Repository navigation
test(scim): replay Okta Tier 1.5 fixtures through chi router (V2-305) - #37
Merged
Merged
Conversation
Nic-dorman
changed the base branch from
nic/v2-273-tier1.5-okta-fixtures
to
master
May 18, 2026 16:31
3 tasks
Nic-dorman
added a commit
that referenced
this pull request
May 19, 2026
The handler test suite grew past the 10m budget on PR #37 (Okta SCIM fixture replay, 11 new tests). Race detector legs hit the timeout on the sqlite matrix; non-race legs finished in ~2-3m. 15m gives headroom without masking pathological hangs. Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Adds internal/handlers/scim_okta_fixtures_test.go which: - Table-drives all 8 captured Okta fixtures through the live SCIM handler stack (create / update / deactivate / reactivate / existence check / group add / group remove / group metadata-patch no-op) - Normalizes per-run fields (timestamps, generated ids) before comparison so structurally-equivalent responses compare equal - Pre-seeds each fixture's prerequisite DB state with sentinel users + the target user so captured ids (Users/4, Groups/1) resolve Three dedicated cases prove the findings noted in the fixtures README: - TestSCIM_OktaFixture_PasswordIsIgnored: confirms indelible discards the random password Okta sends in POST /Users; verifies that a local login attempt with that captured password fails (401, not 200). - TestSCIM_OktaFixture_GroupMetadataPATCHIsNoop: confirms the no-op "replace id+displayName" PATCH Okta sends before every membership op leaves the group state unchanged. - TestSCIM_OktaFixture_FilterByValueRemove: confirms the SCIM filter path members[value eq "X"] parses correctly when Okta uses it for membership removes. All 11 tests pass on SQLite. Postgres should pass automatically via the V2-270 CI matrix since these run under internal/handlers/. Closes V2-305. Acceptance for V2-273 Tier 1.5 now complete pending merge. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Nic-dorman
force-pushed
the
nic/v2-305-okta-fixtures-replay
branch
from
May 19, 2026 09:38
967815d to
c01ec64
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
internal/handlers/scim_okta_fixtures_test.go— a Go test that table-drives all 8 captured Okta fixtures through the live SCIM handler stackWhat this proves
Every commit to indelible's SCIM code now gets checked against the real Okta wire format — without anyone needing a live tenant. This is the missing CI surface that turns the captured fixtures from documentation into a regression gate.
The 3 dedicated cases — one per finding from the rehearsal
TestSCIM_OktaFixture_PasswordIsIgnoredTestSCIM_OktaFixture_GroupMetadataPATCHIsNoopreplace id+displayNamePATCH Okta sends before every membership op leaves group state unchanged.TestSCIM_OktaFixture_FilterByValueRemovemembers[value eq "X"]filter path parses correctly when used for removes (the shape both Okta and AAD use).Implementation notes
id,value,Users/N,Groups/N,created,lastModified) get replaced with placeholders on both expected and actual before structural JSON comparison.scimTestEnv,setupSCIMTest,env.do).Stacking
This PR contains 3 commits but only the last one is unique to V2-305:
Once PR #27 and PR #36 merge, the diff collapses to just commit #3. Base is set to
nic/v2-273-tier1.5-okta-fixturesso GitHub auto-tracks the dependency chain.Test plan
go test ./internal/handlers/ -run TestSCIM_OktaFixture -v— all 11 pass locally on SQLiteV2-273 acceptance status (after this merges)
Closes V2-305.
Co-Authored-By: Claude Opus 4.7 (1M context) noreply@anthropic.com