SCIM Schema校验中如何为active及主邮箱字段设置默认值?
解决SCIM Schema中active和主邮箱primary字段默认值配置问题
问题根源
你尝试在自定义Schema中重新定义核心SCIM User Schema的字段(如active),这会触发Schema发现过程中的冲突,导致返回值为空。核心SCIM字段需直接在核心Schema定义中修改,而非自定义扩展Schema。
正确配置示例
1. Active字段(核心User Schema)
在核心urn:ietf:params:scim:schemas:core:2.0:User Schema中,为active字段添加defaultValue:
{ "id": "urn:ietf:params:scim:schemas:core:2.0:User:active", "name": "active", "type": "boolean", "mutability": "readWrite", "defaultValue": true, "returned": "default", "uniqueness": "none", "description": "A Boolean value indicating the user's administrative status." }
2. 主邮箱Primary字段(核心User Schema的emails子属性)
emails是多值复杂类型,需在其subAttributes中为primary字段设置默认值:
{ "id": "urn:ietf:params:scim:schemas:core:2.0:User:emails", "name": "emails", "type": "complex", "multiValued": true, "returned": "default", "description": "Email addresses for the user.", "subAttributes": [ { "id": "urn:ietf:params:scim:schemas:core:2.0:User:emails:value", "name": "value", "type": "string", "mutability": "readWrite", "returned": "default", "uniqueness": "server", "description": "The email address." }, { "id": "urn:ietf:params:scim:schemas:core:2.0:User:emails:primary", "name": "primary", "type": "boolean", "mutability": "readWrite", "returned": "default", "defaultValue": true, "description": "A Boolean value indicating the 'primary' or preferred attribute value for this attribute, e.g., the preferred email address." }, { "id": "urn:ietf:params:scim:schemas:core:2.0:User:emails:type", "name": "type", "type": "string", "mutability": "readWrite", "returned": "default", "description": "A label indicating the attribute's function, e.g., 'work' or 'home'.", "canonicalValues": ["work", "home", "other"] } ] }
关键注意事项
- 禁止在自定义Schema中重定义核心SCIM字段,否则会导致Schema发现异常。
- 微软SCIM验证工具严格遵循SCIM 2.0规范,确保配置符合规范要求。
- 若基于Azure AD集成SCIM,部分默认值逻辑可能需在AD端配置或服务端代码中实现,并非所有SCIM实现都完全支持通过Schema定义
defaultValue。
内容的提问来源于stack exchange,提问作者cu2
相关产品推荐
相关产品推荐

