Every SCIM operation becomes the x:Account get, query or set JMAP makes, as the service principal, so permissions, tenant scope and limits, address uniqueness and account destruction are enforced in one place. Discovery is anonymous; everything else takes an API key as a bearer token and nothing else. Domains open to SCIM carry a flag in the domain cache. Filters take eq and and, answered from the account indexes, with unindexed attributes checked on at most 200 candidates. Cursors are stateless, HMAC-sealed under the server key. PATCH applies to the resource in memory and saves it as a PUT, so it is all or nothing. Groups get an address from their display name on the principal's domain; membership is written on each user. Every write emits one of five new scim.* events (ids 637 to 641), also added to the packaged schema. The helpers the surviving SCIM suites import are rebuilt from the spec; scim_tests runs the new acceptance suite and the surviving tenant isolation suite, and both pass.
30 lines
591 B
Rust
30 lines
591 B
Rust
/*
|
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
|
*
|
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
|
*/
|
|
|
|
#![warn(clippy::large_futures)]
|
|
|
|
pub mod api;
|
|
pub mod auth;
|
|
pub mod branding; // inbuxa: branding
|
|
pub mod form;
|
|
pub mod live; // inbuxa: monitoring (MON-20 to MON-24)
|
|
pub mod request;
|
|
pub mod scim; // inbuxa: SCIM 2.0 provisioning
|
|
|
|
use common::Inner;
|
|
use std::sync::Arc;
|
|
|
|
#[derive(Clone)]
|
|
pub struct HttpSessionManager {
|
|
pub inner: Arc<Inner>,
|
|
}
|
|
|
|
impl HttpSessionManager {
|
|
pub fn new(inner: Arc<Inner>) -> Self {
|
|
Self { inner }
|
|
}
|
|
}
|