Trim access-review connector comments

Cut verbose inline comments across the access-review connector changes:
the mechanical fact stays at the read site, while incident backstory
("millions of error logs in prod") and provider-specific rationale (why
Clerk reviews the wrong population) move to the commit history where they
belong. Also tighten a loose "a 4xx" to "an auth/not-found 4xx" so the
terminal-classification contract is not overstated. No behavior change.

Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com>
This commit is contained in:
Aurélien Sibiril
2026-07-22 17:19:08 +02:00
parent a7bcbbcd85
commit a0ead155db
7 changed files with 28 additions and 53 deletions

View File

@@ -146,15 +146,10 @@ func (h *sourceNameHandler) Process(ctx context.Context, source coredata.AccessR
},
)
if err != nil {
// Setting up the resolver failed: the connector is gone, its
// credentials cannot be decrypted, or an eager token refresh failed
// on a revoked OAuth refresh token. Returning nil without marking the
// source synced leaves name_synced_at NULL, so the worker re-claims
// the same row every drain cycle with no delay — a single dead
// connector then hot-loops the vendor token endpoint (millions of
// error logs in prod). Treat it as terminal: keep the generic name
// and mark the source synced so it stops re-claiming. A
// reconnect/reconfigure clears name_synced_at to try again.
// Resolver setup failed (missing connector, undecryptable credential,
// or an eager refresh on a revoked token). Mark the source synced
// rather than returning nil: an unsynced row is re-claimed every poll
// with no backoff and hot-loops the vendor. A reconnect clears it.
h.logger.WarnCtx(
ctx,
"cannot set up name resolver, keeping generic name",