ExScimPhoenix

Phoenix integration for ExScim. Provides a full set of SCIM 2.0 HTTP endpoints as Phoenix controllers, along with authentication, content-type negotiation, and tenant resolution plugs.

Installation

Add ex_scim_phoenix to your dependencies:

def deps do
[
{:ex_scim_phoenix, "~> 0.2"}
]
end

Usage

Add SCIM routes to your Phoenix router:

defmodule MyAppWeb.Router do
use MyAppWeb, :router
pipeline :scim_api do
plug :accepts, ["json", "scim+json"]
plug ExScimPhoenix.Plugs.ScimContentType
plug ExScimPhoenix.Plugs.ScimAuth
end
scope "/scim/v2" do
pipe_through :scim_api
use ExScimPhoenix.Router
end
end

Available Plugs

Controllers

The router macro registers these controllers automatically:

Authorization Scopes

Scope strings are populated by your AuthProvider.Adapter and enforced per action:

ScopeActions
scim:readGET list, show, search on Users/Groups and all discovery endpoints
scim:createPOST /Users, POST /Groups, POST operations in /Bulk
scim:updatePUT and PATCH on /Users, /Groups; PUT/PATCH operations in /Bulk
scim:deleteDELETE on /Users, /Groups; DELETE operations in /Bulk
scim:me:readGET /Me
scim:me:createPOST /Me
scim:me:updatePUT /Me, PATCH /Me
scim:me:deleteDELETE /Me

For /Bulk, scope is checked per operation - a caller with scim:create only may include POST operations; PUT/PATCH/DELETE operations in the same request will each return a 403 operation result.

See the configuration guide for example scope lists.