fix(integrations): correct OAuth scopes and broken Linear mutations - #8384
waleedlatif1 wants to merge 1 commit into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
1 issue found across 43 files
Confidence score: 3/5
- In
apps/sim/tools/google_groups/update_group.ts,updateGrouprejects credentials allowlisted only foradmin.directory.groupbefore its metadata-only PATCH can run; require only the group scope.
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name="apps/sim/tools/google_groups/update_group.ts">
<violation number="1" location="apps/sim/tools/google_groups/update_group.ts:14">
P2: `updateGroup` requires the membership scope even though its PATCH only manages group metadata, so credentials allowlisted only for `admin.directory.group` fail before the request. Require only the group scope here and reserve `admin.directory.group.member` for member operations.</violation>
</file>
Reply with feedback, questions, or to request a fix.
Fix all with cubic | Re-trigger cubic
| oauth: { | ||
| required: true, | ||
| provider: 'google-groups', | ||
| requiredScopes: GOOGLE_GROUPS_DIRECTORY_SCOPES, |
There was a problem hiding this comment.
P2: updateGroup requires the membership scope even though its PATCH only manages group metadata, so credentials allowlisted only for admin.directory.group fail before the request. Require only the group scope here and reserve admin.directory.group.member for member operations.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At apps/sim/tools/google_groups/update_group.ts, line 14:
<comment>`updateGroup` requires the membership scope even though its PATCH only manages group metadata, so credentials allowlisted only for `admin.directory.group` fail before the request. Require only the group scope here and reserve `admin.directory.group.member` for member operations.</comment>
<file context>
@@ -10,6 +11,7 @@ export const updateGroupTool: ToolConfig<GoogleGroupsUpdateParams, GoogleGroupsR
oauth: {
required: true,
provider: 'google-groups',
+ requiredScopes: GOOGLE_GROUPS_DIRECTORY_SCOPES,
},
</file context>
|
| scopes: [ | ||
| 'PROFILE_READ', | ||
| 'BOOKING_READ', | ||
| 'BOOKING_WRITE', | ||
| 'EVENT_TYPE_READ', | ||
| 'EVENT_TYPE_WRITE', | ||
| 'SCHEDULE_READ', | ||
| 'SCHEDULE_WRITE', |
There was a problem hiding this comment.
Existing Cal.com credentials stop working
Existing Cal.com managed credentials were saved with the old, empty scope list. Adding these seven scopes changes the saved scope-policy version, and token resolution rejects those credentials with MANAGED_CREDENTIAL_NEEDS_REAUTH before it can use or refresh their tokens. Users with those credentials must reconnect, contrary to the rollout expectation that existing tokens keep working. Please account for them in the migration or rollout.
Knowledge Base Used: Identity, authentication, and authorization
Summary
apps.groups.settings, which was never requested. Added it, and pinned each Groups tool'srequiredScopesso service-account (domain-wide delegation) and managed credentials keep working for directory tools without the new scopeSites.Read.All(site search) andFiles.ReadWrite.All(library items); added those plusFiles.Read.All(all delegated, no admin consent)DELETE /meetings/{id}/recordings) needscloud_recording:delete:meeting_recording; added it and to the tool'srequiredScopesscope), and move token exchange + refresh to the documentedhttps://api.cal.com/v2/auth/oauth2/token(the legacy route returns noscope, so credentials were stored scopeless). Droppedscopelessfrom the managed connectorprojectStatusDeleteand Archive Label calledissueLabelArchive, neither exists in Linear's schema. NowprojectStatusArchiveandissueLabelRetire(reversible, matches "archive"); tool ids unchangedPUT /me/drive/...) needsFiles.ReadWrite; added. Dropped unused admin-consentGroup.Read.All/Group.ReadWrite.All(every endpoint's least-privileged permission is already requested), including the trigger's hardcoded listGroup.*(Planner no longer needs admin consent), Redditaccount/flair/modflair/modmail, Jira granulardelete:*:jira+read:issue.vote:jira(write:jira-work/read:jira-workcover them)Rollout (order matters)
cloud_recording:delete:meeting_recordingto the Zoom Marketplace app before deploying, or Zoom rejects authorization with invalid scopeapps.groups.settingsto domain-wide delegation to use the settings toolsType of Change
Testing
bun run type-check(apps/sim), 1,590 tests across lib/oauth, auth connectors, credentials, selectors, credential-groups, triggers, Teams, Linear, Jira/JSM/Reddit connectorsbun run lint,check:audits,docs:check,tool-metadata:check,docs-manifest:checkChecklist
test-auditauthoring gate)