refactor(auth_v2): drop duplicate SCIM error helper and private re-exports

S7 is already handled self-contained by the SCIM router's route_class (renders
401/403 as a SCIM Error while preserving WWW-Authenticate), so remove the
redundant errors.scim_error_response and its AuthSecurity docstring note. Also
stop re-exporting private underscore helpers from the oidc/saml sub-package
__init__s; the public names (config + build_*_router) remain re-exported and
test code references the concrete modules for internals.
This commit is contained in:
Yassin Kortam 2026-06-10 19:45:14 -07:00
parent fec8e0a039
commit a9be3d23e0
4 changed files with 4 additions and 39 deletions

View file

@ -3,9 +3,6 @@ from __future__ import annotations
from typing import Optional
from fastapi import HTTPException
from fastapi.responses import JSONResponse
SCIM_ERROR_SCHEMA = "urn:ietf:params:scim:api:messages:2.0:Error"
class AuthError(HTTPException):
@ -55,16 +52,3 @@ def forbidden_permission() -> AuthError:
def account_disabled() -> AuthError:
return AuthError(403, "Account disabled")
def scim_error_response(exc: Exception) -> JSONResponse:
status_code = exc.status_code if isinstance(exc, HTTPException) else 500
detail = exc.detail if isinstance(exc, HTTPException) else "Internal server error"
return JSONResponse(
status_code=status_code,
content={
"schemas": [SCIM_ERROR_SCHEMA],
"status": str(status_code),
"detail": str(detail),
},
)

View file

@ -1,9 +1,4 @@
from .config import OIDCProviderConfig
from .router import _provider_key, _user_from_userinfo, build_oidc_router
from .router import build_oidc_router
__all__ = [
"OIDCProviderConfig",
"build_oidc_router",
"_provider_key",
"_user_from_userinfo",
]
__all__ = ["OIDCProviderConfig", "build_oidc_router"]

View file

@ -1,15 +1,4 @@
from .config import SAMLConfig
from .router import (
_map_attributes,
_metadata_source,
_user_from_mapped,
build_saml_router,
)
from .router import build_saml_router
__all__ = [
"SAMLConfig",
"build_saml_router",
"_map_attributes",
"_metadata_source",
"_user_from_mapped",
]
__all__ = ["SAMLConfig", "build_saml_router"]

View file

@ -40,9 +40,6 @@ class AuthSecurity:
uvicorn with ``--no-proxy-headers`` and let this module resolve the client IP,
or leave ``trusted_proxy_cidrs`` empty and rely on uvicorn's
``--forwarded-allow-ips``. Do not enable both.
To return SCIM-shaped error bodies, register ``errors.scim_error_response`` as
the host app's exception handler for the SCIM routes.
"""
def __init__(