RELEASE 0.5.1

My UNA Mail Doctor 0.5.1

Microsoft OAuth2 App Only

Version 0.5.1 adds unattended Microsoft Exchange Online IMAP authentication using the OAuth 2.0 client-credentials grant.

  • Adds Microsoft OAuth2 - App Only as a third mailbox authentication mode.
  • Preserves the existing Microsoft OAuth2 Device Code workflow and stored refresh tokens.
  • Encrypts the Microsoft application client secret in the existing Sodium-backed credential vault.
  • Requests access tokens only when needed and never stores them.
  • Binds stored credentials to authentication mode, tenant ID, application client ID and mailbox username.
  • Clears incompatible credential material when the authentication mode or Microsoft identity changes.
  • Uses the existing read-only Exchange IMAP XOAUTH2 transport.
  • Keeps Exchange OAuth restricted to outlook.office365.com:993 with SSL/TLS certificate validation.

Microsoft Entra and Exchange Online provisioning remains an administrator responsibility. Mail Doctor does not create applications, grant tenant consent, create Exchange service principals or assign mailbox permissions.

Email Health accessibility

  • Adds an Email Health text-size control with 80% through 125% scaling.
  • Saves the selected size in the administrator's browser.
  • Leaves UNA Studio navigation and other module pages unchanged.

Upgrade

The 0.5.0_0.5.1 UNA updater replaces the OAuth, mailbox, Email Health Studio, module service, database service and version-metadata files. The module and database service copies close the Email Health runtime dependency chain for 0.5.0 installations that predate those methods.

No database schema changes are required and the updater executes no SQL. Existing mailbox configuration, encrypted credentials, bounce evidence, suppression history and Email Health data are preserved.

Release safety

Release requires:

  • PHP syntax validation for every module PHP file;
  • standalone App-Only token and mailbox tests;
  • Device Code OAuth regression testing;
  • live App-Only token acquisition and read-only IMAP authentication;
  • Test, Peek and DSN Scan validation;
  • credential-preservation and identity-invalidation validation;
  • a secret and token leakage scan;
  • Studio Bounce Mailbox validation;
  • Studio Downloaded product-information popup validation.