SCIM: Disable auto assign organization if the user has been provisioned (#101307)
* Add isProvisioned field to model * Add new isProvisioned column to migration * Disable auto assignment to organization if the user is provisioned * add annotation to user model * add annotation to user models * Remove IsProvisioned field from Identity * Move new field assignenment and add default value * Update annotations for user query results * Remove isProvisioned from identity * Add new column to test * Resolve user from identity at SyncOrgHook
This commit is contained in:
@@ -50,6 +50,16 @@ func (s *OrgSync) SyncOrgRolesHook(ctx context.Context, id *authn.Identity, _ *a
|
||||
return nil
|
||||
}
|
||||
|
||||
// ignore org syncing if the user is provisioned
|
||||
usr, err := s.userService.GetByID(ctx, &user.GetUserByIDQuery{ID: userID})
|
||||
if err != nil {
|
||||
ctxLogger.Error("Failed to get user from provided identity", "error", err)
|
||||
return nil
|
||||
}
|
||||
if usr.IsProvisioned {
|
||||
return nil
|
||||
}
|
||||
|
||||
ctxLogger.Debug("Syncing organization roles", "extOrgRoles", id.OrgRoles)
|
||||
// don't sync org roles if none is specified
|
||||
if len(id.OrgRoles) == 0 {
|
||||
|
||||
Reference in New Issue
Block a user