Skip to content

Commit 3601f58

Browse files
authored
feat(search): unify source setup and organization usage (#7735)
* fix(search): streamline Atlassian source setup * fix(search): validate Atlassian keys beyond discovery limits * fix(search): preserve partial Confluence lookup failures * fix(search): remove redundant source account banner * feat(search): unify source setup and organization usage
1 parent 8d9875c commit 3601f58

152 files changed

Lines changed: 33702 additions & 1292 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

apps/docs/content/docs/search/confluence.mdx

Lines changed: 23 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -31,21 +31,16 @@ Teammates authorize Sim's shared Confluence app, which also requests workflow pe
3131

3232
### Choose Confluence
3333

34-
Open your organization's **Settings → Sources**, turn on **Confluence**, then select **Set up** (or **Manage**) → **Add source**. This opens service-account setup.
34+
Open **Settings → Sources → Add source** and select **Confluence**. This opens **Connect Confluence site** with service-account authentication. To connect another site later, open **Confluence** from the Sources list and select **Add Confluence site**.
3535

3636
</Step>
3737
<Step>
3838

3939
### Choose the account and spaces
4040

41-
Under **Indexing account**, select a service account or [add one](#using-a-service-account). Enter the same **Confluence Domain** as the credential, then choose **Spaces**. To enter comma-separated keys such as `ENG, PRODUCT`, use the switch beside the Spaces field.
41+
Under **Service account**, select a service account or [add one](#using-a-service-account). Enter the same **Confluence site** as the credential, then choose **Spaces**. **All** in the dropdown selects every space the account can currently browse; newly created spaces are not added automatically. Clear the picker search before selecting all.
4242

43-
<Image className="mx-auto h-auto w-full max-w-md"
44-
src="/static/search/confluence-setup.png"
45-
alt="Confluence source setup with a service account, site domain, and spaces"
46-
width={500}
47-
height={374}
48-
/>
43+
To enter comma-separated keys such as `ENG, PRODUCT`, use the switch beside **Spaces**. Switching between the picker and manual entry keeps your selection.
4944

5045
Open **More options** for content type, labels, and metadata tags. The default is **Pages only**; choose **All content** to include blog posts.
5146

@@ -65,9 +60,22 @@ For workspace Search, start from **Search → Add source**. Available methods de
6560

6661
## Connect member accounts
6762

68-
After an admin allows Confluence, open **Integrations → Connect**. If no source exists, enter **Confluence Domain** and **Space Keys**, then connect your account. To use another site or space scope, choose the row labeled **Connect a different site or content scope**.
63+
After an admin allows Confluence, open **Integrations → Connect**. For an existing source, authorize your account; you do not choose its spaces again.
64+
65+
If no source exists, or you choose **Connect a different site or content scope**:
66+
67+
1. Under **Your account**, select a saved account or choose **Connect account**. Authorize using the Atlassian email matching your verified Sim email.
68+
2. Enter the hostname under **Atlassian site**, then choose **Spaces**. Use **All** in the dropdown for the complete current list, or **Enter keys manually** for comma-separated keys. You can select up to 1,000 spaces in this form.
69+
3. Select **Connect & Sync**. Sim saves the selected scope and starts indexing with your account.
70+
71+
<Image className="mx-auto h-auto w-full max-w-md"
72+
src="/static/search/confluence-personal-setup.png"
73+
alt="Confluence personal source setup with a saved account, Atlassian site, and selected spaces"
74+
width={501}
75+
height={502}
76+
/>
6977

70-
Admins manage these sources under **Settings → Sources → Confluence → Manage**. An **Account for browsing** populates the space picker; it does not enroll that account for Search. Manual space keys work without a browsing account.
78+
Admins manage these sources under **Settings → Sources → Confluence**. When configuring a member-account connection, an **Account for browsing** populates the space picker; a saved personal Search account can be reused here. Choosing a browsing account does not enroll it for Search. Manual space keys work without a browsing account.
7179

7280
## Using a service account
7381

@@ -95,7 +103,7 @@ read:group:confluence
95103
Use all 12 scopes for account validation, pickers, content, permissions, and directory reads. Central indexing does not need write scopes.
96104

97105
4. Review and create the token, then copy it. Atlassian shows it only once.
98-
5. In Sim's source form, use **Indexing account** to add a service account. Paste the **API token**, enter **Site domain** (hostname only), and select **Add service account**. Continue in the source form with the same domain.
106+
5. In Sim's source form, use **Service account** to add a service account. Paste the **API token**, enter **Site domain** (hostname only), and select **Add service account**. Continue in the source form with the same domain.
99107

100108
<Image className="mx-auto h-auto w-full max-w-md"
101109
src="/static/credentials/atlassian/admin-auth-type-picker.png"
@@ -104,13 +112,13 @@ Use all 12 scopes for account validation, pickers, content, permissions, and dir
104112
height={551}
105113
/>
106114

107-
See Atlassian's [account setup](https://support.atlassian.com/user-management/docs/manage-your-service-accounts/) and [token instructions](https://support.atlassian.com/user-management/docs/manage-api-tokens-for-service-accounts/). Scopes do not grant space or page access. To replace an expiring token or change scopes, add a new credential in the source's **Settings**, select **Change indexing account**, and verify a sync before revoking the old token.
115+
See Atlassian's [account setup](https://support.atlassian.com/user-management/docs/manage-your-service-accounts/) and [token instructions](https://support.atlassian.com/user-management/docs/manage-api-tokens-for-service-accounts/). Scopes do not grant space or page access. To replace an expiring token or change scopes, add a new credential in the source's **Settings**, select **Change service account**, and verify a sync before revoking the old token.
108116

109117
## Configuration and indexed content
110118

111119
| Setting | What it controls |
112120
| --- | --- |
113-
| **Confluence Domain** | Cloud hostname only, such as `your-team.atlassian.net`; omit page URLs and `/wiki`. |
121+
| **Confluence site** | Cloud hostname only, such as `your-team.atlassian.net`; omit page URLs and `/wiki`. |
114122
| **Spaces / Space Keys** | Required spaces. The picker and manual input set the same scope. |
115123
| **Content Type** | **Pages only** (default), **Blog posts only**, or **All content** for both. |
116124
| **Filter by Label** | Optional comma-separated labels; content can match any listed label. |
@@ -122,7 +130,7 @@ Search manages the schedule and hides item limits. It indexes published/current
122130

123131
Central sources combine space permissions, page and ancestor restrictions, and group membership. Before returning central content, Sim uses your personal connection to check that you still have access to the configured Confluence site. If Atlassian cannot confirm that access, the content is hidden. Member sources use each person's provider listing. Sim admin status does not grant access to all pages, and permission changes take effect after syncing and processing.
124132

125-
Open **Settings → Sources → Confluence → Manage**, then a source's **Documents**, **Settings**, or **Sync history**. Invite teammates through **Settings → Members → Invite** or SSO, then have them connect through **Integrations**. **Accounts → Request connections** only requests a provider connection; it does not invite people to the organization.
133+
Open **Settings → Sources → Confluence**, then a source's **Documents**, **Settings**, or **Sync history**. Invite teammates through **Settings → Members → Invite** or SSO, then have them connect through **Integrations**. **People → Request connections** only requests a provider connection; it does not invite people to the organization.
126134

127135
## Troubleshooting
128136

@@ -147,6 +155,6 @@ Configure one shared Confluence OAuth app for teammates' connections:
147155
2. Under **Authorization → OAuth 2.0 (3LO)**, add `https://<your-sim-domain>/api/auth/oauth2/callback/confluence` as a callback.
148156
3. Under **Permissions**, add the Confluence API and its full `confluence` scope list from [Sim's OAuth configuration](https://github.com/simstudioai/sim/blob/staging/apps/sim/lib/oauth/oauth.ts), including `read:group:confluence`. Add **User Identity API → read:me**. Sim requests `offline_access` for refresh tokens; the service-account list above does not replace this shared OAuth scope set.
149157
4. Enable sharing under **Distribution**. Set `CONFLUENCE_CLIENT_ID` and `CONFLUENCE_CLIENT_SECRET` from the app's **Settings**, verify `NEXT_PUBLIC_APP_URL`, and restart Sim.
150-
5. Connect from **Integrations** and select the configured site. After changing the OAuth client or requested scopes, use **Settings → Sources → More → Refresh connection settings**, then have affected teammates reconnect.
158+
5. Connect from **Integrations** and select the configured site. After changing the OAuth client or requested scopes, use **Settings → Sources → More → Update sign-in settings**, then have affected teammates reconnect.
151159

152160
The callback must match Sim's scheme, hostname, port, and path exactly. If only the app owner can connect, check **Distribution**. See the [Atlassian OAuth guide](https://developer.atlassian.com/cloud/confluence/oauth-2-3lo-apps/) and [Sim deployment reference](/platform/self-hosting/integrations-oauth).

apps/docs/content/docs/search/connect-your-account.mdx

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ For a central Google source, use your primary Workspace email and open **Search*
2323

2424
## Open Integrations
2525

26-
Open **Integrations** in the main sidebar, find the provider or source, and select **Connect**. Your first connection may ask for a GitHub repository, Confluence domain and space keys, or Jira domain and project keys. Enter the required fields and select **Connect**. If the provider is missing, ask an organization admin to turn it on under **Settings → Sources**.
26+
Open **Integrations** in the main sidebar, find the provider or source, and select **Connect**. First-time setup can also ask which content to index. For [Confluence](/search/confluence) and [Jira](/search/jira), connect your Atlassian account first, then choose the site and spaces or projects and select **Connect & Sync**. [GitHub](/search/github) asks for a repository. If the provider is missing, ask an organization admin to add it under **Settings → Sources → Add source**.
2727

2828
To connect another supported repository, site, or project scope, find the provider row labeled **Connect a different site or content scope** and select **Connect**. Connecting an existing source does not ask you to configure it again.
2929

@@ -36,7 +36,7 @@ To connect another supported repository, site, or project scope, find the provid
3636

3737
Complete the provider's authorization in the new tab. Choose the account associated with your verified Sim email. The provider may require your organization's SSO or app approval.
3838

39-
The authorization tab closes when the connection completes and Integrations updates. If the tab stays open, return to Integrations. Your account is saved when authorization completes; there is no separate submit step. If the popup was blocked or closed, allow popups and select **Connect** again. While authorization is pending, use **Open again**.
39+
The authorization tab closes when the connection completes and Integrations updates. If the tab stays open, return to Integrations. For an existing source, your account is saved when authorization completes. For first-time Atlassian setup, return to the form, choose your content, and select **Connect & Sync**. If the popup was blocked or closed, allow popups and select **Connect** again. While authorization is pending, use **Open again**.
4040

4141
</Step>
4242
<Step>
@@ -74,7 +74,7 @@ An account connection request does not invite you into the Sim organization. You
7474

7575
On the main **Integrations** page, use **Reconnect** beside an expired connection to renew it. To withdraw an account, open its row's actions menu and select **Disconnect**, then confirm. If several accounts are connected, choose the account to disconnect. Disconnecting stops that account from being used for organization indexing and workflows, and removes Search access that depends on it.
7676

77-
Admins manage setup from **Settings → Sources**. Select **Manage** beside the integration. Providers with personal connections have **Accounts** and a source list under **Advanced** (Google) or **Sources**. Without personal connections, the source list opens directly. This does not grant the admin access to every document.
77+
Admins manage setup from **Settings → Sources**. Open an integration, then its connection to see **Documents**, **Settings**, and **Sync history**. **People** shows account contributors across integrations and supports filtering by integration. This does not grant the admin access to every document.
7878

7979
## If you get stuck
8080

@@ -87,7 +87,7 @@ Admins manage setup from **Settings → Sources**. Select **Manage** beside the
8787
| **Verify email** | Verify your Sim email to return to the connection page. Reopen the original link if you are not redirected. |
8888
| Expired or cancelled authorization | Return to the original connection page and start again. If the invitation itself expired, ask the admin for a new request. |
8989
| Access revoked | Ask the organization admin to restore your account contribution access before reconnecting. |
90-
| Needs admin attention | Ask your admin to open **Settings → Sources**, select **Manage** beside the integration, and open its source or sync configuration to inspect the error. |
90+
| Needs admin attention | Ask your admin to open **Settings → Sources**, select the integration, and open its connection to inspect the error. |
9191

9292
<Callout type="info">
9393
Your Sim role does not override document access at the source. Connecting a different account or receiving a Search link does not share someone else's mailbox, private calendar, or restricted documents with you.

0 commit comments

Comments
 (0)