Add Neon access review driver support

Register Neon as a connector provider and add a new access review
driver that fetches organization members from the Neon API with
cursor-based pagination.

Neon's OAuth is partner-gated, so the connector is API-key only
(Bearer, the default scheme). A personal or organization API key can
belong to several organizations; the operator supplies the ID of the
one to review. The members endpoint exposes per-user MFA state
(has_mfa) and deactivation, which map to the access entry MFA status
and active flag; the stable account UUID (user_id) is used as the
external ID over the membership ID.

Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com>
This commit is contained in:
Aurélien Sibiril
2026-06-10 00:49:57 +02:00
parent 7640376d32
commit ec858e58df
17 changed files with 763 additions and 1 deletions

View File

@@ -172,6 +172,12 @@ func apiKeyConnectorSettings(input types.CreateAPIKeyConnectorInput) (json.RawMe
}
return json.Marshal(&coredata.RenderConnectorSettings{OwnerID: *input.RenderWorkspaceID})
case coredata.ConnectorProviderNeon:
if input.NeonOrganizationID == nil || *input.NeonOrganizationID == "" {
return nil, fmt.Errorf("cannot create neon connector: neonOrganizationId is required")
}
return json.Marshal(&coredata.NeonConnectorSettings{OrganizationID: *input.NeonOrganizationID})
}
return nil, nil

View File

@@ -70,6 +70,7 @@ enum ConnectorProvider
ZENDESK @goEnum(value: "go.probo.inc/probo/pkg/coredata.ConnectorProviderZendesk")
QOVERY @goEnum(value: "go.probo.inc/probo/pkg/coredata.ConnectorProviderQovery")
RENDER @goEnum(value: "go.probo.inc/probo/pkg/coredata.ConnectorProviderRender")
NEON @goEnum(value: "go.probo.inc/probo/pkg/coredata.ConnectorProviderNeon")
}
type ConnectorProviderInfo {
@@ -150,6 +151,7 @@ input CreateAPIKeyConnectorInput {
betterStackTeamName: String
qoveryOrganizationId: String
renderWorkspaceId: String
neonOrganizationId: String
}
type CreateAPIKeyConnectorPayload {