Skip to content

Commit c1663ca

Browse files
committed
fix(api): make SSO administration atomic and align CLI actions
1 parent 0aaaaab commit c1663ca

51 files changed

Lines changed: 1367 additions & 803 deletions

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎apps/docs/content/docs/cli/credentials.mdx‎

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -61,8 +61,7 @@ List Credential Members (OAuth login or personal API key required)
6161

6262
| Option | Required | Description |
6363
| --- | --- | --- |
64-
| `--limit <n>` | No | Maximum items to return (0 for everything). Defaults to `100`. |
65-
| `--cursor <value>` | No | Continue from nextCursor returned by a previous result. |
64+
| `--limit <n>` | No | Maximum items to return (0 for everything). Defaults to `0`. |
6665
| `--sort-by <value>` | No | Field used to sort the result. Sorting by `name` is case-sensitive and follows the storage collation, so do not rely on a case-insensitive order. Accepted values: `email`, `name`. |
6766
| `--sort-order <value>` | No | Sort direction. Accepted values: `asc`, `desc`. |
6867

‎apps/docs/content/docs/cli/organizations.mdx‎

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -41,8 +41,7 @@ List Organization Domains (OAuth login or personal API key required)
4141
| Option | Required | Description |
4242
| --- | --- | --- |
4343
| `--organization <value>` | Yes | Organization identifier. |
44-
| `--limit <n>` | No | Maximum items to return (0 for everything). Defaults to `100`. |
45-
| `--cursor <value>` | No | Continue from nextCursor returned by a previous result. |
44+
| `--limit <n>` | No | Maximum items to return (0 for everything). Defaults to `0`. |
4645
| `--sort-by <value>` | No | Field used to sort the result. Accepted values: `domain`. |
4746
| `--sort-order <value>` | No | Sort direction. Accepted values: `asc`, `desc`. |
4847

@@ -556,8 +555,7 @@ List SSO Providers (OAuth login or personal API key required)
556555
| Option | Required | Description |
557556
| --- | --- | --- |
558557
| `--organization <value>` | Yes | Organization identifier. |
559-
| `--limit <n>` | No | Maximum items to return (0 for everything). Defaults to `100`. |
560-
| `--cursor <value>` | No | Continue from nextCursor returned by a previous result. |
558+
| `--limit <n>` | No | Maximum items to return (0 for everything). Defaults to `0`. |
561559
| `--sort-by <value>` | No | Field used to sort the result. Accepted values: `providerId`, `domain`. |
562560
| `--sort-order <value>` | No | Sort direction. Accepted values: `asc`, `desc`. |
563561

@@ -586,7 +584,7 @@ Save SSO Provider (OAuth login or personal API key required)
586584
| `--no-jit-provisioning-enabled` | No | Send --jit-provisioning-enabled as false. |
587585
| `--mapping <json\|@file>` | No | Identity-provider claims mapped to user fields. (JSON, or @path / @- to read a file or stdin). |
588586
| `--client-id <value>` | No | Identity provider client identifier. Available when providerType is oidc. Required when providerType is oidc. |
589-
| `--client-secret <value>` | No | Write-only client secret; the redacted marker from Get SSO Provider preserves an existing secret. Available when providerType is oidc. Required when providerType is oidc. |
587+
| `--client-secret <value\|@file>` | No | Write-only OIDC client secret; the redacted marker from providers get preserves an existing secret. Passing it inline exposes it to shell history and process listings. Required when --provider-type is oidc (@path / @- reads a file or stdin verbatim, including trailing newlines; @@value for a literal leading @). |
590588
| `--scopes <json\|@file>` | No | OIDC scopes; offline_access is omitted. Available when providerType is oidc. (JSON, or @path / @- to read a file or stdin). |
591589
| `--pkce` | No | Use PKCE for the authorization flow. Available when providerType is oidc. |
592590
| `--no-pkce` | No | Send --pkce as false. |

‎apps/docs/content/docs/cli/reference.mdx‎

Lines changed: 4 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -490,8 +490,7 @@ sim credentials members list <credentialId> [options]
490490

491491
| Option | Required | Description |
492492
| --- | --- | --- |
493-
| `--limit <n>` | No | Maximum items to return (0 for everything). Defaults to `100`. |
494-
| `--cursor <value>` | No | Continue from nextCursor returned by a previous result. |
493+
| `--limit <n>` | No | Maximum items to return (0 for everything). Defaults to `0`. |
495494
| `--sort-by <value>` | No | Field used to sort the result. Sorting by `name` is case-sensitive and follows the storage collation, so do not rely on a case-insensitive order. Accepted values: `email`, `name`. |
496495
| `--sort-order <value>` | No | Sort direction. Accepted values: `asc`, `desc`. |
497496

@@ -3153,8 +3152,7 @@ sim organizations domains list [options]
31533152
| Option | Required | Description |
31543153
| --- | --- | --- |
31553154
| `--organization <value>` | Yes | Organization identifier. |
3156-
| `--limit <n>` | No | Maximum items to return (0 for everything). Defaults to `100`. |
3157-
| `--cursor <value>` | No | Continue from nextCursor returned by a previous result. |
3155+
| `--limit <n>` | No | Maximum items to return (0 for everything). Defaults to `0`. |
31583156
| `--sort-by <value>` | No | Field used to sort the result. Accepted values: `domain`. |
31593157
| `--sort-order <value>` | No | Sort direction. Accepted values: `asc`, `desc`. |
31603158

@@ -3668,8 +3666,7 @@ sim organizations sso providers list [options]
36683666
| Option | Required | Description |
36693667
| --- | --- | --- |
36703668
| `--organization <value>` | Yes | Organization identifier. |
3671-
| `--limit <n>` | No | Maximum items to return (0 for everything). Defaults to `100`. |
3672-
| `--cursor <value>` | No | Continue from nextCursor returned by a previous result. |
3669+
| `--limit <n>` | No | Maximum items to return (0 for everything). Defaults to `0`. |
36733670
| `--sort-by <value>` | No | Field used to sort the result. Accepted values: `providerId`, `domain`. |
36743671
| `--sort-order <value>` | No | Sort direction. Accepted values: `asc`, `desc`. |
36753672

@@ -3698,7 +3695,7 @@ sim organizations sso providers save [options]
36983695
| `--no-jit-provisioning-enabled` | No | Send --jit-provisioning-enabled as false. |
36993696
| `--mapping <json\|@file>` | No | Identity-provider claims mapped to user fields. (JSON, or @path / @- to read a file or stdin). |
37003697
| `--client-id <value>` | No | Identity provider client identifier. Available when providerType is oidc. Required when providerType is oidc. |
3701-
| `--client-secret <value>` | No | Write-only client secret; the redacted marker from Get SSO Provider preserves an existing secret. Available when providerType is oidc. Required when providerType is oidc. |
3698+
| `--client-secret <value\|@file>` | No | Write-only OIDC client secret; the redacted marker from providers get preserves an existing secret. Passing it inline exposes it to shell history and process listings. Required when --provider-type is oidc (@path / @- reads a file or stdin verbatim, including trailing newlines; @@value for a literal leading @). |
37023699
| `--scopes <json\|@file>` | No | OIDC scopes; offline_access is omitted. Available when providerType is oidc. (JSON, or @path / @- to read a file or stdin). |
37033700
| `--pkce` | No | Use PKCE for the authorization flow. Available when providerType is oidc. |
37043701
| `--no-pkce` | No | Send --pkce as false. |

‎apps/docs/openapi-v2-billing.json‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -475,6 +475,7 @@
475475
"ORGANIZATION_MEMBERSHIP_REQUIRED",
476476
"ORGANIZATION_ADMIN_REQUIRED",
477477
"ENTERPRISE_PLAN_REQUIRED",
478+
"SSO_DISABLED",
478479
"SSO_DOMAIN_NOT_VERIFIED",
479480
"SSO_PROVIDER_LIMIT_REACHED",
480481
"ORGANIZATION_PLAN_REQUIRED",

‎apps/docs/openapi-v2-files-audit.json‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3836,6 +3836,7 @@
38363836
"ORGANIZATION_MEMBERSHIP_REQUIRED",
38373837
"ORGANIZATION_ADMIN_REQUIRED",
38383838
"ENTERPRISE_PLAN_REQUIRED",
3839+
"SSO_DISABLED",
38393840
"SSO_DOMAIN_NOT_VERIFIED",
38403841
"SSO_PROVIDER_LIMIT_REACHED",
38413842
"ORGANIZATION_PLAN_REQUIRED",

‎apps/docs/openapi-v2-knowledge.json‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4732,6 +4732,7 @@
47324732
"ORGANIZATION_MEMBERSHIP_REQUIRED",
47334733
"ORGANIZATION_ADMIN_REQUIRED",
47344734
"ENTERPRISE_PLAN_REQUIRED",
4735+
"SSO_DISABLED",
47354736
"SSO_DOMAIN_NOT_VERIFIED",
47364737
"SSO_PROVIDER_LIMIT_REACHED",
47374738
"ORGANIZATION_PLAN_REQUIRED",

‎apps/docs/openapi-v2-logs.json‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -866,6 +866,7 @@
866866
"ORGANIZATION_MEMBERSHIP_REQUIRED",
867867
"ORGANIZATION_ADMIN_REQUIRED",
868868
"ENTERPRISE_PLAN_REQUIRED",
869+
"SSO_DISABLED",
869870
"SSO_DOMAIN_NOT_VERIFIED",
870871
"SSO_PROVIDER_LIMIT_REACHED",
871872
"ORGANIZATION_PLAN_REQUIRED",

‎apps/docs/openapi-v2-resources.json‎

Lines changed: 33 additions & 39 deletions
Original file line numberDiff line numberDiff line change
@@ -6918,11 +6918,11 @@
69186918
"name": "organizationId",
69196919
"in": "path",
69206920
"required": true,
6921-
"description": "Organization whose single sign-on settings are managed.",
6921+
"description": "Organization whose single sign-on settings and verified domains are managed.",
69226922
"schema": {
69236923
"type": "string",
69246924
"minLength": 1,
6925-
"description": "Organization whose single sign-on settings are managed."
6925+
"description": "Organization whose single sign-on settings and verified domains are managed."
69266926
}
69276927
},
69286928
{
@@ -7034,11 +7034,11 @@
70347034
"name": "organizationId",
70357035
"in": "path",
70367036
"required": true,
7037-
"description": "Organization whose single sign-on settings are managed.",
7037+
"description": "Organization whose single sign-on settings and verified domains are managed.",
70387038
"schema": {
70397039
"type": "string",
70407040
"minLength": 1,
7041-
"description": "Organization whose single sign-on settings are managed."
7041+
"description": "Organization whose single sign-on settings and verified domains are managed."
70427042
}
70437043
}
70447044
],
@@ -7142,11 +7142,11 @@
71427142
"name": "organizationId",
71437143
"in": "path",
71447144
"required": true,
7145-
"description": "Organization whose single sign-on settings are managed.",
7145+
"description": "Organization whose single sign-on settings and verified domains are managed.",
71467146
"schema": {
71477147
"type": "string",
71487148
"minLength": 1,
7149-
"description": "Organization whose single sign-on settings are managed."
7149+
"description": "Organization whose single sign-on settings and verified domains are managed."
71507150
}
71517151
},
71527152
{
@@ -7222,11 +7222,11 @@
72227222
"name": "organizationId",
72237223
"in": "path",
72247224
"required": true,
7225-
"description": "Organization whose single sign-on settings are managed.",
7225+
"description": "Organization whose single sign-on settings and verified domains are managed.",
72267226
"schema": {
72277227
"type": "string",
72287228
"minLength": 1,
7229-
"description": "Organization whose single sign-on settings are managed."
7229+
"description": "Organization whose single sign-on settings and verified domains are managed."
72307230
}
72317231
},
72327232
{
@@ -7304,11 +7304,11 @@
73047304
"name": "organizationId",
73057305
"in": "path",
73067306
"required": true,
7307-
"description": "Organization whose single sign-on settings are managed.",
7307+
"description": "Organization whose single sign-on settings and verified domains are managed.",
73087308
"schema": {
73097309
"type": "string",
73107310
"minLength": 1,
7311-
"description": "Organization whose single sign-on settings are managed."
7311+
"description": "Organization whose single sign-on settings and verified domains are managed."
73127312
}
73137313
},
73147314
{
@@ -7325,7 +7325,7 @@
73257325
}
73267326
],
73277327
"requestBody": {
7328-
"required": true,
7328+
"required": false,
73297329
"description": "Configuration accepted by Set Primary SSO Provider.",
73307330
"content": {
73317331
"application/json": {
@@ -7403,11 +7403,11 @@
74037403
"name": "organizationId",
74047404
"in": "path",
74057405
"required": true,
7406-
"description": "Organization whose single sign-on settings are managed.",
7406+
"description": "Organization whose single sign-on settings and verified domains are managed.",
74077407
"schema": {
74087408
"type": "string",
74097409
"minLength": 1,
7410-
"description": "Organization whose single sign-on settings are managed."
7410+
"description": "Organization whose single sign-on settings and verified domains are managed."
74117411
}
74127412
}
74137413
],
@@ -7471,11 +7471,11 @@
74717471
"name": "organizationId",
74727472
"in": "path",
74737473
"required": true,
7474-
"description": "Organization whose single sign-on settings are managed.",
7474+
"description": "Organization whose single sign-on settings and verified domains are managed.",
74757475
"schema": {
74767476
"type": "string",
74777477
"minLength": 1,
7478-
"description": "Organization whose single sign-on settings are managed."
7478+
"description": "Organization whose single sign-on settings and verified domains are managed."
74797479
}
74807480
}
74817481
],
@@ -7558,11 +7558,11 @@
75587558
"name": "organizationId",
75597559
"in": "path",
75607560
"required": true,
7561-
"description": "Organization whose single sign-on settings are managed.",
7561+
"description": "Organization whose single sign-on settings and verified domains are managed.",
75627562
"schema": {
75637563
"type": "string",
75647564
"minLength": 1,
7565-
"description": "Organization whose single sign-on settings are managed."
7565+
"description": "Organization whose single sign-on settings and verified domains are managed."
75667566
}
75677567
},
75687568
{
@@ -7674,11 +7674,11 @@
76747674
"name": "organizationId",
76757675
"in": "path",
76767676
"required": true,
7677-
"description": "Organization whose single sign-on settings are managed.",
7677+
"description": "Organization whose single sign-on settings and verified domains are managed.",
76787678
"schema": {
76797679
"type": "string",
76807680
"minLength": 1,
7681-
"description": "Organization whose single sign-on settings are managed."
7681+
"description": "Organization whose single sign-on settings and verified domains are managed."
76827682
}
76837683
}
76847684
],
@@ -7782,11 +7782,11 @@
77827782
"name": "organizationId",
77837783
"in": "path",
77847784
"required": true,
7785-
"description": "Organization whose single sign-on settings are managed.",
7785+
"description": "Organization whose single sign-on settings and verified domains are managed.",
77867786
"schema": {
77877787
"type": "string",
77887788
"minLength": 1,
7789-
"description": "Organization whose single sign-on settings are managed."
7789+
"description": "Organization whose single sign-on settings and verified domains are managed."
77907790
}
77917791
},
77927792
{
@@ -7803,7 +7803,7 @@
78037803
}
78047804
],
78057805
"requestBody": {
7806-
"required": true,
7806+
"required": false,
78077807
"description": "Configuration accepted by Verify Organization Domain.",
78087808
"content": {
78097809
"application/json": {
@@ -7881,11 +7881,11 @@
78817881
"name": "organizationId",
78827882
"in": "path",
78837883
"required": true,
7884-
"description": "Organization whose single sign-on settings are managed.",
7884+
"description": "Organization whose single sign-on settings and verified domains are managed.",
78857885
"schema": {
78867886
"type": "string",
78877887
"minLength": 1,
7888-
"description": "Organization whose single sign-on settings are managed."
7888+
"description": "Organization whose single sign-on settings and verified domains are managed."
78897889
}
78907890
},
78917891
{
@@ -8066,9 +8066,6 @@
80668066
"404": {
80678067
"$ref": "#/components/responses/NotFound"
80688068
},
8069-
"409": {
8070-
"$ref": "#/components/responses/Conflict"
8071-
},
80728069
"429": {
80738070
"$ref": "#/components/responses/RateLimited"
80748071
},
@@ -8179,9 +8176,6 @@
81798176
"404": {
81808177
"$ref": "#/components/responses/NotFound"
81818178
},
8182-
"409": {
8183-
"$ref": "#/components/responses/Conflict"
8184-
},
81858179
"413": {
81868180
"$ref": "#/components/responses/PayloadTooLarge"
81878181
},
@@ -8280,9 +8274,6 @@
82808274
"404": {
82818275
"$ref": "#/components/responses/NotFound"
82828276
},
8283-
"409": {
8284-
"$ref": "#/components/responses/Conflict"
8285-
},
82868277
"429": {
82878278
"$ref": "#/components/responses/RateLimited"
82888279
},
@@ -10771,6 +10762,7 @@
1077110762
"ORGANIZATION_MEMBERSHIP_REQUIRED",
1077210763
"ORGANIZATION_ADMIN_REQUIRED",
1077310764
"ENTERPRISE_PLAN_REQUIRED",
10765+
"SSO_DISABLED",
1077410766
"SSO_DOMAIN_NOT_VERIFIED",
1077510767
"SSO_PROVIDER_LIMIT_REACHED",
1077610768
"ORGANIZATION_PLAN_REQUIRED",
@@ -19937,11 +19929,12 @@
1993719929
"description": "Set Primary SSO Provider result."
1993819930
},
1993919931
"SetPrimarySsoProviderBody": {
19932+
"default": {},
19933+
"title": "Set Primary SSO Provider body",
19934+
"description": "Configuration accepted by Set Primary SSO Provider.",
1994019935
"type": "object",
1994119936
"properties": {},
19942-
"additionalProperties": false,
19943-
"title": "Set Primary SSO Provider body",
19944-
"description": "Configuration accepted by Set Primary SSO Provider."
19937+
"additionalProperties": false
1994519938
},
1994619939
"GetSsoPolicyResponse": {
1994719940
"type": "object",
@@ -20228,11 +20221,12 @@
2022820221
"description": "Verify Organization Domain result."
2022920222
},
2023020223
"VerifyOrganizationDomainBody": {
20224+
"default": {},
20225+
"title": "Verify Organization Domain body",
20226+
"description": "Configuration accepted by Verify Organization Domain.",
2023120227
"type": "object",
2023220228
"properties": {},
20233-
"additionalProperties": false,
20234-
"title": "Verify Organization Domain body",
20235-
"description": "Configuration accepted by Verify Organization Domain."
20229+
"additionalProperties": false
2023620230
},
2023720231
"RemoveOrganizationDomainResponse": {
2023820232
"type": "object",

‎apps/docs/openapi-v2-tables.json‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5021,6 +5021,7 @@
50215021
"ORGANIZATION_MEMBERSHIP_REQUIRED",
50225022
"ORGANIZATION_ADMIN_REQUIRED",
50235023
"ENTERPRISE_PLAN_REQUIRED",
5024+
"SSO_DISABLED",
50245025
"SSO_DOMAIN_NOT_VERIFIED",
50255026
"SSO_PROVIDER_LIMIT_REACHED",
50265027
"ORGANIZATION_PLAN_REQUIRED",

‎apps/docs/openapi-v2-workflows.json‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5722,6 +5722,7 @@
57225722
"ORGANIZATION_MEMBERSHIP_REQUIRED",
57235723
"ORGANIZATION_ADMIN_REQUIRED",
57245724
"ENTERPRISE_PLAN_REQUIRED",
5725+
"SSO_DISABLED",
57255726
"SSO_DOMAIN_NOT_VERIFIED",
57265727
"SSO_PROVIDER_LIMIT_REACHED",
57275728
"ORGANIZATION_PLAN_REQUIRED",

0 commit comments

Comments
 (0)