fix(okta): stop partial updates erasing stored profile data (#6751)

* fix(okta): stop partial updates erasing stored profile data

Post-merge audit of the Okta integration (follows #6741), verified against the
OpenAPI spec bundled in okta-sdk-golang/.generator.

Two updates could silently destroy data:

- `update_group` targets `PUT /api/v1/groups/{groupId}`, which Okta documents as
  `replaceGroup` — it swaps the profile wholesale. Sending only the two fields
  the tool exposes erased the stored description on every rename, and dropped
  every org-defined custom attribute along with it. The tool now reads the group
  and overlays the supplied fields before replacing, matching the read-modify-
  write `salesforce_update_custom_field` already uses for the same hazard.
- `update_user` gated its profile fields on `!== undefined`, so an empty string
  reached Okta and blanked the stored value. The block strips blanks before they
  get there, but the tool is `user-or-llm` and a model routinely emits `""` for a
  field it has nothing to say about, so the guard belongs on the tool.

Also corrected:

- `forgetDevices` defaults to true at Okta, so the unseeded switch rendered off
  while remembered factors were in fact being cleared.
- Group rules take a plain keyword on `search`, not the SCIM-style expression the
  shared Search field's wand generates, so they get their own field.
- `get_logs` dropped `limit=0`, which the spec documents as valid.
- `get_user` emitted an activation timestamp under `activated`, which the block
  declares as the lifecycle boolean; the timestamp is now `activatedAt`.
- Descriptions that overstated what an endpoint does: `list_users` omits
  DEPROVISIONED users, `delete_user` deactivates before it deletes,
  `delete_group_rule` answers 202, and `excludedGroupIds` is always empty because
  Okta does not support group exclusions.

* fix(okta): forward the abort signal through the group read-modify-write

* test(okta): rename the shared body-builder helper

* fix(okta): key the send-email and search mappings off the operation

* docs(okta): use TSDoc for the new block annotations
This commit is contained in:
Waleed
2026-08-15 17:18:28 -07:00
committed by GitHub
parent 852906ec91
commit cbbcca970c
17 changed files with 449 additions and 70 deletions
@@ -40,7 +40,7 @@ Integrate Okta identity management into your workflow. Manage users, groups, and
### List Users from Okta
List all users in your Okta organization with optional search and filtering
List users in your Okta organization with optional search and filtering. Users with a DEPROVISIONED status are omitted unless a search or filter expression selects them.
#### Input
@@ -308,7 +308,7 @@ Permanently delete a user from your Okta organization. Can only be performed on
| Parameter | Type | Description |
| --------- | ---- | ----------- |
| `userId` | string | Deleted user ID |
| `deleted` | boolean | Whether the user was deleted |
| `deleted` | boolean | Whether the delete request was accepted. An ACTIVE user is deactivated by the first call and needs a second call to actually be deleted. |
| `success` | boolean | Operation success status |
### List Groups from Okta
@@ -396,7 +396,7 @@ Create a new group in your Okta organization
### Update Group in Okta
Update a group profile in your Okta organization. Only groups of OKTA_GROUP type can be updated. All profile properties must be specified (full replacement).
Update a group profile in your Okta organization. Only groups of OKTA_GROUP type can be updated. Fields left blank keep their stored value.
#### Input
@@ -552,7 +552,7 @@ List the group rules in your Okta organization. Each rule assigns users to group
| ↳ `expressionType` | string | Expression language, typically urn:okta:expression:1.0 |
| ↳ `assignUserToGroupIds` | array | Groups that matching users are assigned to |
| ↳ `excludedUserIds` | array | Users excluded from the rule |
| ↳ `excludedGroupIds` | array | Groups excluded from the rule |
| ↳ `excludedGroupIds` | array | Groups excluded from the rule. Always empty — Okta does not currently support group exclusions. |
| `count` | number | Number of rules returned |
| `nextCursor` | string | Cursor for the next page, or null on the last page |
| `hasMore` | boolean | Whether more rules are available |
@@ -584,7 +584,7 @@ Retrieve a single Okta group rule by ID, including the expression that decides w
| `expressionType` | string | Expression language, typically urn:okta:expression:1.0 |
| `assignUserToGroupIds` | array | Groups that matching users are assigned to |
| `excludedUserIds` | array | Users excluded from the rule |
| `excludedGroupIds` | array | Groups excluded from the rule |
| `excludedGroupIds` | array | Groups excluded from the rule. Always empty — Okta does not currently support group exclusions. |
| `success` | boolean | Operation success status |
### Create Group Rule in Okta
@@ -616,7 +616,7 @@ Create a group rule that automatically assigns users matching an Okta expression
| `expressionType` | string | Expression language, typically urn:okta:expression:1.0 |
| `assignUserToGroupIds` | array | Groups that matching users are assigned to |
| `excludedUserIds` | array | Users excluded from the rule |
| `excludedGroupIds` | array | Groups excluded from the rule |
| `excludedGroupIds` | array | Groups excluded from the rule. Always empty — Okta does not currently support group exclusions. |
| `success` | boolean | Operation success status |
### Activate Group Rule in Okta
@@ -677,7 +677,7 @@ Permanently delete a group rule. Destructive and irreversible. Optionally also r
| Parameter | Type | Description |
| --------- | ---- | ----------- |
| `groupRuleId` | string | Deleted group rule ID |
| `deleted` | boolean | Whether the rule was deleted |
| `deleted` | boolean | Whether the deletion was accepted. Okta answers 202 and removes the rule asynchronously. |
| `success` | boolean | Operation success status |
### List Factors from Okta