Skip to content

Commit 4930bee

Browse files
GH-2358 | inactivity_period Cannot Be Set To Null (#2614)
1 parent d9c7669 commit 4930bee

14 files changed

Lines changed: 14716 additions & 9736 deletions

File tree

Lines changed: 165 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,165 @@
1+
resource "okta_app_saml" "test" {
2+
label = "testAcc_replace_with_uuid"
3+
sso_url = "http://google.com"
4+
recipient = "http://here.com"
5+
destination = "http://its-about-the-journey.com"
6+
audience = "http://audience.com"
7+
subject_name_id_template = "$${user.userName}"
8+
subject_name_id_format = "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"
9+
response_signed = true
10+
signature_algorithm = "RSA_SHA256"
11+
digest_algorithm = "SHA256"
12+
honor_force_authn = false
13+
authn_context_class_ref = "urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport"
14+
single_logout_issuer = "https://dunshire.okta.com"
15+
single_logout_url = "https://dunshire.okta.com/logout"
16+
single_logout_certificate = "MIIFnDCCA4QCCQDBSLbiON2T1zANBgkqhkiG9w0BAQsFADCBjzELMAkGA1UEBhMCVVMxDjAMBgNV\r\nBAgMBU1haW5lMRAwDgYDVQQHDAdDYXJpYm91MRcwFQYDVQQKDA5Tbm93bWFrZXJzIEluYzEUMBIG\r\nA1UECwwLRW5naW5lZXJpbmcxDTALBgNVBAMMBFNub3cxIDAeBgkqhkiG9w0BCQEWEWVtYWlsQGV4\r\nYW1wbGUuY29tMB4XDTIwMTIwMzIyNDY0M1oXDTMwMTIwMTIyNDY0M1owgY8xCzAJBgNVBAYTAlVT\r\nMQ4wDAYDVQQIDAVNYWluZTEQMA4GA1UEBwwHQ2FyaWJvdTEXMBUGA1UECgwOU25vd21ha2VycyBJ\r\nbmMxFDASBgNVBAsMC0VuZ2luZWVyaW5nMQ0wCwYDVQQDDARTbm93MSAwHgYJKoZIhvcNAQkBFhFl\r\nbWFpbEBleGFtcGxlLmNvbTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBANMmWDjXPdoa\r\nPyzIENqeY9njLan2FqCbQPSestWUUcb6NhDsJVGSQ7XR+ozQA5TaJzbP7cAJUj8vCcbqMZsgOQAu\r\nO/pzYyQEKptLmrGvPn7xkJ1A1xLkp2NY18cpDTeUPueJUoidZ9EJwEuyUZIktzxNNU1pA1lGijiu\r\n2XNxs9d9JR/hm3tCu9Im8qLVB4JtX80YUa6QtlRjWR/H8a373AYCOASdoB3c57fIPD8ATDNy2w/c\r\nfCVGiyKDMFB+GA/WTsZpOP3iohRp8ltAncSuzypcztb2iE+jijtTsiC9kUA2abAJqqpoCJubNShi\r\nVff4822czpziS44MV2guC9wANi8u3Uyl5MKsU95j01jzadKRP5S+2f0K+n8n4UoV9fnqZFyuGAKd\r\nCJi9K6NlSAP+TgPe/JP9FOSuxQOHWJfmdLHdJD+evoKi9E55sr5lRFK0xU1Fj5Ld7zjC0pXPhtJf\r\nsgjEZzD433AsHnRzvRT1KSNCPkLYomznZo5n9rWYgCQ8HcytlQDTesmKE+s05E/VSWNtH84XdDrt\r\nieXwfwhHfaABSu+WjZYxi9CXdFCSvXhsgufUcK4FbYAHl/ga/cJxZc52yFC7Pcq0u9O2BSCjYPdQ\r\nDAHs9dhT1RhwVLM8RmoAzgxyyzau0gxnAlgSBD9FMW6dXqIHIp8yAAg9cRXhYRTNAgMBAAEwDQYJ\r\nKoZIhvcNAQELBQADggIBADofEC1SvG8qa7pmKCjB/E9Sxhk3mvUO9Gq43xzwVb721Ng3VYf4vGU3\r\nwLUwJeLt0wggnj26NJweN5T3q9T8UMxZhHSWvttEU3+S1nArRB0beti716HSlOCDx4wTmBu/D1MG\r\nt/kZYFJw+zuzvAcbYct2pK69AQhD8xAIbQvqADJI7cCK3yRry+aWtppc58P81KYabUlCfFXfhJ9E\r\nP72ffN4jVHpX3lxxYh7FKAdiKbY2FYzjsc7RdgKI1R3iAAZUCGBTvezNzaetGzTUjjl/g1tcVYij\r\nltH9ZOQBPlUMI88lxUxqgRTerpPmAJH00CACx4JFiZrweLM1trZyy06wNDQgLrqHr3EOagBF/O2h\r\nhfTehNdVr6iq3YhKWBo4/+RL0RCzHMh4u86VbDDnDn4Y6HzLuyIAtBFoikoKM6UHTOa0Pqv2bBr5\r\nwbkRkVUxl9yJJw/HmTCdfnsM9dTOJUKzEglnGF2184Gg+qJDZB6fSf0EAO1F6sTqiSswl+uHQZiy\r\nDaZzyU7Gg5seKOZ20zTRaX3Ihj9Zij/ORnrARE7eM/usKMECp+7syUwAUKxDCZkGiUdskmOhhBGL\r\nJtbyK3F2UvoJoLsm3pIcvMak9KwMjSTGJB47ABUP1+w+zGcNk0D5Co3IJ6QekiLfWJyQ+kKsWLKt\r\nzOYQQatrnBagM7MI2/T4\r\n"
17+
18+
attribute_statements {
19+
type = "GROUP"
20+
name = "groups"
21+
filter_type = "REGEX"
22+
filter_value = ".*"
23+
}
24+
}
25+
26+
data "okta_app_signon_policy" "test" {
27+
app_id = okta_app_saml.test.id
28+
}
29+
30+
resource "okta_user" "test" {
31+
count = 5
32+
first_name = "TestAcc"
33+
last_name = "Smith"
34+
login = "testAcc_${count.index}@example.com"
35+
email = "testAcc_${count.index}@example.com"
36+
}
37+
38+
resource "okta_group" "this" {
39+
count = 5
40+
name = "testAcc_${count.index}"
41+
description = "testAcc_${count.index}"
42+
}
43+
44+
resource "okta_user_type" "test" {
45+
name = "testAcc_replace_with_uuid"
46+
display_name = "Terraform Acceptance Test User Type Updated"
47+
description = "Terraform Acceptance Test User Type Updated"
48+
}
49+
50+
resource "okta_network_zone" "test" {
51+
name = "testAcc_replace_with_uuid"
52+
type = "IP"
53+
gateways = ["1.2.3.4/24", "2.3.4.5-2.3.4.15"]
54+
proxies = ["2.2.3.4/24", "3.3.4.5-3.3.4.15"]
55+
status = "ACTIVE"
56+
}
57+
58+
data "okta_user_type" "default" {
59+
name = "user"
60+
}
61+
62+
resource "okta_policy_device_assurance_android" "test" {
63+
name = "testAcc-replace_with_uuid"
64+
os_version = "12"
65+
jailbreak = false
66+
}
67+
68+
resource "okta_app_signon_policy_rule" "test" {
69+
name = "testAcc_replace_with_uuid_updated"
70+
policy_id = data.okta_app_signon_policy.test.id
71+
access = "ALLOW"
72+
custom_expression = "user.status == \"ACTIVE\""
73+
device_is_managed = false
74+
device_is_registered = true
75+
factor_mode = "2FA"
76+
groups_excluded = [
77+
okta_group.this[2].id,
78+
okta_group.this[3].id,
79+
okta_group.this[4].id
80+
]
81+
groups_included = [
82+
okta_group.this[0].id,
83+
okta_group.this[1].id
84+
]
85+
device_assurances_included = [
86+
okta_policy_device_assurance_android.test.id
87+
]
88+
network_connection = "ZONE"
89+
network_includes = [
90+
okta_network_zone.test.id
91+
]
92+
platform_include {
93+
os_type = "ANDROID"
94+
type = "MOBILE"
95+
}
96+
platform_include {
97+
os_type = "IOS"
98+
type = "MOBILE"
99+
}
100+
platform_include {
101+
os_type = "MACOS"
102+
type = "DESKTOP"
103+
}
104+
# FIXME Okta API for /api/v1/policies/{policyId}/rules/{ruleId}
105+
# is not returning os_expression even when it has been set throwing off the TF state.
106+
# platform_include {
107+
# os_expression = ".*"
108+
# os_type = "OTHER"
109+
# type = "DESKTOP"
110+
# }
111+
# platform_include {
112+
# os_expression = ".*"
113+
# os_type = "OTHER"
114+
# type = "MOBILE"
115+
# }
116+
risk_score = "MEDIUM"
117+
platform_include {
118+
os_type = "WINDOWS"
119+
type = "DESKTOP"
120+
}
121+
platform_include {
122+
os_type = "CHROMEOS"
123+
type = "DESKTOP"
124+
}
125+
priority = 98
126+
re_authentication_frequency = "PT43800H"
127+
type = "ASSURANCE"
128+
user_types_excluded = [
129+
okta_user_type.test.id
130+
]
131+
user_types_included = [
132+
data.okta_user_type.default.id
133+
]
134+
users_excluded = [
135+
okta_user.test[2].id,
136+
okta_user.test[3].id,
137+
okta_user.test[4].id
138+
]
139+
users_included = [
140+
okta_user.test[0].id,
141+
okta_user.test[1].id
142+
]
143+
constraints = [
144+
jsonencode({
145+
"knowledge" : {
146+
"reauthenticateIn" : "PT2H",
147+
"types" : ["password"],
148+
"required" : false
149+
},
150+
"possession" : {
151+
"deviceBound" : "REQUIRED",
152+
"required" : false
153+
}
154+
}),
155+
jsonencode({
156+
"possession" : {
157+
"deviceBound" : "REQUIRED",
158+
"hardwareProtection" : "REQUIRED",
159+
"userPresence" : "OPTIONAL",
160+
"userVerification" : "OPTIONAL",
161+
"required" : false
162+
}
163+
})
164+
]
165+
}
Lines changed: 1 addition & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -1,34 +1,4 @@
1-
resource "okta_app_saml" "test" {
2-
label = "testAcc_replace_with_uuid"
3-
sso_url = "http://google.com"
4-
recipient = "http://here.com"
5-
destination = "http://its-about-the-journey.com"
6-
audience = "http://audience.com"
7-
subject_name_id_template = "$${user.userName}"
8-
subject_name_id_format = "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"
9-
response_signed = true
10-
signature_algorithm = "RSA_SHA256"
11-
digest_algorithm = "SHA256"
12-
honor_force_authn = false
13-
authn_context_class_ref = "urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport"
14-
single_logout_issuer = "https://dunshire.okta.com"
15-
single_logout_url = "https://dunshire.okta.com/logout"
16-
single_logout_certificate = "MIIFnDCCA4QCCQDBSLbiON2T1zANBgkqhkiG9w0BAQsFADCBjzELMAkGA1UEBhMCVVMxDjAMBgNV\r\nBAgMBU1haW5lMRAwDgYDVQQHDAdDYXJpYm91MRcwFQYDVQQKDA5Tbm93bWFrZXJzIEluYzEUMBIG\r\nA1UECwwLRW5naW5lZXJpbmcxDTALBgNVBAMMBFNub3cxIDAeBgkqhkiG9w0BCQEWEWVtYWlsQGV4\r\nYW1wbGUuY29tMB4XDTIwMTIwMzIyNDY0M1oXDTMwMTIwMTIyNDY0M1owgY8xCzAJBgNVBAYTAlVT\r\nMQ4wDAYDVQQIDAVNYWluZTEQMA4GA1UEBwwHQ2FyaWJvdTEXMBUGA1UECgwOU25vd21ha2VycyBJ\r\nbmMxFDASBgNVBAsMC0VuZ2luZWVyaW5nMQ0wCwYDVQQDDARTbm93MSAwHgYJKoZIhvcNAQkBFhFl\r\nbWFpbEBleGFtcGxlLmNvbTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBANMmWDjXPdoa\r\nPyzIENqeY9njLan2FqCbQPSestWUUcb6NhDsJVGSQ7XR+ozQA5TaJzbP7cAJUj8vCcbqMZsgOQAu\r\nO/pzYyQEKptLmrGvPn7xkJ1A1xLkp2NY18cpDTeUPueJUoidZ9EJwEuyUZIktzxNNU1pA1lGijiu\r\n2XNxs9d9JR/hm3tCu9Im8qLVB4JtX80YUa6QtlRjWR/H8a373AYCOASdoB3c57fIPD8ATDNy2w/c\r\nfCVGiyKDMFB+GA/WTsZpOP3iohRp8ltAncSuzypcztb2iE+jijtTsiC9kUA2abAJqqpoCJubNShi\r\nVff4822czpziS44MV2guC9wANi8u3Uyl5MKsU95j01jzadKRP5S+2f0K+n8n4UoV9fnqZFyuGAKd\r\nCJi9K6NlSAP+TgPe/JP9FOSuxQOHWJfmdLHdJD+evoKi9E55sr5lRFK0xU1Fj5Ld7zjC0pXPhtJf\r\nsgjEZzD433AsHnRzvRT1KSNCPkLYomznZo5n9rWYgCQ8HcytlQDTesmKE+s05E/VSWNtH84XdDrt\r\nieXwfwhHfaABSu+WjZYxi9CXdFCSvXhsgufUcK4FbYAHl/ga/cJxZc52yFC7Pcq0u9O2BSCjYPdQ\r\nDAHs9dhT1RhwVLM8RmoAzgxyyzau0gxnAlgSBD9FMW6dXqIHIp8yAAg9cRXhYRTNAgMBAAEwDQYJ\r\nKoZIhvcNAQELBQADggIBADofEC1SvG8qa7pmKCjB/E9Sxhk3mvUO9Gq43xzwVb721Ng3VYf4vGU3\r\nwLUwJeLt0wggnj26NJweN5T3q9T8UMxZhHSWvttEU3+S1nArRB0beti716HSlOCDx4wTmBu/D1MG\r\nt/kZYFJw+zuzvAcbYct2pK69AQhD8xAIbQvqADJI7cCK3yRry+aWtppc58P81KYabUlCfFXfhJ9E\r\nP72ffN4jVHpX3lxxYh7FKAdiKbY2FYzjsc7RdgKI1R3iAAZUCGBTvezNzaetGzTUjjl/g1tcVYij\r\nltH9ZOQBPlUMI88lxUxqgRTerpPmAJH00CACx4JFiZrweLM1trZyy06wNDQgLrqHr3EOagBF/O2h\r\nhfTehNdVr6iq3YhKWBo4/+RL0RCzHMh4u86VbDDnDn4Y6HzLuyIAtBFoikoKM6UHTOa0Pqv2bBr5\r\nwbkRkVUxl9yJJw/HmTCdfnsM9dTOJUKzEglnGF2184Gg+qJDZB6fSf0EAO1F6sTqiSswl+uHQZiy\r\nDaZzyU7Gg5seKOZ20zTRaX3Ihj9Zij/ORnrARE7eM/usKMECp+7syUwAUKxDCZkGiUdskmOhhBGL\r\nJtbyK3F2UvoJoLsm3pIcvMak9KwMjSTGJB47ABUP1+w+zGcNk0D5Co3IJ6QekiLfWJyQ+kKsWLKt\r\nzOYQQatrnBagM7MI2/T4\r\n"
17-
18-
attribute_statements {
19-
type = "GROUP"
20-
name = "groups"
21-
filter_type = "REGEX"
22-
filter_value = ".*"
23-
}
24-
}
25-
26-
data "okta_app_signon_policy" "test" {
27-
app_id = okta_app_saml.test.id
28-
}
29-
301
resource "okta_app_signon_policy_rule" "test" {
31-
policy_id = data.okta_app_signon_policy.test.id
2+
policy_id = "rsttqgfcplSITe6Gi1d7"
323
name = "testAcc_replace_with_uuid"
334
}
34-

examples/resources/okta_app_signon_policy_rule/reauthentication.tf

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
resource "okta_app_signon_policy_rule" "test_with_reauthenticate_in_chains_only" {
2-
policy_id = "rstpbfm3a3IBq00o11d7"
2+
policy_id = "rsttqnoz5vo4GIoAD1d7"
33
name = "test_with_reauthenticate_in_chains_only"
44
type = "AUTH_METHOD_CHAIN"
55
priority = 3
@@ -62,14 +62,15 @@ resource "okta_app_signon_policy_rule" "test_with_reauthenticate_in_chains_only"
6262

6363

6464
resource "okta_app_signon_policy_rule" "test_with_re_authentication_frequency_only" {
65-
policy_id = "rstpbfm3a3IBq00o11d7"
65+
policy_id = "rsttqnoz5vo4GIoAD1d7"
6666
name = "test_with_re_authentication_frequency_only"
6767
type = "AUTH_METHOD_CHAIN"
6868
priority = 4
6969
network_connection = "ANYWHERE"
7070
access = "ALLOW"
7171
factor_mode = "2FA"
7272
re_authentication_frequency = "PT2H10M"
73+
inactivity_period = "PT1H"
7374
chains = [
7475
jsonencode({
7576
"authenticationMethods" : [

okta/services/idaas/app.go

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -439,15 +439,23 @@ func isACSEndpointSequential(acsEndpointsObj []*sdk.AcsEndpoint) bool {
439439
func deleteApplication(ctx context.Context, d *schema.ResourceData, m interface{}) error {
440440
client := getOktaClientFromMetadata(m)
441441
if d.Get("status").(string) == StatusActive {
442-
_, err := client.Application.DeactivateApplication(ctx, d.Id())
442+
// Okta Core can have eventual consistency issues, use backoff for deactivation as well
443+
boc := utils.NewExponentialBackOffWithContext(ctx, 20*time.Second)
444+
err := backoff.Retry(func() error {
445+
_, err := client.Application.DeactivateApplication(ctx, d.Id())
446+
if doNotRetry(m, err) {
447+
return backoff.Permanent(err)
448+
}
449+
return err
450+
}, boc)
443451
if err != nil {
444452
return err
445453
}
446454
}
447455

448456
// Okta Core can have eventual consistency issues when deactivating an app
449457
// which is required before deleting the app.
450-
boc := utils.NewExponentialBackOffWithContext(ctx, 5*time.Second)
458+
boc := utils.NewExponentialBackOffWithContext(ctx, 30*time.Second)
451459
err := backoff.Retry(func() error {
452460
_, err := client.Application.DeleteApplication(ctx, d.Id())
453461
if doNotRetry(m, err) {

okta/services/idaas/resource_okta_app_signon_policy_rule.go

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -208,7 +208,6 @@ The only difference is that these fields are immutable and can not be managed: '
208208
Type: schema.TypeString,
209209
Optional: true,
210210
Description: "The inactivity duration after which the end user must re-authenticate. Use the ISO 8601 Period format for recurring time intervals.",
211-
Default: "PT1H",
212211
},
213212
"constraints": {
214213
Type: schema.TypeList,
@@ -311,8 +310,6 @@ func resourceAppSignOnPolicyRuleRead(ctx context.Context, d *schema.ResourceData
311310
_ = d.Set("re_authentication_frequency", rule.Actions.AppSignOn.VerificationMethod.ReauthenticateIn)
312311
if rule.Actions.AppSignOn.VerificationMethod.InactivityPeriod != "" {
313312
_ = d.Set("inactivity_period", rule.Actions.AppSignOn.VerificationMethod.InactivityPeriod)
314-
} else {
315-
_ = d.Set("inactivity_period", "PT1H")
316313
}
317314
constraintArr := make([]interface{}, len(rule.Actions.AppSignOn.VerificationMethod.Constraints))
318315
for i := range rule.Actions.AppSignOn.VerificationMethod.Constraints {

okta/services/idaas/resource_okta_app_signon_policy_rule_test.go

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ func TestAccResourceOktaAppSignOnPolicyRule_crud(t *testing.T) {
2424
mgr := newFixtureManager("resources", resources.OktaIDaaSAppSignOnPolicyRule, t.Name())
2525
config := mgr.GetFixtures("basic.tf", t)
2626
updatedConfig := mgr.GetFixtures("basic_updated.tf", t)
27-
27+
updatedConfig2 := mgr.GetFixtures("basic_updated_2.tf", t)
2828
acctest.OktaResourceTest(t, resource.TestCase{
2929
PreCheck: acctest.AccPreCheck(t),
3030
ErrorCheck: testAccErrorChecks(t),
@@ -51,7 +51,6 @@ func TestAccResourceOktaAppSignOnPolicyRule_crud(t *testing.T) {
5151
resource.TestCheckResourceAttr(resourceName, "network_connection", "ANYWHERE"),
5252
resource.TestCheckResourceAttr(resourceName, "constraints.#", "0"),
5353
resource.TestCheckResourceAttr(resourceName, "re_authentication_frequency", "PT2H"),
54-
resource.TestCheckResourceAttr(resourceName, "inactivity_period", "PT1H"),
5554
resource.TestCheckResourceAttr(resourceName, "risk_score", "LOW"),
5655
resource.TestCheckResourceAttr(resourceName, "platform_include.#", "1"),
5756
),
@@ -82,6 +81,12 @@ func TestAccResourceOktaAppSignOnPolicyRule_crud(t *testing.T) {
8281
resource.TestCheckResourceAttr(resourceName, "risk_score", "MEDIUM"),
8382
),
8483
},
84+
{
85+
Config: updatedConfig2,
86+
Check: resource.ComposeTestCheckFunc(
87+
resource.TestCheckResourceAttr(resourceName, "inactivity_period", ""),
88+
),
89+
},
8590
{
8691
ResourceName: resourceName,
8792
ImportState: true,
@@ -374,8 +379,6 @@ func TestAccResourceOktaAppSignOnPolicyRule_default_crud(t *testing.T) {
374379
resource.TestCheckResourceAttr(resourceName, "network_connection", "ANYWHERE"),
375380
resource.TestCheckResourceAttr(resourceName, "constraints.#", "0"),
376381
resource.TestCheckResourceAttr(resourceName, "re_authentication_frequency", "PT2H"),
377-
resource.TestCheckResourceAttr(resourceName, "inactivity_period", "PT1H"),
378-
resource.TestCheckResourceAttr(resourceName, "risk_score", "ANY"),
379382
),
380383
},
381384
},
@@ -462,6 +465,7 @@ func TestAccResourceOktaAppSignOnPolicyRule_ReauthenticationFrequency(t *testing
462465
resource.TestCheckResourceAttrWith(resourceName1, "chains.0", checkReauthenticateInChains),
463466
resource.TestCheckResourceAttrWith(resourceName1, "chains.1", checkReauthenticateInChains),
464467
resource.TestCheckResourceAttr(resourceName2, "re_authentication_frequency", "PT2H10M"),
468+
resource.TestCheckResourceAttr(resourceName2, "inactivity_period", "PT1H"),
465469
),
466470
},
467471
},

0 commit comments

Comments
 (0)