Probe every access review connector on status check

Bad API keys and expired OAuth tokens showed Connected because
probes ran only for OAuth2 and many providers had no ProbeURL.
Add a registry ProbeConnection dispatcher with static, dynamic,
and custom probes so all 41 providers are checked on demand.

Signed-off-by: Bryan Frimin <bryan@probo.com>
This commit is contained in:
Bryan Frimin
2026-06-11 16:47:19 +02:00
parent 26d64a970f
commit 8d8a5ebb26
22 changed files with 587 additions and 106 deletions

View File

@@ -28,10 +28,9 @@ import (
func datadogRegistration() *Registration {
// Datadog is multi-site: the customer's region drives the authorize
// host (built at initiate from the region pick) and the token + API
// host (built at callback from Datadog's `domain` param). AuthURL,
// TokenURL, and ProbeURL are therefore empty — the closures build the
// per-customer hosts, and an empty probe is skipped (a dead token
// surfaces on the first ListAccounts). Confidential client + PKCE map
// host (built at callback from Datadog's `domain` param). AuthURL and
// TokenURL are empty — the closures build the per-customer hosts.
// BuildProbeURL targets the stored API domain. Confidential client + PKCE map
// to the default post-form token-endpoint auth.
return &Registration{
Provider: coredata.ConnectorProviderDatadog,
@@ -40,6 +39,7 @@ func datadogRegistration() *Registration {
RequiresPKCE: true,
BuildAuthURLForSite: connector.DatadogAuthorizeURL,
BuildTokenURLForDomain: connector.DatadogTokenURL,
BuildProbeURL: buildDatadogProbeURL,
NewDriver: func(_ context.Context, c *http.Client, conn *coredata.Connector, _ *log.Logger) (drivers.Driver, error) {
s, err := coredata.ConnectorSettings[coredata.DatadogConnectorSettings](conn)
if err != nil {