Add Microsoft 365 SCIM bridge and access review driver

Microsoft 365's native SCIM endpoint is unreliable, so mirror the
Google Workspace bridge over Microsoft Graph: a new MICROSOFT_365
OAuth2 connector, a SCIM bridge provider listing /v1.0/users with
$select pagination, and an access review driver that derives admin
status from /directoryRoles members. Refactor the bridge runner to
share OAuth2 plumbing across providers and surface the new bridge
type, scopes, UI card, and bootstrap env wiring.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
This commit is contained in:
Bryan Frimin
2026-04-30 12:57:39 +02:00
parent 0aaee9ef73
commit 5e55c888c4
24 changed files with 1050 additions and 18 deletions

View File

@@ -336,6 +336,17 @@ func (b *Builder) Build() (*probodconfig.FullConfig, error) {
})
}
if microsoft365ClientID := b.getEnv("CONNECTOR_MICROSOFT_365_CLIENT_ID"); microsoft365ClientID != "" {
cfg.Probod.Connectors = append(cfg.Probod.Connectors, probodconfig.ConnectorConfig{
Provider: "MICROSOFT_365",
Protocol: "oauth2",
RawConfig: probodconfig.ConnectorConfigOAuth2{
ClientID: microsoft365ClientID,
ClientSecret: b.getEnv("CONNECTOR_MICROSOFT_365_CLIENT_SECRET"),
},
})
}
return cfg, nil
}
@@ -382,6 +393,7 @@ func (b *Builder) validateRequired() error {
{"CONNECTOR_INTERCOM", []string{"CLIENT_SECRET"}},
{"CONNECTOR_BREX", []string{"CLIENT_SECRET"}},
{"CONNECTOR_GOOGLE_WORKSPACE", []string{"CLIENT_SECRET"}},
{"CONNECTOR_MICROSOFT_365", []string{"CLIENT_SECRET"}},
}
for _, p := range oauthProviders {