SCIM: Disable auto assign organization if the user has been provisioned (#101307)

* Add isProvisioned field to model

* Add new isProvisioned column to migration

* Disable auto assignment to organization if the user is provisioned

* add annotation to user model

* add annotation to user models

* Remove IsProvisioned field from Identity

* Move new field assignenment and add default value

* Update annotations for user query results

* Remove isProvisioned from identity

* Add new column to test

* Resolve user from identity at SyncOrgHook
This commit is contained in:
linoman
2025-03-03 17:51:23 +01:00
committed by GitHub
parent 165bca6417
commit b7a0aeeb0d
6 changed files with 27 additions and 2 deletions
@@ -50,6 +50,16 @@ func (s *OrgSync) SyncOrgRolesHook(ctx context.Context, id *authn.Identity, _ *a
return nil
}
// ignore org syncing if the user is provisioned
usr, err := s.userService.GetByID(ctx, &user.GetUserByIDQuery{ID: userID})
if err != nil {
ctxLogger.Error("Failed to get user from provided identity", "error", err)
return nil
}
if usr.IsProvisioned {
return nil
}
ctxLogger.Debug("Syncing organization roles", "extOrgRoles", id.OrgRoles)
// don't sync org roles if none is specified
if len(id.OrgRoles) == 0 {