Add Zendesk access-review connector

Zendesk is a multi-tenant OAuth connector keyed by the customer
subdomain. The customer enters it at connect time; it rides the signed
state to the callback, is re-validated, and is stored on the connector
settings to build the API host.

List staff (agents and admins) via GET /api/v2/users.json with cursor
pagination, mapping role, active/suspended, and 2FA status; end-users
are excluded. The subdomain is validated as a single DNS label at every
trust boundary to close the SSRF vector, and the data client keeps the
SSRF-protected transport.

Zendesk OAuth across customer subdomains requires a Zendesk-approved
global OAuth client; the connector goes live once those credentials are
supplied via bootstrap.

Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com>
This commit is contained in:
Aurélien Sibiril
2026-06-04 18:32:55 +02:00
parent 1c40121591
commit dbd920dc24
19 changed files with 891 additions and 14 deletions

View File

@@ -152,3 +152,37 @@ func TestApplyOAuth2Defaults_CopiesSiteClosures(t *testing.T) {
require.NoError(t, err)
assert.Equal(t, "https://api.us3.datadoghq.com/oauth2/v1/token", tokenURL)
}
// TestApplyOAuth2Defaults_CopiesTokenURLForSiteClosure verifies the
// site-carried-in-state token-URL closure (BuildTokenURLForSite) is copied
// from the Registration onto the OAuth2Connector — the Zendesk shape, where
// both the authorize and token hosts are the customer subdomain.
func TestApplyOAuth2Defaults_CopiesTokenURLForSiteClosure(t *testing.T) {
t.Parallel()
r := provider.NewRegistry()
require.NoError(t, r.Register(&provider.Registration{
Provider: coredata.ConnectorProviderZendesk,
DisplayName: "Zendesk",
OAuth2Scopes: []string{"users:read"},
BuildAuthURLForSite: connector.ZendeskAuthorizeURL,
BuildTokenURLForSite: connector.ZendeskTokenURL,
NewDriver: func(context.Context, *http.Client, *coredata.Connector, *log.Logger) (drivers.Driver, error) {
return nil, nil
},
}))
var c connector.OAuth2Connector
require.NoError(t, r.ApplyOAuth2Defaults("ZENDESK", "https://probo.example/cb", &c))
require.NotNil(t, c.BuildAuthURLForSite)
require.NotNil(t, c.BuildTokenURLForSite)
require.Nil(t, c.BuildTokenURLForDomain)
authURL, err := c.BuildAuthURLForSite("acme")
require.NoError(t, err)
assert.Equal(t, "https://acme.zendesk.com/oauth/authorizations/new", authURL)
tokenURL, err := c.BuildTokenURLForSite("acme")
require.NoError(t, err)
assert.Equal(t, "https://acme.zendesk.com/oauth/tokens", tokenURL)
}