• Hi,

    I was a previous user of Postman SMTP before migrating to your plugin today due to an alert about Postman’s security vulnerabilities. Postman used to work perfectly for many years. Website is classes.purplefoodie.com.

    1) OAuth2.0
    Today I deleted Postman and installed Post. I used the wizard to configure via OAuth2.0, creating a new ClientID and secret. However, I was unable to pass this stage: “You have configured OAuth 2.0 authentication, but have not received permission to use it. Grant permission with Google.” as Google tells me this plugin isn’t verified. I tried creating a new Client ID from scratch, and am certain I pasted the details correctly, so the issue is elsewhere. Since I was able to connect this Gmail API easily while using Postman, there doesn’t appear to be a problem with my hosting service (HostGator).
    I also coincidentally received an alert an hour after all this that someoene from Salt Lake City just tried to access my gmail account, which I blocked. I am not sure if this was the plugin attempting to connect to Gmail.

    2) Plain
    If I do a regular setup without OAuth2.0, using my gmail credentials, I see in the dashboard that: “Postman is configured. Postman will send mail via SMTP-STARTTLS to smtp.gmail.com:587 using Password (Plain) authentication.”
    However, sending a test email still fails. The error is “Please log in via your web browser and then try again”.

    How do I solve this?

Viewing 2 replies - 1 through 2 (of 2 total)
  • Thread Starter arjwiz

    (@arjwiz)

    Update: I was able to get the first method to work by going into the advanced settings in google and granting access to OAuth2.0. Google alerted me that the plugin will have access to read and manage email, and is an unverified plugin. Is this expected? Is it still recommended to grant access? I thought this was the major vulnerability with the original Postman plugin that you had fixed?

    Hi,

    Welcome back.

    the vulnerability fixed and has nothing to do the OAuth.

    Check my full guide on how to configure it properly with OAuth and no password.
    https://www.cloudways.com/blog/post-smtp-mailer-fork-of-wordpress-postman-smtp-plugin/

    Feel free to ask any question you have.

Viewing 2 replies - 1 through 2 (of 2 total)
  • The topic ‘Test email fails with both OAuth2.0 and Plain’ is closed to new replies.