fix(auth): drop the redundant 2nd Outlook token request on sign-in (extra onboarding failure point) #306

Closed
opened 2026-07-04 06:50:26 +00:00 by JMR-dev · 0 comments
JMR-dev commented 2026-07-04 06:50:26 +00:00 (Migrated from github.com)

Phase-3 review (LOW/efficiency+reliability). OutlookAuthManager.exchangeToken(:110): the code exchange (:86) already requests openid email offline_access $OUTLOOK_SCOPE, so tokenResponse.accessToken is already a valid outlook.office.com token usable for IMAP verification and accessTokenExpirationTime is present — yet it immediately calls refreshForScope(authState, OUTLOOK_SCOPE), a second round-trip that redeems+rotates the just-issued refresh token and adds a needless failure point (a transient network error on that 2nd call fails the whole sign-in after consent+code-exchange succeeded). Fix: build OAuthResult directly from the code-exchange tokenResponse (accessToken + authState.jsonSerializeString()), dropping the extra refresh.

Phase-3 review (LOW/efficiency+reliability). `OutlookAuthManager.exchangeToken`(:110): the code exchange (:86) already requests `openid email offline_access $OUTLOOK_SCOPE`, so `tokenResponse.accessToken` is already a valid outlook.office.com token usable for IMAP verification and `accessTokenExpirationTime` is present — yet it immediately calls `refreshForScope(authState, OUTLOOK_SCOPE)`, a second round-trip that redeems+rotates the just-issued refresh token and adds a needless failure point (a transient network error on that 2nd call fails the whole sign-in after consent+code-exchange succeeded). **Fix:** build `OAuthResult` directly from the code-exchange `tokenResponse` (`accessToken` + `authState.jsonSerializeString()`), dropping the extra refresh.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: JMR-dev/LibreMail#306