Add Scaleway, Yousign, Railway and Crisp access-review connectors

Four API-key, single-tenant (Pattern 3) connectors:

- Scaleway: secret key in the X-Auth-Token header plus an Organization ID
  setting; GET /iam/v1alpha1/users (owner/member, status, two-factor),
  per-connection BuildProbeURL.
- Yousign: Bearer API key; GET /v3/users (admin/owner/member, is_active);
  production host with a static probe.
- Railway: Bearer account token; GraphQL me{workspaces{members}} aggregated
  and deduplicated across workspaces; custom probe, since Railway returns
  HTTP 200 with an errors body on a rejected token.
- Crisp: plugin token as HTTP Basic (identifier:key) plus a Website ID
  setting and the X-Crisp-Tier header; GET /v1/website/{id}/operators/list,
  custom probe and name resolver.

Scaleway and Crisp carry a required extra setting, so the console add-source
dialog maps organizationId/websiteId onto their scalewayOrganizationId and
crispWebsiteId API-key inputs; without that mapping the value is silently
dropped and the create is rejected.

Cassette-backed driver tests plus unit tests for the cross-workspace
deduplication, the probe contracts and the role/MFA helpers.

Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com>
This commit is contained in:
Aurélien Sibiril
2026-06-27 20:03:10 +02:00
parent 22df5742ee
commit b408aab59d
30 changed files with 2024 additions and 1 deletions

View File

@@ -174,6 +174,20 @@ type (
LangfuseConnectorSettings struct {
BaseURL string `json:"base_url"`
}
// ScalewayConnectorSettings stores the Scaleway Organization ID. A secret
// key is bound to one Organization, but GET /iam/v1alpha1/users requires
// the organization_id explicitly, so it is captured up front.
ScalewayConnectorSettings struct {
OrganizationID string `json:"organization_id"`
}
// CrispConnectorSettings stores the Crisp Website ID. A plugin token can
// be connected to several websites, so the reviewed website is captured up
// front as the {website_id} path segment on /v1/website/{website_id}/...
CrispConnectorSettings struct {
WebsiteID string `json:"website_id"`
}
)
// GrantType returns the OAuth2 grant type recorded on the connector's