SCIM: Disable auto assign organization if the user has been provisioned (#101307)

* Add isProvisioned field to model

* Add new isProvisioned column to migration

* Disable auto assignment to organization if the user is provisioned

* add annotation to user model

* add annotation to user models

* Remove IsProvisioned field from Identity

* Move new field assignenment and add default value

* Update annotations for user query results

* Remove isProvisioned from identity

* Add new column to test

* Resolve user from identity at SyncOrgHook
This commit is contained in:
linoman
2025-03-03 17:51:23 +01:00
committed by GitHub
parent 165bca6417
commit b7a0aeeb0d
6 changed files with 27 additions and 2 deletions
+7 -1
View File
@@ -47,6 +47,8 @@ type User struct {
Created time.Time
Updated time.Time
LastSeenAt time.Time
IsProvisioned bool `xorm:"is_provisioned"`
}
type CreateUserCommand struct {
@@ -64,6 +66,7 @@ type CreateUserCommand struct {
SkipOrgSetup bool
DefaultOrgRole string
IsServiceAccount bool
IsProvisioned bool
}
type GetUserByLoginQuery struct {
@@ -114,7 +117,8 @@ type SearchUsersQuery struct {
SortOpts []model.SortOption
Filters []Filter
IsDisabled *bool
IsDisabled *bool
IsProvisioned *bool
}
type SearchUserQueryResult struct {
@@ -137,6 +141,7 @@ type UserSearchHitDTO struct {
LastSeenAtAge string `json:"lastSeenAtAge"`
AuthLabels []string `json:"authLabels"`
AuthModule AuthModuleConversion `json:"-"`
IsProvisioned bool `json:"-" xorm:"is_provisioned"`
}
type GetUserProfileQuery struct {
@@ -161,6 +166,7 @@ type UserProfileDTO struct {
CreatedAt time.Time `json:"createdAt"`
AvatarURL string `json:"avatarUrl"`
AccessControl map[string]bool `json:"accessControl,omitempty"`
IsProvisioned bool `json:"-"`
}
// implement Conversion interface to define custom field mapping (xorm feature)