// Copyright (c) 2026 Probo Inc . // // Permission is hereby granted, free of charge, to any person obtaining a copy // of this software and associated documentation files (the "Software"), to deal // in the Software without restriction, including without limitation the rights // to use, copy, modify, merge, publish, distribute, sublicense, and/or sell // copies of the Software, and to permit persons to whom the Software is // furnished to do so, subject to the following conditions: // // The above copyright notice and this permission notice shall be included in // all copies or substantial portions of the Software. // // THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR // IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, // FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE // AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER // LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, // OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE // SOFTWARE. package bridge_test import ( "context" "net/http" "net/http/httptest" "testing" "github.com/stretchr/testify/assert" "github.com/stretchr/testify/require" scimbridge "go.probo.inc/probo/pkg/iam/scim/bridge" scimclient "go.probo.inc/probo/pkg/iam/scim/bridge/client" ) type mockProvider struct { users scimclient.Users } func (p *mockProvider) Name() string { return "mock" } func (p *mockProvider) ListUsers(_ context.Context) (scimclient.Users, error) { return p.users, nil } func TestBridge_Run_DeletesInactiveExcludedUsers(t *testing.T) { t.Parallel() deleteCalled := false server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { switch { case r.Method == http.MethodGet && r.URL.Path == "/Users": w.Header().Set("Content-Type", "application/scim+json") _, _ = w.Write([]byte(`{ "schemas": ["urn:ietf:params:scim:api:messages:2.0:ListResponse"], "totalResults": 1, "startIndex": 1, "itemsPerPage": 100, "Resources": [{ "id": "gid://probo/MembershipProfile/abc", "userName": "excluded@example.com", "displayName": "Excluded User", "active": false, "externalId": "ext-1" }] }`)) case r.Method == http.MethodDelete: deleteCalled = true w.WriteHeader(http.StatusNoContent) default: http.NotFound(w, r) } })) t.Cleanup(server.Close) provider := &mockProvider{users: scimclient.Users{}} client := scimclient.NewClient(server.Client(), server.URL, "token") bridge := scimbridge.NewBridge( provider, client, scimbridge.WithExcludedUserNames([]string{"excluded@example.com"}), ) created, updated, deleted, deactivated, skipped, err := bridge.Run(context.Background()) require.NoError(t, err) assert.True(t, deleteCalled) assert.Equal(t, 0, created) assert.Equal(t, 0, updated) assert.Equal(t, 1, deleted) assert.Equal(t, 0, deactivated) assert.Equal(t, 0, skipped) }