Sign in on the mail server's own page (OAuth with PKCE), sessions hold tokens; tenants on every edition

Contract C-8 and C-10: with OAUTH_CLIENT_SECRET set, sign-in goes through the
server's page and the session keeps sealed tokens, renewed before they expire,
instead of a password. Push keeps a credential that renews itself. A password
change signs the session out, since the server revokes its tokens. The mock
answers OAuth for tests and development. Eleven new strings, in all nine
catalogues.
This commit is contained in:
jcoffey-dev committed 2026-09-18 15:30:37 -07:00
1 parent c118184975
commit 8857bdac30
24 files changed
+1058 -74

No files matched your search

+2
View File
@@ -31,6 +31,8 @@ export interface JmapSession {
maxUploadBytes: number;
sessionId: string;
loginName: string;
/** "oauth" when signed in on the mail server's page (ihasmail-inbuxa); absent from older servers. */
signIn?: "oauth" | "password";
remember: boolean;
/** Locale configured for the account in Stalwart, if the server exposes it. */
userLocale?: string | null;