Skip to content

fix(knowledge): unschedule a connector whose credential the source rejected and prompt to reconnect - #8158

Merged
waleedlatif1 merged 2 commits into
stagingfrom
fix/connector-reconnect-on-revoked-credential
Sep 22, 2026
Merged

waleedlatif1 merged 2 commits into
stagingfrom
fix/connector-reconnect-on-revoked-credential

Conversation

@waleedlatif1

Copy link
Copy Markdown
Collaborator

Summary

  • A connector whose OAuth credential the source rejects outright (a revoked or expired grant, invalid_grant on refresh) kept retrying on its schedule with a generic "failed to obtain access token" error, and every attempt raised an alert. Retrying cannot help until someone reauthorizes the credential
  • The refresh path already records a terminal error for such an account; the sync engine now reads that flag when a credential resolves no token. A terminal rejection unschedules the connector with a dedicated error and counts as a skipped run (no failure ladder, no alert), exactly like the existing removed-credential path. A passing failure without the flag keeps the failure ladder as before
  • Reauthorizing the credential puts every connector it had unscheduled back on schedule immediately, with its failure count cleared; connectors paused or disabled for another reason keep their state
  • The connector recovery row shows the same "Reconnect to resume syncing" prompt it already shows for a removed credential; since the credential is still attached, its button opens the reauthorize flow

Type of Change

  • Bug fix

Testing

  • Sync engine: a rejected credential unschedules the connector as a skipped run with the new error and no failure count; a resolved-no-token credential without a terminal flag still walks the failure ladder
  • Credential service: the terminal flag is read on the account the credential resolves to, on the installation scope for Slack, and not at all for a service account
  • Reconnect hooks: reauthorizing a credential issues the resume write; the resume helper targets only connectors carrying the rejected-credential error
  • Removing the unschedule branch or the resume call fails the corresponding tests; 3,221 connector, credential, OAuth and knowledge-application tests pass
  • bun run lint, check:audits (47 audits), docs-manifest:check, type-check pass; cleanup passes run on the UI change

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Sep 22, 2026 8:58pm UTC

Request Review

@greptile-apps

greptile-apps Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

The PR appears safe to merge; the previous blocking findings are resolved and no new actionable defect was established.

Summary

This PR prevents connectors with terminally rejected OAuth credentials from repeatedly retrying and alerting, and restores eligible connectors after reauthorization.

  • Detects terminal credential refresh failures and unschedules affected connectors as skipped runs.
  • Rechecks terminal state to handle concurrent reauthorization and reports persistence failures as failed runs.
  • Resumes only connectors carrying the dedicated revoked-credential error, including Slack installation siblings sharing the repaired token chain.
  • Adds the reconnect prompt and focused coverage for sync, credential resolution, and recovery behavior.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart TD
  A[Scheduled connector sync] --> B[Resolve OAuth access token]
  B -->|Token available| C[Continue synchronization]
  B -->|No token| D{Terminal refresh error recorded?}
  D -->|No| E[Use ordinary failure ladder]
  D -->|Yes| F{Still rejected when outcome is recorded?}
  F -->|No, reauthorized concurrently| E
  F -->|Yes| G[Record failed sync log]
  G --> H[Set connector to revoked error and unschedule]
  H --> I[Return credential_revoked skip]
  J[Credential reauthorized] --> K[Clear terminal refresh flag]
  K --> L[Resume matching revoked-error connectors]
  L --> M[Set active, clear failures, schedule immediately]
Loading

Reviews (2) · Last reviewed commit: "fix(knowledge): resume by reconnected ac..."

Comment thread apps/sim/lib/knowledge/connectors/credential-recovery.ts Outdated
Comment thread apps/sim/lib/knowledge/connectors/sync-engine.ts Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 13 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/knowledge/connectors/credential-recovery.ts
Comment thread apps/sim/lib/knowledge/connectors/sync-engine.ts Outdated
…tion, recheck the rejection before unscheduling, and fail a run that cannot record it
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 14 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit 666b4d3 into staging Sep 22, 2026
25 checks passed
@waleedlatif1
waleedlatif1 deleted the fix/connector-reconnect-on-revoked-credential branch September 22, 2026 21:03

This branch was previously deployed

1 inactive deployment
Preview — cbe3076d Deployed Sep 22, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant