Describe the bug
PATCH /connections/{connectionId} accepts end_user, but the request schema does not accept the end user's existing organization. Updating an organization-linked end user therefore clears its native organization fields.
This is still present on master at 8de834738.
Reproduction
- Create a connection through a Connect session with both
end_user and organization.
- Confirm
GET /connection/{connectionId} returns end_user.organization.
- Send:
PATCH /connections/{connectionId}?provider_config_key={integrationId}
Content-Type: application/json
{
"end_user": {
"id": "user-123",
"email": "user@example.com",
"display_name": "Updated name"
}
}
- Read the connection again.
Actual behavior
The end user's organization becomes null.
handlePatchConnection calls EndUserMapper.apiToEndUser(body.end_user) without an organization. The mapper converts that omission to organization: null, and the subsequent end-user update writes null organization fields.
Expected behavior
Updating only end_user identity fields should preserve the existing organization. Alternatively, the PATCH schema should accept an explicit organization update and distinguish omission from clearing.
Additional impact
An end user may be linked to multiple connections. Updating its shared row through one connection can therefore clear the organization for every linked connection.
Describe the bug
PATCH /connections/{connectionId}acceptsend_user, but the request schema does not accept the end user's existing organization. Updating an organization-linked end user therefore clears its native organization fields.This is still present on
masterat8de834738.Reproduction
end_userandorganization.GET /connection/{connectionId}returnsend_user.organization.Actual behavior
The end user's
organizationbecomesnull.handlePatchConnectioncallsEndUserMapper.apiToEndUser(body.end_user)without an organization. The mapper converts that omission toorganization: null, and the subsequent end-user update writes null organization fields.Expected behavior
Updating only
end_useridentity fields should preserve the existing organization. Alternatively, the PATCH schema should accept an explicit organization update and distinguish omission from clearing.Additional impact
An end user may be linked to multiple connections. Updating its shared row through one connection can therefore clear the organization for every linked connection.