Skip to content

SCIM spec parity: field-level pass between SCIMGroupSchema and stable @better-auth/scim's group wire shape (leg 3 of #11632) #11697

Description

@os-sam

Cut out of the #11632 SCIM epic by its owning domain:services seat and filed for the spec seat, because the epic says so in its own scope text:

spec: field-level parity pass between SCIMGroupSchema and stable's group wire shape (unmeasured so far); packages/spec work goes to the spec seat per single-owner rule.

The services lane has zero packages/spec ownership. This card is filed, not taken. No pm:queue — grading is triage's field.

The ruled direction this works within

Maintainer, 2026-08-24, live PM chat on #3653 (「os#3653 立项迁移」). The epic records the consequence: #3653's question A is answered implement"the SCIMGroup family becomes true through this migration, not through retirement."

⇒ This is a parity pass, not a retirement question. That part is settled.

What is actually unmeasured — and what is not

The epic marks the field-level diff "unmeasured so far", and it still is. But two things around it have been measured since the epic was written, by the repaired parity gate (PR #11429, merged 2026-08-23, fixes #11380) running against published @better-auth/scim@1.7.1:

models
gained on stablescimConnectionBinding, scimIdentityTombstone, scimProjectionGrant, scimSubject, scimUser
lost on stablescimGroupRole, scimGroupRoleGrant
keptscimGroup, scimGroupMember

scimGroup and scimGroupMember are in the KEPT column — they exist on both the pinned 1.7.0-rc.1 and stable. So this card is genuinely a field-level question (do the columns agree?), not a model-existence one. Whoever takes it does not need to establish that the models survive; that is measured.

⚠️ Read the model names as what the gate reports, not as spec identifiers. Mapping them onto SCIMGroupSchema's shape is part of this card's work.

Sequencing — this is FIRST, and it does not wait

The epic's Discipline section says "spec first". Concretely:

Not measured

  • The field-level diff itself. That is this card's deliverable. Nothing in this repo has compared SCIMGroupSchema's fields against stable's group wire shape.
  • Whether the parity result forces any authorable-surface movement in packages/spec. Unknown until the diff exists, and it is the spec seat's call either way.

One standing operational note that rides the whole migration

⚠️ Not this card's work, but it governs the window: SCIM-enabled deployments must not let the IdP push groups until the migration lands, and on migration day every SCIM-enabled deployment's IdP must reissue its token (unsalted SHA-256 → keyed HMAC; digests are not portable on any path). That is an operational action with a human owner, tracked on the epic.

Refs: #11632 (the epic, leg 3) · #3653 (decision anchor + the seven-model measurements) · #11380 / PR #11429 (the gate repair that produced the model diff above) · #11693 (the sys_scim_provider disposition — parallel, not a prerequisite) · ADR-0071

Metadata

Metadata

Assignees

Type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions