refactor(auth): remove dead Gmail OAuth code path #40

Merged
JMR-dev merged 1 commits from fix-remove-gmail-oauth into main 2026-07-01 14:41:42 +00:00
JMR-dev commented 2026-07-01 04:44:44 +00:00 (Migrated from github.com)

Closes #39.

What

Gmail authenticates via app password + preconfigured IMAP/SMTP (decision in #9), never OAuth, so the Gmail-OAuth implementation was unreachable dead code. This removes it. Outlook keeps OAuth via AppAuth — only the Gmail-specific path is removed.

  • Delete auth/GmailAuthManager.kt. The shared OAuthResult / FreshToken types (auth/OAuthResult.kt) are kept — the Outlook manager uses them.
  • Remove AuthType.OAUTH_GMAIL from domain/model/Account.kt and its branch in MailConnectionFactory.resolveSecret (the only exhaustive when over AuthType). Also drop the gmailAuthManager injection and the SCOPE_GMAIL constant.
  • Remove gmailOAuthClientId, the GMAIL_OAUTH_CLIENT_ID / GMAIL_OAUTH_REDIRECT_URI BuildConfig fields, and the gmailRedirectScheme val from app/build.gradle.kts.
  • Remove GMAIL_OAUTH_CLIENT_ID from secrets.properties.example.

AppAuth manifest (handled with care)

manifestPlaceholders["appAuthRedirectScheme"] is repointed from the Gmail scheme to the Outlook scheme (org.libremail.outlook), not deleted — AppAuth's bundled manifest requires the placeholder or manifest merge fails. AppAuth's own manifest declares RedirectUriReceiverActivity with an intent-filter for ${appAuthRedirectScheme}, so once the placeholder is Outlook, the app manifest's separate Outlook intent-filter is redundant and was removed. The AppCompat theme override on that activity (the fix for the earlier Theme.AppCompat redirect crash) is preserved via tools:node="merge".

Verified the merged manifest: RedirectUriReceiverActivity ends up with exactly one intent-filter (android:scheme="org.libremail.outlook", from AppAuth via the placeholder) plus the AppCompat theme, and no org.libremail.oauth / googleusercontent leftovers.

No schema change

authType persists as the enum .name in a TEXT column and toDomain already falls back to PASSWORD_IMAP via runCatching, so removing a constant needs no Room schema change or migration, and the remaining values round-trip.

Testing

Fast CI gate all green (JDK 21):

  • :app:assembleDebug ✅ (proves the AppAuth manifest merge still works)
  • :app:testDebugUnitTest ✅
  • :app:lintDebug ✅
  • ktlintCheck + detekt ✅

Grep confirms no GmailAuthManager / OAUTH_GMAIL / GMAIL_OAUTH_* / SCOPE_GMAIL / gmailRedirectScheme references remain in code/build config (README Gmail-OAuth text is intentionally left to the README-owning unit, #20 / #31).

⚠️ No emulator in this environment, so a real Outlook login end-to-end is a manual/CI check I could not perform. The merged-manifest verification above is the closest local proxy; a live Outlook sign-in should be confirmed in CI / on a device before merge, since this area has been fragile before.

🤖 Generated with Claude Code

Closes #39. ## What Gmail authenticates via **app password + preconfigured IMAP/SMTP** (decision in #9), never OAuth, so the Gmail-OAuth implementation was unreachable dead code. This removes it. **Outlook keeps OAuth via AppAuth — only the Gmail-specific path is removed.** - Delete `auth/GmailAuthManager.kt`. The shared `OAuthResult` / `FreshToken` types (`auth/OAuthResult.kt`) are **kept** — the Outlook manager uses them. - Remove `AuthType.OAUTH_GMAIL` from `domain/model/Account.kt` and its branch in `MailConnectionFactory.resolveSecret` (the only exhaustive `when` over `AuthType`). Also drop the `gmailAuthManager` injection and the `SCOPE_GMAIL` constant. - Remove `gmailOAuthClientId`, the `GMAIL_OAUTH_CLIENT_ID` / `GMAIL_OAUTH_REDIRECT_URI` BuildConfig fields, and the `gmailRedirectScheme` val from `app/build.gradle.kts`. - Remove `GMAIL_OAUTH_CLIENT_ID` from `secrets.properties.example`. ## AppAuth manifest (handled with care) `manifestPlaceholders["appAuthRedirectScheme"]` is **repointed** from the Gmail scheme to the Outlook scheme (`org.libremail.outlook`), not deleted — AppAuth's bundled manifest requires the placeholder or manifest merge fails. AppAuth's own manifest declares `RedirectUriReceiverActivity` with an intent-filter for `${appAuthRedirectScheme}`, so once the placeholder is Outlook, the app manifest's separate Outlook intent-filter is redundant and was removed. The AppCompat theme override on that activity (the fix for the earlier `Theme.AppCompat` redirect crash) is **preserved** via `tools:node="merge"`. Verified the **merged** manifest: `RedirectUriReceiverActivity` ends up with exactly one intent-filter (`android:scheme="org.libremail.outlook"`, from AppAuth via the placeholder) plus the AppCompat theme, and no `org.libremail.oauth` / `googleusercontent` leftovers. ## No schema change `authType` persists as the enum `.name` in a TEXT column and `toDomain` already falls back to `PASSWORD_IMAP` via `runCatching`, so removing a constant needs no Room schema change or migration, and the remaining values round-trip. ## Testing Fast CI gate all green (JDK 21): - `:app:assembleDebug` ✅ (proves the AppAuth manifest merge still works) - `:app:testDebugUnitTest` ✅ - `:app:lintDebug` ✅ - `ktlintCheck` + `detekt` ✅ Grep confirms no `GmailAuthManager` / `OAUTH_GMAIL` / `GMAIL_OAUTH_*` / `SCOPE_GMAIL` / `gmailRedirectScheme` references remain in code/build config (README Gmail-OAuth text is intentionally left to the README-owning unit, #20 / #31). ⚠️ **No emulator in this environment**, so a **real Outlook login end-to-end is a manual/CI check I could not perform.** The merged-manifest verification above is the closest local proxy; a live Outlook sign-in should be confirmed in CI / on a device before merge, since this area has been fragile before. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign in to join this conversation.