Skip to content

Handle SCIM group syncing with very large user+group syncs - #19496

Merged
snipe merged 1 commit into
developfrom
scim-groups-fix
Aug 16, 2026
Merged

snipe merged 1 commit into
developfrom
scim-groups-fix

Conversation

@snipe

@snipe snipe commented Aug 16, 2026

Copy link
Copy Markdown
Member

This should hopefully fix an OOM crash on SCIM group syncs with large member lists (over 100k). A user syncs their user list from Okta/Azure/etc into Snipe-IT over SCIM, and in the case, one of their groups had 100,000 members in it. When their identity provider tried to push that whole group across in one request, the server ran out of memory and returned a 500 error before it did any real work.

The reason it ran out of memory is that Laravel's form-validation system was set up to check that every single member entry in the request had an ID attached. That all sounds fine, except the way Laravel implements that check is to pre-build a little rule-checker object for each entry before it actually validates anything.

101,000 members means 101,000 rule-checker objects sitting in memory all at once, and that alone was enough to blow past the server's memory ceiling.

Two changes to fix it:

  1. Dropped the "every member must have an ID" validation rule from the group config. That's what was triggering the per-entry rule-checker allocation.
  2. Moved that same check into the code that actually reads the members and attaches them to the group. It walks the list once and, if any member is missing an ID, throws a clean error message telling the client exactly which entries are broken. It's the same safety check, done in the right place, with no per-entry memory overhead.

I also added a defensive upper bound of 200,000 members per request as a guardrail so a genuinely runaway payload (accidental duplication, buggy bespoke client script) still gets rejected cleanly instead of finding some other way to exhaust memory.

So 101k-member groups should sync fine now, 500k+ still gets rejected fast, and clients that send malformed member entries get a helpful 400 error naming the bad rows instead of the previous confusing 500.

@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 7 complexity

Metric Results
Complexity 7

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@snipe
snipe merged commit b5e9b9f into develop Aug 16, 2026
9 of 10 checks passed
@snipe
snipe deleted the scim-groups-fix branch August 16, 2026 10:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant