Skip to content

fix(platform): name a failed import status read on the OAuth apps card - #4400

Merged
yannickmonney merged 2 commits into
mainfrom
fix/oauth-apps-status-read-failure
Oct 9, 2026
Merged

yannickmonney merged 2 commits into
mainfrom
fix/oauth-apps-status-read-failure

Conversation

@yannickmonney

@yannickmonney yannickmonney commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

What changed

The Settings > Connectors OAuth apps card asks the Knowledge import lanes (cloud_import/queries:getOauthAppStatus for OneDrive and for Google Drive's import half) whether a deployment app stands behind their rows. On main, a read that settled in error (data: undefined, isLoading: false, e.g. a 503) collapsed envConfigured to false. The row then said Not configured and offered Configure (and Use Entra ID SSO app on OneDrive), with no failure named and no retry. An admin could override a deployment app that was there.

oauth-apps-card.tsx now reads both status queries through readStateOf, the same pattern #4378 used for the same endpoint in the Documents connect dialog:

  • Row status. A row whose status that read decides, and which neither the org's app list nor the connector catalog already answers, gets statusUnavailable. It shows a Status unavailable badge and no Configure or Use Entra ID SSO app.
  • Alert. One CatalogLoadError names the failure (connectors.oauthApps.statusLoadFailed). Its Try again refetches only the failed status reads, and failureKey makes each new failure announce again.
  • During a retry. The row stays put: loading leaves out a read that is unavailable, so the card doesn't re-mask. Try again is busy, keeps its node and its focus, and keeps them again if the retry fails too.
  • After recovery. A retry that works removes the alert, and a focused Try again hands its focus to the card (SettingsSection with tabIndex={-1}). Configure comes back only once a read answers: configured: false → Not configured, source: 'env' → Deployment app.
  • Rows known from elsewhere keep their answer: an org row from the app list, or Google Drive when the catalog says its connector lane has an env app.
  • App-list alert: unchanged.

Also in this PR:

How I verified it

  • New suite. oauth-apps-card.status-read.test.tsx runs the real hooks, adapters, backendFetch and retry policy against syntheticBackend(). It passes 13/13 in jsdom, covering:
    • a failed OneDrive read and a failed Drive import read;
    • rows known from the app list or the catalog;
    • a held retry: the row holds, Try again is busy and keeps focus, only the failed read refetches, then focus moves to the card;
    • a retry that fails again;
    • both reads failing behind one alert;
    • configured: false, an env source, and the loading mask;
    • EN/DE/FR;
    • an axe pass with the unavailable row and the alert on screen (second commit).
  • Red on main. With main's oauth-apps-card.tsx, 9 of 13 fail. The 4 that pass are the answered or known-row cases.
  • Real Chromium 1194. The 12 tests of the first commit and the existing oauth-apps-card.test.tsx pass 22/22 in headless Chromium through a review-only Vitest config outside the clone, so the focus handoff was checked in a real browser too. The axe test was added after that run.
  • Related suites:
    • the connectors settings components (4 files): 61/61
    • lib/i18n (--project server): 188/188
    • docs docs.test.ts and locale-tree.test.ts: 25/25
    • bun run lint:manual: ok
    • the error-message and single-failure-toast guards: 75/75
  • Static checks:
    • scoped type-aware oxlint over the card and both card suites: 0 warnings, 0 errors
    • oxfmt --check: clean
    • scoped tsc over the card, its suites, connectors-settings.tsx and the ambient files: exit 0, 0 errors
  • Merge check. git merge-tree against all 53 open PR heads that touch automation.md, messages/{en,de,fr}.yml, the card or the connectors docs: each PR conflicts in the same files with this branch as with main, so the branch adds no new conflict.
  • Not run: browser E2E and the backend stack (light phase). The real disconnected-backend interaction and the browser layout remain manual.

Open points for the reviewer

Closes #3893

@yannickmonney

Copy link
Copy Markdown
Contributor Author

Independent exact-head verdict — Codex #11, separate from author Claude #6.

PASS for the scoped review; no blocking findings at 5b152b2c382653a7c7e14a4a7dc26db913e0e1b8 (+530/−22, nine files). This verdict covers that head only.

  • A first getOauthAppStatus read that fails leaves the affected unknown OneDrive/Google Drive row at Status unavailable, hides Configure and OneDrive SSO reuse, and exposes Try again. Retry refetches only the failed reads behind unavailable rows. Both failures share one status alert.
  • The unavailable state survives a retry, including a second failure; the retry button retains focus and becomes busy/inert. Successful recovery removes the alert and hands focus to the card. A successful configured:false, source:null restores Not configured and Configure; deployment and organization app answers remain visible with their existing configuration actions. Independently known app-list/catalog rows retain their answer.
  • Initial loading masks the statuses and actions without exposing Not configured. The existing app-list error alert and its error mapping remain intact in the diff.
  • EN/DE/FR docs describe the implemented failure/retry UI and match the new badge/control labels. Added DE copy uses du, FR uses tu; added DE copy has no sharp s. Both new keys exist in all three catalogs.
  • git merge-tree --write-tree --name-only against all 53 other open heads touching the register, compared with fetched main 8e4c6a40b0, found no additional conflicting files or register conflict hunks. Twenty heads already conflict in the register against main; these retain the same hunk counts. This is not a claim that every older PR merges cleanly.

Observed local verification, existing dependencies only:

  • Card suites: 23/23 passed (13 status-read regression tests + 10 existing tests), /opt/node/bin/node, one worker, jsdom; includes axe and retry/focus assertions. Review-only server.fs.allow handles the anticipated font restriction; workspace package aliases resolve to the reviewed checkout.
  • Platform i18n: 188/188 passed, one worker.
  • Docs docs.test.ts and locale-tree.test.ts: 25/25 passed, one worker.
  • Scoped type-aware oxlint: three files, zero diagnostics, exit 0.
  • oxfmt: both changed TSX files clean; Markdown/YAML are excluded by repository configuration. git diff --check: clean.
  • Scoped TypeScript program: card, both suites, importing connectors settings component, ambient declarations and UI test setup, with the imported closure: exit 0. No whole-platform type check or suite was run.

CI: pending, stalled incident 3q1yb5m7ltvb; read-only check inspection confirmed pending jobs. No rerun, push, merge or status change. Real-browser layout and disconnected live-backend interaction were not exercised in this review. Existing stale-refresh and app-list-failure behavior remains outside this change.

Delivery fallback for TALE-316 and TALE-359 (3729d02a-eb44-42b2-a68e-1bec2cebbcd6): workspace_status returned unavailable / not_granted, so task access/comment schemas were unavailable. This single PR comment is the requested fallback for both task destinations.

@yannickmonney
yannickmonney force-pushed the fix/oauth-apps-status-read-failure branch from 5b152b2 to bd44527 Compare October 9, 2026 02:17
@yannickmonney
yannickmonney force-pushed the fix/oauth-apps-status-read-failure branch 2 times, most recently from 75121d3 to cd45be2 Compare October 9, 2026 04:29
The Settings > Connectors OAuth apps card read a failed Knowledge import
status read (OneDrive, Google Drive's import lane) as "Not configured" and
offered Configure, so an admin could override a deployment app that was
there. The rows that read decides now say "Status unavailable" without
Configure or the Entra ID SSO reuse, and one alert names the failure with
Try again, which runs only the failed reads. A row the app list or the
connector catalog already answers keeps its answer; the app-list alert is
unchanged.

Copy in EN/DE/FR, a sentence in the admin connectors docs, and the
automation register entry for the new jsdom suite.
@yannickmonney
yannickmonney force-pushed the fix/oauth-apps-status-read-failure branch from cd45be2 to 9421bc2 Compare October 9, 2026 04:46
@yannickmonney
yannickmonney added this pull request to the merge queue Oct 9, 2026
@yannickmonney
yannickmonney added this pull request to the merge queue Oct 9, 2026
@yannickmonney
yannickmonney merged commit 0a5486b into main Oct 9, 2026
64 checks passed
@yannickmonney
yannickmonney deleted the fix/oauth-apps-status-read-failure branch October 9, 2026 22:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug(platform): Connector OAuth settings mislabel failed cloud-import app reads as Not configured

1 participant