Skip to content

test(scim): replay Okta Tier 1.5 fixtures through chi router (V2-305) - #37

Merged
Nic-dorman merged 1 commit into
masterfrom
nic/v2-305-okta-fixtures-replay
May 19, 2026
Merged

Nic-dorman merged 1 commit into
masterfrom
nic/v2-305-okta-fixtures-replay

Conversation

@Nic-dorman

Copy link
Copy Markdown
Member

Summary

  • Adds internal/handlers/scim_okta_fixtures_test.go — a Go test that table-drives all 8 captured Okta fixtures through the live SCIM handler stack
  • 8 lifecycle replays (create, update, deactivate, reactivate, existence-check, group add/remove, group metadata no-op) + 3 dedicated cases proving the findings from the fixtures README
  • All 11 tests pass on SQLite (~5s total). Postgres should pass automatically via the V2-270 CI matrix.

What this proves

Every commit to indelible's SCIM code now gets checked against the real Okta wire format — without anyone needing a live tenant. This is the missing CI surface that turns the captured fixtures from documentation into a regression gate.

The 3 dedicated cases — one per finding from the rehearsal

Test Finding it proves
TestSCIM_OktaFixture_PasswordIsIgnored Indelible discards Okta's random initial password. Confirmed by attempting a local login with the captured password and asserting 401, not 200.
TestSCIM_OktaFixture_GroupMetadataPATCHIsNoop The no-op replace id+displayName PATCH Okta sends before every membership op leaves group state unchanged.
TestSCIM_OktaFixture_FilterByValueRemove The members[value eq "X"] filter path parses correctly when used for removes (the shape both Okta and AAD use).

Implementation notes

  • ID normalization via regex (option B from the V2-305 ticket discussion). Per-run-varying fields (id, value, Users/N, Groups/N, created, lastModified) get replaced with placeholders on both expected and actual before structural JSON comparison.
  • Per-fixture seed function that brings the DB to the state each captured fixture implies — admin (id=1) + sentinels + the fixture user (id=4) for user-targeting fixtures; same plus a seeded group with the right pre-state for group-targeting fixtures.
  • No new test deps — uses stdlib + the existing PR fix(scim): unbreak provisioning + add Tier 1 handler tests (V2-273) #27 scaffolding (scimTestEnv, setupSCIMTest, env.do).

Stacking

This PR contains 3 commits but only the last one is unique to V2-305:

  1. PR fix(scim): unbreak provisioning + add Tier 1 handler tests (V2-273) #27's commit (Tier 1 handler tests + SCIM mount fix) — base scaffolding
  2. PR test(scim): Okta Tier 1.5 fixtures from real-tenant capture (V2-273) #36's commit (8 Okta fixtures + README) — the data this PR consumes
  3. This PR's commit — the replay test

Once PR #27 and PR #36 merge, the diff collapses to just commit #3. Base is set to nic/v2-273-tier1.5-okta-fixtures so GitHub auto-tracks the dependency chain.

Test plan

  • go test ./internal/handlers/ -run TestSCIM_OktaFixture -v — all 11 pass locally on SQLite
  • CI runs Postgres leg (handled automatically by V2-270 matrix)
  • Reviewer: spot-check one of the dedicated cases to validate the assertion shape matches the finding it claims to prove

V2-273 acceptance status (after this merges)

Closes V2-305.

Co-Authored-By: Claude Opus 4.7 (1M context) noreply@anthropic.com

@Nic-dorman
Nic-dorman changed the base branch from nic/v2-273-tier1.5-okta-fixtures to master May 18, 2026 16:31
@Nic-dorman Nic-dorman closed this May 18, 2026
@Nic-dorman Nic-dorman reopened this May 18, 2026
Nic-dorman added a commit that referenced this pull request May 19, 2026
The handler test suite grew past the 10m budget on PR #37 (Okta SCIM
fixture replay, 11 new tests). Race detector legs hit the timeout on
the sqlite matrix; non-race legs finished in ~2-3m. 15m gives headroom
without masking pathological hangs.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Adds internal/handlers/scim_okta_fixtures_test.go which:

- Table-drives all 8 captured Okta fixtures through the live SCIM
  handler stack (create / update / deactivate / reactivate / existence
  check / group add / group remove / group metadata-patch no-op)
- Normalizes per-run fields (timestamps, generated ids) before
  comparison so structurally-equivalent responses compare equal
- Pre-seeds each fixture's prerequisite DB state with sentinel users
  + the target user so captured ids (Users/4, Groups/1) resolve

Three dedicated cases prove the findings noted in the fixtures README:

- TestSCIM_OktaFixture_PasswordIsIgnored: confirms indelible discards
  the random password Okta sends in POST /Users; verifies that a local
  login attempt with that captured password fails (401, not 200).
- TestSCIM_OktaFixture_GroupMetadataPATCHIsNoop: confirms the no-op
  "replace id+displayName" PATCH Okta sends before every membership op
  leaves the group state unchanged.
- TestSCIM_OktaFixture_FilterByValueRemove: confirms the SCIM filter
  path members[value eq "X"] parses correctly when Okta uses it for
  membership removes.

All 11 tests pass on SQLite. Postgres should pass automatically via
the V2-270 CI matrix since these run under internal/handlers/.

Closes V2-305. Acceptance for V2-273 Tier 1.5 now complete pending merge.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@Nic-dorman
Nic-dorman force-pushed the nic/v2-305-okta-fixtures-replay branch from 967815d to c01ec64 Compare May 19, 2026 09:38
@Nic-dorman
Nic-dorman merged commit aab9207 into master May 19, 2026
9 checks passed
@Nic-dorman
Nic-dorman deleted the nic/v2-305-okta-fixtures-replay branch May 19, 2026 10:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant