smtp.OAuth

An OAuth credential authenticates to SMTP with an access token instead of a password, through XOAUTH2.

Usage

Source

smtp.OAuth(
    username,
    credential,
    scope=None,
)

connect() gets one token from credential, and sends it with username through smtplib.SMTP.auth. It sends no token to a server that does not offer AUTH XOAUTH2, and raises AuthenticationError instead.

Epistole derives the scope from the issuer. A graph.ClientSecret or graph.Certificate requests https://outlook.office365.com/.default. A graph.ManagedIdentity requests the resource https://outlook.office365.com instead, because msal’s managed identity client takes no scope. A Gmail value requests https://mail.google.com/, which Gmail requires though it also grants reading and deleting every message. Epistole cannot read the issuer of a TokenCredential, so it takes scope instead. See ADR-0011.

Attributes

username: str

The mailbox the token belongs to, sent as XOAUTH2’s user. smtplib encodes it as ASCII, so connect() raises UnicodeEncodeError for any other character.

credential: (
    graph.ClientSecret
    | graph.Certificate
    | graph.ManagedIdentity
    | gmail.ServiceAccount
    | gmail.AuthorizedUser
    | TokenCredential
)

A value from epistole.graph or epistole.gmail, or a TokenCredential.

scope: str | None
The scope a TokenCredential’s get_token receives. It is required with a TokenCredential, and OAuth raises TypeError for it with any other credential.

Methods

Name Description
__post_init__() Raise TypeError for a credential of another type, for a TokenCredential without scope, or for any other credential with it (ADR-0011).

__post_init__()

Raise TypeError for a credential of another type, for a TokenCredential without scope, or for any other credential with it (ADR-0011).

Usage

Source

__post_init__()