Files
sim/apps
Waleed 14d9542f2a fix(credentials): capture the correct provider identity on connect and rotate (#6201)
* fix(credentials): capture the correct provider identity on connect and rotate

Attio OAuth recorded an arbitrary workspace member instead of the authorizing
user, so two members connecting under one Sim user collapsed into a single
account row via the stale-sibling dedupe. Notion read `profile.person.email`,
which never exists on a bot token. Synthetic connector emails were minted on
live third-party domains. Google service-account rotation left the credential
labeled with the old key's client_email and skipped audit metadata entirely.
Box and Salesforce identity lookups failed silently with no logger in either
file.

Service-account principals are now a single ServiceAccountPrincipal union
(user / tenant / lookup_failed / null) mirrored centrally into both audit and
stored metadata, so a principal can no longer be captured and forgotten, and
"which account is this credential?" is answerable from SQL.

* fix(credentials): keep the provider-reported name when identity lookup degrades

Box and Salesforce returned early on a missing user id, discarding a `name` or
`login` the response did carry and relabeling the credential to the enterprise
or host fallback. Only the principal should degrade; the human label still
beats an id-derived string.

Also notes the Salesforce `openid` scope in the connect help text. The client
credentials minter sends no scope parameter — effective scopes come from the
customer's Connected App — so without `openid` the userinfo lookup can 403 and
the run-as user silently never reaches the audit record.
2026-08-03 09:29:26 -07:00
..