Split connector extra settings per credential path
Registration.ExtraSettings was a single flat list, but the API-key and client-credentials connect dialogs need different fields whenever a provider offers both paths, because a different create resolver and a different driver sits behind each. Replace it with APIKeyExtraSettings and ClientCredentialsExtraSettings, and split the GraphQL surface to match so a client cannot render one path's settings on the other. This fixes two connectors that could not be connected at all. 1Password declared accountId and region only, which are the client-credentials shape. The API-key dialog therefore rendered those two fields, mapAPIKeyExtraSettingToField returned nil for both so buildExtraFields discarded them, and the SCIM-bridge driver failed on an empty SCIMBridgeURL. The console already mapped scimBridgeUrl, but no registration declared that key, so the branch was dead. It now declares scimBridgeUrl on the API-key path and accountId + region on client credentials. Langfuse declared baseUrl as required, but mapAPIKeyExtraSettingToField had no LANGFUSE case, so buildExtraFields dropped the value the customer typed and the mutation failed with "langfuseBaseUrl is required". Every other extra-settings provider had a case. The GraphQL input field, the settings struct, the probe builder and the driver were all already correct; only the console mapping was missing. buildExtraFields now takes the settings list explicitly instead of reading it off the provider, so each dialog passes its own path's list and cannot silently iterate the other one. Register rejects a settings list for a path the provider does not offer, and an empty or duplicate setting key within one list. A key repeated across the two lists is allowed: that is how a dual-path provider declares a setting both dialogs need. The new resolver tests walk the whole chain the console walks, from the key a Registration declares through the mutation input field to the persisted settings struct, so a key renamed on one side and not the other fails in CI instead of at connect time. Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com>
This commit is contained in:
@@ -41,7 +41,12 @@ func TestAccessReviewDrivers(t *testing.T) {
|
||||
oauthConfigured
|
||||
apiKeySupported
|
||||
clientCredentialsSupported
|
||||
extraSettings {
|
||||
apiKeyExtraSettings {
|
||||
key
|
||||
label
|
||||
required
|
||||
}
|
||||
clientCredentialsExtraSettings {
|
||||
key
|
||||
label
|
||||
required
|
||||
@@ -50,19 +55,22 @@ func TestAccessReviewDrivers(t *testing.T) {
|
||||
}
|
||||
`
|
||||
|
||||
type settingInfo struct {
|
||||
Key string `json:"key"`
|
||||
Label string `json:"label"`
|
||||
Required bool `json:"required"`
|
||||
}
|
||||
|
||||
var result struct {
|
||||
AccessReviewDrivers []struct {
|
||||
Provider string `json:"provider"`
|
||||
DisplayName string `json:"displayName"`
|
||||
DocumentationURL *string `json:"documentationUrl"`
|
||||
OauthConfigured bool `json:"oauthConfigured"`
|
||||
APIKeySupported bool `json:"apiKeySupported"`
|
||||
ClientCredentialsSupported bool `json:"clientCredentialsSupported"`
|
||||
ExtraSettings []struct {
|
||||
Key string `json:"key"`
|
||||
Label string `json:"label"`
|
||||
Required bool `json:"required"`
|
||||
} `json:"extraSettings"`
|
||||
Provider string `json:"provider"`
|
||||
DisplayName string `json:"displayName"`
|
||||
DocumentationURL *string `json:"documentationUrl"`
|
||||
OauthConfigured bool `json:"oauthConfigured"`
|
||||
APIKeySupported bool `json:"apiKeySupported"`
|
||||
ClientCredentialsSupported bool `json:"clientCredentialsSupported"`
|
||||
APIKeyExtraSettings []settingInfo `json:"apiKeyExtraSettings"`
|
||||
ClientCredentialsExtraSettings []settingInfo `json:"clientCredentialsExtraSettings"`
|
||||
} `json:"accessReviewDrivers"`
|
||||
}
|
||||
|
||||
@@ -72,18 +80,40 @@ func TestAccessReviewDrivers(t *testing.T) {
|
||||
|
||||
providerNames := make(map[string]bool)
|
||||
docURLByProvider := make(map[string]*string)
|
||||
apiKeySettingKeys := make(map[string][]string)
|
||||
clientCredentialsSettingKeys := make(map[string][]string)
|
||||
|
||||
for _, info := range result.AccessReviewDrivers {
|
||||
assert.NotEmpty(t, info.Provider)
|
||||
assert.NotEmpty(t, info.DisplayName)
|
||||
assert.NotNil(t, info.ExtraSettings)
|
||||
assert.NotNil(t, info.APIKeyExtraSettings)
|
||||
assert.NotNil(t, info.ClientCredentialsExtraSettings)
|
||||
providerNames[info.Provider] = true
|
||||
docURLByProvider[info.Provider] = info.DocumentationURL
|
||||
|
||||
for _, s := range info.APIKeyExtraSettings {
|
||||
apiKeySettingKeys[info.Provider] = append(apiKeySettingKeys[info.Provider], s.Key)
|
||||
}
|
||||
|
||||
for _, s := range info.ClientCredentialsExtraSettings {
|
||||
clientCredentialsSettingKeys[info.Provider] = append(clientCredentialsSettingKeys[info.Provider], s.Key)
|
||||
}
|
||||
}
|
||||
|
||||
assert.True(t, providerNames["BREX"], "expected BREX provider to be present")
|
||||
assert.True(t, providerNames["HUBSPOT"], "expected HUBSPOT provider to be present")
|
||||
|
||||
// 1Password is the only provider offering both connect paths, and each path
|
||||
// needs different settings: the SCIM-bridge driver behind the API key, the
|
||||
// Users API driver behind client credentials. A client rendering one path's
|
||||
// settings on the other would collect fields the create resolver rejects.
|
||||
assert.Equal(t, []string{"scimBridgeUrl"}, apiKeySettingKeys["ONE_PASSWORD"])
|
||||
assert.Equal(t, []string{"accountId", "region"}, clientCredentialsSettingKeys["ONE_PASSWORD"])
|
||||
|
||||
// A single-path provider declares its settings on that path only.
|
||||
assert.Equal(t, []string{"baseUrl"}, apiKeySettingKeys["LANGFUSE"])
|
||||
assert.Empty(t, clientCredentialsSettingKeys["LANGFUSE"])
|
||||
|
||||
// A documented provider exposes its probo.com docs URL; an undocumented one
|
||||
// exposes null. See pkg/connector/provider/docs.go.
|
||||
require.Contains(t, docURLByProvider, "ANTHROPIC")
|
||||
|
||||
Reference in New Issue
Block a user