Pass OAuth2 scopes to connector at initiate time

Add an InitiateOptions struct to the Connector interface so each
caller can declare the scopes it needs instead of having them baked
into the connector at registration. The HTTP handler reads repeated
?scope= query parameters from /connectors/initiate and forwards them.

Also restore GOOGLE_WORKSPACE and LINEAR provider definitions which
were silently dropped from the bootstrap config refactor.

Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com>
This commit is contained in:
Aurélien Sibiril
2026-04-07 14:53:09 +02:00
parent 4cc0e31214
commit e006f335b2
6 changed files with 111 additions and 20 deletions

View File

@@ -26,8 +26,16 @@ import (
type (
ProtocolType string
// InitiateOptions holds per-call options passed by the caller initiating
// a connector flow. Different callers may need different configurations
// for the same provider — for OAuth2, the most common case is requesting
// a different set of scopes (e.g. SCIM bridge vs access review).
InitiateOptions struct {
Scopes []string
}
Connector interface {
Initiate(ctx context.Context, provider string, organizationID gid.GID, r *http.Request) (string, error)
Initiate(ctx context.Context, provider string, organizationID gid.GID, opts InitiateOptions, r *http.Request) (string, error)
Complete(ctx context.Context, r *http.Request) (Connection, *gid.GID, string, error) // returns: connection, organizationID, continueURL, error
}