Add DocuSign partner OAuth2 with PKCE and picker

DocuSign approved our partner integration, so the connector can now
complete a real OAuth2 authorization-code flow. The integration key
has PKCE enabled, so RequiresPKCE is set; the confidential grant still
authenticates the token exchange with Basic auth and replays the
verifier as the documented hardening layer.

A DocuSign user may have access to several accounts, so this replaces
the previous auto-default-account behavior with a Pattern-1 picker:
the user chooses the account after OAuth, the choice is stored on
DocuSignConnectorSettings, and the driver and name resolver resolve
the selected account's data-center base URI from /oauth/userinfo.

Other changes:
- Request the extended scope so the refresh token's 30-day window
  rolls on each use; without it the token hard-expires 30 days after
  consent and breaks the connection.
- Drop API-key support: DocuSign has no static API key, only OAuth.
- Return ("", nil) from the name resolver on terminal failures so the
  source-name worker does not retry a revoked token forever.
- Add a driver test and cassette; the test previously skipped in CI
  for lack of a cassette.

Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com>
This commit is contained in:
Aurélien Sibiril
2026-06-08 23:17:18 +02:00
parent 474907e15c
commit baf9ca2fe9
8 changed files with 235 additions and 88 deletions

View File

@@ -26,17 +26,27 @@ import (
func TestDocuSignDriver(t *testing.T) {
t.Parallel()
// Account UUID matches the userinfo cassette: the driver resolves the
// selected account's data-center base URI before listing its users.
const accountID = "a1a1a1a1-1111-4111-8111-111111111111"
rec := newRecorder(t, "testdata/docusign", "DOCUSIGN_TOKEN")
client := newVCRClient(rec, bearerAuth(os.Getenv("DOCUSIGN_TOKEN")))
driver := NewDocuSignDriver(client)
driver := NewDocuSignDriver(client, accountID)
records, err := driver.ListAccounts(context.Background())
require.NoError(t, err)
require.NotEmpty(t, records)
assert.Len(t, records, 2)
r := records[0]
assert.NotEmpty(t, r.Email)
assert.NotEmpty(t, r.FullName)
assert.NotEmpty(t, r.ExternalID)
assert.NotEmpty(t, r.Roles)
assert.Equal(t, "jane.doe@example.com", r.Email)
assert.Equal(t, "Jane Doe", r.FullName)
assert.Equal(t, "11111111-1111-4111-8111-111111111111", r.ExternalID)
assert.Equal(t, []string{"Account Administrator"}, r.Roles)
assert.Equal(t, "CTO", r.JobTitle)
assert.True(t, r.IsAdmin)
require.NotNil(t, r.Active)
assert.True(t, *r.Active)
assert.False(t, records[1].IsAdmin)
}