Probe every access review connector on status check

Bad API keys and expired OAuth tokens showed Connected because
probes ran only for OAuth2 and many providers had no ProbeURL.
Add a registry ProbeConnection dispatcher with static, dynamic,
and custom probes so all 41 providers are checked on demand.

Signed-off-by: Bryan Frimin <bryan@probo.com>
This commit is contained in:
Bryan Frimin
2026-06-11 16:47:19 +02:00
parent 26d64a970f
commit 8d8a5ebb26
22 changed files with 587 additions and 106 deletions

View File

@@ -30,15 +30,14 @@ import (
// possible — it authenticates with a read-only API token presented under the
// `SSWS` Authorization scheme (APIKeyAuthScheme), plus the customer's org
// domain. The token + domain identify exactly one org, so there is no picker
// and no OAuth metadata. ProbeURL is empty because the API host is per-org and
// there is no static URL to probe; a dead token surfaces on the first
// ListAccounts.
// and no OAuth metadata. BuildProbeURL targets the org's own API host.
func oktaRegistration() *Registration {
return &Registration{
Provider: coredata.ConnectorProviderOkta,
DisplayName: "Okta",
SupportsAPIKey: true,
APIKeyAuthScheme: "SSWS",
BuildProbeURL: buildOktaProbeURL,
ExtraSettings: []ExtraSetting{
{Key: "domain", Label: "Okta Domain", Required: true},
},