fix: 100% coverage, WCAG accessibility fixes, and documentation updates for per-user OAuth wizards

Test coverage:
- Add config=None branch test for dropbox, onedrive, google_drive views (100% coverage)
- Add WATCH_FOLDER source-type test (folder_path vs folder key)
- Add integration-not-found fallback-to-admin-mode test

WCAG 2.1 AA fixes:
- Add aria-labelledby="modalTitle" to role="dialog" modals in setup templates
- Add aria-hidden="true" to decorative SVGs in callback templates
- Add role="status" aria-label="Loading" to spinner divs
- Add aria-live="polite" to processing-message and success/folder-selection regions
- Add role="alert" aria-live="assertive" to error containers
- Update "Return to Setup" link to preserve integration_id in user mode

Docs: update DropboxSetup.md, GoogleDriveSetup.md, OneDriveSetup.md with per-user OAuth flow section

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
This commit is contained in:
copilot-swe-agent[bot]
2026-03-09 20:19:19 +00:00
parent 2d01e71afd
commit 0529ae53ff
12 changed files with 259 additions and 58 deletions
+16 -2
View File
@@ -16,14 +16,28 @@ This guide explains how to set up the Google Drive integration for DocuElevate.
For a complete list of configuration options, see the [Configuration Guide](ConfigurationGuide.md).
## Authentication Methods
## Authentication Methods and Setup Flows
DocuElevate supports two authentication methods for Google Drive:
1. **OAuth Authentication (Recommended)** - User-based authentication that provides better security and control. Recommended for most deployments.
2. **Service Account Authentication** - Server-to-server authentication that doesn't require user interaction. Useful for specific enterprise deployments.
## Method 1: OAuth Authentication Setup (Recommended)
### Per-User OAuth Flow (Integrations Dashboard)
End users can authorize their own Google Drive integration directly from the **Integrations** dashboard — no admin involvement required:
1. Navigate to `/integrations` and click **+ Add Destination** (or **+ Add Source** for Watch Folder).
2. Create a Google Drive destination integration (or a Watch Folder with `source_type = google_drive`).
3. Click the **Authorize** button — it opens the OAuth wizard pre-loaded with your integration's configuration.
4. Enter your Google OAuth Client ID and Client Secret in the wizard.
5. Click **Start Authentication Flow** and authorize access in Google.
6. Credentials are saved automatically to your personal integration record; the page redirects back to `/integrations`.
7. Re-authorization is available at any time via the **Re-Authorize** button.
> **Note:** Credentials are stored encrypted per-integration. Each user can hold multiple Google Drive integrations with independent tokens targeting different folders or accounts.
## Method 1: OAuth Authentication Setup (System-Level)
The OAuth method is preferred as it:
- Provides better security with token expiration and refresh