From nobody Thu Jul  7 10:36:46 2022
Return-Path: <phil.hunt@independentid.com>
X-Original-To: scim@ietfa.amsl.com
Delivered-To: scim@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id 3A76FC15A73F
 for <scim@ietfa.amsl.com>; Thu,  7 Jul 2022 10:36:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.903
X-Spam-Level: 
X-Spam-Status: No, score=-1.903 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
 HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, SPF_HELO_NONE=0.001,
 SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001,
 URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001]
 autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key)
 header.d=independentid-com.20210112.gappssmtp.com
Received: from mail.ietf.org ([50.223.129.194])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id hi1klrMY4fA8 for <scim@ietfa.amsl.com>;
 Thu,  7 Jul 2022 10:36:41 -0700 (PDT)
Received: from mail-pg1-x531.google.com (mail-pg1-x531.google.com
 [IPv6:2607:f8b0:4864:20::531])
 (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)
 key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256)
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id B6A35C157B4A
 for <scim@ietf.org>; Thu,  7 Jul 2022 10:35:59 -0700 (PDT)
Received: by mail-pg1-x531.google.com with SMTP id q82so12597196pgq.6
 for <scim@ietf.org>; Thu, 07 Jul 2022 10:35:59 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=independentid-com.20210112.gappssmtp.com; s=20210112;
 h=from:message-id:mime-version:subject:date:in-reply-to:cc:to
 :references; bh=Nw1f1JvuThEjVRdWAyN0Y+yhVJYZjZRnvjelWbRLDjA=;
 b=XgeQ1cGi1Hz0F+Yi55hEyCsJz+d2ciEE69mMHWz7qAUb+Y3UOvN1ruKRWbmKBW448+
 EuBST03vdjIaXvTbb+rkf1imvm/9/OvzAVmlbH1CAaggvT4sde1zYW3w1nD6wE5I29Pi
 /5SAr8d4Vd2+54oSmuXO0YfKs2qNLt8g3bIKT3wMhM/clf3rAJxIvgVwCcG4/LLMYg0d
 b9KDqXPO3175Mad3a2HwFM4CtKeQu6cxbkflzaYbpscNUt1EQxN1auMc6LE3UgGODhog
 rIJJv5cm3eJ+ZjuEeZpoRaIpSJZIKcABL/X4m4VQp+8WKAkEVzW0HYiGNaTcXiSu1/F9
 exkA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20210112;
 h=x-gm-message-state:from:message-id:mime-version:subject:date
 :in-reply-to:cc:to:references;
 bh=Nw1f1JvuThEjVRdWAyN0Y+yhVJYZjZRnvjelWbRLDjA=;
 b=qhOy0TguusnMPqCKQ9VyFQ5MNKfqFN6c39NWl88haYjFMXfusFhcF7C8j50YGtdOrG
 h7m5HMjBKyTxESusiQVgaYu6j5w44W/3VeFRCsaNn8CpCTZ1PxmdZMbf7cxJrHmQEiYC
 E9/BNHSgpSHRvo/rPJiUTmNFqNUPKujwEsErfBDJnctk77n9SpK11CUekxW2YKQQ/PuK
 tS2u6G5yODMLMPFz7fbjTxVb2N8BTKg71nWkk4LfBszUvo/t/tCoNiSDDRMY5lwnEM7C
 3TlWG5H6Mghk19l2bRPZqm4Fd4H3GAfWvG0A8pUMVqSAI5CFwoXBDDEqkp9jFmNPkzCB
 +t5A==
X-Gm-Message-State: AJIora8BIIUFQTkqklkj30BauN3V52d6o1nJGIsM+eyygbjgMVLU8XA+
 RcofsRigRqGE9MRvQovA6ceeS4R+DUxUUw==
X-Google-Smtp-Source: AGRyM1vMRQfWACzFaWr4XVFq16kk/Y2HvA8f4b1HCivlsw/eq7Xi58zECv5GZIt/v61Iles1OmGb9g==
X-Received: by 2002:a17:903:1207:b0:16a:7e87:dad3 with SMTP id
 l7-20020a170903120700b0016a7e87dad3mr53990184plh.99.1657215358857; 
 Thu, 07 Jul 2022 10:35:58 -0700 (PDT)
Received: from smtpclient.apple (node-1w7jr9qjhqzxomcnng94hruik.ipv6.telus.net.
 [2001:569:7316:ae00:75b5:8761:3d20:a43c])
 by smtp.gmail.com with ESMTPSA id
 n8-20020a170902d2c800b0016be593b9e6sm9043295plc.167.2022.07.07.10.35.57
 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
 Thu, 07 Jul 2022 10:35:58 -0700 (PDT)
From: Phillip Hunt <phil.hunt@independentid.com>
Message-Id: <E034E806-F3BF-41B0-88BE-FC9C4E420561@independentid.com>
Content-Type: multipart/alternative;
 boundary="Apple-Mail=_C1A9D46B-F07A-49A2-B391-48030302D75A"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3696.100.31\))
Date: Thu, 7 Jul 2022 10:35:57 -0700
In-Reply-To: <7792b174-48ad-181c-11e1-9adb5ff3bc54@audriga.com>
Cc: Danny Zollner <Danny.Zollner@microsoft.com>,
 "scim@ietf.org" <scim@ietf.org>
To: Julien Schneider <julien@audriga.com>
References: <bc9c53f8-82fd-57e9-8fe0-166e91048d6b@audriga.com>
 <MN2PR00MB07189D4A9DA54A11131E9896FF839@MN2PR00MB0718.namprd00.prod.outlook.com>
 <7792b174-48ad-181c-11e1-9adb5ff3bc54@audriga.com>
X-Mailer: Apple Mail (2.3696.100.31)
Archived-At: <https://mailarchive.ietf.org/arch/msg/scim/9HPgM8c6jyTCjVhwmBRt5pgd-Ms>
Subject: Re: [scim] [EXTERNAL] Query on a specific known resource
X-BeenThere: scim@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Simple Cloud Identity Management BOF <scim.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/scim>,
 <mailto:scim-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/scim/>
List-Post: <mailto:scim@ietf.org>
List-Help: <mailto:scim-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/scim>,
 <mailto:scim-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 07 Jul 2022 17:36:45 -0000


--Apple-Mail=_C1A9D46B-F07A-49A2-B391-48030302D75A
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Julien,

You are not wrong.  All queries regardless of path MUST have a =
ListResponse.

It may seem logical to make the jump to just returning a single resource =
for a query that can only return a single result, but this is not =
permitted in the RFC. =46rom a protocol point of view, allowing skipping =
ListResponse makes the protocol more complex because it creates =
=E2=80=9Cexceptions=E2=80=9D which have to be handled. For example, what =
happens if no filter match etc.

For the group:  For historical information, the issue is actually more =
complex than it seems.   For SCIM queries SCIM=E2=80=99s profile of HTTP =
overrides both HTTP GET (retrieves a resource) and HTTP POST (create a =
resource) to perform a search function. In the case of GET, url based =
filters cause privacy concerns because of the leak of confidential =
information in URLs. The GET method does not allow request bodies. =
Because of thies, SCIM also supports http POST queries. The HTTP =
definition suggests creation a resource.  Dual purposing these methods =
for search queries created necessary complexity. One of the basic rules =
of thumb is that whenever a =E2=80=9Cfilter=E2=80=9D shows up in a =
request, the request becomes a SCIM Query which mandates a ListResponse.

I discussed this at length with authors of the HTTP specifications and =
worked with Julian Reschke (co-author of HTTP) to submit a proposal for =
a HTTP SEARCH method.  This would unburden GET and POST methods and =
simplify protocol overall.  Julian indicated to me at the time of =
finalizing SCIM (around IETF93), that this issue comes up frequently for =
him as one of the HTTP authors.  In the end, the HTTPbis WG chose not to =
create a new method because there is too much water under the bridge.  =
See: https://httpwg.org/wg-materials/ietf93/ietf-93-httpbis-search.pdf

Phillip Hunt
@independentid
phil.hunt@independentid.com




> On Jul 7, 2022, at 12:57 AM, Julien Schneider <julien@audriga.com> =
wrote:
>=20
> Hi Danny, hi Phillip, hi everyone,
>=20
> Thanks for your answers. I think the confusing part (for me at least) =
is "Queries MAY be made against a single resource or a resource type =
endpoint ......." at the beginning of RFC7644 section 3.4.2., followed =
by "Responses MUST be identified using the following URI: =
"urn:ietf:params:scim:api:messages:2.0:ListResponse" ".
>=20
> My interpretation is that "GET =
/Users/2819c223-7f76-453a-919d-413861904646?attributes=3DuserName" is a =
query against a single resource, and should then have a "ListResponse" =
response? Where am I wrong here?
>=20
> Thanks
>=20
> Julien Schneider
> Tel: +49 721 170293 16
> Fax: +49 721 170293 179
>=20
> http://www.audriga.com <http://www.audriga.com/> | =
http://www.twitter.com/audriga <http://www.twitter.com/audriga>
>=20
> =
--------------------------------------------------------------------------=

> audriga GmbH |  Alter Schlachthof 57  | 76137 Karlsruhe
> Sitz der Gesellschaft: Karlsruhe - Amtsgericht Mannheim - HRB 713034
> Gesch=C3=A4ftsf=C3=BChrer: Dr. Frank Dengler, Dr.-Ing. Hans-J=C3=B6rg =
Happel
> =
--------------------------------------------------------------------------=

> On 07/07/2022 04:51, Danny Zollner wrote:
>> Hi Julien,
>> =20
>> RFC 7644 section 3.4.2 specifically is talking about queries. =
Retrieving or modifying known resources (i.e.: GET /Users/12345 ) does =
not require a ListResponse type response. A query of GET =
/Users?filter=3Ddisplayname contains =E2=80=9Ccontoso.com=E2=80=9D or =
GET /Users?attributes=3DuserName would require a ListResponse type =
response, as it does not identify a specific resource in the query URL =
via ID value (i.e.: =E2=80=9C12345=E2=80=9D in the previous example). On =
the other hand, GET /Users/12345?attributes=3DuserName does not require =
the ListResponse type response as it does identify a specific resource.
>> =20
>> To explicitly answer the final question in your email =E2=80=93 the =
expected response to GET =
/Users/2819c223-7f76-453a-919d-413861904646?attributes=3DuserNamewould =
be the second example you provided.
>> =20
>> Cheers,
>> =20
>> Danny Zollner
>> =20
>> From: scim <scim-bounces@ietf.org> <mailto:scim-bounces@ietf.org> On =
Behalf Of Julien Schneider
>> Sent: Wednesday, July 6, 2022 3:41 AM
>> To: scim@ietf.org <mailto:scim@ietf.org>
>> Subject: [EXTERNAL] [scim] Query on a specific known resource
>> =20
>>=20
>> Some people who received this message don't often get email from =
julien@audriga.com <mailto:julien@audriga.com>. Learn why this is =
important <https://aka.ms/LearnAboutSenderIdentification>=09
>> Hi all,
>>=20
>> I have a question about queries performed against a SCIM resource =
object (like "/Users/{id}").
>>=20
>> The RFC (https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2 =
<https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fdatat=
racker.ietf.org%2Fdoc%2Fhtml%2Frfc7644%23section-3.4.2&data=3D05%7C01%7Cda=
nny.zollner%40microsoft.com%7C29270780ce9941a0687808da5f2b53db%7C72f988bf8=
6f141af91ab2d7cd011db47%7C1%7C0%7C637926937860837552%7CUnknown%7CTWFpbGZsb=
3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C20=
00%7C%7C%7C&sdata=3DfVtTna44Hr973Z79OsTegu9U9%2FpDwRcBZignfi5Eluk%3D&reser=
ved=3D0>) states:=20
>> Responses MUST be identified using the following URI:
>>    "urn:ietf:params:scim:api:messages:2.0:ListResponse"
>>=20
>> If I understand correctly, that means the "schemas" parameter of the =
response to those queries must be set to:
>> "schemas":["urn:ietf:params:scim:api:messages:2.0:ListResponse"]
>>=20
>> While I understand how that applies to queries on a resource type =
endpoint (like "/Users") or on the SCIM server root, I don't understand =
how that applies to queries on a specific resource object.
>> If I understand correctly, queries on a specific resource object =
actually are quite identical to "retrieving a known resource" =
(https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.1 =
<https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fdatat=
racker.ietf.org%2Fdoc%2Fhtml%2Frfc7644%23section-3.4.1&data=3D05%7C01%7Cda=
nny.zollner%40microsoft.com%7C29270780ce9941a0687808da5f2b53db%7C72f988bf8=
6f141af91ab2d7cd011db47%7C1%7C0%7C637926937860837552%7CUnknown%7CTWFpbGZsb=
3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C20=
00%7C%7C%7C&sdata=3DDQEZdlY7XBONxFIegf1SCJfpdjpDdWzBvh5%2FzB%2B2EpQ%3D&res=
erved=3D0>) which are a GET on a specific resource, like:
>> GET /Users/2819c223-7f76-453a-919d-413861904646
>> Responses to those requests should have the "schemas" parameter set =
to the resource schema(s):
>> {
>>      "schemas":["urn:ietf:params:scim:schemas:core:2.0:User"],
>>      "id":"2819c223-7f76-453a-919d-413861904646",
>> ...
>> }
>>=20
>> Now, how should the response to the following query should look like? =
And to what value should the "schemas" parameter of the response be set?
>> GET /Users/2819c223-7f76-453a-919d-413861904646?attributes=3DuserName
>>=20
>> Should it be:
>>    {
>>      =
"schemas":["urn:ietf:params:scim:api:messages:2.0:ListResponse"],
>>      "totalResults":1,
>>      "Resources":[
>>        {
>>          "id":"2819c223-7f76-453a-919d-413861904646",
>>          "userName":"bjensen"
>>        }
>>      ]
>>    }
>>=20
>> Or something like:
>>    {
>>      "schemas":["urn:ietf:params:scim:schemas:core:2.0:User"],
>>      "id":"2819c223-7f76-453a-919d-413861904646",
>>      "meta":{
>>        "resourceType":"User",
>>        "created":"2011-08-01T18:29:49.793Z",
>>        "lastModified":"2011-08-01T18:29:49.793Z",
>>        "location":
>>    =
"https://example.com/v2/Users/2819c223-7f76-453a-919d-413861904646" =
<https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fexamp=
le.com%2Fv2%2FUsers%2F2819c223-7f76-453a-919d-413861904646&data=3D05%7C01%=
7Cdanny.zollner%40microsoft.com%7C29270780ce9941a0687808da5f2b53db%7C72f98=
8bf86f141af91ab2d7cd011db47%7C1%7C0%7C637926937860837552%7CUnknown%7CTWFpb=
GZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%=
7C2000%7C%7C%7C&sdata=3DHRI2UjMUWpVqb0IzoOcpDNA%2FVVDBG3lZ4gU6C60Gr1I%3D&r=
eserved=3D0>,
>>        "version":"W\/\"f250dd84f0671c3\""
>>      },
>>      "userName":"bjensen"
>>    }
>>=20
>> Thanks a lot in advance
>>=20
>> --=20
>> Julien Schneider
>> Tel: +49 721 170293 16
>> Fax: +49 721 170293 179
>> =20
>> http://www.audriga.com =
<https://nam06.safelinks.protection.outlook.com/?url=3Dhttp%3A%2F%2Fwww.au=
driga.com%2F&data=3D05%7C01%7Cdanny.zollner%40microsoft.com%7C29270780ce99=
41a0687808da5f2b53db%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C63792693=
7860837552%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJ=
BTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7C%7C&sdata=3D37nDJF0vyrffA22bld7R3W=
HNu11PnoLTmWCne%2FGCios%3D&reserved=3D0> | =
http://www.twitter.com/audriga =
<https://nam06.safelinks.protection.outlook.com/?url=3Dhttp%3A%2F%2Fwww.tw=
itter.com%2Faudriga&data=3D05%7C01%7Cdanny.zollner%40microsoft.com%7C29270=
780ce9941a0687808da5f2b53db%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C6=
37926937860837552%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2lu=
MzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7C%7C&sdata=3DP5As3bPNzRa4zSX=
SdYj9%2BirwGEkk6%2BYy5jkVKNAQnYw%3D&reserved=3D0>
>> =20
>> =
--------------------------------------------------------------------------=

>> audriga GmbH |  Alter Schlachthof 57  | 76137 Karlsruhe
>> Sitz der Gesellschaft: Karlsruhe - Amtsgericht Mannheim - HRB 713034
>> Gesch=C3=A4ftsf=C3=BChrer: Dr. Frank Dengler, Dr.-Ing. Hans-J=C3=B6rg =
Happel
>> =
--------------------------------------------------------------------------=

>=20
> _______________________________________________
> scim mailing list
> scim@ietf.org
> https://www.ietf.org/mailman/listinfo/scim


--Apple-Mail=_C1A9D46B-F07A-49A2-B391-48030302D75A
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" =
class=3D"">Julien,<div class=3D""><br class=3D""></div><div class=3D"">You=
 are not wrong. &nbsp;All queries regardless of path MUST have a =
ListResponse.</div><div class=3D""><br class=3D""></div><div class=3D"">It=
 may seem logical to make the jump to just returning a single resource =
for a query that can only return a single result, but this is not =
permitted in the RFC. =46rom a protocol point of view, allowing skipping =
ListResponse makes the protocol more complex because it creates =
=E2=80=9Cexceptions=E2=80=9D which have to be handled. For example, what =
happens if no filter match etc.</div><div class=3D""><br =
class=3D""></div><div class=3D"">For the group: &nbsp;For historical =
information, the issue is actually more complex than it seems. &nbsp; =
For SCIM queries SCIM=E2=80=99s profile of HTTP overrides both HTTP GET =
(retrieves a resource) and HTTP POST (create a resource) to perform a =
search function. In the case of GET, url based filters cause privacy =
concerns because of the leak of confidential information in URLs. The =
GET method does not allow request bodies. Because of thies, SCIM also =
supports http POST queries. The HTTP definition suggests creation a =
resource. &nbsp;Dual purposing these methods for search queries created =
necessary complexity. One of the basic rules of thumb is that whenever a =
=E2=80=9Cfilter=E2=80=9D shows up in a request, the request becomes a =
SCIM Query which mandates a ListResponse.</div><div class=3D""><br =
class=3D""></div><div class=3D"">I discussed this at length with authors =
of the HTTP specifications and worked with Julian Reschke (co-author of =
HTTP) to submit a proposal for a HTTP SEARCH method. &nbsp;This would =
unburden GET and POST methods and simplify protocol overall. =
&nbsp;Julian indicated to me at the time of finalizing SCIM (around =
IETF93), that this issue comes up frequently for him as one of the HTTP =
authors. &nbsp;In the end, the HTTPbis WG chose not to create a new =
method because there is too much water under the bridge. =
&nbsp;See:&nbsp;<a =
href=3D"https://httpwg.org/wg-materials/ietf93/ietf-93-httpbis-search.pdf"=
 =
class=3D"">https://httpwg.org/wg-materials/ietf93/ietf-93-httpbis-search.p=
df</a></div><div class=3D""><br class=3D""></div><div class=3D""><div =
class=3D"">
<div dir=3D"auto" style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, =
0); letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; word-wrap: =
break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" =
class=3D""><div>Phillip Hunt</div><div>@independentid</div><div><a =
href=3D"mailto:phil.hunt@independentid.com" =
class=3D"">phil.hunt@independentid.com</a></div><div class=3D""><br =
class=3D""></div></div><br class=3D"Apple-interchange-newline"><br =
class=3D"Apple-interchange-newline">
</div>
<div><br class=3D""><blockquote type=3D"cite" class=3D""><div =
class=3D"">On Jul 7, 2022, at 12:57 AM, Julien Schneider &lt;<a =
href=3D"mailto:julien@audriga.com" class=3D"">julien@audriga.com</a>&gt; =
wrote:</div><br class=3D"Apple-interchange-newline"><div class=3D""><meta =
charset=3D"UTF-8" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: 400; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">Hi Danny, hi Phillip, hi everyone,</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: 400; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: 400; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: 400; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">Thanks for your answers. I think =
the confusing part (for me at least) is "Queries MAY be made<span =
class=3D"Apple-converted-space">&nbsp;</span></span><u =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: 400; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px;" class=3D""><b class=3D"">against a =
single resource</b></u><span style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: 400; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D""><span class=3D"Apple-converted-space">&nbsp;</span>or a =
resource type endpoint ......." at the beginning of RFC7644 section =
3.4.2., followed by "Responses MUST be identified using the following =
URI: "urn:ietf:params:scim:api:messages:2.0:ListResponse" ".</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: 400; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: 400; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: 400; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">My interpretation is that =
"</span><b style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; =
font-size: 12px; font-style: normal; font-variant-caps: normal; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D"">GET =
/Users/2819c223-7f76-453a-919d-413861904646?attributes=3DuserName</b><span=
 style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: 400; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">" is a query against a single =
resource, and should then have a "ListResponse" response? Where am I =
wrong here?</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: 400; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: 400; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: 400; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" =
class=3D"">Thanks</span><br style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: 400; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: 400; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><pre class=3D"moz-signature" =
cols=3D"72" style=3D"margin: 0in 0in 0.0001pt; font-size: 10pt; =
font-family: &quot;Courier New&quot;; caret-color: rgb(0, 0, 0); =
font-style: normal; font-variant-caps: normal; font-weight: 400; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;">Julien Schneider
Tel: +49 721 170293 16
Fax: +49 721 170293 179

<a class=3D"moz-txt-link-freetext" href=3D"http://www.audriga.com/" =
style=3D"color: blue; text-decoration: =
underline;">http://www.audriga.com</a> | <a =
class=3D"moz-txt-link-freetext" href=3D"http://www.twitter.com/audriga" =
style=3D"color: blue; text-decoration: =
underline;">http://www.twitter.com/audriga</a>

=
--------------------------------------------------------------------------=

audriga GmbH |  Alter Schlachthof 57  | 76137 Karlsruhe
Sitz der Gesellschaft: Karlsruhe - Amtsgericht Mannheim - HRB 713034
Gesch=C3=A4ftsf=C3=BChrer: Dr. Frank Dengler, Dr.-Ing. Hans-J=C3=B6rg =
Happel
=
--------------------------------------------------------------------------=
</pre><div class=3D"moz-cite-prefix" style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: 400; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;">On 07/07/2022 04:51, Danny Zollner wrote:<br =
class=3D""></div><blockquote type=3D"cite" =
cite=3D"mid:MN2PR00MB07189D4A9DA54A11131E9896FF839@MN2PR00MB0718.namprd00.=
prod.outlook.com" style=3D"font-family: Helvetica; font-size: 12px; =
font-style: normal; font-variant-caps: normal; font-weight: 400; =
letter-spacing: normal; orphans: auto; text-align: start; text-indent: =
0px; text-transform: none; white-space: normal; widows: auto; =
word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><div =
class=3D"WordSection1" style=3D"page: WordSection1;"><div style=3D"margin:=
 0in; font-size: 11pt; font-family: Calibri, sans-serif;" class=3D"">Hi =
Julien,<o:p class=3D""></o:p></div><div style=3D"margin: 0in; font-size: =
11pt; font-family: Calibri, sans-serif;" class=3D""><o:p =
class=3D"">&nbsp;</o:p></div><div style=3D"margin: 0in; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">RFC 7644 section 3.4.2 =
specifically is talking about queries. Retrieving or modifying known =
resources (i.e.: GET /Users/12345 ) does not require a ListResponse type =
response. A query of<span class=3D"Apple-converted-space">&nbsp;</span><b =
class=3D"">GET /Users?filter=3Ddisplayname contains =E2=80=9C<a =
href=3D"http://contoso.com" class=3D"">contoso.com</a>=E2=80=9D</b><span =
class=3D"Apple-converted-space">&nbsp;</span>or<span =
class=3D"Apple-converted-space">&nbsp;</span><b class=3D"">GET =
/Users?attributes=3DuserName</b><span =
class=3D"Apple-converted-space">&nbsp;</span>would require a =
ListResponse type response, as it does not identify a specific resource =
in the query URL via ID value (i.e.: =E2=80=9C12345=E2=80=9D in the =
previous example). On the other hand,<span =
class=3D"Apple-converted-space">&nbsp;</span><b class=3D"">GET =
/Users/12345?attributes=3DuserName<span =
class=3D"Apple-converted-space">&nbsp;</span></b>does not require the =
ListResponse type response as it does identify a specific resource.<o:p =
class=3D""></o:p></div><div style=3D"margin: 0in; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D""><o:p =
class=3D"">&nbsp;</o:p></div><div style=3D"margin: 0in; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">To explicitly answer the =
final question in your email =E2=80=93 the expected response to<span =
class=3D"Apple-converted-space">&nbsp;</span><b class=3D"">GET =
/Users/2819c223-7f76-453a-919d-413861904646?attributes=3DuserName</b>would=
 be the second example you provided.<o:p class=3D""></o:p></div><div =
style=3D"margin: 0in; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D""><o:p class=3D"">&nbsp;</o:p></div><div =
style=3D"margin: 0in; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D"">Cheers,<o:p class=3D""></o:p></div><div =
style=3D"margin: 0in; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D""><o:p class=3D"">&nbsp;</o:p></div><div =
style=3D"margin: 0in; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D"">Danny Zollner<o:p class=3D""></o:p></div><div =
style=3D"margin: 0in; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D""><o:p class=3D"">&nbsp;</o:p></div><div =
class=3D""><div style=3D"border-style: solid none none; =
border-top-width: 1pt; border-top-color: rgb(225, 225, 225); padding: =
3pt 0in 0in;" class=3D""><div style=3D"margin: 0in; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D""><b class=3D"">From:</b><span=
 class=3D"Apple-converted-space">&nbsp;</span>scim<span =
class=3D"Apple-converted-space">&nbsp;</span><a =
class=3D"moz-txt-link-rfc2396E" href=3D"mailto:scim-bounces@ietf.org" =
style=3D"color: blue; text-decoration: =
underline;">&lt;scim-bounces@ietf.org&gt;</a><span =
class=3D"Apple-converted-space">&nbsp;</span><b class=3D"">On Behalf =
Of<span class=3D"Apple-converted-space">&nbsp;</span></b>Julien =
Schneider<br class=3D""><b class=3D"">Sent:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Wednesday, July 6, 2022 =
3:41 AM<br class=3D""><b class=3D"">To:</b><span =
class=3D"Apple-converted-space">&nbsp;</span><a =
class=3D"moz-txt-link-abbreviated" href=3D"mailto:scim@ietf.org" =
style=3D"color: blue; text-decoration: underline;">scim@ietf.org</a><br =
class=3D""><b class=3D"">Subject:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>[EXTERNAL] [scim] Query on =
a specific known resource<o:p class=3D""></o:p></div></div></div><div =
style=3D"margin: 0in; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D""><o:p class=3D"">&nbsp;</o:p></div><table =
class=3D"MsoNormalTable" width=3D"100%" cellspacing=3D"0" =
cellpadding=3D"0" border=3D"0" align=3D"left" style=3D"width: =
981px;"><tbody class=3D""><tr class=3D""><td style=3D"background-color: =
rgb(166, 166, 166); padding: 5.25pt 1.5pt;" class=3D""><br =
class=3D""></td><td width=3D"100%" style=3D"width: 947px; =
background-color: rgb(234, 234, 234); padding: 5.25pt 3.75pt 5.25pt =
11.25pt;" class=3D""><div class=3D""><div style=3D"margin: 0in; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D""><span =
style=3D"font-size: 9pt; font-family: wf_segoe-ui_normal; color: rgb(33, =
33, 33);" class=3D"">Some people who received this message don't often =
get email from<span class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:julien@audriga.com" moz-do-not-send=3D"true" =
class=3D"moz-txt-link-freetext" style=3D"color: blue; text-decoration: =
underline;">julien@audriga.com</a>.<span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"https://aka.ms/LearnAboutSenderIdentification" =
moz-do-not-send=3D"true" style=3D"color: blue; text-decoration: =
underline;" class=3D"">Learn why this is important</a><o:p =
class=3D""></o:p></span></div></div></td><td width=3D"75" style=3D"width: =
56.25pt; background-color: rgb(234, 234, 234); padding: 5.25pt 3.75pt;" =
class=3D""><br class=3D""></td></tr></tbody></table><div class=3D""><div =
style=3D"margin: 0in; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D"">Hi all,<br class=3D""><br class=3D"">I have a =
question about queries performed against a SCIM resource object (like =
"/Users/{id}").<br class=3D""><br class=3D"">The RFC (<a =
href=3D"https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%=
2Fdatatracker.ietf.org%2Fdoc%2Fhtml%2Frfc7644%23section-3.4.2&amp;data=3D0=
5%7C01%7Cdanny.zollner%40microsoft.com%7C29270780ce9941a0687808da5f2b53db%=
7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637926937860837552%7CUnknown%=
7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6=
Mn0%3D%7C2000%7C%7C%7C&amp;sdata=3DfVtTna44Hr973Z79OsTegu9U9%2FpDwRcBZignf=
i5Eluk%3D&amp;reserved=3D0" moz-do-not-send=3D"true" style=3D"color: =
blue; text-decoration: underline;" =
class=3D"">https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2</a>=
) states:<span class=3D"Apple-converted-space">&nbsp;</span><o:p =
class=3D""></o:p></div><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">Responses MUST be identified using the following URI:<o:p =
class=3D""></o:p></pre><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">&nbsp;&nbsp; =
"urn:ietf:params:scim:api:messages:2.0:ListResponse"<o:p =
class=3D""></o:p></pre><div style=3D"margin: 0in; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D""><br class=3D"">If I =
understand correctly, that means the "schemas" parameter of the response =
to those queries must be set to:<o:p class=3D""></o:p></div><pre =
style=3D"margin: 0in 0in 0.0001pt; font-size: 10pt; font-family: =
&quot;Courier New&quot;;" =
class=3D"">"schemas":["urn:ietf:params:scim:api:messages:2.0:ListResponse"=
]<o:p class=3D""></o:p></pre><div style=3D"margin: 0in; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D""><br class=3D"">While I =
understand how that applies to queries on a resource type endpoint (like =
"/Users") or on the SCIM server root, I don't understand how that =
applies to queries on a specific resource object.<br class=3D"">If I =
understand correctly, queries on a specific resource object actually are =
quite identical to "retrieving a known resource" (<a =
href=3D"https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%=
2Fdatatracker.ietf.org%2Fdoc%2Fhtml%2Frfc7644%23section-3.4.1&amp;data=3D0=
5%7C01%7Cdanny.zollner%40microsoft.com%7C29270780ce9941a0687808da5f2b53db%=
7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637926937860837552%7CUnknown%=
7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6=
Mn0%3D%7C2000%7C%7C%7C&amp;sdata=3DDQEZdlY7XBONxFIegf1SCJfpdjpDdWzBvh5%2Fz=
B%2B2EpQ%3D&amp;reserved=3D0" moz-do-not-send=3D"true" style=3D"color: =
blue; text-decoration: underline;" =
class=3D"">https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.1</a>=
) which are a GET on a specific resource, like:<o:p =
class=3D""></o:p></div><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" class=3D"">GET =
/Users/2819c223-7f76-453a-919d-413861904646<o:p =
class=3D""></o:p></pre><div style=3D"margin: 0in; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">Responses to those =
requests should have the "schemas" parameter set to the resource =
schema(s):<o:p class=3D""></o:p></div><pre style=3D"margin: 0in 0in =
0.0001pt; font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">{<o:p class=3D""></o:p></pre><pre style=3D"margin: 0in 0in =
0.0001pt; font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp; =
"schemas":["urn:ietf:params:scim:schemas:core:2.0:User"],<o:p =
class=3D""></o:p></pre><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp; =
"id":"2819c223-7f76-453a-919d-413861904646",<o:p =
class=3D""></o:p></pre><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" class=3D"">...<o:p=
 class=3D""></o:p></pre><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" class=3D"">}<o:p =
class=3D""></o:p></pre><div style=3D"margin: 0in; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D""><br class=3D"">Now, how =
should the response to the following query should look like? And to what =
value should the "schemas" parameter of the response be set?<o:p =
class=3D""></o:p></div><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" class=3D"">GET =
/Users/2819c223-7f76-453a-919d-413861904646?attributes=3DuserName<o:p =
class=3D""></o:p></pre><div style=3D"margin: 0in; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D""><br class=3D"">Should it =
be:<o:p class=3D""></o:p></div><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">&nbsp;&nbsp; {<o:p class=3D""></o:p></pre><pre style=3D"margin:=
 0in 0in 0.0001pt; font-size: 10pt; font-family: &quot;Courier =
New&quot;;" class=3D"">&nbsp;&nbsp;&nbsp;&nbsp; =
"schemas":["urn:ietf:params:scim:api:messages:2.0:ListResponse"],<o:p =
class=3D""></o:p></pre><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp; "totalResults":1,<o:p =
class=3D""></o:p></pre><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp; "Resources":[<o:p =
class=3D""></o:p></pre><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; {<o:p =
class=3D""></o:p></pre><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
"id":"2819c223-7f76-453a-919d-413861904646",<o:p =
class=3D""></o:p></pre><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
"userName":"bjensen"<o:p class=3D""></o:p></pre><pre style=3D"margin: =
0in 0in 0.0001pt; font-size: 10pt; font-family: &quot;Courier =
New&quot;;" class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; }<o:p =
class=3D""></o:p></pre><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp; ]<o:p class=3D""></o:p></pre><pre =
style=3D"margin: 0in 0in 0.0001pt; font-size: 10pt; font-family: =
&quot;Courier New&quot;;" class=3D"">&nbsp;&nbsp; }<o:p =
class=3D""></o:p></pre><div style=3D"margin: 0in; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D""><br class=3D"">Or =
something like:<o:p class=3D""></o:p></div><pre style=3D"margin: 0in 0in =
0.0001pt; font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">&nbsp;&nbsp; {<o:p class=3D""></o:p></pre><pre style=3D"margin:=
 0in 0in 0.0001pt; font-size: 10pt; font-family: &quot;Courier =
New&quot;;" class=3D"">&nbsp;&nbsp;&nbsp;&nbsp; =
"schemas":["urn:ietf:params:scim:schemas:core:2.0:User"],<o:p =
class=3D""></o:p></pre><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp; =
"id":"2819c223-7f76-453a-919d-413861904646",<o:p =
class=3D""></o:p></pre><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp; "meta":{<o:p =
class=3D""></o:p></pre><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
"resourceType":"User",<o:p class=3D""></o:p></pre><pre style=3D"margin: =
0in 0in 0.0001pt; font-size: 10pt; font-family: &quot;Courier =
New&quot;;" class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
"created":"2011-08-01T18:29:49.793Z",<o:p class=3D""></o:p></pre><pre =
style=3D"margin: 0in 0in 0.0001pt; font-size: 10pt; font-family: =
&quot;Courier New&quot;;" class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
"lastModified":"2011-08-01T18:29:49.793Z",<o:p class=3D""></o:p></pre><pre=
 style=3D"margin: 0in 0in 0.0001pt; font-size: 10pt; font-family: =
&quot;Courier New&quot;;" class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
"location":<o:p class=3D""></o:p></pre><pre style=3D"margin: 0in 0in =
0.0001pt; font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">&nbsp;&nbsp; <a =
href=3D"https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%=
2Fexample.com%2Fv2%2FUsers%2F2819c223-7f76-453a-919d-413861904646&amp;data=
=3D05%7C01%7Cdanny.zollner%40microsoft.com%7C29270780ce9941a0687808da5f2b5=
3db%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637926937860837552%7CUnkn=
own%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJX=
VCI6Mn0%3D%7C2000%7C%7C%7C&amp;sdata=3DHRI2UjMUWpVqb0IzoOcpDNA%2FVVDBG3lZ4=
gU6C60Gr1I%3D&amp;reserved=3D0" moz-do-not-send=3D"true" style=3D"color: =
blue; text-decoration: underline;" =
class=3D"">"https://example.com/v2/Users/2819c223-7f76-453a-919d-413861904=
646"</a>,<o:p class=3D""></o:p></pre><pre style=3D"margin: 0in 0in =
0.0001pt; font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
"version":"W\/\"f250dd84f0671c3\""<o:p class=3D""></o:p></pre><pre =
style=3D"margin: 0in 0in 0.0001pt; font-size: 10pt; font-family: =
&quot;Courier New&quot;;" class=3D"">&nbsp;&nbsp;&nbsp;&nbsp; },<o:p =
class=3D""></o:p></pre><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp; "userName":"bjensen"<o:p =
class=3D""></o:p></pre><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">&nbsp;&nbsp; }<o:p class=3D""></o:p></pre><div style=3D"margin:=
 0in; font-size: 11pt; font-family: Calibri, sans-serif;" class=3D""><br =
class=3D"">Thanks a lot in advance<br class=3D""><br class=3D""><o:p =
class=3D""></o:p></div><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" class=3D"">-- =
<o:p class=3D""></o:p></pre><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" class=3D"">Julien =
Schneider<o:p class=3D""></o:p></pre><pre style=3D"margin: 0in 0in =
0.0001pt; font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">Tel: +49 721 170293 16<o:p class=3D""></o:p></pre><pre =
style=3D"margin: 0in 0in 0.0001pt; font-size: 10pt; font-family: =
&quot;Courier New&quot;;" class=3D"">Fax: +49 721 170293 179<o:p =
class=3D""></o:p></pre><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" class=3D""><o:p =
class=3D"">&nbsp;</o:p></pre><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" class=3D""><a =
href=3D"https://nam06.safelinks.protection.outlook.com/?url=3Dhttp%3A%2F%2=
Fwww.audriga.com%2F&amp;data=3D05%7C01%7Cdanny.zollner%40microsoft.com%7C2=
9270780ce9941a0687808da5f2b53db%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0=
%7C637926937860837552%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoi=
V2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7C%7C&amp;sdata=3D37nDJF0=
vyrffA22bld7R3WHNu11PnoLTmWCne%2FGCios%3D&amp;reserved=3D0" =
moz-do-not-send=3D"true" style=3D"color: blue; text-decoration: =
underline;" class=3D"">http://www.audriga.com</a> | <a =
href=3D"https://nam06.safelinks.protection.outlook.com/?url=3Dhttp%3A%2F%2=
Fwww.twitter.com%2Faudriga&amp;data=3D05%7C01%7Cdanny.zollner%40microsoft.=
com%7C29270780ce9941a0687808da5f2b53db%7C72f988bf86f141af91ab2d7cd011db47%=
7C1%7C0%7C637926937860837552%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiL=
CJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7C%7C&amp;sdata=3D=
P5As3bPNzRa4zSXSdYj9%2BirwGEkk6%2BYy5jkVKNAQnYw%3D&amp;reserved=3D0" =
moz-do-not-send=3D"true" style=3D"color: blue; text-decoration: =
underline;" class=3D"">http://www.twitter.com/audriga</a><o:p =
class=3D""></o:p></pre><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" class=3D""><o:p =
class=3D"">&nbsp;</o:p></pre><pre style=3D"margin: 0in 0in 0.0001pt; =
font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">---------------------------------------------------------------=
-----------<o:p class=3D""></o:p></pre><pre style=3D"margin: 0in 0in =
0.0001pt; font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">audriga GmbH |&nbsp; Alter Schlachthof 57&nbsp; | 76137 =
Karlsruhe<o:p class=3D""></o:p></pre><pre style=3D"margin: 0in 0in =
0.0001pt; font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">Sitz der Gesellschaft: Karlsruhe - Amtsgericht Mannheim - HRB =
713034<o:p class=3D""></o:p></pre><pre style=3D"margin: 0in 0in =
0.0001pt; font-size: 10pt; font-family: &quot;Courier New&quot;;" =
class=3D"">Gesch=C3=A4ftsf=C3=BChrer: Dr. Frank Dengler, Dr.-Ing. =
Hans-J=C3=B6rg Happel<o:p class=3D""></o:p></pre><pre style=3D"margin: =
0in 0in 0.0001pt; font-size: 10pt; font-family: &quot;Courier =
New&quot;;" =
class=3D"">---------------------------------------------------------------=
-----------<o:p class=3D""></o:p></pre></div></div></blockquote><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: 400; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: 400; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" =
class=3D"">_______________________________________________</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: 400; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: 400; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">scim mailing list</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: 400; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: 400; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D""><a href=3D"mailto:scim@ietf.org" =
class=3D"">scim@ietf.org</a></span><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: 400; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: 400; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D""><a href=3D"https://www.ietf.org/mailman/listinfo/scim" =
class=3D"">https://www.ietf.org/mailman/listinfo/scim</a></span></div></bl=
ockquote></div><br class=3D""></div></body></html>=

--Apple-Mail=_C1A9D46B-F07A-49A2-B391-48030302D75A--

