User tests: Successful: Unsuccessful:
This PR adds SMTP OAuth2 support in Global Configuration for outgoing mail on 6.2-dev.
Implemented changes:
smtpoauth2com_configcommon and tenant-specificThe previous provider-specific legacy wrappers (m365auth, m365callback, m365checktoken) were removed/adjusted because there was no real historical route contract to preserve in core.
com_config).com_config.oauth2_state) using hash_equals.core.admin check) before writing config.smtpoauth2.This PR description now documents:
AI assistance was used to help draft/refine parts of implementation and PR text.
All code, behavior, and security assumptions were manually reviewed and tested by the author before submission.
| Status | New | ⇒ | Pending |
| Category | ⇒ | Administration com_config Language & Strings Libraries |
Please fill out the PR form correctly, especially the AI disclaimer. Also please format your text correctly. Right now the description is hardly readable.
Okay, done. Code changes will be pulled soon
| Labels |
Added:
Language Change
PR-6.2-dev
|
||
Addressed in latest commit; thread outdated.
| Category | Administration com_config Language & Strings Libraries | ⇒ | Administration com_config Language & Strings Layout Libraries |
Added layout file for oauth2token field
All review points addressed, CI green, ready for merge.
This pull request has conflicts, please resolve those before we can evaluate the pull request.
| Labels |
Added:
Conflicting Files
|
||
| Labels |
Removed:
Conflicting Files
|
||
System tests failed broadly across unrelated areas (Cypress, 36/156). Re-running CI as likely infra/flaky failure.
numerous codestyle issues with the xml have been marked as resolved but they have not been
Fixed — added COM_CONFIG_MAIL_OAUTH2_BUTTON_CHECK, _BUTTON_ISSUE, _BUTTON_REISSUE, COM_CONFIG_OAUTH2_TENANT_MODE_COMMON and _TENANT.
numerous codestyle issues with the xml have been marked as resolved but they have not been
Fixed — the closing > on oauth2_provider, oauth2_tenant_mode and oauth2_smtp_secure fields now uses 3-tab indentation consistent with the surrounding code.
@Hackwar @brianteeman All review findings have been addressed in the latest commits. Could you please take another look?
Summary of changes since last review:
Added missing language strings (BUTTON_CHECK, BUTTON_ISSUE, BUTTON_REISSUE, OAUTH2_TENANT_MODE_COMMON/TENANT)
Reverted accidental re-sorting of existing language keys; restored accidentally deleted WEBSERVICES_CORS_OFF_* strings
Fixed XML closing > indentation (3 tabs) on the 3 new list fields
Replaced hardcoded Uri::root().'administrator/' with Uri::base() in ConfigHelper
Removed unused $params variable and replaced Factory::getApplication() with $this->app
All CI checks pass (Windows integration test flakiness re-triggered via empty commit)
This pull request has conflicts, please resolve those before we can evaluate the pull request.
| Labels |
Added:
Conflicting Files
|
||
| Labels |
Removed:
Conflicting Files
|
||
Hi, i just stumbled across this one. Wondering what the status is?
Hi, i just stumbled across this one. Wondering what the status is?
Needs testing
@dawe78 Do you have some instructions on setting this up correctly with an office 365 account? i tried setting it up i created the app, created a secret chose scope https://outlook.office.com/SMTP.Send, Oauth tenant mode is set to tenant.
in 365 what permissions does it need?
I added both Graph SMTP.Send and Office 365 Online Mail.Send
When i use the error resolver it checks logs and it seems authentication was successful.

But in backend i still get this error: Failed to acquire OAuth2 refresh token.
This notification is after i succesfully granted permission and am being sent back to joomla.
I'm on vacation right now, will add testing instructions and settings for mailbox in August asap
Just checked: in my app, permissions are set for
Mail.ReadWrite
offline_access
SMTP.Send
User.Read
I think, all these permissions are required, but I will check in August
I'm on vacation right now, will add testing instructions and settings for mailbox in August asap
Have a great vacation! :D
I'm on vacation right now, will add testing instructions and settings for mailbox in August asap
Have a great vacation! 😄
It would be great if we can have some tests soon, Joomla 6.2 Beta is coming soon ...
Hi,
I was wondering what is the best way to describe oauth2 config for preset providers. I could add a xml field of type note for each predefined provider and display provider field depending on which provider was selected. In this note field provider-specific config could be described including required permissions. But does this match to joomla coding rules?
@brianteeman is it an option?
That seems a good option to me - but not my decision
@dawe78 I will create a pr against your PR and also a variant against the main joomla repo so tests and prebuilts will be generated.
I will reduce/remove the vendor options and make it more generic, simply because we don't want a new "vendor specific solution" in core again. I'm a bit surprised nobody wrote this here yet.
If the new pr fits the needs you can accept it in your repo and it can go into joomla core afterwards, I hope this is ok for you.
If the new pr fits the needs you can accept it in your repo and it can go into joomla core afterwards, I hope this is ok for you.
Yes, lets do it. I wanted to make configuration for main providers more easy, but generic form is okay for me as well.
| Status | Pending | ⇒ | Closed |
| Closed_Date | 0000-00-00 00:00:00 | ⇒ | 2026-08-24 08:34:13 |
| Closed_By | ⇒ | HLeithner |
Please fill out the PR form correctly, especially the AI disclaimer. Also please format your text correctly. Right now the description is hardly readable.
Why do you have custom routes for the different providers as legacy fallback, when they never existed in the first place? Your docblocks are incomplete. How do those callbacks against the admin com_config work, when the calling provider is not an authorised user? Seems to me as if that would fail. This needs at least documentation on how to use and test in this PR.