4 Commits
Author SHA1 Message Date
Matthieu MALVACHE 70c5d1a839 fix: v1.7.2 - SSO sessions survive reloads with external identity providers
Request offline_access so the IdP issues a refresh token, and add an
OAUTH_SCOPES override for providers that reject or extend the default
list. Closes #104
2026-09-19 17:35:23 +02:00
Matthieu MALVACHE 20487d56f5 fix: send id_token_hint and client_id on the OIDC end-session redirect
Keycloak rejects an end-session request that carries
post_logout_redirect_uri without id_token_hint or client_id. Store the
id_token from the token exchange in an httpOnly cookie, pass it as
id_token_hint together with client_id on logout, and clear it with the
refresh token.

Fixes #102
2026-08-28 02:21:16 +02:00
Matthieu MALVACHE 384b757815 feat: v1.4.0 - folder management, mail multi-selection, bug fixes
New features:
- Folder management with context menu, inline editing, drag-and-drop (#44)
- Mail multi-selection with batch move/delete and shift-click (#43)

Bug fixes:
- Health endpoint false-positive restarts (#41, thanks @wrenix and @ClemaX)
- Identity deletion failing (#42, thanks @freddij)
- Inline CID images, email list flicker, dark mode clipboard tint

Feature requests from @dlecourtaltimafr (#43, #44).
Contact pagination fix contributed by @capitanroy (#46).

Dependencies: Next.js 16.2.1, Tailwind 4.2.2, Zustand 5.0.12,
flatted CVE fix (GHSA-rf6f-7fwh-wjgh).
2026-03-23 15:24:46 +01:00
Matthieu MALVACHE ec06b0c494 feat: add OAuth2/OIDC with PKCE for SSO login
Add opt-in SSO authentication alongside Basic Auth. OAuth endpoints are
auto-discovered via .well-known, with support for external IdPs
(Keycloak, Authentik) via configurable OAUTH_ISSUER_URL. Sessions
persist through httpOnly refresh token cookies with automatic renewal.
2026-02-25 23:41:37 +01:00