From c50d2657f4f12b2957b542e5de96f51b51fd3369 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Aur=C3=A9lien=20Sibiril?= <81782+aureliensibiril@users.noreply.github.com> Date: Wed, 22 Jul 2026 13:15:53 +0200 Subject: [PATCH] Request Brex companies.readonly scope for name resolution MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The Brex name resolver calls GET /v2/company to build the source display name, but the connector only requested openid, offline_access, and users.readonly -- and users.readonly covers /v2/users (the account fetch), not /v2/company. So the company endpoint 403'd for every Brex source, which the source-name worker retried forever (2.9M errors in 7 days) until the terminal-error handling stopped the loop. Add companies.readonly so the endpoint resolves. Verified as the exact scope string against Brex's OAuth authorize flow (the "Companies: Read only" developer scope maps to companies.readonly). Existing Brex connectors must reconnect to re-consent to the added scope; until they do, /v2/company still 403s but is now handled cleanly (terminal -> generic name, no loop) rather than silently retried. Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com> --- pkg/connector/provider/brex.go | 16 ++++++++++------ 1 file changed, 10 insertions(+), 6 deletions(-) diff --git a/pkg/connector/provider/brex.go b/pkg/connector/provider/brex.go index 3f1bde46d..84b79dc64 100644 --- a/pkg/connector/provider/brex.go +++ b/pkg/connector/provider/brex.go @@ -31,12 +31,16 @@ import ( func brexRegistration() *Registration { return &Registration{ - Provider: coredata.ConnectorProviderBrex, - DisplayName: "Brex", - AuthURL: "https://accounts-api.brex.com/oauth2/default/v1/authorize", - TokenURL: "https://accounts-api.brex.com/oauth2/default/v1/token", - ProbeURL: "https://platform.brexapis.com/v2/users/me", - OAuth2Scopes: []string{"openid", "offline_access", "users.readonly"}, + Provider: coredata.ConnectorProviderBrex, + DisplayName: "Brex", + AuthURL: "https://accounts-api.brex.com/oauth2/default/v1/authorize", + TokenURL: "https://accounts-api.brex.com/oauth2/default/v1/token", + ProbeURL: "https://platform.brexapis.com/v2/users/me", + // companies.readonly is required by the name resolver's GET /v2/company + // call; without it Brex 403s that endpoint (users.readonly covers only + // /v2/users, which the driver uses). Existing Brex connectors must + // reconnect to re-consent to the added scope. + OAuth2Scopes: []string{"openid", "offline_access", "users.readonly", "companies.readonly"}, SupportsAPIKey: true, NewDriver: func(_ context.Context, c *http.Client, _ *coredata.Connector, _ *log.Logger) (drivers.Driver, error) { return drivers.NewBrexDriver(c), nil