Diagnosed on-device 2026-07-06: a personal outlook.com account with IMAP disabled (the "Let devices and apps use POP/IMAP" toggle is OFF by default on new accounts) produces a confusing onboarding failure:
The IMAP AUTHENTICATE XOAUTH2 step against outlook.office365.com:993 is then rejected by the server with a generic jakarta.mail.AuthenticationFailedException: AUTHENTICATE failed (from ImapClient.openConnectedStore -> IMAPStore.protocolConnect).
The user sees an opaque "authentication failed" with no hint that the real cause is an account-side IMAP toggle they can flip.
Confirmed account-config, not code: the same build signs in fine on an IMAP-enabled account.
Goal
Detect this specific pattern -- OAuth token obtained successfully, but IMAP AUTHENTICATE failed -- and show a descriptive, actionable message instead of the generic error, e.g.:
"Signed in successfully, but Outlook rejected IMAP access for this account. Make sure IMAP is turned on: Outlook.com -> Settings -> Mail -> Sync email -> 'Let devices and apps use POP/IMAP'."
Scope / approach
Distinguish token/consent failure (fix = re-auth/scopes) from token-OK-but-IMAP-AUTHENTICATE-rejected (fix = enable IMAP / provider policy). Only the latter gets the "enable IMAP" prompt.
Map AuthenticationFailedException ("AUTHENTICATE failed") at the IMAP-connect step, when a valid OAuth token was just obtained, to a typed error -> provider-aware message + a hint/link to the provider's IMAP-enable setting.
Primarily Outlook/Microsoft, but generalize: Gmail/Yahoo/iCloud can have IMAP-disabled/app-access states too -- provider-specific copy where known, a sensible generic otherwise.
Touch points: account-setup error handling (AccountSetupViewModel), the IMAP connect path (ImapClient.openConnectedStore), and wherever AuthenticationFailedException is caught/surfaced.
DoD
Descriptive message shipped with tests (unit-test the exception->message mapping; instrumented/E2E for the setup-screen error state). PII-free (never log the token/email). Relates to the onboarding epic and the prior Outlook login fixes. Evidence: on-device logcat 2026-07-06.
## Context
Diagnosed on-device 2026-07-06: a **personal `outlook.com` account with IMAP disabled** (the "Let devices and apps use POP/IMAP" toggle is OFF by default on new accounts) produces a confusing onboarding failure:
- OAuth consent + token exchange **succeed** (valid XOAUTH2 token, no AADSTS error).
- The IMAP `AUTHENTICATE XOAUTH2` step against `outlook.office365.com:993` is then **rejected** by the server with a generic `jakarta.mail.AuthenticationFailedException: AUTHENTICATE failed` (from `ImapClient.openConnectedStore` -> `IMAPStore.protocolConnect`).
- The user sees an opaque "authentication failed" with no hint that the real cause is an account-side IMAP toggle they can flip.
Confirmed account-config, not code: the same build signs in fine on an IMAP-enabled account.
## Goal
Detect this specific pattern -- **OAuth token obtained successfully, but IMAP `AUTHENTICATE failed`** -- and show a descriptive, actionable message instead of the generic error, e.g.:
> "Signed in successfully, but Outlook rejected IMAP access for this account. Make sure IMAP is turned on: Outlook.com -> Settings -> Mail -> Sync email -> 'Let devices and apps use POP/IMAP'."
## Scope / approach
- Distinguish **token/consent failure** (fix = re-auth/scopes) from **token-OK-but-IMAP-AUTHENTICATE-rejected** (fix = enable IMAP / provider policy). Only the latter gets the "enable IMAP" prompt.
- Map `AuthenticationFailedException` ("AUTHENTICATE failed") at the IMAP-connect step, when a valid OAuth token was just obtained, to a typed error -> provider-aware message + a hint/link to the provider's IMAP-enable setting.
- Primarily Outlook/Microsoft, but generalize: Gmail/Yahoo/iCloud can have IMAP-disabled/app-access states too -- provider-specific copy where known, a sensible generic otherwise.
- Touch points: account-setup error handling (`AccountSetupViewModel`), the IMAP connect path (`ImapClient.openConnectedStore`), and wherever `AuthenticationFailedException` is caught/surfaced.
## DoD
Descriptive message shipped with tests (unit-test the exception->message mapping; instrumented/E2E for the setup-screen error state). PII-free (never log the token/email). Relates to the onboarding epic and the prior Outlook login fixes. Evidence: on-device logcat 2026-07-06.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Context
Diagnosed on-device 2026-07-06: a personal
outlook.comaccount with IMAP disabled (the "Let devices and apps use POP/IMAP" toggle is OFF by default on new accounts) produces a confusing onboarding failure:AUTHENTICATE XOAUTH2step againstoutlook.office365.com:993is then rejected by the server with a genericjakarta.mail.AuthenticationFailedException: AUTHENTICATE failed(fromImapClient.openConnectedStore->IMAPStore.protocolConnect).Confirmed account-config, not code: the same build signs in fine on an IMAP-enabled account.
Goal
Detect this specific pattern -- OAuth token obtained successfully, but IMAP
AUTHENTICATE failed-- and show a descriptive, actionable message instead of the generic error, e.g.:Scope / approach
AuthenticationFailedException("AUTHENTICATE failed") at the IMAP-connect step, when a valid OAuth token was just obtained, to a typed error -> provider-aware message + a hint/link to the provider's IMAP-enable setting.AccountSetupViewModel), the IMAP connect path (ImapClient.openConnectedStore), and whereverAuthenticationFailedExceptionis caught/surfaced.DoD
Descriptive message shipped with tests (unit-test the exception->message mapping; instrumented/E2E for the setup-screen error state). PII-free (never log the token/email). Relates to the onboarding epic and the prior Outlook login fixes. Evidence: on-device logcat 2026-07-06.