Files
korax-public/korax-gmail-login-discontinuation.md
2026-07-04 14:00:48 +03:00

40 lines
2.3 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Discontinuing Native Gmail Login in Korax
**Date:** July 2026
## Summary
Korax will no longer support native "Sign in with Google" / Gmail OAuth login. Users who want to use a Gmail account with Korax will need to connect it via IMAP/SMTP with a Google App Password instead.
## Why
Korax's Gmail integration relies on the `gmail.modify` OAuth scope to read, send, and manage messages on the user's behalf. Google classifies `gmail.modify` as a **restricted scope**.
As of 2026, any app requesting a restricted scope must complete an annual **CASA (Cloud Application Security Assessment) at AL1** (formerly "Tier 2"). This assessment:
- Requires either a paid authorized-lab security scan (roughly $500$4,500/year) or a paid commercial self-scan — the previous free, fully self-service scanning option has been discontinued by Google.
- Must be renewed every year, for as long as the app requests the scope.
- Takes 26 weeks to complete, with no guarantee of first-pass approval.
For an independent app like Korax, this recurring cost and process isn't sustainable to keep native Gmail OAuth alive.
## What this means for users
- **New setup:** Gmail accounts can still be connected to Korax, but via IMAP/SMTP using a [Google App Password](https://myaccount.google.com/apppasswords) instead of the "Sign in with Google" button.
- **Requirement:** App Passwords require Google 2-Step Verification (2FA) to be enabled on the account.
- **Existing users:** Korax is still in open beta with no existing users on native Gmail login, so there is no migration or cutover date to manage — this change applies from the start.
- **Other providers:** Non-Gmail accounts (any standard IMAP/SMTP provider) are unaffected.
## Alternatives considered
| Option | Why not chosen |
|---|---|
| Authorized lab CASA scan | Ongoing annual cost not viable for a one-time-purchase indie app |
| Commercial self-scan | Still a recurring paid cost; free self-scan path was removed by Google |
| Narrower OAuth scopes (`gmail.send`, `gmail.labels`) | Don't cover reading/decrypting mail content, which is core to Korax's PGP functionality |
| Drop Gmail support entirely | Not chosen — IMAP/App Password path preserves functionality without the compliance overhead |
## Questions
If you run into issues setting up Gmail via App Password, use the built-in bug reporting feature in the app.