You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
fix(microsoft): support personal accounts without changing existing connections - #8784
Add personal Microsoft account connections for OneDrive, Outlook, and Word through one optional, separate OAuth app.
Preserve existing Microsoft connections and sign-in, including their original client during refresh and reconnect. Keep account selection, managed credentials, and knowledge sources aligned.
Document setup and account-type restrictions. Personal options remain hidden until configured; either client can be deployed independently.
Type of Change
Bug fix
Testing
Root VITEST_MAX_WORKERS=4 bun run test --concurrency=1 -- --pool=forks --maxWorkers=6 --retry=1; focused regression suites; six Postgres integration cases covering source provisioning, credential visibility and isolation; five HTTP integration cases covering PKCE, signed identity tokens, nonce rejection, refresh rotation, and client isolation. Integration runs produce a JSON report. The stop-after HTTP acceptance suite also passes with source fixtures waiting for durable persistence before reuse. Lint, type checks, 58 audits, docs manifest, block registry, and workflow checks pass.
Live Microsoft validation: identity and scope verification, refresh for all three personal providers, OneDrive file operations, production Word document operations, Outlook drafts and calendar events. All 17 checks passed; temporary fixtures were removed.
Checklist
Code follows project style guidelines
Self-reviewed my changes
Tests added/updated and passing (new tests pass the test-audit authoring gate)
[High risk] Adds new OAuth providers for Microsoft personal accounts.
The PR appears safe to merge; no actionable issues remain from this review.
What we checked:
Successful runs pass the wait: The response uses the stored execution ID. The script requires a completed run, and the log writer saves its status and end time.
Summary
Adds separate personal Microsoft connections for OneDrive, Outlook, and Word while keeping existing connections tied to their original app.
Personal account choices appear only when configured.
Compatible personal credentials work with organization pickers and member sources.
The latest changes document isMicrosoftPersonalProvider and wait for saved source runs before reusing them.
All three previous threads were checked against the current code. Their fixes are present; no new actionable issues were found.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
Connect[Connect an account] --> Choice{Configured account type}
Choice -->|Work or school| Existing[Existing Microsoft app]
Choice -->|Personal| Personal[Separate personal Microsoft app]
Existing --> WorkGrant[Original provider ID]
Personal --> PersonalGrant[Personal provider ID]
WorkGrant --> Refresh[Refresh through the issuing app]
PersonalGrant --> Refresh
WorkGrant --> Service[Compatible service and source choices]
PersonalGrant --> Service
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Type of Change
Testing
Root
VITEST_MAX_WORKERS=4 bun run test --concurrency=1 -- --pool=forks --maxWorkers=6 --retry=1; focused regression suites; six Postgres integration cases covering source provisioning, credential visibility and isolation; five HTTP integration cases covering PKCE, signed identity tokens, nonce rejection, refresh rotation, and client isolation. Integration runs produce a JSON report. The stop-after HTTP acceptance suite also passes with source fixtures waiting for durable persistence before reuse. Lint, type checks, 58 audits, docs manifest, block registry, and workflow checks pass.Live Microsoft validation: identity and scope verification, refresh for all three personal providers, OneDrive file operations, production Word document operations, Outlook drafts and calendar events. All 17 checks passed; temporary fixtures were removed.
Checklist
test-auditauthoring gate)