Repository navigation
fix(auth): stop requesting retired dataset scopes - #126
Conversation
|
@claude review the current PR head 40437e3 against REVIEW.md. Preserve the intentional dataset removal and the remaining issue, agent tool, and page permissions. The PR now includes the Google redirect regression and a verification map. All 550 local tests, typecheck, lint, and build pass. Review the plain-English RCA in the updated description. |
|
Warning Polylane could not verify the production impact of this pull request. Checked the scope removal in Chart attached: coreplane-prod account worker errors, last 48h. Also considered · 2 refuted
Analysed against 7 cloud accounts and 1 repository
Polylane could not find the cloud resources this repository manages, so this review looked at the entire cloud account. Connect this repository to its resources and the next review will focus on exactly what this code deploys to. Polylane analysed Did this help? React 👍 or 👎 so the next review is sharper. |
There was a problem hiding this comment.
No verdict submitted — not approving.
Reviewed at 40437e3.
For agents
Full review
Review blocked by infrastructure: the mandatory git rev-parse HEAD check returned metadata_unavailable / aborted, with no commit output. I could not verify the checkout against 40437e3ac0e0e5bb7d40d36a69c05bcf677b9878, so I stopped without submitting findings or a verdict.
There was a problem hiding this comment.
LGTM: no issues found
Reviewed at 6b5fcb2.
For agents
Rationale: Only the three retired dataset scopes are removed; the remaining 61 permissions and authorization safeguards are preserved.
Full review
No actionable findings; live Google and device sign-in with a released binary remain unverified.
Google sign-in succeeds, but Polylane refuses to finish connecting the CLI. The consent page shows
Invalid scopes requested.The cause is a missed update between two repositories. The CLI still asks for dataset permissions that Polylane no longer allows. Polylane rejects the entire connection request when any requested permission is invalid.
Backend PR #4391 intentionally removed unused customer telemetry ingestion and datasets. Its migration also removed dataset permissions from registered applications. It merged October 7 at 2:47 p.m. Pacific and reached production at 5:41 p.m. Pacific. The separate CLI release was not updated. The current published CLI, version 0.2.48, still sends the old permission list.
This PR removes only the three dataset permissions from CLI sign-in. It preserves all other permissions and the server's authorization rules. It also checks the CLI permission list against the generated API definition, so a removed permission causes a build check to fail.
Verification:
features/oauth-login.mdrecords the sign-in checks and the remaining live check.Users need a new CLI release, then an update and a fresh sign-in. A successful Google sign-in with that released version remains unverified. No customer account or permissions were changed during this investigation.
This explains the supplied screenshot. We have not confirmed the cause of attempts before the October 7 deployment.