From 56c042b7ed4f0fa5e4de5eab256c394891d2ba3f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Aur=C3=A9lien=20Sibiril?= <81782+aureliensibiril@users.noreply.github.com> Date: Tue, 7 Apr 2026 14:53:16 +0200 Subject: [PATCH] Add OAuth2 scope sources for access review, slack, googleworkspace MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Each module that initiates an OAuth2 flow now declares its scopes in its own package instead of duplicating them in the frontend or in shared connector config: - pkg/accessreview/drivers: per-provider scopes for the access review drivers - pkg/slack: scopes for the compliance page integration - pkg/iam/scim/bridge/provider/googleworkspace: scopes for the SCIM provisioning bridge These constants are surfaced to the frontend via GraphQL fields so the frontend never hardcodes scope strings. Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com> --- pkg/accessreview/drivers/oauth2_scopes.go | 43 +++++++++++++++++++ .../provider/googleworkspace/oauth2_scopes.go | 27 ++++++++++++ pkg/slack/oauth2_scopes.go | 26 +++++++++++ 3 files changed, 96 insertions(+) create mode 100644 pkg/accessreview/drivers/oauth2_scopes.go create mode 100644 pkg/iam/scim/bridge/provider/googleworkspace/oauth2_scopes.go create mode 100644 pkg/slack/oauth2_scopes.go diff --git a/pkg/accessreview/drivers/oauth2_scopes.go b/pkg/accessreview/drivers/oauth2_scopes.go new file mode 100644 index 000000000..84031c8c3 --- /dev/null +++ b/pkg/accessreview/drivers/oauth2_scopes.go @@ -0,0 +1,43 @@ +// Copyright (c) 2026 Probo Inc . +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH +// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY +// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT, +// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM +// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR +// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR +// PERFORMANCE OF THIS SOFTWARE. + +package drivers + +import "go.probo.inc/probo/pkg/coredata" + +// providerOAuth2Scopes maps each access review provider to the OAuth2 scopes +// the corresponding driver requires to list user accounts. The map is the +// single source of truth for access-review OAuth2 scopes — surfaced via +// GraphQL so the frontend never hardcodes scope strings. +var providerOAuth2Scopes = map[coredata.ConnectorProvider][]string{ + coredata.ConnectorProviderHubSpot: {"settings.users.read"}, + coredata.ConnectorProviderGitHub: {"read:org"}, + coredata.ConnectorProviderSentry: {"org:read", "member:read"}, + coredata.ConnectorProviderBrex: {"openid", "offline_access"}, + coredata.ConnectorProviderDocuSign: {"signature"}, + coredata.ConnectorProviderLinear: {"read"}, + coredata.ConnectorProviderGoogleWorkspace: { + "https://www.googleapis.com/auth/admin.directory.user.readonly", + "https://www.googleapis.com/auth/admin.directory.group.member.readonly", + }, + // Notion and Intercom intentionally omitted: Notion uses extra-auth-params + // instead of scopes, Intercom configures scopes at the app level. +} + +// ProviderOAuth2Scopes returns the OAuth2 scopes the access review driver +// for the given provider needs. Returns nil for providers that do not need +// any scopes (Notion, Intercom) or for non-access-review providers. +func ProviderOAuth2Scopes(provider coredata.ConnectorProvider) []string { + return providerOAuth2Scopes[provider] +} diff --git a/pkg/iam/scim/bridge/provider/googleworkspace/oauth2_scopes.go b/pkg/iam/scim/bridge/provider/googleworkspace/oauth2_scopes.go new file mode 100644 index 000000000..692486129 --- /dev/null +++ b/pkg/iam/scim/bridge/provider/googleworkspace/oauth2_scopes.go @@ -0,0 +1,27 @@ +// Copyright (c) 2026 Probo Inc . +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH +// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY +// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT, +// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM +// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR +// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR +// PERFORMANCE OF THIS SOFTWARE. + +package googleworkspace + +var ( + // OAuth2Scopes are the Google Workspace OAuth2 scopes required by the + // SCIM provisioning bridge. The bridge reads users, user schemas, group + // members, and customer info from the Admin Directory API. + OAuth2Scopes = []string{ + "https://www.googleapis.com/auth/admin.directory.user.readonly", + "https://www.googleapis.com/auth/admin.directory.userschema.readonly", + "https://www.googleapis.com/auth/admin.directory.group.member.readonly", + "https://www.googleapis.com/auth/admin.directory.customer.readonly", + } +) diff --git a/pkg/slack/oauth2_scopes.go b/pkg/slack/oauth2_scopes.go new file mode 100644 index 000000000..21ced9ed1 --- /dev/null +++ b/pkg/slack/oauth2_scopes.go @@ -0,0 +1,26 @@ +// Copyright (c) 2026 Probo Inc . +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH +// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY +// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT, +// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM +// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR +// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR +// PERFORMANCE OF THIS SOFTWARE. + +package slack + +var ( + // OAuth2Scopes are the Slack OAuth2 scopes required by the compliance + // page integration. The compliance page joins channels and posts + // messages on behalf of the connected workspace. + OAuth2Scopes = []string{ + "chat:write", + "channels:join", + "incoming-webhook", + } +)