Add active status field to access entries

Track whether an account is active (enabled) or disabled at the
source system. The field is nullable so existing entries without
this data remain valid.

- DB migration adds active BOOLEAN column to access_entries
- Coredata read/write/upsert/filter wiring for the new column
- Review engine propagates Active from source accounts
- GraphQL schema exposes active on AccessEntry and AccessEntryFilter
- MCP spec, types, and resolvers expose active and fix missing
  account_type filter that was wired in GraphQL but not MCP
- CLI list command adds --active filter flag and ACTIVE output column
- Console campaign detail table shows Active/Disabled status badge
- E2e and unit tests updated to cover the new field

Signed-off-by: Bryan Frimin <bryan@probo.com>
This commit is contained in:
Bryan Frimin
2026-06-11 08:40:49 +02:00
parent 95a12d338b
commit c913e97c35
13 changed files with 171 additions and 3 deletions

View File

@@ -43,6 +43,7 @@ type (
MFAStatus MFAStatus `db:"mfa_status"`
AuthMethod AccessEntryAuthMethod `db:"auth_method"`
AccountType AccessEntryAccountType `db:"account_type"`
Active *bool `db:"active"`
LastLogin *time.Time `db:"last_login"`
AccountCreatedAt *time.Time `db:"account_created_at"`
ExternalID string `db:"external_id"`
@@ -130,6 +131,7 @@ SELECT
mfa_status,
auth_method,
account_type,
active,
last_login,
account_created_at,
external_id,
@@ -196,6 +198,7 @@ INSERT INTO
mfa_status,
auth_method,
account_type,
active,
last_login,
account_created_at,
external_id,
@@ -225,6 +228,7 @@ VALUES (
@mfa_status,
@auth_method,
@account_type,
@active,
@last_login,
@account_created_at,
@external_id,
@@ -256,6 +260,7 @@ VALUES (
"mfa_status": e.MFAStatus,
"auth_method": e.AuthMethod,
"account_type": e.AccountType,
"active": e.Active,
"last_login": e.LastLogin,
"account_created_at": e.AccountCreatedAt,
"external_id": e.ExternalID,
@@ -347,6 +352,7 @@ SELECT
mfa_status,
auth_method,
account_type,
active,
last_login,
account_created_at,
external_id,
@@ -414,6 +420,7 @@ SELECT
mfa_status,
auth_method,
account_type,
active,
last_login,
account_created_at,
external_id,
@@ -629,6 +636,7 @@ INSERT INTO access_entries (
mfa_status,
auth_method,
account_type,
active,
last_login,
account_created_at,
external_id,
@@ -657,6 +665,7 @@ INSERT INTO access_entries (
@mfa_status,
@auth_method,
@account_type,
@active,
@last_login,
@account_created_at,
@external_id,
@@ -680,6 +689,7 @@ ON CONFLICT (access_review_campaign_id, access_source_id, account_key) DO UPDATE
mfa_status = EXCLUDED.mfa_status,
auth_method = EXCLUDED.auth_method,
account_type = EXCLUDED.account_type,
active = EXCLUDED.active,
last_login = EXCLUDED.last_login,
account_created_at = EXCLUDED.account_created_at,
external_id = EXCLUDED.external_id,
@@ -702,6 +712,7 @@ ON CONFLICT (access_review_campaign_id, access_source_id, account_key) DO UPDATE
"mfa_status": e.MFAStatus,
"auth_method": e.AuthMethod,
"account_type": e.AccountType,
"active": e.Active,
"last_login": e.LastLogin,
"account_created_at": e.AccountCreatedAt,
"external_id": e.ExternalID,

View File

@@ -23,6 +23,7 @@ type AccessEntryFilter struct {
Flag *AccessEntryFlag
IncrementalTag *AccessEntryIncrementalTag
IsAdmin *bool
Active *bool
AuthMethod *AccessEntryAuthMethod
AccountType *AccessEntryAccountType
}
@@ -58,6 +59,12 @@ func (f *AccessEntryFilter) SQLFragment() string {
ELSE TRUE
END
AND
CASE
WHEN @filter_active::boolean IS NOT NULL THEN
active = @filter_active::boolean
ELSE TRUE
END
AND
CASE
WHEN @filter_auth_method::text IS NOT NULL THEN
auth_method = @filter_auth_method::text
@@ -82,6 +89,7 @@ func (f *AccessEntryFilter) SQLArguments() pgx.StrictNamedArgs {
"filter_flag": nil,
"filter_incremental_tag": nil,
"filter_is_admin": nil,
"filter_active": nil,
"filter_auth_method": nil,
"filter_account_type": nil,
}
@@ -102,6 +110,10 @@ func (f *AccessEntryFilter) SQLArguments() pgx.StrictNamedArgs {
args["filter_is_admin"] = *f.IsAdmin
}
if f.Active != nil {
args["filter_active"] = *f.Active
}
if f.AuthMethod != nil {
args["filter_auth_method"] = string(*f.AuthMethod)
}

View File

@@ -350,6 +350,82 @@ func TestAccessEntry_Upsert_RefreshesSourceTrackingFields(t *testing.T) {
assert.Nil(t, loaded.DecidedAt)
}
func TestAccessEntry_Upsert_RefreshesActiveStatus(t *testing.T) {
t.Parallel()
client := test.PGClient(t)
ctx := context.Background()
fx := seedAccessEntryFixture(t, ctx, client)
tenantID := fx.scope.GetTenantID()
t0 := time.Now().UTC().Truncate(time.Microsecond)
activeTrue := true
activeFalse := false
entryID := gid.New(tenantID, coredata.AccessEntryEntityType)
first := &coredata.AccessEntry{
ID: entryID,
OrganizationID: fx.organizationID,
AccessReviewCampaignID: fx.campaignID,
AccessSourceID: fx.sourceID,
Email: "user@example.com",
FullName: "User",
Role: "member",
MFAStatus: coredata.MFAStatusUnknown,
AuthMethod: coredata.AccessEntryAuthMethodUnknown,
AccountType: coredata.AccessEntryAccountTypeUser,
Active: &activeTrue,
ExternalID: "ext-active",
AccountKey: fx.accountKey,
IncrementalTag: coredata.AccessEntryIncrementalTagNew,
Flags: []coredata.AccessEntryFlag{},
FlagReasons: []string{},
Decision: coredata.AccessEntryDecisionPending,
CreatedAt: t0,
UpdatedAt: t0,
}
require.NoError(t, client.WithTx(ctx, func(ctx context.Context, tx pg.Tx) error {
return first.Upsert(ctx, tx, fx.scope)
}))
t1 := t0.Add(1 * time.Hour)
second := &coredata.AccessEntry{
ID: gid.New(tenantID, coredata.AccessEntryEntityType),
OrganizationID: fx.organizationID,
AccessReviewCampaignID: fx.campaignID,
AccessSourceID: fx.sourceID,
Email: "user@example.com",
FullName: "User",
Role: "member",
MFAStatus: coredata.MFAStatusUnknown,
AuthMethod: coredata.AccessEntryAuthMethodUnknown,
AccountType: coredata.AccessEntryAccountTypeUser,
Active: &activeFalse,
ExternalID: "ext-active",
AccountKey: fx.accountKey,
IncrementalTag: coredata.AccessEntryIncrementalTagUnchanged,
Flags: []coredata.AccessEntryFlag{},
FlagReasons: []string{},
Decision: coredata.AccessEntryDecisionPending,
CreatedAt: t1,
UpdatedAt: t1,
}
require.NoError(t, client.WithTx(ctx, func(ctx context.Context, tx pg.Tx) error {
return second.Upsert(ctx, tx, fx.scope)
}))
loaded := &coredata.AccessEntry{}
require.NoError(t, client.WithConn(ctx, func(ctx context.Context, conn pg.Querier) error {
return loaded.LoadByID(ctx, conn, fx.scope, entryID)
}))
require.NotNil(t, loaded.Active)
assert.False(t, *loaded.Active)
}
// TestAccessEntry_Upsert_InsertsActiveAccount covers the shape FetchSource
// builds for an active account: a PENDING decision and explicit empty
// flags / flag_reasons slices. The access_entries.flags and flag_reasons
@@ -377,6 +453,7 @@ func TestAccessEntry_Upsert_InsertsActiveAccount(t *testing.T) {
MFAStatus: coredata.MFAStatusUnknown,
AuthMethod: coredata.AccessEntryAuthMethodUnknown,
AccountType: coredata.AccessEntryAccountTypeUser,
Active: new(true),
ExternalID: "ext-active",
AccountKey: fx.accountKey,
IncrementalTag: coredata.AccessEntryIncrementalTagNew,
@@ -397,6 +474,8 @@ func TestAccessEntry_Upsert_InsertsActiveAccount(t *testing.T) {
return loaded.LoadByID(ctx, conn, fx.scope, entryID)
}))
require.NotNil(t, loaded.Active)
assert.True(t, *loaded.Active)
assert.Equal(t, coredata.AccessEntryDecisionPending, loaded.Decision)
assert.Equal(t, []coredata.AccessEntryFlag{}, loaded.Flags)
assert.Equal(t, []string{}, loaded.FlagReasons)

View File

@@ -0,0 +1,16 @@
-- Copyright (c) 2026 Probo Inc <hello@probo.com>.
--
-- Permission to use, copy, modify, and/or distribute this software for any
-- purpose with or without fee is hereby granted, provided that the above
-- copyright notice and this permission notice appear in all copies.
--
-- THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
-- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
-- AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
-- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
-- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
-- OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
-- PERFORMANCE OF THIS SOFTWARE.
ALTER TABLE access_entries
ADD COLUMN active BOOLEAN;