The Brex name resolver calls GET /v2/company to build the source display name, but the connector only requested openid, offline_access, and users.readonly -- and users.readonly covers /v2/users (the account fetch), not /v2/company. So the company endpoint 403'd for every Brex source, which the source-name worker retried forever (2.9M errors in 7 days) until the terminal-error handling stopped the loop. Add companies.readonly so the endpoint resolves. Verified as the exact scope string against Brex's OAuth authorize flow (the "Companies: Read only" developer scope maps to companies.readonly). Existing Brex connectors must reconnect to re-consent to the added scope; until they do, /v2/company still 403s but is now handled cleanly (terminal -> generic name, no loop) rather than silently retried. Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com>
2.3 KiB
2.3 KiB