-
Notifications
You must be signed in to change notification settings - Fork 3
plat 470
State: fixed on main; not deployed. Local frontend receives the change on the required fast-forward update. Priority: P2.
The account UI used modern service icons and Change access only when the server had a platform Google app. Without it, locally uploaded named OAuth JSON clients fell back to older account cards and checkbox forms. A mailbox with Google-granted gmail.readonly but allow_read_access disabled could show both Send only and Gmail: Read, leaving users and Builder unclear about what to enable.
- WorkflowEmailPanel and the shared Gmail pane always use GoogleAccountList and GoogleAccountConnect across workflow, Crew, Code and Relay targets.
- The connect form offers the administrator-configured Company Google app, existing named clients, or a new named OAuth JSON upload. The company option needs no per-account upload. Named clients use the existing connection/auth APIs. Uploads never request replacement of an existing client; the reserved platform name is not available for upload.
- Existing accounts reconnect by their current ID and OAuth client, even when no platform app exists. Changes to optional services send the complete list with services_set, including clearing the list.
- Account cards show saved AgentWorks settings and checked Google permissions separately, explain already-granted Gmail reading that is disabled in AgentWorks, and flag selected access absent from Google.
- Existing owner/admin, workspace and read-only restrictions remain. No account permission is automatically enabled or changed. Failed app discovery is visible and does not hide legacy reconnection.
- Builder instructions and in-product help cover both sources and distinguish Google grants from the application read opt-in. Sign-in links remain copyable for another browser profile.
Focused frontend tests cover both sources together, named-client selection, JSON registration without replacement, legacy reconnect with no company app, workspace isolation, permission drift, broader and restricted Google scopes, private/shared management restrictions, and service replacement. Frontend type checking and the full production build pass.
Deploy/restart hosted frontends when desired. No cloud app, Pub/Sub, user account or OAuth credential was changed by this task.
Auto-synced from docs/ on main. Edit there, not here.