Commit b44596f
authored
fix(knowledge): treat Google Workspace users without Gmail or Calendar as out of scope, not listing failures (#8168)
* fix(knowledge): treat Google Workspace users without Gmail or Calendar as out of scope, not listing failures
Admin-mode Gmail recorded a Directory user without a mailbox, and Calendar recorded a
403 notACalendarUser, as per-user listing failures. Both are standing account properties,
so the connector stayed partial, deletion reconciliation never ran, and the scheduler
re-probed the same accounts every retry window.
- Directory enumeration no longer schedules Gmail users whose mailbox is not set up; the
hourly Directory refresh picks them up once provisioned. A partition queued earlier
completes with an empty page instead of a failure.
- A Calendar 403 whose only reason is notACalendarUser completes the user's partition
cleanly and re-probes it no sooner than the Directory refresh (permissions keep their
own refresh cadence). Bare forbidden and mixed-reason 403s stay retryable failures.
* fix(knowledge): keep a Google Workspace user's visible documents until a missing service outlasts propagation
Google applies service and organizational-unit changes within 24 hours, so a missing
mailbox or notACalendarUser can be transient for a user whose documents are already
indexed, and a mid-listing answer does not prove the whole account lacks the service.
- The scheduler skips a service-not-enabled user only on their first provider page, and
only when readers see none of their documents or the condition was first observed at
least 24 hours ago. Otherwise it is a retained failure, as before, whose first
observation is kept in the partition failure; after 24 hours a mid-listing user
restarts from their first page.
- Permission passes skip on the first page, since a retained failure refreshes nothing.
- Gmail Directory enumeration keeps scheduling a user without a mailbox while readers
still see their mail; the crawl reports the missing mailbox to the scheduler instead of
completing the user.
- Visibility is read through doc_acl_gin_idx for the user's token behind an OFFSET 0
fence, bounded by that user's grants.
* fix(knowledge): read a user's visible documents from the ACL index and cover the probe in PostgreSQL
The visibility probe moves to its own module so it can run against a real database.
Planned inline, LIMIT 1 made a sequential scan of the document table look cheaper than
doc_acl_gin_idx, because PostgreSQL cannot estimate array overlap. A materialized CTE now
reads the user's grants from the index first, bounding the probe by that user's grants.
The email goes through userToken, so a mixed-case or padded directory address matches the
normalized ACL token.
The new PostgreSQL integration test covers fresh, stale and missing permission evidence,
another user's grant, another connector, excluded, archived and deleted documents, and
email normalization, and runs in the Search progress PostgreSQL CI step.1 parent aaca125 commit b44596f
12 files changed
Lines changed: 456 additions & 74 deletions
File tree
- .github/workflows
- apps/sim
- connectors
- google-workspace
- lib/knowledge
- __integration__
- connectors
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
271 | 271 | | |
272 | 272 | | |
273 | 273 | | |
| 274 | + | |
274 | 275 | | |
275 | 276 | | |
276 | 277 | | |
| |||
Lines changed: 26 additions & 17 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
| 5 | + | |
5 | 6 | | |
6 | 7 | | |
7 | 8 | | |
| 9 | + | |
8 | 10 | | |
9 | 11 | | |
10 | 12 | | |
| |||
483 | 485 | | |
484 | 486 | | |
485 | 487 | | |
486 | | - | |
| 488 | + | |
487 | 489 | | |
488 | | - | |
489 | | - | |
490 | | - | |
491 | | - | |
| 490 | + | |
| 491 | + | |
| 492 | + | |
| 493 | + | |
492 | 494 | | |
493 | 495 | | |
494 | 496 | | |
| 497 | + | |
495 | 498 | | |
496 | | - | |
497 | | - | |
| 499 | + | |
498 | 500 | | |
499 | 501 | | |
500 | 502 | | |
501 | 503 | | |
502 | 504 | | |
503 | 505 | | |
504 | 506 | | |
505 | | - | |
506 | | - | |
507 | | - | |
| 507 | + | |
| 508 | + | |
| 509 | + | |
508 | 510 | | |
509 | | - | |
| 511 | + | |
510 | 512 | | |
511 | 513 | | |
512 | 514 | | |
513 | 515 | | |
514 | 516 | | |
515 | 517 | | |
516 | | - | |
| 518 | + | |
517 | 519 | | |
518 | 520 | | |
519 | 521 | | |
520 | 522 | | |
521 | 523 | | |
522 | 524 | | |
523 | 525 | | |
| 526 | + | |
| 527 | + | |
| 528 | + | |
| 529 | + | |
| 530 | + | |
| 531 | + | |
| 532 | + | |
| 533 | + | |
524 | 534 | | |
525 | 535 | | |
526 | 536 | | |
| |||
626 | 636 | | |
627 | 637 | | |
628 | 638 | | |
629 | | - | |
630 | | - | |
631 | | - | |
632 | | - | |
| 639 | + | |
| 640 | + | |
| 641 | + | |
633 | 642 | | |
634 | 643 | | |
635 | 644 | | |
| |||
643 | 652 | | |
644 | 653 | | |
645 | 654 | | |
646 | | - | |
| 655 | + | |
647 | 656 | | |
648 | 657 | | |
649 | 658 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
161 | 161 | | |
162 | 162 | | |
163 | 163 | | |
164 | | - | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
165 | 193 | | |
166 | 194 | | |
167 | 195 | | |
168 | 196 | | |
169 | 197 | | |
170 | 198 | | |
171 | 199 | | |
172 | | - | |
| 200 | + | |
| 201 | + | |
173 | 202 | | |
174 | 203 | | |
175 | 204 | | |
176 | 205 | | |
177 | 206 | | |
178 | 207 | | |
179 | 208 | | |
180 | | - | |
| 209 | + | |
181 | 210 | | |
182 | 211 | | |
183 | 212 | | |
| |||
317 | 346 | | |
318 | 347 | | |
319 | 348 | | |
320 | | - | |
321 | | - | |
322 | | - | |
| 349 | + | |
| 350 | + | |
323 | 351 | | |
324 | 352 | | |
325 | 353 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
7 | 17 | | |
8 | 18 | | |
9 | | - | |
10 | | - | |
11 | | - | |
12 | | - | |
13 | | - | |
14 | | - | |
15 | | - | |
16 | | - | |
17 | | - | |
18 | | - | |
19 | | - | |
| 19 | + | |
20 | 20 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
205 | 205 | | |
206 | 206 | | |
207 | 207 | | |
| 208 | + | |
| 209 | + | |
208 | 210 | | |
209 | 211 | | |
210 | 212 | | |
| |||
Lines changed: 90 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
0 commit comments