Add PostHog Cloud OAuth and self-hosted support

PostHog Cloud authenticates via CIMD OAuth (public client, PKCE)
through the region-agnostic oauth.posthog.com gateway, with an API-key
fallback. PostHog Self-Hosted is a separate provider using an API key
and an instance URL.

The shared driver discovers the data region by probing us/eu for OAuth
connections, since the gateway does not serve the data API, and pins
pagination to the resolved host.

Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com>
This commit is contained in:
Aurélien Sibiril
2026-05-29 12:24:21 +02:00
parent 6e65c56235
commit 3888ff95cd
10 changed files with 406 additions and 55 deletions

View File

@@ -86,7 +86,7 @@ func TestApplyOAuth2Defaults_AuthURLFromSlug(t *testing.T) {
func TestApplyOAuth2Defaults_PKCEDefaults(t *testing.T) {
t.Parallel()
for _, p := range []string{"PAGERDUTY"} {
for _, p := range []string{"PAGERDUTY", "POSTHOG"} {
t.Run(p, func(t *testing.T) {
t.Parallel()
@@ -98,3 +98,18 @@ func TestApplyOAuth2Defaults_PKCEDefaults(t *testing.T) {
})
}
}
// TestApplyOAuth2Defaults_PublicClientTokenAuth verifies that PostHog, a
// public (CIMD) client, propagates token_endpoint_auth_method "none" so the
// token exchange omits a client_secret.
func TestApplyOAuth2Defaults_PublicClientTokenAuth(t *testing.T) {
t.Parallel()
r := provider.NewBuiltinRegistry()
c := &connector.OAuth2Connector{}
require.NoError(t, r.ApplyOAuth2Defaults("POSTHOG", "https://example.com/cb", c))
assert.Equal(t, "none", c.TokenEndpointAuth,
"PostHog must use token_endpoint_auth_method none (public client)")
assert.True(t, c.RequiresPKCE, "PostHog public client must require PKCE")
}