ADORSYS-GIS / ADORSYS-GIS/lightbridge-authz
[Story]: SCIM conformance testing against Okta and Entra ID
- Lingua principale
- Rust
- Stelle
- 0
- Fork
- 1
- Merge medio
- 7h 7m
- PR unite (30g)
- 237
Descrizione
## Summary
Run and document formal SCIM conformance testing against Okta and Microsoft Entra ID, the two IdPs enterprise buyers overwhelmingly standardize on.
## Intent / Source of truth
A SCIM implementation that has never been run against a real IdP's provisioning connector routinely breaks on vendor-specific quirks (attribute casing, pagination cursors, PATCH semantics); this must be proven before any enterprise pilot. Part of [Epic] SCIM 2.0 provisioning and de-provisioning.
## Scope
- [ ] Okta SCIM test-tenant walkthrough: create, update, group sync, deactivate
- [ ] Entra ID provisioning test connection walkthrough covering the same flows
- [ ] Written conformance report with any vendor-specific workarounds documented
- [ ] Regression test suite capturing the discovered edge cases
## Out of scope
- Conformance against other IdPs (Ping, OneLogin, etc.) unless a customer requires it
## Verification
Both IdP test connections show green/successful provisioning cycles end-to-end (create → update → group change → deactivate), captured in the conformance report with screenshots/logs.
## Risk assessment
IdP-specific quirks discovered late in a customer pilot damage trust; front-loading this testing is the whole point of the story.
## AI Usage Declaration
Drafted with AI assistance during the 2026-08-13 cross-repo backlog consolidation and enterprise-readiness research. A human owns intent, verification and consequences.
Guida per i contributori
Apri la guida per i contributori
Direzione di ricerca
Start with the Okta SCIM test-tenant walkthrough and the Entra ID provisioning test connection, exercising create, update, group change or sync, and deactivate. Record successful end-to-end cycles in the conformance report with screenshots or logs, document vendor-specific workarounds, and capture discovered edge cases in the regression test suite.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- rust
- Ambito
- authentication, authorization, documentation, testing
- Tipo di issue
- Funzionalità
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Stato di attività
- Tranquilla
- Chiarezza
- Abbastanza chiara
- Idoneità per principianti
- 35/100