| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
feat(oauth2_cc): fall back to JWT exp for OAUTH2_CC token expiry (#7605) ## Describe the problem and your solution - fall back to JWT exp for OAUTH2_CC token expiry <!-- Issue ticket number and link (if applicable) --> <!-- Testing instructions (skip if just adding/editing providers) --> <!-- This is an auto-generated description by cubic. --> <a href="https://cubic.dev/pr/NangoHQ/nango/pull/7605?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. --> | 14 天前 | |
fix: control logging function output (#7810) <!-- Describe the problem and your solution --> <!-- Issue ticket number and link (if applicable) --> <!-- Testing instructions (skip if just adding/editing providers) --> <!-- This is an auto-generated description by cubic. --> <a href="https://cubic.dev/pr/NangoHQ/nango/pull/7810?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. --> | 1 天前 | |
feat(webhooks): add allow unverified webhooks integration option (NAN-7312) (#7726) NAN-7312 Adds an "Allow unverified webhooks" option on integrations, off by default and editable from the integration settings. When it is on, webhooks with a missing or unverifiable signature are processed and still flagged as unverified. Invalid signatures are always rejected. GitHub App, GitHub App OAuth, Gmail, Salesforce and Microsoft Teams now respect the option, with their existing feature flags kept as a fallback. DB: adds `allow_unverified_webhooks boolean NOT NULL DEFAULT false` to `_nango_configs`. <!-- This is an auto-generated description by cubic. --> <a href="https://cubic.dev/pr/NangoHQ/nango/pull/7726?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. --> | 5 天前 | |
chore: eslint pass on import order 3 (#4296) ## Changes - Last pass to activate import order rules we were definitely not getting there manually <!-- Summary by @propel-code-bot --> --- This PR performs a comprehensive, automated update to the import statements across the entire codebase to fully enforce ESLint's import/order rules, as well as related import linting conventions. The 'import/order' rule in the ESLint configuration is raised from 'warn' to 'error', and many TypeScript and JavaScript source files are modified to reorder, group, and separate import/type import statements accordingly. No business logic or functional behavior is changed; all modifications are organizational and related to linting compliance. <details> <summary><strong>Key Changes</strong></summary> • Systematic reordering and grouping of import and type import statements in all TypeScript and JavaScript files, aligning with stricter ESLint import/order rules. • ESLint configuration (eslint.config.mjs) updated: 'import/order' set to 'error' and related rules adjusted; minor tuning to linting options for clarity and performance. • No code logic, functionality, or documentation changes introduced-scope is strictly import organization and enforcement of lint rules. </details> <details> <summary><strong>Affected Areas</strong></summary> • All source code files (.ts/.js) across the repository • eslint.config.mjs (ESLint config for import/style rules) </details> *This summary was automatically generated by @propel-code-bot* | 1 年前 | |
feat(webhooks): add allow unverified webhooks integration option (NAN-7312) (#7726) NAN-7312 Adds an "Allow unverified webhooks" option on integrations, off by default and editable from the integration settings. When it is on, webhooks with a missing or unverifiable signature are processed and still flagged as unverified. Invalid signatures are always rejected. GitHub App, GitHub App OAuth, Gmail, Salesforce and Microsoft Teams now respect the option, with their existing feature flags kept as a fallback. DB: adds `allow_unverified_webhooks boolean NOT NULL DEFAULT false` to `_nango_configs`. <!-- This is an auto-generated description by cubic. --> <a href="https://cubic.dev/pr/NangoHQ/nango/pull/7726?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. --> | 5 天前 | |
fix(server): omit action input (#7804) <!-- Describe the problem and your solution --> <!-- Issue ticket number and link (if applicable) --> <!-- Testing instructions (skip if just adding/editing providers) --> <!-- This is an auto-generated description by cubic. --> <a href="https://cubic.dev/pr/NangoHQ/nango/pull/7804?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. --> | 1 天前 | |
feat(microsoft-teams): optionally mint Teams Dev Portal tokens (#7677) ## Problem The [Teams Developer Portal API](https://dev.teams.microsoft.com) (`/api/appdefinitions`, `/api/botframework`, ...) is the only public HTTP surface for programmatically managing Teams apps and bot registrations. Its tokens use a different Entra audience (`https://dev.teams.microsoft.com`) than Microsoft Graph, so a single OAuth2 access token cannot serve both APIs, and today a `microsoft-teams` connection only carries a Graph token. ## Solution Follow the established `one-drive`/`sharepoint-online` secondary-token pattern to optionally issue a Teams Dev Portal token from the same user consent: - **Post-connection hook**: after the existing `tenantId` extraction, redeem the connection's refresh token for the `https://dev.teams.microsoft.com/AppDefinitions.ReadWrite` scope and store `devPortalAccessToken` (with `expires_at`) in `connection_config`. This only happens when the integration explicitly requests the Dev Portal scope — messaging-only integrations skip it entirely. Failures are logged with the provider error body (status + response data) and leave `devPortalAccessToken` unset, degrading the integration to messaging-only rather than breaking the existing connection. - **Provider client refresh**: `microsoft-teams` is added to `shouldUseProviderClient`; `refreshMicrosoftTeamsToken` re-mints the Dev Portal token alongside the Graph token, keyed on the `connection_config` entry (mirroring `refreshSharepointToken`). The initial code exchange is a plain `authorization_code` grant, identical to `createSharepointToken`. - **Refresh trigger**: `shouldRefreshCredentials` treats an expired `devPortalAccessToken` as a refresh trigger, and the refreshed token is persisted back into `connection_config` (mirroring `sharepointAccessToken`/`botFrameworkAccessToken` handling). - **Docs**: the microsoft-teams setup guide documents the dual-token behavior, mirroring the OneDrive guide's "SharePoint and Graph tokens" section. The nested `refresh_token` in `devPortalAccessToken` is stripped by the existing generic `withoutRefreshTokenProperties` sanitization when connections are served. ### Behavior for existing connections All microsoft-teams connections (messaging-only and Dev-Portal-enabled) now refresh through `refreshMicrosoftTeamsToken` in `provider.client.ts` instead of `getFreshOAuth2Credentials`. Two things `getFreshOAuth2Credentials` provides need parity coverage on the new path: **`assertSafeOAuthUrl` — kept.** The outer `refreshToken` dispatch in `provider.client.ts` already calls `assertSafeOAuthUrl` on the primary token URL (and any refresh URL) before delegating to `refreshMicrosoftTeamsToken`, so every existing connection keeps the URL safety check on its primary refresh. `refreshMicrosoftTeamsToken` also now calls `assertSafeOAuthUrl` on the dev portal token URL for parity, even though the host is hardcoded to `login.microsoftonline.com` and the only interpolated segment is a tenant UUID from the parsed JWT. **Provider error body logging — restored.** `getFreshOAuth2Credentials` surfaces the token endpoint error payload via `logCtx.http({ meta: { body: errorPayload } })`. The previous `refreshMicrosoftTeamsToken` catch collapsed everything to `err.message` (typically `"Request failed with status code 400"`), which would have lost Entra's `error`/`error_description`. The catch now inspects `err.response.data`: on axios errors it logs `status` + `body` via the module logger and throws `NangoError('microsoft_teams_refresh_token_request_error', { status, body })`, so the provider payload is preserved end-to-end. Non-axios failures still fall back to `err.message`. Without the Dev Portal scope on the integration, the post-connection hook still exits early — no `devPortalAccessToken` is ever written and the refresh guard never fires — so the custom refresh path degrades to the standard refresh-token grant with the same error-body coverage described above. ## Testing - `npm run ts-build` passes - Added `shouldRefreshCredentials` unit tests for the `microsoft-teams` branch (expired / fresh / absent `devPortalAccessToken`); `vitest --dir packages/shared/lib/services/connections` and `connection.service.unit.test.ts` pass - `npm run lint` — 0 errors; `prettier --check` clean on all changed files <!-- This is an auto-generated description by cubic. --> <a href="https://cubic.dev/pr/NangoHQ/nango/pull/7677?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. --> --------- Co-authored-by: mastracode <284800079+mastra-platform[bot]@users.noreply.github.com> Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com> Co-authored-by: Hassan_Wari <85742599+hassan254-prog@users.noreply.github.com> | 1 天前 | |
feat: rename environments (#3864) <!-- Describe the problem and your solution --> ### Description This PR contains cherry-picked files (with tweaks) from #3849, excluding anything related to deleting environments. - Added new `Main` section to environment settings with `EditableInput` for environment name. <img width="952" alt="image" src="https://github.com/user-attachments/assets/04a06c7e-300c-4a66-b82b-acb46cd6c7cc" /> - Prod environment shouldn't be renamable with informative tooltip <img width="641" alt="image" src="https://github.com/user-attachments/assets/731e172d-b920-41fe-9a0e-cad15edd2f78" /> - Tweaked `Create Environment` button be blocked and show different tooltip based on plan, when maximum amount of environments is reached <img width="419" alt="image" src="https://github.com/user-attachments/assets/9430bab5-9bd9-4ba1-b61f-1d209e9ecf69" /> - Removed message from create environment dialog that said only the prod environment is billed. <!-- Issue ticket number and link (if applicable) --> ### Ticket [NAN-2685](https://linear.app/nango/issue/NAN-2685/editdelete-environments-in-the-ui) <!-- Testing instructions (skip if just adding/editing providers) --> ### Testing instructions Checkout to branch and test mentioned changes in UI. | 1 年前 | |
feat: add @nangohq/kms package (#6471) add @nangohq/kms package: - resolve data encryption key from NANGO_ENCRYPTION_KEY and load/unwrap wrapped key in the background to verify equality - refactor encryption logic in the rest of the codebase to use the `kms` package. No change in behavior so far. Encryption key is still loaded from NANGO_ENCRYPTION_KEY. Once I have verified that infra is all setup correctly I'll make a PR to load the wrapped key instead. <!-- Issue ticket number and link (if applicable) --> <!-- Testing instructions (skip if just adding/editing providers) --> | 3 个月前 | |
feat(integrations): linear incoming webhooks support (#1617) | 2 年前 | |
fix(posthog): fix duplicate persons and internal filters in PostHog (#7716) ## Context PostHog counts people and accounts wrong. The webapp identifies people by email and the server by user id, so every user is two persons. The internal filter matches names in emails, which hides real customers and can't see server events. Staff impersonating an account show up as that customer's activity. ## Changes - The webapp identifies people by user id, the same distinct id the server uses. Email and name stay as person properties. - The server sets `is_internal` on the `company` group when an account is created or a user accepts an invite. It is true when every user has a `@nango.dev` email. - The server sends no events or group updates in a request whose session is impersonating an account. - The webapp stops capturing before the impersonation reload, and whenever `/meta` reports `debugMode`. Capturing resumes in the next normal session. Fixes [NAN-7195](https://linear.app/nango/issue/NAN-7195) ## Testing - Tests cover `@nango.dev` and other-domain signups, impersonated requests that name an account, and `is_internal` not being resent or overwritten by later server events. - Not verifiable before merge: the PostHog side needs production traffic. After deploy, impersonate an account and check Live events shows nothing from it. ## Follow-ups - One-off scripts: merge each user's existing email person into their user-id person, and set `is_internal` on existing accounts. Needed before the project's internal filter switches to `is_internal`. <!-- This is an auto-generated description by cubic. --> <a href="https://cubic.dev/pr/NangoHQ/nango/pull/7716?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. --> | 5 天前 |