feat(auth): detect "IMAP disabled" AUTHENTICATE failures and prompt the user to enable IMAP #390

Closed
opened 2026-07-06 23:41:09 +00:00 by JMR-dev · 0 comments
JMR-dev commented 2026-07-06 23:41:09 +00:00 (Migrated from github.com)

Context

Diagnosed on-device 2026-07-06: a personal outlook.com account with IMAP disabled (the "Let devices and apps use POP/IMAP" toggle is OFF by default on new accounts) produces a confusing onboarding failure:

  • OAuth consent + token exchange succeed (valid XOAUTH2 token, no AADSTS error).
  • The IMAP AUTHENTICATE XOAUTH2 step against outlook.office365.com:993 is then rejected by the server with a generic jakarta.mail.AuthenticationFailedException: AUTHENTICATE failed (from ImapClient.openConnectedStore -> IMAPStore.protocolConnect).
  • The user sees an opaque "authentication failed" with no hint that the real cause is an account-side IMAP toggle they can flip.

Confirmed account-config, not code: the same build signs in fine on an IMAP-enabled account.

Goal

Detect this specific pattern -- OAuth token obtained successfully, but IMAP AUTHENTICATE failed -- and show a descriptive, actionable message instead of the generic error, e.g.:

"Signed in successfully, but Outlook rejected IMAP access for this account. Make sure IMAP is turned on: Outlook.com -> Settings -> Mail -> Sync email -> 'Let devices and apps use POP/IMAP'."

Scope / approach

  • Distinguish token/consent failure (fix = re-auth/scopes) from token-OK-but-IMAP-AUTHENTICATE-rejected (fix = enable IMAP / provider policy). Only the latter gets the "enable IMAP" prompt.
  • Map AuthenticationFailedException ("AUTHENTICATE failed") at the IMAP-connect step, when a valid OAuth token was just obtained, to a typed error -> provider-aware message + a hint/link to the provider's IMAP-enable setting.
  • Primarily Outlook/Microsoft, but generalize: Gmail/Yahoo/iCloud can have IMAP-disabled/app-access states too -- provider-specific copy where known, a sensible generic otherwise.
  • Touch points: account-setup error handling (AccountSetupViewModel), the IMAP connect path (ImapClient.openConnectedStore), and wherever AuthenticationFailedException is caught/surfaced.

DoD

Descriptive message shipped with tests (unit-test the exception->message mapping; instrumented/E2E for the setup-screen error state). PII-free (never log the token/email). Relates to the onboarding epic and the prior Outlook login fixes. Evidence: on-device logcat 2026-07-06.

## Context Diagnosed on-device 2026-07-06: a **personal `outlook.com` account with IMAP disabled** (the "Let devices and apps use POP/IMAP" toggle is OFF by default on new accounts) produces a confusing onboarding failure: - OAuth consent + token exchange **succeed** (valid XOAUTH2 token, no AADSTS error). - The IMAP `AUTHENTICATE XOAUTH2` step against `outlook.office365.com:993` is then **rejected** by the server with a generic `jakarta.mail.AuthenticationFailedException: AUTHENTICATE failed` (from `ImapClient.openConnectedStore` -> `IMAPStore.protocolConnect`). - The user sees an opaque "authentication failed" with no hint that the real cause is an account-side IMAP toggle they can flip. Confirmed account-config, not code: the same build signs in fine on an IMAP-enabled account. ## Goal Detect this specific pattern -- **OAuth token obtained successfully, but IMAP `AUTHENTICATE failed`** -- and show a descriptive, actionable message instead of the generic error, e.g.: > "Signed in successfully, but Outlook rejected IMAP access for this account. Make sure IMAP is turned on: Outlook.com -> Settings -> Mail -> Sync email -> 'Let devices and apps use POP/IMAP'." ## Scope / approach - Distinguish **token/consent failure** (fix = re-auth/scopes) from **token-OK-but-IMAP-AUTHENTICATE-rejected** (fix = enable IMAP / provider policy). Only the latter gets the "enable IMAP" prompt. - Map `AuthenticationFailedException` ("AUTHENTICATE failed") at the IMAP-connect step, when a valid OAuth token was just obtained, to a typed error -> provider-aware message + a hint/link to the provider's IMAP-enable setting. - Primarily Outlook/Microsoft, but generalize: Gmail/Yahoo/iCloud can have IMAP-disabled/app-access states too -- provider-specific copy where known, a sensible generic otherwise. - Touch points: account-setup error handling (`AccountSetupViewModel`), the IMAP connect path (`ImapClient.openConnectedStore`), and wherever `AuthenticationFailedException` is caught/surfaced. ## DoD Descriptive message shipped with tests (unit-test the exception->message mapping; instrumented/E2E for the setup-screen error state). PII-free (never log the token/email). Relates to the onboarding epic and the prior Outlook login fixes. Evidence: on-device logcat 2026-07-06.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: JMR-dev/LibreMail#390