We are developing a centralized email notifications service (let's call it EmailService) in .NET Core 3.1. Its purpose is to expose a REST API endpoint (ex. POST /SendMail) which will be available to all other company applications. When some application calls /SendMail, it passes fields such as to, cc, subject and htmlBody in JSON format. EmailService then sends the email from Microsoft account to the given emails with specified content. Think of it like no-reply@company.com notification.
Diagram:
From this description it is quite obvious that EmailService is some kind of background-running deamon process without user interaction. When its REST API endpoint /SendMail is called, it must authenticate against Microsoft server and send an email to the customer.
We are using MailKit for sending email messages and SMTP client/protocol like this:
using (var client = new SmtpClient())
{
client.Connect ("smtp.friends.com", 587, false);
client.Authenticate ("no-reply@company.com", "access_token");
client.Send (message);
client.Disconnect (true);
}
I have the following questions:
- How should I configure "App registration" inside Azure portal for our use case (daemon background process)?
- How should I handle the tokens inside .NET Core application? I assume that there should be some kind of never-expiring(?)
refresh_tokenwhich can be used to retrieve newaccess_tokenwhen it expires? - We should use
https://graph.microsoft.com/SMTP.Sendscope, right? - Since
EmailServicewill be a long-running process it should follow the principle: "configure once, work automatically from then on".
