Add Cursor access-review driver

Fetch team members from the Cursor Admin API (GET /teams/members)
and map them to access records. The endpoint is not paginated, so
a single request returns the whole team; removed members are
returned as inactive rather than dropped, and team owners are
flagged as admins.

Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com>
This commit is contained in:
Aurélien Sibiril
2026-05-28 23:44:37 +02:00
parent 0149ca4f55
commit 427af88f3a
4 changed files with 261 additions and 0 deletions

View File

@@ -15,6 +15,7 @@
package drivers
import (
"encoding/base64"
"net/http"
"os"
"testing"
@@ -100,6 +101,17 @@ func bearerAuth(token string) string {
return "Bearer " + token
}
// basicAuth returns the HTTP Basic auth header value for a username with
// an empty password ("Basic base64(<username>:)"), or "" if the username
// is empty. Cursor presents its admin API key as the Basic auth username.
func basicAuth(username string) string {
if username == "" {
return ""
}
return "Basic " + base64.StdEncoding.EncodeToString([]byte(username+":"))
}
// newVCRClient creates an *http.Client backed by the recorder's transport,
// with an optional Authorization header injected into requests (for recording
// mode). The authValue should be the complete header value, e.g.