-
Notifications
You must be signed in to change notification settings - Fork 474
feat(shared,js): add Google Workspace credentials and sync to DirectorySync #9718
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
a124dac
af8da55
230f280
63c92e0
c2eae2f
d4c2c5e
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,2 @@ | ||
| --- | ||
| --- |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -18,6 +18,11 @@ export interface DirectorySyncJSON extends ClerkResourceJSON { | |
| enabled: boolean; | ||
| group_role_mapping_enabled: boolean; | ||
| attribute_mapping: Record<string, string>; | ||
| /** | ||
| * Whether a validated identity-provider credential is stored for this directory. Only present for | ||
| * pull-based providers; push-based directories authenticate with a bearer token and omit it. | ||
| */ | ||
| credentials_configured?: boolean | null; | ||
| /** | ||
| * The SCIM bearer token. Only present on create and rotate responses; it | ||
| * cannot be retrieved again afterwards. | ||
|
|
@@ -50,6 +55,11 @@ export interface DirectorySyncResource extends ClerkResource { | |
| groupRoleMappingEnabled: boolean; | ||
| /** The SCIM attribute paths mapped onto Clerk user attributes. */ | ||
| attributeMapping: Record<string, string>; | ||
| /** | ||
| * Whether a validated identity-provider credential is stored for this directory. `null` for | ||
| * push-based providers, which authenticate with a bearer token and have no credential. | ||
| */ | ||
| credentialsConfigured: boolean | null; | ||
| /** | ||
| * The SCIM bearer token. Only populated on the resource returned by | ||
| * `Organization.createDirectorySync` and `rotateToken`; `null` everywhere | ||
|
|
@@ -77,6 +87,26 @@ export interface DirectorySyncResource extends ClerkResource { | |
| * Gets the users the identity provider has provisioned into the directory. | ||
| */ | ||
| getUsers: (params?: GetDirectorySyncUsersParams) => Promise<ClerkPaginatedResponse<DirectorySyncUserResource>>; | ||
| /** | ||
| * Stores the credential a pull-based directory reads the identity provider with, and activates the | ||
| * directory once the provider accepts it. Calling it again replaces the stored credential, which is | ||
| * how a rotated key is applied. | ||
| * | ||
| * The credential is validated against the identity provider before it is stored, so a rejected key or | ||
| * a misconfigured delegation rejects with a message describing what to fix. Surface that message: it | ||
| * is the only thing telling the administrator what is wrong with their setup. | ||
| */ | ||
| setCredentials: (params: SetDirectorySyncCredentialsParams) => Promise<DirectorySyncResource>; | ||
| /** | ||
| * Starts a sync for a pull-based directory instead of waiting for the next scheduled one. Rejects | ||
| * while a sync is already running. | ||
| */ | ||
| sync: () => Promise<void>; | ||
| /** | ||
| * Gets the result of the directory's most recent sync. Every field is `null` before the first sync | ||
| * completes. | ||
| */ | ||
| getSyncStatus: () => Promise<DirectorySyncStatusResource>; | ||
| __internal_toSnapshot: () => DirectorySyncJSONSnapshot; | ||
| } | ||
|
|
||
|
|
@@ -129,3 +159,37 @@ export type GetDirectorySyncUsersParams = { | |
| initialPage?: number; | ||
| pageSize?: number; | ||
| }; | ||
|
|
||
| /** | ||
| * The outcome of a directory's last sync run. | ||
| */ | ||
| export type DirectorySyncRunStatus = 'running' | 'succeeded' | 'failed' | 'cancelled'; | ||
|
|
||
| export interface DirectorySyncStatusJSON { | ||
| last_synced_at: number | null; | ||
| last_sync_status: DirectorySyncRunStatus | null; | ||
| last_sync_error: string | null; | ||
| last_sync_changed_user_count?: number | null; | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: sed -n '150,195p' packages/shared/src/types/directorySync.ts
rg -n "last_sync_changed_user_count|DirectorySyncStatusJSON" packages/shared packages/clerk-jsRepository: clerk/javascript Length of output: 2378 Document
🤖 Prompt for AI Agents |
||
| } | ||
|
|
||
| export interface DirectorySyncStatusResource { | ||
| /** When the last sync finished, or `null` if none has completed. */ | ||
| lastSyncedAt: Date | null; | ||
| /** The outcome of the last sync, or `null` if none has completed. */ | ||
| lastSyncStatus: DirectorySyncRunStatus | null; | ||
| /** Why the last sync failed, when it did. */ | ||
| lastSyncError: string | null; | ||
| /** | ||
| * How many users the last sync created or updated, or `null` when none has | ||
| * completed. Those users are provisioned after the sync itself finishes, so | ||
| * a count above zero means more are still on their way. | ||
| */ | ||
| lastSyncChangedUserCount: number | null; | ||
| } | ||
|
|
||
| export type SetDirectorySyncCredentialsParams = { | ||
| /** The service account key, as the JSON document downloaded from the identity provider. */ | ||
| serviceAccountJson: string; | ||
| /** The directory administrator the service account impersonates when reading the directory. */ | ||
| subjectEmail: string; | ||
| }; | ||
Uh oh!
There was an error while loading. Please reload this page.