feat(msmail): sync shared and delegated mailboxes over Microsoft Graph - #1
Merged
Merged
Conversation
`add-o365 <mailbox> --graph --as <user>` signs in as the user, verifies the ID token is that user's, requests Mail.Read.Shared, and saves the token under the mailbox's address. The source records the user in its sync config, and sync points the Graph mail client at /users/<mailbox> instead of /me, so the same per-folder delta walk and $value MIME download read the shared mailbox. delete-staged refuses these accounts for now: deletion would need Mail.ReadWrite.Shared, and the own-mailbox client must not act on them. TJC-3129 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
arcaputo3
force-pushed
the
tjc-3129-msgvault-graph-shared-mailbox
branch
from
October 5, 2026 19:00
fa70bb1 to
b6d254d
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Graph mail sync (
add-o365 --graph) reads only the signed-in user's own mailbox: every request goes to/me, the token asks only forMail.Read, andadd-o365requires the account address to match the signed-in identity. A shared mailbox, or another user's mailbox the user has delegated access to, cannot be archived.Behavior
--assigns in as the named user and verifies the ID token is theirs; signing in as the mailbox itself is refused. The grant addsMail.Read.Shared.tokens/msmail_<mailbox>.json, and the source'ssync_configrecords{"signed_in_as": "<user>"}./users/<mailbox>/…for folders, delta walks and$valuedownloads. Delta links Graph returns keep that path, so incremental sync is unchanged.--as(or with--asnaming the mailbox) turns the account back into an own-mailbox account.delete-stagedrefuses shared-mailbox accounts for now: deletion would needMail.ReadWrite.Shared, and the own-mailbox client must never act on them.--aswithout--graphis rejected; IMAP sync is unchanged.Review boundaries
internal/msmail/client.go: mailbox root (/meor/users/<address>);DeltaStartURLbecomes a method.internal/microsoft/graph_oauth.go:GraphMailSharedScopes,NewGraphMailSharedManager,AuthorizeAs(Authorizedelegates to it).cmd/msgvault/cmd:--asflag,msmailSourceConfig, sync wiring, deletion guard.Linear: TJC-3129
🤖 Generated with Claude Code