Add Neon access review driver support
Register Neon as a connector provider and add a new access review driver that fetches organization members from the Neon API with cursor-based pagination. Neon's OAuth is partner-gated, so the connector is API-key only (Bearer, the default scheme). A personal or organization API key can belong to several organizations; the operator supplies the ID of the one to review. The members endpoint exposes per-user MFA state (has_mfa) and deactivation, which map to the access entry MFA status and active flag; the stable account UUID (user_id) is used as the external ID over the membership ID. Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com>
This commit is contained in:
@@ -325,6 +325,76 @@ func TestRenderNameResolver(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestNeonNameResolver(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
t.Run("empty organization id returns nothing without HTTP call", func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
client := &http.Client{Transport: roundTripperFunc(func(*http.Request) (*http.Response, error) {
|
||||
t.Fatalf("resolver should not make an HTTP call for an empty organization id")
|
||||
return nil, nil
|
||||
})}
|
||||
|
||||
got, err := NewNeonNameResolver(client, "").ResolveInstanceName(context.Background())
|
||||
require.NoError(t, err)
|
||||
assert.Empty(t, got)
|
||||
})
|
||||
|
||||
cases := []struct {
|
||||
name string
|
||||
status int
|
||||
body string
|
||||
want string
|
||||
}{
|
||||
{
|
||||
name: "200 returns name",
|
||||
status: http.StatusOK,
|
||||
body: `{"id":"org-cool-breeze-12345678","name":"Acme Inc","handle":"acme-inc-org-cool-breeze-12345678","plan":"launch"}`,
|
||||
want: "Acme Inc",
|
||||
},
|
||||
{
|
||||
name: "401 is terminal (no error, no name)",
|
||||
status: http.StatusUnauthorized,
|
||||
body: `{"error":"unauthorized"}`,
|
||||
want: "",
|
||||
},
|
||||
{
|
||||
name: "404 is terminal (no error, no name)",
|
||||
status: http.StatusNotFound,
|
||||
body: `{"error":"not found"}`,
|
||||
want: "",
|
||||
},
|
||||
{
|
||||
name: "500 is terminal (no error, no name)",
|
||||
status: http.StatusInternalServerError,
|
||||
body: `{"error":"boom"}`,
|
||||
want: "",
|
||||
},
|
||||
}
|
||||
|
||||
for _, tc := range cases {
|
||||
t.Run(tc.name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
assert.Equal(t, http.MethodGet, r.Method)
|
||||
assert.Equal(t, "/api/v2/organizations/org-cool-breeze-12345678", r.URL.Path)
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
w.WriteHeader(tc.status)
|
||||
_, _ = w.Write([]byte(tc.body))
|
||||
}))
|
||||
defer srv.Close()
|
||||
|
||||
client := &http.Client{Transport: &hostRewriter{target: srv.URL}}
|
||||
|
||||
got, err := NewNeonNameResolver(client, "org-cool-breeze-12345678").ResolveInstanceName(context.Background())
|
||||
require.NoError(t, err)
|
||||
assert.Equal(t, tc.want, got)
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestTailscaleNameResolver(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
|
||||
Reference in New Issue
Block a user