Fix Heroku connection probe Accept header

Heroku's connection-status probe used a static ProbeURL, which the
generic probe issues with `Accept: application/json`. Heroku negotiates
the API version through the Accept media type and returns 400 for an
unversioned request, which doProbeRequest reads as "connected" -- so the
probe never caught a revoked token (it only surfaced at the first
ListAccounts).

Probe via a probeHeroku closure that sends
`Accept: application/vnd.heroku+json; version=3` instead. Verified live:
a dead token returns 400 with application/json but 401 with the
versioned header, which doProbeRequest correctly maps to rejected.

Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com>
This commit is contained in:
Aurélien Sibiril
2026-06-15 23:17:52 +02:00
parent 6a285a59b9
commit 0de4216ce6
3 changed files with 81 additions and 5 deletions

View File

@@ -31,6 +31,7 @@ import (
const (
anthropicAPIVersion = "2023-06-01"
anthropicUsersProbeURL = "https://api.anthropic.com/v1/organizations/users?limit=1"
herokuAccountProbeURL = "https://api.heroku.com/account"
linearGraphQLEndpoint = "https://api.linear.app/graphql"
mondayGraphQLEndpoint = "https://api.monday.com/v2"
posthogOrganizationPath = "/api/organizations/@current/"
@@ -410,6 +411,26 @@ func probeAnthropic(
return doProbeRequest(httpClient, req)
}
func probeHeroku(
ctx context.Context,
httpClient *http.Client,
_ *coredata.Connector,
) error {
req, err := http.NewRequestWithContext(ctx, http.MethodGet, herokuAccountProbeURL, nil)
if err != nil {
return fmt.Errorf("cannot create probe request: %w", err)
}
// Heroku negotiates the API version through the Accept media type; the
// generic "application/json" the default probe sends yields 400 (not
// 401/403), which doProbeRequest would read as "connected" and mask a
// dead token. Send the versioned Accept so a revoked token surfaces as
// 401 (verified live: 400 with application/json, 401 with this header).
req.Header.Set("Accept", "application/vnd.heroku+json; version=3")
return doProbeRequest(httpClient, req)
}
func probePostHog(
ctx context.Context,
httpClient *http.Client,