Skip to content

fix(integrations): correct OAuth scopes and broken Linear mutations - #8384

Open
waleedlatif1 wants to merge 1 commit into
stagingfrom
fix/integration-scope-bugs
Open

waleedlatif1 wants to merge 1 commit into
stagingfrom
fix/integration-scope-bugs

Conversation

@waleedlatif1

Copy link
Copy Markdown
Collaborator

Summary

  • Google Groups: Get/Update Settings call the Groups Settings API, whose only scope is apps.groups.settings, which was never requested. Added it, and pinned each Groups tool's requiredScopes so service-account (domain-wide delegation) and managed credentials keep working for directory tools without the new scope
  • Microsoft Excel: SharePoint file source needs Sites.Read.All (site search) and Files.ReadWrite.All (library items); added those plus Files.Read.All (all delegated, no admin consent)
  • Zoom: delete-all recordings (DELETE /meetings/{id}/recordings) needs cloud_recording:delete:meeting_recording; added it and to the tool's requiredScopes
  • Cal.com: request the 7 scopes the tools use (new Cal.com clients reject authorization without scope), and move token exchange + refresh to the documented https://api.cal.com/v2/auth/oauth2/token (the legacy route returns no scope, so credentials were stored scopeless). Dropped scopeless from the managed connector
  • Linear: Delete Project Status called projectStatusDelete and Archive Label called issueLabelArchive, neither exists in Linear's schema. Now projectStatusArchive and issueLabelRetire (reversible, matches "archive"); tool ids unchanged
  • Microsoft Teams: attachment upload (PUT /me/drive/...) needs Files.ReadWrite; added. Dropped unused admin-consent Group.Read.All / Group.ReadWrite.All (every endpoint's least-privileged permission is already requested), including the trigger's hardcoded list
  • Unused scopes dropped: Planner Group.* (Planner no longer needs admin consent), Reddit account/flair/modflair/modmail, Jira granular delete:*:jira + read:issue.vote:jira (write:jira-work / read:jira-work cover them)
  • Regenerated integration docs and tool metadata; self-hosting guide updated for Cal.com and Microsoft admin consent

Rollout (order matters)

  • Zoom: add cloud_recording:delete:meeting_recording to the Zoom Marketplace app before deploying, or Zoom rejects authorization with invalid scope
  • Cal.com: deploy while the Cal.com OAuth client is still legacy, then enable the same 7 scopes on the client. Existing tokens keep working
  • Google Groups: enable the Groups Settings API in the GCP project; service-account admins add apps.groups.settings to domain-wide delegation to use the settings tools
  • Google Groups, Excel, Zoom, Teams users reconnect to pick up new scopes. Dropped scopes need no reconnect

Type of Change

  • Bug fix

Testing

  • Each fix re-verified against provider docs (Google discovery doc, Graph permissions reference, Zoom OpenAPI, Cal.com OpenAPI/oauth docs, Linear schema, Reddit/Atlassian scope docs) before changing code
  • bun run type-check (apps/sim), 1,590 tests across lib/oauth, auth connectors, credentials, selectors, credential-groups, triggers, Teams, Linear, Jira/JSM/Reddit connectors
  • bun run lint, check:audits, docs:check, tool-metadata:check, docs-manifest:check

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs Ready Ready Preview Sep 28, 2026 7:16pm UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 43 files

Confidence score: 3/5

  • In apps/sim/tools/google_groups/update_group.ts, updateGroup rejects credentials allowlisted only for admin.directory.group before its metadata-only PATCH can run; require only the group scope.
Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="apps/sim/tools/google_groups/update_group.ts">

<violation number="1" location="apps/sim/tools/google_groups/update_group.ts:14">
P2: `updateGroup` requires the membership scope even though its PATCH only manages group metadata, so credentials allowlisted only for `admin.directory.group` fail before the request. Require only the group scope here and reserve `admin.directory.group.member` for member operations.</violation>
</file>

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

oauth: {
required: true,
provider: 'google-groups',
requiredScopes: GOOGLE_GROUPS_DIRECTORY_SCOPES,

@cubic-dev-ai cubic-dev-ai Bot Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2: updateGroup requires the membership scope even though its PATCH only manages group metadata, so credentials allowlisted only for admin.directory.group fail before the request. Require only the group scope here and reserve admin.directory.group.member for member operations.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At apps/sim/tools/google_groups/update_group.ts, line 14:

<comment>`updateGroup` requires the membership scope even though its PATCH only manages group metadata, so credentials allowlisted only for `admin.directory.group` fail before the request. Require only the group scope here and reserve `admin.directory.group.member` for member operations.</comment>

<file context>
@@ -10,6 +11,7 @@ export const updateGroupTool: ToolConfig<GoogleGroupsUpdateParams, GoogleGroupsR
   oauth: {
     required: true,
     provider: 'google-groups',
+    requiredScopes: GOOGLE_GROUPS_DIRECTORY_SCOPES,
   },
 
</file context>
Fix with cubic

@greptile-apps

greptile-apps Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 4/5

[High risk] OAuth scope and token endpoint changes across multiple integrations.

The PR should not merge until existing Cal.com managed credentials remain usable or their required reconnection is addressed in the rollout.

Findings

  1. P1 Existing Cal.com credentials stop working ▶

Summary

The PR updates OAuth scope requests and token handling across several integrations, corrects two Linear mutations, and refreshes their documentation and metadata.

  • It separates Google Groups settings permissions from directory-tool permissions and adds permissions for Excel, Teams, and Zoom operations.
  • It moves Cal.com token exchange and refresh to the v2 endpoint and requests explicit scopes; existing Cal.com managed credentials need attention because the new scope policy invalidates their stored policy version.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[Existing Cal.com managed credential] --> B[Stored empty-scope policy version]
  C[New seven-scope policy] --> D[Current policy version]
  B --> E{Versions match?}
  D --> E
  E -->|No| F[Needs reauthorization]
  F --> G[Tool cannot use existing token]
Loading

Reviews (1) · Last reviewed commit: "fix(integrations): correct OAuth scopes ..."

Comment on lines +1192 to +1199
scopes: [
'PROFILE_READ',
'BOOKING_READ',
'BOOKING_WRITE',
'EVENT_TYPE_READ',
'EVENT_TYPE_WRITE',
'SCHEDULE_READ',
'SCHEDULE_WRITE',

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Existing Cal.com credentials stop working

Existing Cal.com managed credentials were saved with the old, empty scope list. Adding these seven scopes changes the saved scope-policy version, and token resolution rejects those credentials with MANAGED_CREDENTIAL_NEEDS_REAUTH before it can use or refresh their tokens. Users with those credentials must reconnect, contrary to the rollout expectation that existing tokens keep working. Please account for them in the migration or rollout.

Knowledge Base Used: Identity, authentication, and authorization

This branch was successfully deployed

1 active deployment
Preview — ae0e68cd Deployed Sep 28, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant