OracleIAM
Integrate with Oracle's services to execute CRUD and Group operations for employee lifecycle processes.
Authentication & Identity Management · Oracle IAM
Details
| ID | OracleIAM |
|---|---|
| Provider | Oracle |
| Category | Authentication & Identity Management |
| From Version | 6.0.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | Agentix XSIAM Cloud Posture Security EDR Cortex Cloud Cloud Runtime Security |
README
Integrate with Oracle Identity Access Management service to execute CRUD (create, read, update, and delete) operations for employee lifecycle processes.
What does this pack do?
- Create a user.
- Retrieve the details of an existing user.
- Update an existing user.
- Disable an active user.
- Create an empty group.
- Retrieve the information for a group including its members.
- Permanently remove a group.
- Updates an existing group resource.
For more information, refer to the Identity Lifecycle Management article.
Configure OracleIAM in Cortex
| Parameter | Description | Required |
|---|---|---|
| Base URL | True | |
| Client ID | True | |
| Client Secret | True | |
| Allow creating users | False | |
| Allow updating users | False | |
| Allow enabling users | False | |
| Allow disabling users | False | |
| Automatically create user if not found in update command | False | |
| Incoming Mapper | True | |
| Outgoing Mapper | Cortex XSOAR only parameter. | False |
| Trust any certificate (not secure) | False | |
| Use system proxy settings | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
iam-create-user
Creates a user.
Base Command
iam-create-user
Input
| Argument Name | Description | Required |
|---|---|---|
| user-profile | User Profile indicator details. | Required |
| allow-enable | When set to true, after the command execution the status of the user in the 3rd-party integration will be active. Possible values are: true, false. Default is true. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| IAM.Vendor.active | Boolean | When true, indicates that the employee’s status is active in the 3rd-party integration. |
| IAM.Vendor.brand | String | Name of the integration. |
| IAM.Vendor.details | string | Provides the raw data from the 3rd-party integration. |
| IAM.Vendor.email | String | The employee’s email address. |
| IAM.Vendor.errorCode | Number | HTTP error response code. |
| IAM.Vendor.errorMessage | String | Reason why the API failed. |
| IAM.Vendor.id | String | The employee’s user ID in the app. |
| IAM.Vendor.instanceName | string | Name of the integration instance. |
| IAM.Vendor.success | Boolean | When true, indicates that the command was executed successfully. |
| IAM.Vendor.username | String | The employee’s username in the app. |
Command Example
!iam-create-user user-profile={"username": "test user name", "email": "john.doe@example.com", "givenname": "test", "surname": "test", "displayname": "test"}
Context Example
{
"IAM": {
"UserProfile": {
"displayname": "test",
"email": "john.doe@example.com",
"givenname": "test",
"surname": "test",
"username": "test user name"
},
"Vendor": {
"action": "create",
"active": true,
"brand": "OracleIAM",
"details": {
"active": true,
"displayName": "test test",
"emails": [
{
"primary": false,
"secondary": false,
"type": "recovery",
"value": "john.doe@example.com",
"verified": false
},
{
"primary": true,
"secondary": false,
"type": "work",
"value": "john.doe@example.com",
"verified": false
}
],
"id": "123456",
"idcsCreatedBy": {
"$ref": "https://test.identity.oraclecloud.com:443/admin/v1/Apps/123456",
"display": "Test",
"type": "App",
"value": "123456"
},
"idcsLastModifiedBy": {
"$ref": "https://test.identity.oraclecloud.com:443/admin/v1/Apps/123456",
"display": "Test",
"type": "App",
"value": "123456"
},
"meta": {
"created": "2021-08-23T08:00:58.029Z",
"lastModified": "2021-08-23T08:00:58.029Z",
"location": "https://test.identity.oraclecloud.com:443/admin/v1/Apps/123456",
"resourceType": "User",
"version": "1234"
},
"name": {
"familyName": "test",
"formatted": "test test",
"givenName": "test"
},
"schemas": [
"urn:ietf:params:scim:schemas:core:2.0:User",
"urn:ietf:params:scim:schemas:oracle:idcs:extension:userState:User",
"urn:ietf:params:scim:schemas:oracle:idcs:extension:user:User"
],
"urn:ietf:params:scim:schemas:oracle:idcs:extension:user:User": {
"isFederatedUser": false
},
"urn:ietf:params:scim:schemas:oracle:idcs:extension:userState:User": {
"locked": {
"on": false
}
},
"userName": "test user name"
},
"email": "john.doe@example.com",
"errorCode": null,
"errorMessage": "",
"id": "123456",
"instanceName": "OracleIAM_instance_1",
"reason": "",
"skipped": false,
"success": true,
"username": "test user name"
}
}
}
Human Readable Output
Create User Results (OracleIAM)
brand instanceName success active id username details OracleIAM OracleIAM_instance_1 true true 123456 test user name john.doe@example.com idcsCreatedBy: {“type”: “App”, “display”: “Test”, “value”: “123456”, “$ref”: “https://test.identity.oraclecloud.com:443/admin/v1/Apps/123456”}
iam-get-user
Retrieves a single user resource.
Base Command
iam-get-user
Input
| Argument Name | Description | Required |
|---|---|---|
| user-profile | A User Profile indicator. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| IAM.Vendor.active | Boolean | When true, indicates that the employee’s status is active in the 3rd-party integration. |
| IAM.Vendor.brand | String | Name of the integration. |
| IAM.Vendor.details | string | Provides the raw data from the 3rd-party integration. |
| IAM.Vendor.email | String | The employee’s email address. |
| IAM.Vendor.errorCode | Number | HTTP error response code. |
| IAM.Vendor.errorMessage | String | Reason why the API failed. |
| IAM.Vendor.id | String | The employee’s user ID in the app. |
| IAM.Vendor.instanceName | string | Name of the integration instance. |
| IAM.Vendor.success | Boolean | When true, indicates that the command was executed successfully. |
| IAM.Vendor.username | String | The employee’s username in the app. |
Command Example
!iam-get-user user-profile={"username": "test user name"}
Context Example
{
"IAM": {
"UserProfile": {
"Email": "john.doe@example.com",
"Given Name": "test",
"Surname": "test",
"Username": "test user name"
},
"Vendor": {
"action": "get",
"active": true,
"brand": "OracleIAM",
"details": {
"active": true,
"displayName": "test test",
"emails": [
{
"primary": false,
"secondary": false,
"type": "recovery",
"value": "john.doe@example.com",
"verified": false
},
{
"primary": true,
"secondary": false,
"type": "work",
"value": "john.doe@example.com",
"verified": false
}
],
"id": "123456",
"idcsCreatedBy": {
"$ref": "https://test.identity.oraclecloud.com:443/admin/v1/Apps/123456",
"display": "Test",
"type": "App",
"value": "123456"
},
"idcsLastModifiedBy": {
"$ref": "https://test.identity.oraclecloud.com:443/admin/v1/Apps/123456",
"display": "Test",
"type": "App",
"value": "123456"
},
"meta": {
"created": "2021-08-23T08:00:58.029Z",
"lastModified": "2021-08-23T08:00:58.029Z",
"location": "https://test.identity.oraclecloud.com:443/admin/v1/Users/123456",
"resourceType": "User",
"version": "123456"
},
"name": {
"familyName": "test",
"formatted": "test test",
"givenName": "test"
},
"schemas": [
"urn:ietf:params:scim:schemas:core:2.0:User",
"urn:ietf:params:scim:schemas:oracle:idcs:extension:userState:User",
"urn:ietf:params:scim:schemas:oracle:idcs:extension:user:User"
],
"urn:ietf:params:scim:schemas:oracle:idcs:extension:user:User": {
"isFederatedUser": false
},
"urn:ietf:params:scim:schemas:oracle:idcs:extension:userState:User": {
"locked": {
"on": false
}
},
"userName": "test user name"
},
"email": null,
"errorCode": null,
"errorMessage": "",
"id": "123456",
"instanceName": "OracleIAM_instance_1",
"reason": "",
"skipped": false,
"success": true,
"username": "test user name"
}
}
}
Human Readable Output
Get User Results (OracleIAM)
brand instanceName success active id username details OracleIAM OracleIAM_instance_1 true true 123456 test user name idcsCreatedBy: {“type”: “App”, “display”: “Palo”, “value”: “123456”, “$ref”: “https://test.identity.oraclecloud.com:443/admin/v1/Apps/123456”}
iam-update-user
Updates an existing user with the data passed in the user-profile argument.
Base Command
iam-update-user
Input
| Argument Name | Description | Required |
|---|---|---|
| user-profile | A User Profile indicator. | Required |
| allow-enable | When set to true, after the command execution the status of the user in the 3rd-party integration will be active. Possible values are: true, false. Default is true. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| IAM.Vendor.active | Boolean | When true, indicates that the employee’s status is active in the 3rd-party integration. |
| IAM.Vendor.brand | String | Name of the integration. |
| IAM.Vendor.details | string | Provides the raw data from the 3rd-party integration. |
| IAM.Vendor.email | String | The employee’s email address. |
| IAM.Vendor.errorCode | Number | HTTP error response code. |
| IAM.Vendor.errorMessage | String | Reason why the API failed. |
| IAM.Vendor.id | String | The employee’s user ID in the app. |
| IAM.Vendor.instanceName | string | Name of the integration instance. |
| IAM.Vendor.success | Boolean | When true, indicates that the command was executed successfully. |
| IAM.Vendor.username | String | The employee’s username in the app. |
Command Example
!iam-update-user user-profile=`{"username": "test user name"}`
Context Example
{
"IAM": {
"UserProfile": {
"username": "test user name"
},
"Vendor": {
"action": "update",
"active": true,
"brand": "OracleIAM",
"details": {
"active": true,
"displayName": "test test",
"emails": [
{
"primary": false,
"secondary": false,
"type": "recovery",
"value": "john.doe@example.com",
"verified": false
},
{
"primary": true,
"secondary": false,
"type": "work",
"value": "john.doe@example.com",
"verified": false
}
],
"id": "7611ff137b37449abb1337925c891283",
"idcsCreatedBy": {
"$ref": "https://test.identity.oraclecloud.com:443/admin/v1/Apps/123456",
"display": "Test",
"type": "App",
"value": "123456"
},
"idcsLastModifiedBy": {
"$ref": "https://test.identity.oraclecloud.com:443/admin/v1/Apps/123456",
"display": "Test",
"type": "App",
"value": "123456"
},
"meta": {
"created": "2021-08-23T08:00:58.029Z",
"lastModified": "2021-08-23T08:01:06.948Z",
"location": "https://test.identity.oraclecloud.com:443/admin/v1/Users/123456",
"resourceType": "User",
"version": "123456"
},
"name": {
"familyName": "test",
"formatted": "test test",
"givenName": "test"
},
"schemas": [
"urn:ietf:params:scim:schemas:core:2.0:User",
"urn:ietf:params:scim:schemas:oracle:idcs:extension:userState:User",
"urn:ietf:params:scim:schemas:oracle:idcs:extension:user:User"
],
"urn:ietf:params:scim:schemas:oracle:idcs:extension:user:User": {
"isFederatedUser": false
},
"urn:ietf:params:scim:schemas:oracle:idcs:extension:userState:User": {
"locked": {
"on": false
}
},
"userName": "test user name"
},
"email": null,
"errorCode": null,
"errorMessage": "",
"id": "123456",
"instanceName": "OracleIAM_instance_1",
"reason": "",
"skipped": false,
"success": true,
"username": "test user name"
}
}
}
Human Readable Output
Update User Results (OracleIAM)
brand instanceName success active id username details OracleIAM OracleIAM_instance_1 true true 123456 test user name idcsCreatedBy: {“type”: “App”, “display”: “Palo”, “value”: “123456”, “$ref”: “https://test.identity.oraclecloud.com:443/admin/v1/Apps/123456”}
iam-disable-user
Disable an active user.
Base Command
iam-disable-user
Input
| Argument Name | Description | Required |
|---|---|---|
| user-profile | A User Profile indicator. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| IAM.Vendor.active | Boolean | When true, indicates that the employee’s status is active in the 3rd-party integration. |
| IAM.Vendor.brand | String | Name of the integration. |
| IAM.Vendor.details | string | Provides the raw data from the 3rd-party integration. |
| IAM.Vendor.email | String | The employee’s email address. |
| IAM.Vendor.errorCode | Number | HTTP error response code. |
| IAM.Vendor.errorMessage | String | Reason why the API failed. |
| IAM.Vendor.id | String | The employee’s user ID in the app. |
| IAM.Vendor.instanceName | string | Name of the integration instance. |
| IAM.Vendor.success | Boolean | When true, indicates that the command was executed successfully. |
| IAM.Vendor.username | String | The employee’s username in the app. |
Command Example
!iam-disable-user user-profile=`{"username": "test user name"}`
Context Example
{
"IAM": {
"UserProfile": {
"username": "test user name"
},
"Vendor": {
"action": "disable",
"active": false,
"brand": "OracleIAM",
"details": {
"active": false,
"displayName": "test test",
"emails": [
{
"primary": false,
"secondary": false,
"type": "recovery",
"value": "john.doe@example.com",
"verified": false
},
{
"primary": true,
"secondary": false,
"type": "work",
"value": "john.doe@example.com",
"verified": false
}
],
"id": "123456",
"idcsCreatedBy": {
"$ref": "https://test.identity.oraclecloud.com:443/admin/v1/Apps/123456",
"display": "Test",
"type": "App",
"value": "123456"
},
"idcsLastModifiedBy": {
"$ref": "https://test.identity.oraclecloud.com:443/admin/v1/Apps/123456",
"display": "Test",
"type": "App",
"value": "123456"
},
"meta": {
"created": "2021-08-23T08:00:58.029Z",
"lastModified": "2021-08-23T08:01:03.884Z",
"location": "https://test.identity.oraclecloud.com:443/admin/v1/Users/123456",
"resourceType": "User",
"version": "123456"
},
"name": {
"familyName": "test",
"formatted": "test test",
"givenName": "test"
},
"schemas": [
"urn:ietf:params:scim:schemas:core:2.0:User",
"urn:ietf:params:scim:schemas:oracle:idcs:extension:userState:User",
"urn:ietf:params:scim:schemas:oracle:idcs:extension:user:User"
],
"urn:ietf:params:scim:schemas:oracle:idcs:extension:user:User": {
"isFederatedUser": false
},
"urn:ietf:params:scim:schemas:oracle:idcs:extension:userState:User": {
"locked": {
"on": false
}
},
"userName": "test user name"
},
"email": null,
"errorCode": null,
"errorMessage": "",
"id": "123456",
"instanceName": "OracleIAM_instance_1",
"reason": "",
"skipped": false,
"success": true,
"username": "test user name"
}
}
}
Human Readable Output
Disable User Results (OracleIAM)
brand instanceName success active id username details OracleIAM OracleIAM_instance_1 true false 123456 test user name idcsCreatedBy: {“type”: “App”, “display”: “Palo”, “value”: “123456”, “$ref”: “https://test.identity.oraclecloud.com:443/admin/v1/Apps/123456”}
iam-create-group
Creates an empty group
Base Command
iam-create-group
Input
| Argument Name | Description | Required |
|---|---|---|
| scim | Group SCIM data with the display name. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| CreateGroup.id | String | Group ID |
| CreateGroup.displayName | String | Display name of the group. |
| CreateGroup.success | Boolean | Success status of the command. |
| CreateGroup.errorCode | Number | Error code if there is a failure. |
| CreateGroup.errorMessage | Unknown | Error details if there is a failure. |
Command Example
!iam-create-group scim=`{"displayName": "The Best Group"}`
Context Example
{
"CreateGroup": {
"brand": "OracleIAM",
"displayName": "The Best Group",
"id": "111111",
"instanceName": "OracleIAM_instance_1",
"success": true
}
}
Human Readable Output
Oracle Cloud Create Group
brand displayName id instanceName success OracleIAM The Best Group 111111 OracleIAM_instance_1 true
iam-get-group
Retrieves the group information including members
Base Command
iam-get-group
Input
| Argument Name | Description | Required |
|---|---|---|
| scim | Group SCIM data. | Required |
| includeMembers | Whether members need to be included in the response. Possible values are: true, false. Default is false. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| GetGroup.id | String | Group ID. |
| GetGroup.displayName | String | Display name of the group. |
| GetGroup.members.display | String | Display name of the group member. |
| GetGroup.members.value | String | ID of the group member. |
| GetGroup.success | Boolean | Success status of the command. |
| GetGroup.errorCode | Number | Error code if there is a failure. |
| GetGroup.errorMessage | Unknown | Error details if there is a failure. |
Command Example
!iam-get-group scim=`{"id": "121212"}`
Context Example
{
"GetGroup": {
"brand": "OracleIAM",
"displayName": "New Group",
"id": "121212",
"instanceName": "OracleIAM_instance_1",
"success": true
}
}
Human Readable Output
Oracle Cloud Get Group
brand displayName id instanceName success OracleIAM New Group 121212 OracleIAM_instance_1 true
iam-delete-group
Permanently removes a group.
Base Command
iam-delete-group
Input
| Argument Name | Description | Required |
|---|---|---|
| scim | Group SCIM with ID. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| DeleteGroup.id | String | Group ID. |
| DeleteGroup.displayName | String | Display name of the group. |
| DeleteGroup.success | Boolean | Success status of the command. |
| DeleteGroup.errorCode | Number | Error code if there is a failure. |
| DeleteGroup.errorMessage | Unknown | Error details if there is a failure. |
Command Example
!iam-delete-group scim={"id": "121212"}
Context Example
{
"DeleteGroup": {
"brand": "OracleIAM",
"id": "121212",
"instanceName": "OracleIAM_instance_1",
"success": true
}
}
Human Readable Output
Oracle Cloud Delete Group
brand id instanceName success OracleIAM 121212 OracleIAM_instance_1 true
iam-update-group
Updates an existing group resource. This command allows individual (or groups of) users to be added or removed from the group with a single operation. A maximum of 15,000 users can be modified in a single call.
Base Command
iam-update-group
Input
| Argument Name | Description | Required |
|---|---|---|
| scim | Group SCIM data. | Required |
| memberIdsToAdd | List of members IDs to add. A maximum of 15,000 users per call can be modified using this command. | Optional |
| memberIdsToDelete | List of members IDs to be deleted from the group. A maximum of 15,000 users per call can be modified using this command. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| UpdateGroup.id | String | Group ID. |
| UpdateGroup.displayName | String | Display name of the group. |
| UpdateGroup.success | Boolean | Success status of the command. |
| UpdateGroup.errorCode | Number | Error code if there is a failure. |
| UpdateGroup.errorMessage | Unknown | Error details if there is a failure. |
Command Example
!iam-update-group scim={"id": "121212"} memberIdsToAdd=["123456"]
Context Example
{
"UpdateGroup": {
"brand": "OracleIAM",
"id": "121212",
"instanceName": "OracleIAM_instance_1",
"success": true
}
}
Human Readable Output
Oracle Cloud Update Group
brand id instanceName success OracleIAM 121212 OracleIAM_instance_1 true
Configuration parameters
url— Base URL (required)credentials— Client ID (required)create_user_enabled— Allow creating usersupdate_user_enabled— Allow updating usersenable_user_enabled— Allow enabling usersdisable_user_enabled— Allow disabling userscreate_if_not_exists— Automatically create user if not found in update commandmapper_in— Incoming Mapper (required)mapper_out— Outgoing Mapperinsecure— Trust any certificate (not secure)proxy— Use system proxy settings
Commands (9)
-
get-mapping-fieldsRetrieves a User Profile schema, which holds all of the user fields within the application. Used for outgoing-mapping through the Get Schema option.
-
iam-create-groupCreates an empty group.
-
iam-create-userCreates a user.
-
iam-delete-groupPermanently removes a group.
-
iam-disable-userDisable an active user.
-
iam-get-groupRetrieves the group information including members.
-
iam-get-userRetrieves a single user resource.
-
iam-update-groupUpdates an existing group resource. This command allows individual (or groups of) users to be added or removed from the group with a single operation. A maximum of 15,000 users can be modified in a single call.
-
iam-update-userUpdates an existing user with the data passed in the user-profile argument.
import pytest import requests_mock from IAMApiModule import * from OracleIAM import Client, create_group_command, delete_group_command, get_group_command, main, update_group_command APP_USER_OUTPUT = { "id": "123456", "userName": "mock_user_name", "first_name": "mock_first_name", "last_name": "mock_last_name", "active": "true", "email": "test@test.com", } APP_DISABLED_USER_OUTPUT = { "id": "123456", "userName": "mock_user_name", "first_name": "mock_first_name", "last_name": "mock_last_name", "active": "false", "email": "test@test.com", } APP_UPDATED_USER_OUTPUT = { "id": "123456", "userName": "new_mock_user_name", "first_name": "new_mock_first_name", "last_name": "new_mock_last_name", "active": "true", "email": "new_test@test.com", } APP_GROUP_OUTPUT = { "id": "1234", "displayName": "The group name", } def mock_client(): client = Client(base_url="https://test.com", headers={}) return client def get_outputs_from_user_profile(user_profile): entry_context = user_profile.to_entry() outputs = entry_context.get("Contents") return outputs class TestGetUserCommand: def test_existing_user(self): """ Given: - An app client object - A user-profile argument that contains an email of a user When: - The user exists in the application - Calling function get_user_command Then: - Ensure the resulted User Profile object holds the correct user details """ with requests_mock.Mocker() as m: m.post("https://test.com/oauth2/v1/token", json={}) m.get('https://test.com/admin/v1/Users?filter=userName eq "mock_user_name"', json={"Resources": [{"id": "123456"}]}) m.get("https://test.com/admin/v1/Users/123456", json=APP_USER_OUTPUT) client = mock_client() args = {"user-profile": {"username": "mock_user_name"}} user_profile = IAMCommand(get_user_iam_attrs=["username"]).get_user(client, args) outputs = get_outputs_from_user_profile(user_profile) assert outputs.get("action") == IAMActions.GET_USER assert outputs.get("success") is True assert outputs.get("active") == "true" assert outputs.get("id") == "123456" assert outputs.get("username") == "mock_user_name" assert outputs.get("details", {}).get("first_name") == "mock_first_name" assert outputs.get("details", {}).get("last_name") == "mock_last_name" def test_non_existing_user(self): """ Given: - An app client object - A user-profile argument that contains an email a user When: - The user does not exist in the application - Calling function get_user_command Then: - Ensure the resulted User Profile object holds information about an unsuccessful result. """ with requests_mock.Mocker() as m: m.post("https://test.com/oauth2/v1/token", json={}) m.get('https://test.com/admin/v1/Users?filter=userName eq "mock_user_name"', json={"Resources": []}) client = mock_client() args = {"user-profile": {"username": "mock_user_name"}} user_profile = IAMCommand(get_user_iam_attrs=["username"]).get_user(client, args) outputs = get_outputs_from_user_profile(user_profile) assert outputs.get("action") == IAMActions.GET_USER assert outputs.get("success") is False assert outputs.get("errorCode") == IAMErrors.USER_DOES_NOT_EXIST[0] assert outputs.get("errorMessage") == IAMErrors.USER_DOES_NOT_EXIST[1] def test_get_bad_response(self, mocker): """ Given: - An app client object - A user-profile argument that contains an email of a non-existing user in the application When: - Calling function get_user_command - A bad response (500) is returned from the application API Then: - Ensure the resulted User Profile object holds information about the bad response. """ import demistomock as demisto mocker.patch.object(demisto, "error") with requests_mock.Mocker() as m: m.post("https://test.com/oauth2/v1/token", json={}) m.get( 'https://test.com/admin/v1/Users?filter=userName eq "mock_user_name"', status_code=500, json={"detail": "INTERNAL SERVER ERROR"}, ) client = mock_client() args = {"user-profile": {"username": "mock_user_name"}} user_profile = IAMCommand(get_user_iam_attrs=["username"]).get_user(client, args) outputs = get_outputs_from_user_profile(user_profile) assert outputs.get("action") == IAMActions.GET_USER assert outputs.get("success") is False assert outputs.get("errorCode") == 500 assert "INTERNAL SERVER ERROR" in outputs.get("errorMessage") class TestCreateUserCommand: def test_success(self): """ Given: - An app client object - A user-profile argument that contains an email of a non-existing user in the application When: - Calling function create_user_command Then: - Ensure a User Profile object with the user data is returned """ with requests_mock.Mocker() as m: m.post("https://test.com/oauth2/v1/token", json={}) m.get('https://test.com/admin/v1/Users?filter=userName eq "mock_user_name"', json={"Resources": []}) m.post("https://test.com/admin/v1/Users", json=APP_USER_OUTPUT) client = mock_client() args = {"user-profile": {"username": "mock_user_name"}} user_profile = IAMCommand(get_user_iam_attrs=["username"]).create_user(client, args) outputs = get_outputs_from_user_profile(user_profile) assert outputs.get("action") == IAMActions.CREATE_USER assert outputs.get("success") is True assert outputs.get("active") == "true" assert outputs.get("id") == "123456" assert outputs.get("username") == "mock_user_name" assert outputs.get("details", {}).get("first_name") == "mock_first_name" assert outputs.get("details", {}).get("last_name") == "mock_last_name" def test_user_already_exists(self): """ Given: - An app client object - A user-profile argument that contains an email of a user When: - The user already exists in the application and disabled - allow-enable argument is false - Calling function create_user_command Then: - Ensure the command is considered successful and the user is still disabled """ with requests_mock.Mocker() as m: m.post("https://test.com/oauth2/v1/token", json={}) m.get('https://test.com/admin/v1/Users?filter=userName eq "mock_user_name"', json={"Resources": [{"id": "123456"}]}) m.get("https://test.com/admin/v1/Users/123456", json=APP_DISABLED_USER_OUTPUT) m.patch("https://test.com/admin/v1/Users/123456", json=APP_DISABLED_USER_OUTPUT) client = mock_client() args = {"user-profile": {"username": "mock_user_name"}} user_profile = IAMCommand(get_user_iam_attrs=["username"]).create_user(client, args) outputs = get_outputs_from_user_profile(user_profile) assert outputs.get("action") == IAMActions.UPDATE_USER assert outputs.get("success") is True assert outputs.get("active") == "false" assert outputs.get("id") == "123456" assert outputs.get("username") == "mock_user_name" assert outputs.get("details", {}).get("first_name") == "mock_first_name" assert outputs.get("details", {}).get("last_name") == "mock_last_name" class TestUpdateUserCommand: def test_non_existing_user(self): """ Given: - An app client object - A user-profile argument that contains user data When: - The user does not exist in the application - create-if-not-exists parameter is checked - Create User command is enabled - Calling function update_user_command Then: - Ensure the create action is executed - Ensure a User Profile object with the user data is returned """ with requests_mock.Mocker() as m: m.post("https://test.com/oauth2/v1/token", json={}) m.get('https://test.com/admin/v1/Users?filter=userName eq "mock_user_name"', json={"Resources": []}) m.post("https://test.com/admin/v1/Users", json=APP_USER_OUTPUT) client = mock_client() args = {"user-profile": {"username": "mock_user_name"}} user_profile = IAMCommand(create_if_not_exists=True, get_user_iam_attrs=["username"]).update_user(client, args) outputs = get_outputs_from_user_profile(user_profile) assert outputs.get("action") == IAMActions.CREATE_USER assert outputs.get("success") is True assert outputs.get("active") == "true" assert outputs.get("id") == "123456" assert outputs.get("username") == "mock_user_name" assert outputs.get("details", {}).get("first_name") == "mock_first_name" assert outputs.get("details", {}).get("last_name") == "mock_last_name" def test_command_is_disabled(self): """ Given: - An app client object - A user-profile argument that contains user data When: - Update User command is disabled - Calling function update_user_command Then: - Ensure the command is considered successful and skipped """ with requests_mock.Mocker() as m: m.post("https://test.com/oauth2/v1/token", json={}) client = mock_client() args = {"user-profile": {"username": "mock_user_name"}} user_profile = IAMCommand(is_update_enabled=False, get_user_iam_attrs=["username"]).update_user(client, args) outputs = get_outputs_from_user_profile(user_profile) assert outputs.get("action") == IAMActions.UPDATE_USER assert outputs.get("success") is True assert outputs.get("skipped") is True assert outputs.get("reason") == "Command is disabled." def test_allow_enable(self): """ Given: - An app client object - A user-profile argument that contains user data When: - The user is disabled in the application - allow-enable argument is true - Calling function update_user_command Then: - Ensure the user is enabled at the end of the command execution. """ with requests_mock.Mocker() as m: m.post("https://test.com/oauth2/v1/token", json={}) m.get('https://test.com/admin/v1/Users?filter=userName eq "mock_user_name"', json={"Resources": [{"id": "123456"}]}) m.get("https://test.com/admin/v1/Users/123456", json=APP_USER_OUTPUT) m.patch("https://test.com/admin/v1/Users/123456", json=APP_UPDATED_USER_OUTPUT) client = mock_client() args = {"user-profile": {"username": "mock_user_name"}, "allow-enable": "true"} user_profile = IAMCommand(get_user_iam_attrs=["username"]).update_user(client, args) outputs = get_outputs_from_user_profile(user_profile) assert outputs.get("action") == IAMActions.UPDATE_USER assert outputs.get("success") is True assert outputs.get("active") == "true" assert outputs.get("id") == "123456" assert outputs.get("username") == "new_mock_user_name" assert outputs.get("details", {}).get("first_name") == "new_mock_first_name" assert outputs.get("details", {}).get("last_name") == "new_mock_last_name" class TestDisableUserCommand: def test_non_existing_user(self): """ Given: - An app client object - A user-profile argument that contains an email of a user When: - create-if-not-exists parameter is unchecked - The user does not exist in the application - Calling function disable_user_command Then: - Ensure the command is considered successful and skipped """ with requests_mock.Mocker() as m: m.post("https://test.com/oauth2/v1/token", json={}) m.get('https://test.com/admin/v1/Users?filter=userName eq "mock_user_name"', json={"Resources": []}) client = mock_client() args = {"user-profile": {"username": "mock_user_name"}} user_profile = IAMCommand(get_user_iam_attrs=["username"]).disable_user(client, args) outputs = get_outputs_from_user_profile(user_profile) assert outputs.get("action") == IAMActions.DISABLE_USER assert outputs.get("success") is True assert outputs.get("skipped") is True assert outputs.get("reason") == IAMErrors.USER_DOES_NOT_EXIST[1] class TestGetGroupCommand: def test_with_id(self, mocker): """ Given: - An app client object - A scim argument that contains an ID of a group When: - The group exists in the application - Calling the main function with 'iam-get-group' command Then: - Ensure the resulted 'CommandResults' object holds the correct group details """ mock_result = mocker.patch("OracleIAM.CommandResults") args = {"scim": '{"id": "1234"}'} with requests_mock.Mocker() as m: m.post("https://test.com/oauth2/v1/token", json={}) m.get("https://test.com/admin/v1/Groups/1234", json=APP_GROUP_OUTPUT) client = mock_client() get_group_command(client, args) assert mock_result.call_args.kwargs["outputs"]["success"] is True assert mock_result.call_args.kwargs["outputs"]["id"] == "1234" assert mock_result.call_args.kwargs["outputs"]["displayName"] == "The group name" def test_with_display_name(self, mocker): """ Given: - An app client object - A scim argument that contains a displayName of a group When: - The group exists in the application - Calling the main function with 'iam-get-group' command Then: - Ensure the resulted 'CommandResults' object holds the correct group details """ mock_result = mocker.patch("OracleIAM.CommandResults") args = {"scim": '{"displayName": "The group name"}'} with requests_mock.Mocker() as m: m.post("https://test.com/oauth2/v1/token", json={}) m.get( 'https://test.com/admin/v1/Groups?filter=displayName eq "The+group+name"', json={"totalResults": 1, "Resources": [APP_GROUP_OUTPUT]}, ) client = mock_client() get_group_command(client, args) assert mock_result.call_args.kwargs["outputs"]["id"] == "1234" assert mock_result.call_args.kwargs["outputs"]["displayName"] == "The group name" def test_non_existing_group(self, mocker): """ Given: - An app client object - A scim argument that contains an ID and displayName of a mon_existing group When: - The group not exists in the application - Calling the main function with 'iam-get-group' command Then: - Ensure the resulted 'CommandResults' object holds information about an unsuccessful result. """ mock_result = mocker.patch("OracleIAM.CommandResults") args = {"scim": '{"id": "1234", "displayName": "The group name"}'} with requests_mock.Mocker() as m: m.post("https://test.com/oauth2/v1/token", json={}) m.get("https://test.com/admin/v1/Groups/1234", status_code=404, text="Group Not Found") client = mock_client() get_group_command(client, args) assert mock_result.call_args.kwargs["outputs"]["success"] is False assert mock_result.call_args.kwargs["outputs"]["id"] == "1234" assert mock_result.call_args.kwargs["outputs"]["errorCode"] == 404 assert mock_result.call_args.kwargs["outputs"]["errorMessage"] == "Group Not Found" def test_id_and_display_name_empty(self): """ Given: - An app client object - A scim argument that not contains an ID and displayName of a group When: - Calling the main function with 'iam-get-group' command Then: - Ensure that an error is raised with an expected message. """ args = {"scim": {}} with requests_mock.Mocker() as m: m.post("https://test.com/oauth2/v1/token", json={}) client = mock_client() with pytest.raises(Exception) as e: get_group_command(client, args) assert str(e.value) == 'You must supply either "id" or "displayName" in the scim data' class TestCreateGroupCommand: def test_success(self, mocker): """ Given: - An app client object - A scim argument that contains a displayName of a non-existing group in the application When: - Calling the main function with 'iam-create-group' command Then: - Ensure the resulted 'CommandResults' object holds information about the created group. """ mock_result = mocker.patch("OracleIAM.CommandResults") args = {"scim": '{"displayName": "The group name"}'} with requests_mock.Mocker() as m: m.post("https://test.com/oauth2/v1/token", json={}) m.post("https://test.com/admin/v1/Groups", status_code=201, json=APP_GROUP_OUTPUT) client = mock_client() create_group_command(client, args) assert mock_result.call_args.kwargs["outputs"]["success"] is True assert mock_result.call_args.kwargs["outputs"]["id"] == "1234" assert mock_result.call_args.kwargs["outputs"]["displayName"] == "The group name" def test_group_already_exist(self): """ Given: - An app client object - A scim argument that contains a displayName of an existing group in the application When: - Calling the main function with 'iam-create-group' command Then: - Ensure that an error is raised with an expected message. """ args = {"scim": '{"displayName": "The group name"}'} with requests_mock.Mocker() as m: m.post("https://test.com/oauth2/v1/token", json={}) m.post("https://test.com/admin/v1/Groups", status_code=400, json={"detail": "Group already exist", "status": 400}) client = mock_client() res = create_group_command(client, args) assert res.raw_response.get("errorCode") == 400 assert "Group already exist" in res.raw_response.get("errorMessage") def test_display_name_empty(self): """ Given: - An app client object - A scim argument that not contains a displayName When: - Calling the main function with 'iam-create-group' command Then: - Ensure that an error is raised with an expected message. """ args = {"scim": "{}"} with requests_mock.Mocker() as m: m.post("https://test.com/oauth2/v1/token", json={}) client = mock_client() with pytest.raises(Exception) as e: create_group_command(client, args) assert str(e.value) == 'You must supply "displayName" of the group in the scim data' class TestUpdateGroupCommand: def test_success(self, mocker): """ Given: - An app client object - A scim argument that contains a group ID and a memberIdsToAdd/memberIdsToDelete argument of the members who are supposed to be updated. When: - Calling the main function with 'iam-update-group' Then: - Ensure the resulted 'CommandResults' object holds information about the updated group. """ mock_result = mocker.patch("OracleIAM.CommandResults") args = {"scim": '{"id": "1234"}', "memberIdsToAdd": ["111111"], "memberIdsToDelete": ["222222"]} with requests_mock.Mocker() as m: m.post("https://test.com/oauth2/v1/token", json={}) m.patch("https://test.com/admin/v1/Groups/1234", status_code=200, json={}) client = mock_client() update_group_command(client, args) assert mock_result.call_args.kwargs["outputs"]["success"] is True assert mock_result.call_args.kwargs["outputs"]["id"] == "1234" def test_nothing_to_update(self): """ Given: - An app client object - A scim argument that contains a group ID. When: - Calling the main function with 'iam-update-group' Then: - Ensure that an error is raised with an expected message. """ args = {"scim": '{"id": "1234", "displayName": "The group name"}'} with requests_mock.Mocker() as m: m.post("https://test.com/oauth2/v1/token", json={}) client = mock_client() with pytest.raises(Exception) as e: update_group_command(client, args) assert str(e.value) == 'You must supply either "memberIdsToAdd" or "memberIdsToDelete" in the scim data' class TestDeleteGroupCommand: def test_success(self, mocker): """ Given: - An app client object - A scim argument that contains a group ID. When: - Calling the main function with 'iam-delete-group' Then: - Ensure the resulted 'CommandResults' object holds information about the deleted group. """ mock_result = mocker.patch("OracleIAM.CommandResults") args = {"scim": '{"id": "1234"}'} with requests_mock.Mocker() as m: m.post("https://test.com/oauth2/v1/token", json={}) m.delete("https://test.com/admin/v1/Groups/1234", status_code=204, json={}) client = mock_client() delete_group_command(client, args) assert mock_result.call_args.kwargs["outputs"]["success"] is True assert mock_result.call_args.kwargs["outputs"]["id"] == "1234" def test_non_existing_group(self): """ Given: - An app client object - A scim argument that contains a non-existing group ID. When: - Calling the main function with 'iam-delete-group' Then: - Ensure that an error is raised with an expected message. """ args = {"scim": '{"id": "1234"}'} with requests_mock.Mocker() as m: m.post("https://test.com/oauth2/v1/token", json={}) m.delete("https://test.com/admin/v1/Groups/1234", status_code=404, text="Group Not Found") client = mock_client() with pytest.raises(Exception) as e: delete_group_command(client, args) assert e.value.res.status_code == 404 assert "Group Not Found" in str(e.value) def test_id_is_empty(self): """ Given: - An app client object - A scim argument that not contains a group ID. When: - Calling the main function with 'iam-delete-group' Then: - Ensure that an error is raised with an expected message. """ args = {"scim": "{}"} with requests_mock.Mocker() as m: m.post("https://test.com/oauth2/v1/token", json={}) client = mock_client() with pytest.raises(Exception) as e: delete_group_command(client, args) assert str(e.value) == 'You must supply "id" in the scim data' def test_get_mapping_fields_command(mocker): """ Given: - An app client object When: - User schema in the application contains the fields 'field1' and 'field2' - Calling function get_mapping_fields_command Then: - Ensure a GetMappingFieldsResponse object that contains the application fields is returned """ import demistomock as demisto mocker.patch.object(demisto, "command", return_value="get-mapping-fields") mocker.patch.object(demisto, "params", return_value={"url": "https://test.com"}) mock_result = mocker.patch("OracleIAM.return_results") schema = { "attributes": [ {"name": "field1", "description": "desc1"}, {"name": "field2", "description": "desc2"}, ] } with requests_mock.Mocker() as m: m.post("https://test.com/oauth2/v1/token", json={}) m.get("https://test.com/admin/v1/Schemas/urn:ietf:params:scim:schemas:core:2.0:User", json=schema) main() mapping = mock_result.call_args.args[0].extract_mapping() assert mapping.get(IAMUserProfile.DEFAULT_INCIDENT_TYPE, {}).get("field1") == "desc1" assert mapping.get(IAMUserProfile.DEFAULT_INCIDENT_TYPE, {}).get("field2") == "desc2"