Add DocuSign partner OAuth2 with PKCE and picker
DocuSign approved our partner integration, so the connector can now
complete a real OAuth2 authorization-code flow. The integration key
has PKCE enabled, so RequiresPKCE is set; the confidential grant still
authenticates the token exchange with Basic auth and replays the
verifier as the documented hardening layer.
A DocuSign user may have access to several accounts, so this replaces
the previous auto-default-account behavior with a Pattern-1 picker:
the user chooses the account after OAuth, the choice is stored on
DocuSignConnectorSettings, and the driver and name resolver resolve
the selected account's data-center base URI from /oauth/userinfo.
Other changes:
- Request the extended scope so the refresh token's 30-day window
rolls on each use; without it the token hard-expires 30 days after
consent and breaks the connection.
- Drop API-key support: DocuSign has no static API key, only OAuth.
- Return ("", nil) from the name resolver on terminal failures so the
source-name worker does not retry a revoked token forever.
- Add a driver test and cassette; the test previously skipped in CI
for lack of a cassette.
Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com>
This commit is contained in:
@@ -88,6 +88,15 @@ type (
|
||||
TeamID string `json:"team_id"`
|
||||
}
|
||||
|
||||
// DocuSignConnectorSettings holds the DocuSign account the user picked
|
||||
// after OAuth. A DocuSign user can have access to multiple accounts, so
|
||||
// the post-OAuth picker scopes the access source to one; AccountID is the
|
||||
// selected account's UUID. The driver and name resolver re-resolve the
|
||||
// account's data-center base URI from /oauth/userinfo at fetch time.
|
||||
DocuSignConnectorSettings struct {
|
||||
AccountID string `json:"account_id"`
|
||||
}
|
||||
|
||||
VercelConnectorSettings struct {
|
||||
TeamID string `json:"team_id"`
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user