Repository navigation
Fix HubSpot authorization after granular ticket scope migration - #245
Conversation
There was a problem hiding this comment.
🟢 Approval recommended
The scope migration is consistently applied across defaults, tests, and documentation, and no conflicting legacy-scope dependencies were found in related client logic.
Pull request overview
Updates the HubSpot connector’s default OAuth scope set to align with HubSpot’s granular replacement of the legacy tickets scope, while preserving CMS permissions as optional and ensuring file/HubDB scopes are not requested by default.
Changes:
- Replace legacy
ticketswith the four granular ticket object/schema scopes in the HubSpot REST connector defaults. - Strengthen TypeScript and Qore OAuth tests to assert the new ticket scopes are requested and that legacy/file/HubDB scopes are not.
- Document the granular scope migration and clarify which layers own scope configuration (and which do not require changes).
File summaries
| File | Description |
|---|---|
| ts/src/apps/hubspot/rest.ts | Updates default oauth2_scopes to use granular ticket scopes instead of legacy tickets. |
| ts/src/tests/hubspot-oauth.test.ts | Updates/extends assertions for new ticket scopes and confirms file/HubDB/legacy scopes are excluded. |
| test/hubspot-oauth.qtest | Adds consent-URL scope assertions for granular ticket scopes and validates profile overrides don’t inherit unwanted scopes. |
| docs/hubspot-cms-oauth.md | Documents the ticket granular scope migration and clarifies optional vs required scope responsibilities. |
Review details
- Files reviewed: 4/4 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
The pinned Ubuntu and Alpine manifests no longer exist in the registry, so both jobs fail before checkout. Follow the branch tags published by qore-test-base instead of digests that become untagged after rebuilds. Validated both registry images for linux/amd64, GitLab CI lint without warnings, shell syntax, all six CI support tests, and the HubSpot OAuth suite (14 cases, 371 assertions).
There was a problem hiding this comment.
🟡 Changes recommended
The GitLab CI change to mutable base-image tags (:develop/:develop-alpine) materially reduces build reproducibility and should be pinned to an immutable reference (or an equivalent deterministic alternative) before approval.
Get a fresh assessment by requesting another Copilot review.
Review details
Suppressed comments (2)
Previously missed (1) — in code that hasn't changed since the last review.
test/hubspot-oauth.qtest:316
- The new comment says "CMS-only candidate" but the profile being tested explicitly requests
crm.objects.contacts.read, so it isn’t actually CMS-only. This makes the test harder to understand; reword to reflect that the test is about overrides not inheriting additional default scopes.
.gitlab-ci.yml:45
- Same concern as
test-ubuntu: using the mutable:develop-alpinetag makes the Alpine test environment non-deterministic across runs. Prefer pinning to an immutable digest (optionally alongside the retention tag) or a versioned tag published by the base-image pipeline.
# Follow the published Alpine branch tag as well, rather than an unretained digest.
image: $CI_REGISTRY/infrastructure/qore-test-base/qore-test-base:develop-alpine
- Files reviewed: 5/5 changed files
- Comments generated: 1
- Review effort level: Lite
HubSpot's migrated app configuration no longer lists the legacy
ticketsscope, but the connector still requested it during authorization. Request the four replacement ticket object/schema scopes while retaining the existing optional CMS permissions.Keep file, HubDB, and timeline scopes out of the default connection: their conditional availability in the external app does not make them requirements for every installation. Document which layers own scope configuration and why the generic Qore OAuth engine and Qorus API token broker need no change for these scope names.
Validation: TypeScript compilation passed; all five OAuth metadata tests passed; the Qore OAuth integration suite passed 14 cases and 371 assertions, including generated URI scope checks and explicit profile overrides. Tests used
qore --enable-debug -r. The existing external app must be migrated before deploying these defaults; persisted connection overrides require separate review.This corrects a verified scope mismatch. It does not claim to resolve the separate HubDB authorization error: HubSpot's saved installation record already contains HubDB scopes that the candidate's outgoing request does not include.