mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-08-20 16:02:19 +00:00
93a74f229a
* oauth: add ServiceNow provider; make per-instance OAuth registry-driven
ServiceNow's OAuth endpoints are per-instance
(https://<instance>.service-now.com/oauth_auth.do + /oauth_token.do), like
Snowflake's. Rather than add another bespoke special-case, generalize:
a registry entry may carry a `connect_config_template` (label/placeholder/
help_url + {instance}-templated auth_url/token_url + req_body_auth +
optional extra_params_key/strip_suffix). The instance-settings UI renders
one generic instance-name input for any such provider and substitutes
{instance} to build the per-client connect_config — a new per-instance
provider needs only a JSON entry, no frontend code.
- oauth_connect.json: servicenow + snowflake_oauth now carry a
connect_config_template (snowflake keeps its account_identifier
extra_params key for backward compatibility).
- windmill-oauth: add the ConnectConfigTemplate struct (frontend-only
metadata; the backend's existing connect_config override resolves the
concrete URLs generically — no other backend change).
- AuthSettings/InstanceSettings: replace the Snowflake + ServiceNow
special-cases with one registry-driven path (instanceInputs map,
setupTemplatedOauthUrls, loadInstanceInputs); per-instance providers are
derived from the registry for the builtins list + dropdown.
Pairs with windmill-integrations#139 (ServiceNow hub integration).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* ci: point ee-repo-ref at servicenow-oauth EE branch (revert at merge)
Temporary CI pointer so check_ee_full / cargo_test build against the EE
slack-literal fix (windmill-ee-private#602). Revert to a pinned SHA once
that EE PR is merged.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
215 lines
7.4 KiB
JSON
215 lines
7.4 KiB
JSON
{
|
|
"github": {
|
|
"auth_url": "https://github.com/login/oauth/authorize",
|
|
"token_url": "https://github.com/login/oauth/access_token",
|
|
"scopes": ["workflow", "repo"]
|
|
},
|
|
"gitlab": {
|
|
"auth_url": "https://gitlab.com/oauth/authorize",
|
|
"token_url": "https://gitlab.com/oauth/token",
|
|
"scopes": ["api"]
|
|
},
|
|
"bitbucket": {
|
|
"auth_url": "https://bitbucket.org/site/oauth2/authorize",
|
|
"token_url": "https://bitbucket.org/site/oauth2/access_token",
|
|
"scopes": ["repository"]
|
|
},
|
|
"slack": {
|
|
"auth_url": "https://slack.com/oauth/authorize",
|
|
"token_url": "https://slack.com/api/oauth.access",
|
|
"scopes": ["chat:write:user", "users:read", "users:read.email"]
|
|
},
|
|
"supabase_wizard": {
|
|
"auth_url": "https://api.supabase.com/v1/oauth/authorize",
|
|
"token_url": "https://api.supabase.com/v1/oauth/token",
|
|
"scopes": ["all"]
|
|
},
|
|
"gsheets": {
|
|
"auth_url": "https://accounts.google.com/o/oauth2/v2/auth",
|
|
"token_url": "https://oauth2.googleapis.com/token",
|
|
"scopes": ["https://www.googleapis.com/auth/spreadsheets"],
|
|
"extra_params": {
|
|
"access_type": "offline",
|
|
"prompt": "consent"
|
|
}
|
|
},
|
|
"gdrive": {
|
|
"auth_url": "https://accounts.google.com/o/oauth2/v2/auth",
|
|
"token_url": "https://oauth2.googleapis.com/token",
|
|
"scopes": ["https://www.googleapis.com/auth/drive"],
|
|
"extra_params": {
|
|
"access_type": "offline",
|
|
"prompt": "consent"
|
|
}
|
|
},
|
|
"gmail": {
|
|
"auth_url": "https://accounts.google.com/o/oauth2/v2/auth",
|
|
"token_url": "https://oauth2.googleapis.com/token",
|
|
"scopes": ["https://www.googleapis.com/auth/gmail.send"],
|
|
"extra_params": {
|
|
"access_type": "offline",
|
|
"prompt": "consent"
|
|
}
|
|
},
|
|
"gcal": {
|
|
"auth_url": "https://accounts.google.com/o/oauth2/v2/auth",
|
|
"token_url": "https://oauth2.googleapis.com/token",
|
|
"scopes": ["https://www.googleapis.com/auth/calendar.events"],
|
|
"extra_params": {
|
|
"access_type": "offline",
|
|
"prompt": "consent"
|
|
}
|
|
},
|
|
"gforms": {
|
|
"auth_url": "https://accounts.google.com/o/oauth2/v2/auth",
|
|
"token_url": "https://oauth2.googleapis.com/token",
|
|
"scopes": ["https://www.googleapis.com/auth/forms"],
|
|
"extra_params": {
|
|
"access_type": "offline",
|
|
"prompt": "consent"
|
|
}
|
|
},
|
|
"gcloud": {
|
|
"auth_url": "https://accounts.google.com/o/oauth2/v2/auth",
|
|
"token_url": "https://oauth2.googleapis.com/token",
|
|
"scopes": ["https://www.googleapis.com/auth/cloud-platform"],
|
|
"extra_params": {
|
|
"access_type": "offline",
|
|
"prompt": "consent"
|
|
}
|
|
},
|
|
"gworkspace": {
|
|
"auth_url": "https://accounts.google.com/o/oauth2/v2/auth",
|
|
"token_url": "https://oauth2.googleapis.com/token",
|
|
"scopes": [
|
|
"https://www.googleapis.com/auth/admin.directory.group",
|
|
"https://www.googleapis.com/auth/admin.directory.user",
|
|
"https://www.googleapis.com/auth/admin.directory.user.security",
|
|
"https://www.googleapis.com/auth/admin.directory.orgunit"
|
|
],
|
|
"extra_params": {
|
|
"access_type": "offline",
|
|
"prompt": "consent"
|
|
}
|
|
},
|
|
"basecamp": {
|
|
"auth_url": "https://launchpad.37signals.com/authorization/new",
|
|
"token_url": "https://launchpad.37signals.com/authorization/token",
|
|
"scopes": [],
|
|
"extra_params": {
|
|
"type": "web_server"
|
|
}
|
|
},
|
|
"linkedin": {
|
|
"auth_url": "https://www.linkedin.com/oauth/v2/authorization",
|
|
"token_url": "https://www.linkedin.com/oauth/v2/accessToken",
|
|
"scopes": ["w_member_social", "r_liteprofile", "r_emailaddress"],
|
|
"req_body_auth": true
|
|
},
|
|
"quickbooks": {
|
|
"auth_url": "https://appcenter.intuit.com/connect/oauth2",
|
|
"token_url": "https://oauth.platform.intuit.com/oauth2/v1/tokens/bearer",
|
|
"scopes": ["com.intuit.quickbooks.accounting"]
|
|
},
|
|
"visma": {
|
|
"auth_url": "https://connect.visma.com/connect/authorize",
|
|
"token_url": "https://connect.visma.com/connect/token",
|
|
"scopes": [
|
|
"offline_access",
|
|
"vismanet_erp_interactive_api:create",
|
|
"vismanet_erp_interactive_api:delete",
|
|
"vismanet_erp_interactive_api:read",
|
|
"vismanet_erp_interactive_api:update"
|
|
]
|
|
},
|
|
"sage_intacct": {
|
|
"auth_url": "https://api.intacct.com/ia/api/v1/oauth2/authorize",
|
|
"token_url": "https://api.intacct.com/ia/api/v1/oauth2/token",
|
|
"scopes": ["offline_access"]
|
|
},
|
|
"spotify": {
|
|
"auth_url": "https://accounts.spotify.com/authorize",
|
|
"token_url": "https://accounts.spotify.com/api/token",
|
|
"scopes": [
|
|
"user-read-playback-state",
|
|
"user-modify-playback-state",
|
|
"user-read-currently-playing",
|
|
"playlist-read-private",
|
|
"playlist-read-collaborative",
|
|
"playlist-modify-private",
|
|
"playlist-modify-public",
|
|
"user-follow-read",
|
|
"user-read-playback-position",
|
|
"user-read-recently-played",
|
|
"user-top-read",
|
|
"user-library-modify",
|
|
"user-library-read"
|
|
]
|
|
},
|
|
"xero": {
|
|
"auth_url": "https://login.xero.com/identity/connect/authorize",
|
|
"token_url": "https://identity.xero.com/connect/token",
|
|
"scopes": ["offline_access", "accounting.transactions"]
|
|
},
|
|
"zoho": {
|
|
"auth_url": "https://accounts.zoho.com/oauth/v2/auth",
|
|
"token_url": "https://accounts.zoho.com/oauth/v2/token",
|
|
"scopes": ["ZohoAssist.sessionapi.ALL"],
|
|
"extra_params": {
|
|
"access_type": "offline"
|
|
}
|
|
},
|
|
"snowflake_oauth": {
|
|
"connect_config_template": {
|
|
"display_name": "Snowflake",
|
|
"label": "Snowflake Account Identifier",
|
|
"placeholder": "<orgname>-<account_name>",
|
|
"help_url": "https://docs.snowflake.com/en/user-guide/admin-account-identifier#using-an-account-name-as-an-identifier",
|
|
"auth_url": "https://{instance}.snowflakecomputing.com/oauth/authorize",
|
|
"token_url": "https://{instance}.snowflakecomputing.com/oauth/token-request",
|
|
"req_body_auth": false,
|
|
"extra_params_key": "account_identifier",
|
|
"resource_mapping": { "account_identifier": "{instance}" }
|
|
}
|
|
},
|
|
"apify": {
|
|
"auth_url": "https://console.apify.com/authorize/oauth",
|
|
"token_url": "https://console-backend.apify.com/oauth/apps/token",
|
|
"scopes": ["profile", "full_api_access"],
|
|
"extra_params": {}
|
|
},
|
|
"docusign": {
|
|
"auth_url": "https://account.docusign.com/oauth/auth",
|
|
"token_url": "https://account.docusign.com/oauth/token",
|
|
"scopes": ["signature"],
|
|
"sandbox": {
|
|
"auth_url": "https://account-d.docusign.com/oauth/auth",
|
|
"token_url": "https://account-d.docusign.com/oauth/token"
|
|
}
|
|
},
|
|
"salesforce": {
|
|
"auth_url": "https://login.salesforce.com/services/oauth2/authorize",
|
|
"token_url": "https://login.salesforce.com/services/oauth2/token",
|
|
"scopes": ["api", "refresh_token", "offline_access"],
|
|
"sandbox": {
|
|
"auth_url": "https://test.salesforce.com/services/oauth2/authorize",
|
|
"token_url": "https://test.salesforce.com/services/oauth2/token"
|
|
}
|
|
},
|
|
"servicenow": {
|
|
"connect_config_template": {
|
|
"display_name": "ServiceNow",
|
|
"label": "ServiceNow Instance",
|
|
"placeholder": "<instance> (e.g. dev12345)",
|
|
"help_url": "https://www.servicenow.com/docs/bundle/zurich-platform-security/page/administer/security/concept/c_OAuthApplications.html",
|
|
"auth_url": "https://{instance}.service-now.com/oauth_auth.do",
|
|
"token_url": "https://{instance}.service-now.com/oauth_token.do",
|
|
"req_body_auth": true,
|
|
"strip_suffix": ".service-now.com",
|
|
"resource_mapping": {
|
|
"instance_url": "https://{instance}.service-now.com"
|
|
}
|
|
}
|
|
}
|
|
}
|