Phase-3 review (LOW/efficiency+reliability). OutlookAuthManager.exchangeToken(:110): the code exchange (:86) already requests openid email offline_access $OUTLOOK_SCOPE, so tokenResponse.accessToken is already a valid outlook.office.com token usable for IMAP verification and accessTokenExpirationTime is present — yet it immediately calls refreshForScope(authState, OUTLOOK_SCOPE), a second round-trip that redeems+rotates the just-issued refresh token and adds a needless failure point (a transient network error on that 2nd call fails the whole sign-in after consent+code-exchange succeeded). Fix: build OAuthResult directly from the code-exchange tokenResponse (accessToken + authState.jsonSerializeString()), dropping the extra refresh.
Phase-3 review (LOW/efficiency+reliability). `OutlookAuthManager.exchangeToken`(:110): the code exchange (:86) already requests `openid email offline_access $OUTLOOK_SCOPE`, so `tokenResponse.accessToken` is already a valid outlook.office.com token usable for IMAP verification and `accessTokenExpirationTime` is present — yet it immediately calls `refreshForScope(authState, OUTLOOK_SCOPE)`, a second round-trip that redeems+rotates the just-issued refresh token and adds a needless failure point (a transient network error on that 2nd call fails the whole sign-in after consent+code-exchange succeeded). **Fix:** build `OAuthResult` directly from the code-exchange `tokenResponse` (`accessToken` + `authState.jsonSerializeString()`), dropping the extra refresh.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Phase-3 review (LOW/efficiency+reliability).
OutlookAuthManager.exchangeToken(:110): the code exchange (:86) already requestsopenid email offline_access $OUTLOOK_SCOPE, sotokenResponse.accessTokenis already a valid outlook.office.com token usable for IMAP verification andaccessTokenExpirationTimeis present — yet it immediately callsrefreshForScope(authState, OUTLOOK_SCOPE), a second round-trip that redeems+rotates the just-issued refresh token and adds a needless failure point (a transient network error on that 2nd call fails the whole sign-in after consent+code-exchange succeeded). Fix: buildOAuthResultdirectly from the code-exchangetokenResponse(accessToken+authState.jsonSerializeString()), dropping the extra refresh.