Gmail will soon require OAUTH credentials - "node-red-node-email" in jeopardy!
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 25/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Da chiarire
- Stato di attività
- Ferma
- Stack tecnologico
- javascript
- Ambito
- authentication
Direzione di ricerca
La issue indica il punto di ingresso node-red-node-email, ma non specifica file o test. Inizia tracciando il suo percorso di autenticazione Gmail IMAP e confrontandolo con la gestione OAuth2 esistente per Exchange e Office365; il lavoro è completo quando Gmail può autenticarsi tramite OAuth2 dopo la disabilitazione dell’accesso basato su password.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Which node are you reporting an issue on?
node-red-node-email
This node will be incapable of using Gmail within the next few months unless modified to connect with OAUTH2.0
Today I received a Google announcement that reads as follows:
Starting September 30, 2024, Google Workspace accounts will only allow access to apps using OAuth. Password-based access (with the exception of App Passwords) will no longer be supported. POP and IMAP are NOT going away and can still be enabled with apps that connect using OAuth.
Dear Administrator,We’re writing to remind you that as we previously shared in this blog post and in an email sent in mid-January, we’ll be turning off access to less secure apps (LSA) — non-Google apps that can access Google accounts with only a username and password (basic authentication) — starting June 15, 2024.
What do you need to know?
Access through basic authentication makes accounts more vulnerable to hijacking attempts. Moving forward, only apps that support a more modern and secure access method called OAuth will be able to access Google Workspace accounts.Access to LSAs will be turned off in two stages:
Beginning June 15, 2024 - The LSA settings will be removed from the Admin console and can no longer be changed. Enabled users can connect after that time, but disabled users will no longer be able to access LSAs. This includes all third-party apps that require password-only access to Gmail, Google Calendar, Contacts via protocols such as CalDAV, CardDAV, IMAP, SMTP, and POP.
The IMAP enable/disable settings will be removed from users’ Gmail settings.
If you’ve been using LSAs prior to this date, you can continue using them until September 30, 2024.
Beginning September 30, 2024 - Access to LSAs will be turned off for all Google Workspace accounts. CalDAV, CardDAV, IMAP, and POP will no longer work when signing in with just a password — you will need to login with a more secure type of access called OAuth.
What do you need to do?
In order for your end users to continue using these types of apps with their Google Workspace accounts, they must switch to a more secure type of access called OAuth (a list of affected users is attached). This authentication method allows apps to access accounts with a digital key instead of requiring a user to reveal their username and password. We recommend that you share the user instructions (in this PDF file) with individuals in your organization to help them make the necessary changes. Alternatively, if your organization is using custom tools, you can ask the developer of the tool to update it to use OAuth. Developer instructions are also in this PDF file.MDM configuration
If your organization uses a mobile device management (MDM) provider to configure IMAP, CalDAV CardDAV, or POP profiles, these services will be phased out according to the timeline below:Beginning June 15, 2024 - MDM push of password based IMAP, CalDAV, CardDAV, and POP will no longer work for customers who try to connect for the first time. If you use Google MDM, you will not be able to turn on "Custom Push Configuration" settings for CalDAV and CardDAV.
Beginning September 30, 2024 - MDM push of password based IMAP, CalDAV, CardDAV, and POP will no longer work for existing users. Admins will need to push a Google Account using their MDM provider, which will re-add their Google accounts to iOS devices using OAuth. If you use Google MDM, “Custom push configuration-CalDAV” and “Custom push configuration-CardDAV” (more details about the settings here) will stop being effective.
Other less secure apps
For any other LSA, ask the developer of the app you are using to start supporting OAuth.
Scanners and other devicesFor scanners or other devices using simple mail transfer protocol (SMTP) or LSAs to send emails, configure to use OAuth, use an alternative method, or configure an App Password for use with the device. If you replace your device, look for one that sends email using OAuth.
Since the node description details how to use OAUTH2.0 for Exchange and Office365, it seems all that should be needed is to check how this code can be used for Gmail IMAP. The announcement contained a link to developer instructions here
What are the steps to reproduce?
N/A
What happens?
N/A
What do you expect to happen?
Hopefully the node will be modified to use OAUTH2.0 with Gmail
Please tell us about your environment:
- Node-RED version: V3.0.2
- node.js version: v18.19.0
- npm version: v10.2.3
- Platform/OS: "Alpine Linux v3.19"
- Browser: Iron Version 122.0.6200.0 (Official Build) (64-bit)
- Lingua principale
- JavaScript
- Stelle
- 1.1k
- Fork
- 610
- Merge medio
- 18h 41m
- PR unite (30g)
- 4
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di node-red/node-red-nodes
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 58/100
node-red/node-red-nodes#1142 · 11 commenti ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
node-red/node-red-nodes#1141 · 15 commenti ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
node-red/node-red-nodes#1130 · 4 commenti ·
-
dependencies
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
node-red/node-red-nodes#1121 · 5 commenti ·
-
upstream
Difficoltà 3/5 1-2 giorni Idoneità per principianti 50/100
node-red/node-red-nodes#1116 · 5 commenti ·
Tutte le issue di node-red/node-red-nodes
Issue simili
-
bug user-priority/P2
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
I maintainer di solito rispondono entro 1 giorno
-
bug confirmed perf
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
videojs/video.js#9400 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
agent/scanner bug hive/hosted-available-lke648397-260827-5n31
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
rescript-lang/rescript#8765 ·
I maintainer di solito rispondono entro 1 giorno
-
feedback simulation workshop
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
githubnext/gh-aw-workshop#4417 ·
I maintainer di solito rispondono entro 1 giorno