (and thus the generated schema) doesn't include the `type` field. This commit adds the `type` field to work around this issue, while still preserving compatibility with filters such as `emails[primary eq true].value`. - https://discord.com/channels/927474939156643850/927866013545025566/1356556668527448191 --------- Co-authored-by: Christer Edvartsen <christer.edvartsen@nav.no> Co-authored-by: Thomas Siegfried Krampl <thomas.siegfried.krampl@nav.no>
This commit is contained in:
@@ -685,6 +685,39 @@ func TestOperationCollection_Apply(t *testing.T) {
|
||||
},
|
||||
wantErr: true,
|
||||
},
|
||||
{
|
||||
name: "replace filter complex subattribute multiple emails primary value",
|
||||
op: &patch.Operation{
|
||||
Operation: patch.OperationTypeReplace,
|
||||
Path: test.Must(filter.ParsePath(`emails[primary eq true].value`)),
|
||||
Value: json.RawMessage(`"jeanie.rebecca.pendleton@example.com"`),
|
||||
},
|
||||
want: &ScimUser{
|
||||
Emails: []*ScimEmail{
|
||||
{
|
||||
Value: "jeanie.rebecca.pendleton@example.com",
|
||||
Primary: true,
|
||||
},
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "replace filter complex subattribute multiple emails type value",
|
||||
op: &patch.Operation{
|
||||
Operation: patch.OperationTypeReplace,
|
||||
Path: test.Must(filter.ParsePath(`emails[type eq "work"].value`)),
|
||||
Value: json.RawMessage(`"jeanie.rebecca.pendleton@example.com"`),
|
||||
},
|
||||
want: &ScimUser{
|
||||
Emails: []*ScimEmail{
|
||||
{
|
||||
Value: "jeanie.rebecca.pendleton@example.com",
|
||||
Primary: true,
|
||||
Type: "work",
|
||||
},
|
||||
},
|
||||
},
|
||||
},
|
||||
}
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
@@ -711,6 +744,7 @@ func TestOperationCollection_Apply(t *testing.T) {
|
||||
{
|
||||
Value: "jeanie.pendleton@example.com",
|
||||
Primary: true,
|
||||
Type: "work",
|
||||
},
|
||||
},
|
||||
PhoneNumbers: []*ScimPhoneNumber{
|
||||
|
Reference in New Issue
Block a user