Commit Graph
271 Commits
Author SHA1 Message Date
Jason Ross 228ea83288 Merge main into feat-162-advanced-settings-hierarchy 2026-07-02 19:56:22 -05:00
Jason Ross 0ef26da933 Merge pull request #173 from JMR-dev/feat-150-battery-deeplink
feat(onboarding): deep-link battery step nearer the per-app background-activity screen (best-effort)
2026-07-02 19:55:54 -05:00
Jason Ross 73f69c5326 Merge main into feat-150-battery-deeplink 2026-07-02 19:44:32 -05:00
Jason Ross aff7133bbb Merge main into feat-162-advanced-settings-hierarchy 2026-07-02 19:44:31 -05:00
Jason Ross e22e6c14dd Merge pull request #175 from JMR-dev/feat-163-default-account
feat(settings): let the user set a default mail account
2026-07-02 19:44:01 -05:00
Jason Ross d6100462a7 Merge main into feat-163-default-account 2026-07-02 19:33:16 -05:00
Jason Ross 56a6776f67 Merge main into feat-162-advanced-settings-hierarchy 2026-07-02 19:33:15 -05:00
Jason Ross 96fb91ce8c Merge main into feat-150-battery-deeplink 2026-07-02 19:33:13 -05:00
Jason Ross 7d92aa6feb Merge pull request #181 from JMR-dev/fix-157-notification-open-message
fix(notifications): reliably open the tapped message from a new-mail notification
2026-07-02 19:32:42 -05:00
Jason Ross 52d99d2bf9 Merge main into feat-150-battery-deeplink 2026-07-02 19:21:15 -05:00
Jason Ross 41d06c5c77 Merge main into fix-157-notification-open-message 2026-07-02 19:21:13 -05:00
Jason Ross 5eebe2e2b1 Merge main into feat-162-advanced-settings-hierarchy 2026-07-02 19:21:12 -05:00
Jason Ross d4412ce5f3 Merge main into feat-163-default-account 2026-07-02 19:21:11 -05:00
Jason Ross 66534d6a0e Merge pull request #183 from JMR-dev/feat-159-report-required-email
feat(reporting): require a reply-to email and a 200-char minimum on problem reports
2026-07-02 19:20:14 -05:00
Jason Ross fce2ae981c Merge main into feat-163-default-account 2026-07-02 19:09:04 -05:00
Jason Ross e475c30f0a Merge main into feat-162-advanced-settings-hierarchy 2026-07-02 19:09:03 -05:00
Jason Ross 68e4e2471c Merge main into fix-157-notification-open-message 2026-07-02 19:09:02 -05:00
Jason Ross 2b38d06c6d Merge main into feat-159-report-required-email 2026-07-02 19:09:01 -05:00
Jason Ross 036df6b2fe Merge main into feat-150-battery-deeplink 2026-07-02 19:09:00 -05:00
Jason Ross 9e2b4bf49f Merge pull request #180 from JMR-dev/feat-153-icloud-onboarding-help
feat(accountsetup): add iCloud app-password/2FA help in onboarding
2026-07-02 19:08:34 -05:00
Jason Ross 6cf15c5af5 Merge branch 'main' into feat-153-icloud-onboarding-help 2026-07-02 18:57:57 -05:00
JMR-devandClaude Opus 4.8 2151bc6d7c feat(reporting): require a reply-to email and a 200-char minimum on problem reports
Adds friction to the "Report a Problem" form: a required email field (basic
local-part@domain.tld validation), a required consent notice about being
contacted at that address, and a 200-character minimum on the comment field
with a live "x/200" counter that turns red (with the field outline) until the
threshold is met. Submit stays disabled until both the comment and email are
valid, mirroring and extending the existing SUBMITTING gate. The email rides
along on DebugReport (userEmail) so it round-trips through the storage JSON
and the exact payload that's previewed, copied, saved, and POSTed. The new
ViewModel-level guard on submit() also fully integrates with the #161
success-confirmation dialog: invalid attempts never reach SUBMITTING/SUCCEEDED,
so the dialog flow is unaffected.

Closes #159

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 18:52:21 -05:00
Jason Ross 4b61c5f875 Merge branch 'main' into feat-150-battery-deeplink 2026-07-02 18:48:12 -05:00
Jason RossandClaude Opus 4.8 3c2bd0b138 ci: run autoupdate in the CI_CD environment so it can read AUTOUPDATE_TOKEN (#182)
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 18:45:39 -05:00
JMR-devandClaude Opus 4.8 69be8a5c69 fix(notifications): reliably open the tapped message from a new-mail notification
MainActivity.onCreate only parsed the incoming intent (pendingCompose /
pendingOpenMessageId) when savedInstanceState == null, on the assumption
that a non-null value always means a config-change recreation (e.g.
rotation), where Android redelivers the same, already-handled intent and
re-parsing would just navigate to a duplicate destination.

But Android also passes a restored, non-null savedInstanceState when it
recreates the activity after the process was killed in the background and
is then relaunched by tapping a notification. There, intent is the new
tap, not a replay, but the guard swallowed it exactly like a rotation, so
pendingOpenMessageId was never set and the tap silently landed wherever
the restored back stack was (typically the mailbox) instead of the
message. That's the #157 regression from the original fix in a6ec00d
(#56). pendingCompose (mailto:/share intents) went through the identical
guard and had the same latent bug.

Replace the savedInstanceState check with IntentHandledMarker, which
marks the Intent instance itself once parsed. A config-change recreation
redelivers that same marked instance, so it's correctly skipped; a
genuinely new intent -- warm via onNewIntent or cold via onCreate after a
process-death relaunch -- is never marked yet, so it's always parsed.
This dedupes on the intent's own identity instead of an unreliable proxy
for it, so it can't confuse the two recreation paths.

Adds IntentHandledMarkerTest covering the marking contract: unhandled on
first look, recognized as handled on a redelivered instance, and still
unhandled on a freshly constructed (but content-equal) instance -- the
process-death case.

Closes #157

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 18:45:18 -05:00
Jason Ross 6490e5e461 Merge branch 'main' into feat-150-battery-deeplink 2026-07-02 18:37:23 -05:00
Jason RossClaude Opus 4.8github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
5f1e611886 feat(reporting): show a clear confirmation dialog after submitting a problem report (#171)
Replace the small inline "Report sent. Thank you!" text with an AlertDialog
carrying the fuller thank-you/no-guarantee message, and gate the screen's
auto-navigate-on-delete LaunchedEffect so it no longer fires while a submit
is in flight or has just succeeded — the dialog's acknowledgement is what
calls onDone() for that path instead. This closes the race where
ReportUploadWorker deletes the report row (and thus flips state.exists to
false) moments after SubmitUiState.SUCCEEDED, which could previously
navigate the user away before the confirmation was ever visible. Discard
and the other non-success paths (FAILED/UNAVAILABLE) are unaffected and
still auto-navigate immediately.

Closes #161

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-02 23:36:36 +00:00
JMR-devandClaude Opus 4.8 72ee1d3774 feat(accountsetup): add iCloud app-password/2FA help in onboarding
iCloud's guided setup screen previously linked only a generic Apple ID
sign-in page and had no two-factor help link, unlike Gmail. Apple also
requires two-factor authentication before it will issue an
app-specific password, so:

- MailProvider.ICLOUD.appPasswordHelpUrl now points at Apple's actual
  app-specific-password instructions (support.apple.com/en-us/102654)
  instead of the generic appleid.apple.com landing page.
- MailProvider.ICLOUD.twoFactorHelpUrl now points at Apple's dedicated
  two-factor-authentication article (support.apple.com/en-us/102660),
  so the existing generic 2FA-help button in AppPasswordSetupScreen
  picks it up automatically, positioned the same as Gmail's (#152).
- The 2FA button now reads "How to turn on Two-Factor Authentication"
  for iCloud instead of Google's "2-Step Verification" wording, via a
  new app_password_2fa_help_icloud string.

Closes #153

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 18:34:14 -05:00
Jason RossClaude Opus 4.8github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
99f6ef19e4 fix(onboarding): request notification permission after welcome screen renders (#168)
* fix(onboarding): request notification permission after welcome screen renders

The POST_NOTIFICATIONS request fired from a MainActivity-root
NotificationPermissionEffect whose LaunchedEffect(Unit) ran on the very
first composition, so the system dialog could pop the instant the icon
was tapped — overlapping cold start/splash before any onboarding context
was on screen.

Move the effect into OnboardingWelcomeScreen so it fires once that screen
(the onboarding start destination) is composed and visible, with the
welcome content behind the dialog. Already-onboarded users launch
straight into the mailbox and never compose the welcome screen, so they
are unaffected; the API 33+ gate and the already-granted no-op are
preserved unchanged.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* test(onboarding): grant POST_NOTIFICATIONS in onboarding E2E to fix API 33+ flow

Moving the notification-permission request into OnboardingWelcomeScreen
(#151) means the system POST_NOTIFICATIONS dialog now pops when that
screen composes. On API 33+ (where it became a runtime permission) the
dialog backgrounded the activity mid-flow, so OnboardingFlowTest failed
with "No compose hierarchies found" on API 33/34/35/36/37 while API
29–32 stayed green.

Pre-grant the permission via a GrantPermissionRule so the dialog never
appears during the flow, guarded for API 33+ (the permission does not
exist below TIRAMISU, so grant nothing there to avoid erroring on older
devices). Adds the androidx.test:rules dependency that provides the rule.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-02 23:23:30 +00:00
Jason RossandClaude Opus 4.8 f353bdc5ec test(compose): add RichTextEditor unit + ComposeScreen UI coverage (#176)
Closes the #36 test-coverage gap left after the rich-text editor shipped:

- RichTextEditorTest.kt (new JVM unit test, 20 cases): exercises the
  Compose-editor glue in RichTextEditor.kt that had no direct coverage -
  applyStyle/applyBlock/applyLink, the AnnotatedString.toRichContent() <->
  RichTextContent.toAnnotatedString() round trip across every span/link/
  alignment/image/baseStyle channel, and the isStyled/hasBlock predicate
  FormattingToolbar uses to light up its buttons. All plain TextFieldValue/
  AnnotatedString/Color types, so it runs on the JVM with no emulator.
  applyBlock/applyLink go from private to internal so the test can reach
  them directly, mirroring applyStyle's existing internal visibility.

- ComposeScreenTest.kt (androidTest, following this file's existing
  createAndroidComposeRule + fake-repository harness): one case taps the
  bullet-list toolbar button and asserts the sent message carries the
  <ul><li> HTML (block markers apply to the caret's line, so no fragile
  on-device range selection is needed); another asserts every toolbar
  button's click-action label matches its string resource, verifying the
  accessibility claim (the labels are onClickLabel, not contentDescription).

Headings remain deliberately out of scope per the ticket - no model/
toolbar changes here.

Closes #36

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 23:09:40 +00:00
Jason RossandClaude Opus 4.8 e72a9b15c6 docs(compose): correct RichTextEditor toolbar accessibility KDoc (onClickLabel, not contentDescription) (#179)
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 17:52:48 -05:00
JMR-devandClaude Opus 4.8 30c5251a68 feat(settings): reorder the Advanced settings section
Reorder the Advanced block's SwitchRows to Push Mail, Load Remote
Images, Encrypt Local Cache, Require Screen Lock, then Allow insecure
STARTTLS fallback (moved last). Relocate the Background battery usage
row out of Advanced entirely and into the main settings list, directly
above local retention ("Storage on this device"), since it's common
enough (OEM battery optimization delaying push mail) that it shouldn't
be hidden behind "Advanced". Pure composable placement — no string
changes, no behavior change to any toggle.

Closes #162

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 17:46:59 -05:00
Jason RossClaude Opus 4.8github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
97d6f9303b fix(accountsetup): show 2-Step Verification link before app-password link for Gmail (#166)
2-Step Verification is a prerequisite for Gmail's app-passwords page, so
render the twoFactorHelpUrl button first when present, then the
appPasswordHelpUrl button. Previously the prerequisite link rendered
second, so a user without 2FA enabled would hit a dead end on the first
button before noticing the second. No visible change for Yahoo/iCloud,
which have no twoFactorHelpUrl.

Closes #152

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-02 22:42:37 +00:00
Jason Ross 788c450cad Merge branch 'main' into feat-163-default-account 2026-07-02 17:34:20 -05:00
JMR-devandClaude Opus 4.8 e06054afb6 feat(settings): let the user set a default mail account
Persist a defaultAccountId preference (SettingsRepository/AppSettings,
following the existing key/field/setter pattern), add a "Default account"
switch to AccountSettingsScreen, and prefer it in ComposeViewModel's
from-account fallback (fromAccountId -> valid default -> first account).
Deleting the default account clears the preference (SettingsRepository
.clearDefaultAccountId), and a stale/foreign id is validated against the
current account list before use so it can never crash or point at a
missing account.

Closes #163

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 17:28:22 -05:00
github-actions[bot] 8230eae962 Merge main into feat-150-battery-deeplink 2026-07-02 22:25:51 +00:00
Jason RossClaude Opus 4.8github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
a48d68c139 fix(mailbox): show spinner during initial folder fetch instead of empty state (#167)
selectFolder() kicked off its background syncFolder() fetch fire-and-forget
with no loading flag, so opening a per-account folder with no cached
messages yet flashed "No messages to display" for the whole IMAP fetch
instead of a spinner. Adds isSyncingFolder, a StateFlow set for the
duration of that sync (mirroring isRefreshing) and cleared via try/finally
regardless of outcome. A private latestFolderSelection token guards the
clear so a stale sync from a folder no longer selected can't hide the
spinner for whichever folder is actually selected now.

MailboxScreen's non-paged empty branch now holds NoMessagesState back
while isSyncingFolder is true, showing a CircularProgressIndicator
instead — mirroring how the unified-inbox paged branch already gates on
loadState.refresh.

Closes #149

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-02 22:25:22 +00:00
JMR-devandClaude Opus 4.8 01841e9faf feat(onboarding): deep-link battery step nearer the per-app background-activity screen (best-effort)
Spiked #150 against the AOSP Settings source (not just the reference docs): no
public, non-hidden Settings action opens the "Unrestricted/Optimized/Restricted"
screen directly for a specific package. ACTION_VIEW_ADVANCED_POWER_USAGE_DETAIL
would, but it's @hide/non-SDK; the other public battery action,
ACTION_IGNORE_BATTERY_OPTIMIZATION_SETTINGS, isn't package-scoped and is a worse
landing for one known app. So ACTION_APPLICATION_DETAILS_SETTINGS (one tap from
the target via "Battery" on stock/Pixel/AOSP) stays the primary target.

BatteryOptimizationManager.settingsIntent() is restructured into a verified,
never-dead-end fallback chain: try app-details, and if it doesn't resolve on
some device, fall back to the battery-optimization list rather than nothing.
The ordering/selection logic is extracted into a small Android-free helper so
it's directly unit-testable; a new instrumented test checks the real candidate
intents/order against a real PackageManager.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 17:19:42 -05:00
Jason RossandClaude Opus 4.8 26d4295c30 feat(settings): reorder top-level settings sections and add appearance subtext (#169)
Reorders SettingsScreen's top-level (non-Advanced) sections per #158:
Accounts, Message downloading, Contacts, Appearance, Settings Backup,
Notifications, Storage on this device, then a header-less trailing
Report a Problem row (mirrors AccountSettingsScreen's headerless
"Remove account" row now that Diagnostics is down to one item).

- Move "Message downloading" up to directly follow Accounts.
- Add a two-line descriptive subtext under the Appearance header
  ("Match device theme" / "Material You theming (Android 12+)"); no
  new toggle, since LibreMailTheme already always follows the system
  light/dark setting via isSystemInDarkTheme().
- Rename settings_backup "Backup" -> "Settings Backup" and
  settings_new_mail "New-mail notifications" -> "New mail
  notifications" (drop hyphen).
- Drop the now-single-item settings_diagnostics header string; keep
  Contacts positioned directly before Appearance (its prior relative
  spot), per the ticket's suggested safest default for the
  unresolved placement question.

Advanced's internal order is untouched (out of scope; tracked by
#162).

Closes #158

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 22:08:30 +00:00
Jason RossandClaude Opus 4.8 31639fdacc fix(mailbox): anchor account-switcher dropdown to its trigger (#165)
The TextButton trigger and its DropdownMenu in AccountSwitcher were
siblings in the drawer's outer Column, so the dropdown's Popup anchored
to the whole Column instead of the button. Wrap both in a shared Box,
the standard Compose pattern, so the menu opens directly below the
account switcher regardless of drawer scroll position or folder count.

Closes #147

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 21:50:00 +00:00
Jason Ross f535561f64 Merge pull request #131 from JMR-dev/spike-imap-connection-reuse
spike(imap): prototype flag-gated connection reuse for folder-open
2026-07-02 15:07:05 -05:00
Jason Ross 5130597447 Merge branch 'main' into spike-imap-connection-reuse 2026-07-02 14:55:53 -05:00
Jason Ross 0a8a463677 Merge pull request #146 from JMR-dev/ci-autoupdate
ci: auto-update armed PRs; drop dead merge_group trigger
2026-07-02 12:48:30 -05:00
JMR-devandClaude Fable 5 d0a5ccb10d ci: auto-update armed PRs; drop dead merge_group trigger
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 12:48:23 -05:00
Jason Ross 1f65743631 Merge pull request #145 from JMR-dev/refactor-keystore-crypto-base
refactor(security): de-duplicate AES-GCM Keystore plumbing and unify the authenticator policy
2026-07-02 12:33:28 -05:00
JMR-devandClaude Fable 5 d424abc6d3 refactor(security): de-duplicate AES-GCM Keystore plumbing and unify authenticator policy
Extract the AES-256-GCM Android Keystore plumbing that `KeystoreCrypto` and
`DatabaseKeyCipher` copy-pasted (~60 lines) into a shared alias-parameterized
base, `AesGcmKeystoreCipher`: the encrypt/decrypt bodies, existing-key lookup /
get-or-create under a lock, key deletion, and the 5 identical GCM constants now
live in ONE place. Each cipher keeps only its delta — the `KeyGenParameterSpec`
(via `keySpecBuilder()`) and, for the auth-bound key, the invalidation handling.

Preserve — deliberately — the two ciphers' different missing-key-on-decrypt
behavior via a `generateKeyOnDecrypt` policy parameter, documented on the base:
- master key (`KeystoreCrypto`, true): auto-generates on a missing alias, correct
  for a first-run key with nothing sealed yet.
- auth-bound cache key (`DatabaseKeyCipher`, false): fails fast, because a missing
  auth-bound key means it was INVALIDATED and silently regenerating it would
  re-arm the lock against a cache that can no longer be decrypted.
Also map the opaque `AEADBadTagException` (thrown when the master path generates a
fresh key then can't decrypt old data) to a clear `GeneralSecurityException`,
while leaving `KeyPermanentlyInvalidatedException` to propagate unwrapped.

Unify the accepted-authenticator policy behind one source of truth,
`AuthenticatorPolicy.ACCEPTED`, mapped into each API's vocabulary
(`AppLockManager.AUTHENTICATORS` for BiometricManager / BiometricPrompt,
`DatabaseKeyCipher.keySpec` for KeyProperties / KeyGenParameterSpec) so the two
can no longer drift — a drift that yields a prompt that succeeds but a key that
throws `UserNotAuthenticatedException` at use.

Add JVM tests for the shared base (both `generateKeyOnDecrypt` modes + the AES-GCM
error mapping) and for the authenticator mapping. #100's seal-exchange and
policy-table safety net stays green.

Closes #102

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 12:21:09 -05:00
Jason Ross 73d6a44a3f Merge pull request #144 from JMR-dev/test-applock-security-core
test(security): cover the app-lock security core (seal exchange, unlock classification, policy table)
2026-07-02 11:55:51 -05:00
Jason Ross 948f3f1bda Merge branch 'main' into test-applock-security-core 2026-07-02 11:43:51 -05:00
JMR-devandClaude Fable 5 5777967375 test(security): cover the app-lock security core
Close the test-coverage gap on the app-lock security core (#100): the
branching that decides when to WIPE user data or drop the lock, which
shipped largely untested.

- AppLockViewModelTest: pin the onAuthenticated unlock/arm classification
  (OK / UNRECOVERABLE / RETRY) and the onForeground LockAction dispatch --
  DISABLE_APP_LOCK persists the setting, CLEAR_* set the pending flag and
  drop the gate BEFORE the awaited re-sync enqueue and process restart,
  and CLEAR_AND_REQUIRE_AUTH clears + restarts but keeps app-lock on.
- KeyInvalidationPolicyTest: make the exhaustive 16-row decision table a
  test, with a completeness guard so no row can be dropped. The common
  (appLock on, encrypt off, secure, valid) -> REQUIRE_AUTH row is now
  pinned, so a mutation to PROCEED (a silent lock bypass) fails.
- DatabaseKeyStoreTest: new JVM tests for the dual-seal exchange
  (sealWithAuth dropping SEALED_MASTER, sealWithMaster, resetSealedPassphrase,
  unlockWithAuth, clear-pending) pinning the "never both seals at once" and
  "not recoverable without auth" invariants.
- SettingsViewModelTest: setAppLock reject / reseal / disable branches.

To make the device-only DatabaseKeyStore crypto JVM-testable, add a
minimal @VisibleForTesting DataStore seam (mirroring AppLockViewModel's
injectable dispatcher); production still uses the real per-app DataStore.
No crypto plumbing is refactored.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 11:41:40 -05:00
Jason Ross 6bc5b90315 Merge pull request #140 from JMR-dev/fix-reader-inline-images
fix(reader): render inline cid: images in HTML emails
2026-07-02 11:36:43 -05:00