ADORSYS-GIS / ADORSYS-GIS/lightbridge-authz

[Story]: SCIM conformance testing against Okta and Entra ID

Open
#251 0 comments 0 reactions 0 assignees View on GitHub
user-story
Dominant language
Rust
Stars
0
Forks
1
Avg merge
7h 7m
Merged PRs (30d)
237

Description

## Summary
Run and document formal SCIM conformance testing against Okta and Microsoft Entra ID, the two IdPs enterprise buyers overwhelmingly standardize on.

## Intent / Source of truth
A SCIM implementation that has never been run against a real IdP's provisioning connector routinely breaks on vendor-specific quirks (attribute casing, pagination cursors, PATCH semantics); this must be proven before any enterprise pilot. Part of [Epic] SCIM 2.0 provisioning and de-provisioning.

## Scope
- [ ] Okta SCIM test-tenant walkthrough: create, update, group sync, deactivate
- [ ] Entra ID provisioning test connection walkthrough covering the same flows
- [ ] Written conformance report with any vendor-specific workarounds documented
- [ ] Regression test suite capturing the discovered edge cases

## Out of scope
- Conformance against other IdPs (Ping, OneLogin, etc.) unless a customer requires it

## Verification
Both IdP test connections show green/successful provisioning cycles end-to-end (create → update → group change → deactivate), captured in the conformance report with screenshots/logs.

## Risk assessment
IdP-specific quirks discovered late in a customer pilot damage trust; front-loading this testing is the whole point of the story.

## AI Usage Declaration
Drafted with AI assistance during the 2026-08-13 cross-repo backlog consolidation and enterprise-readiness research. A human owns intent, verification and consequences.

Contributor guide

Open the contributing guide

Research direction

Start with the Okta SCIM test-tenant walkthrough and the Entra ID provisioning test connection, exercising create, update, group change or sync, and deactivate. Record successful end-to-end cycles in the conformance report with screenshots or logs, document vendor-specific workarounds, and capture discovered edge cases in the regression test suite.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
authentication, authorization, documentation, testing
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.