SCIM
SCIM 2.0 is an open standard for managing accounts and groups. Through SCIM, Nova manages accounts and group memberships in applications that offer a SCIM 2.0 interface.
Connection
- “Base URL”: Nova appends the SCIM paths itself, for example
/scim/v2/Users. If the endpoints are located underhttps://app.example.com/api/scim/v2/, the base URL ishttps://app.example.com/api. - “Auth type”: “Bearer” with a token, “Basic” with “User” and “Password”, or “None”.
- “Last-logon attribute (SCIM)” under “Advanced”, see Last logon.
“Check status” retrieves /scim/v2/ServiceProviderConfig, otherwise the base URL itself.
Accounts
| Action | SCIM call |
|---|---|
| Search | GET /Users with filter userName eq "…" |
| Create | POST /Users |
| Change | PATCH /Users/{id}, operation replace |
| Set password | PATCH on the password attribute |
| Lock, unlock | PATCH on the active attribute |
| Delete | DELETE /Users/{id} |
When creating an account, Nova sends userName (the account ID), displayName, name with first and last name taken from the identity's name, active, the email address as the primary address and, if present, the password. Further simple attributes follow the “Mapping”.
Groups
A job of type “Import SCIM groups” takes over the group catalogue; it reads the groups page by page.
Nova changes memberships with a PATCH on the group (/Groups/{id}, operation add or remove on members); the other members remain untouched. As the member value, Nova passes the account ID under which the account is linked in Nova. During provisioning, Nova looks up the group by its display name (displayName eq "…"). If a group is renamed in the SCIM server, its name has to be updated in Nova, for example by importing again with “Overwrite existing roles”. Before writing, Nova reads the group's members so that the change journal contains only effective changes.
Last logon
SCIM has no standard attribute for the last logon. Nova reads the attribute entered under “Last-logon attribute (SCIM)” – a path with dots is possible. If none is entered or it returns no value, Nova checks lastLogin, lastLogon, lastLoginTime and loginTime.
What differs between SCIM servers
SCIM leaves vendors some room. Before going live, it should be clear:
- whether the endpoints sit under a path ending in
/scim/v2/ - which authentication the server requires – Nova supports bearer tokens and Basic
- whether the server accepts the account ID as a group member value or requires the account's internal SCIM ID
- whether the server supports the filters
eq(foruserNameanddisplayName) andco(group search) - whether
PATCHis supported for accounts (/Users) and groups and whetherpasswordandactivecan be written with it - whether, and under which name, the last logon is provided
A run-through with a test account – create, grant and revoke a group, lock, delete – shows whether a server fits these assumptions.