feat(api): switch OAuth scope to gmail.modify

Enable archive, label, and draft CLI operations after users re-consent; keep the web UI read-only.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
2026-09-22 10:09:25 +07:00
co-authored by Cursor
parent 39eb1bce2f
commit bac8edfb6c
2 changed files with 4 additions and 3 deletions
+1 -1
View File
@@ -17,7 +17,7 @@ export const GOOGLE_REDIRECT_URI =
process.env.GOOGLE_REDIRECT_URI || "http://localhost:5173/callback"; process.env.GOOGLE_REDIRECT_URI || "http://localhost:5173/callback";
export const SESSION_SECRET = process.env.SESSION_SECRET || ""; export const SESSION_SECRET = process.env.SESSION_SECRET || "";
export const GMAIL_SCOPE = "https://www.googleapis.com/auth/gmail.readonly"; export const GMAIL_SCOPE = "https://www.googleapis.com/auth/gmail.modify";
export const OAUTH_SCOPES = [ export const OAUTH_SCOPES = [
GMAIL_SCOPE, GMAIL_SCOPE,
"openid", "openid",
+3 -2
View File
@@ -17,8 +17,9 @@ export default function Login() {
<div className="card-body gap-4"> <div className="card-body gap-4">
<h1 className="card-title text-2xl">Gmail Reader</h1> <h1 className="card-title text-2xl">Gmail Reader</h1>
<p className="text-sm opacity-70"> <p className="text-sm opacity-70">
Sign in with Google to list, search, and read mail. Access is Sign in with Google to list, search, and read mail in this UI. The
read-only. UI is read-only; the CLI can archive, label, and create drafts
after you grant <code>gmail.modify</code>.
</p> </p>
{error ? ( {error ? (
<div role="alert" className="alert alert-error text-sm"> <div role="alert" className="alert alert-error text-sm">