Add Microsoft 365 SCIM bridge and access review driver

Microsoft 365's native SCIM endpoint is unreliable, so mirror the
Google Workspace bridge over Microsoft Graph: a new MICROSOFT_365
OAuth2 connector, a SCIM bridge provider listing /v1.0/users with
$select pagination, and an access review driver that derives admin
status from /directoryRoles members. Refactor the bridge runner to
share OAuth2 plumbing across providers and surface the new bridge
type, scopes, UI card, and bootstrap env wiring.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
This commit is contained in:
Bryan Frimin
2026-04-30 12:57:39 +02:00
parent 0aaee9ef73
commit 5e55c888c4
24 changed files with 1050 additions and 18 deletions

View File

@@ -0,0 +1,35 @@
// Copyright (c) 2026 Probo Inc <hello@getprobo.com>.
//
// Permission to use, copy, modify, and/or distribute this software for any
// purpose with or without fee is hereby granted, provided that the above
// copyright notice and this permission notice appear in all copies.
//
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
// PERFORMANCE OF THIS SOFTWARE.
package microsoft365
var (
// OAuth2Scopes are the Microsoft Graph permission scopes required by the
// SCIM provisioning bridge. The bridge reads users (including the
// extended profile fields populated below) and their managers from the
// Microsoft Graph API.
//
// - openid / profile: identifies the consenting admin.
// - offline_access: required to receive a refresh token.
// - User.Read.All: read all user profiles in the directory.
// - Directory.Read.All: needed to read manager relationships and
// organizational data on every user without per-user consent.
OAuth2Scopes = []string{
"openid",
"profile",
"offline_access",
"https://graph.microsoft.com/User.Read.All",
"https://graph.microsoft.com/Directory.Read.All",
}
)