Commit Graph
221 Commits
Author SHA1 Message Date
JMR-devandClaude Opus 4.8 aee5e57ba8 fix(onboarding): enforce GPL license gate for upgrade users
AppViewModel.startDestination chose onboarding-vs-mailbox purely by
account count, so a user upgrading from a pre-#172 install (accounts
present, licenseAccepted=false) went straight to the mailbox and never
saw the license screen — the license is only the onboarding graph's
start destination. Route to ONBOARDING whenever the license is
unaccepted, even when accounts exist; only an accepted user with an
account lands on the mailbox.

Once such a user accepts, send them straight to their inbox rather than
ONBOARDING_WELCOME ("add your first account"), which would strand a user
who already has accounts. AppViewModel now also exposes hasAccounts for
that post-accept routing decision.

Also guard the pendingCompose mailto/share deep-link with the same
start != ONBOARDING check pendingOpenMessageId already uses, so a
deep-link can't jump past the license gate either.

From the post-batch security review, refs #172.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-03 03:18:36 -05:00
JMR-devandClaude Opus 4.8 96b2da1753 feat(compose): inline images end to end (picker to SMTP/Graph)
Wire inline images through the whole send pipeline.

Compose UI: an image-picker (image/*, persistable URI grant, mirroring the
attachment picker) behind a new toolbar button appended at the END of the
toolbar — after the block/link buttons and the font/size/align controls — so it
never shifts the bullet button the compose E2E taps without scrolling. Picking
an image adds an inline OutgoingAttachment and hands the editor a
PendingInlineImage, which RichTextEditing.insertImage drops as a [image: name]
token + RichImage(contentId) at the caret. Deleting the token drops the image:
onBodyChange reconciles inline attachments against the body's surviving cid:
references. Inline images are tracked in ComposeUiState alongside regular
attachments but kept out of the attachment-chip row.

Domain/persistence: OutgoingAttachment gains contentId/isInline; the shared
draft/outbox attachment JSON carries them (drafts need no migration — an older
draft reads back as a plain attachment). The outbox stages files by index as
before but now also stores per-file {contentId,isInline} metadata in a new
OutboxEntity.attachments column (Room 17 -> 18, MIGRATION_17_18, DEFAULT '' per
the bccAddresses precedent so fresh-install == migrated; 18.json committed). The
send worker pairs each staged file with its metadata by index (with a positional
fallback for messages queued before the column existed).

SMTP (SmtpSender): inline images wrap the body in a multipart/related, each with
a Content-ID matching the HTML's cid: and inline disposition; regular
attachments keep today's multipart/mixed shape.
Graph (GraphSender): inline fileAttachments carry isInline + contentId.

Tests: GreenMail asserts multipart/related with a Content-ID matching the cid;
GraphSenderTest asserts the inline payload; a mapper test proves an inline
image's cid<->file pairing round-trips a draft save/reopen; RichTextEditing
tests cover insertImage (token/RichImage placement + offset shift + html
round-trip); MigrationTest gains migrate17To18. Reader-side cid: rendering stays
out of scope (follow-up).

Closes #77

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-03 01:33:48 -05:00
Jason Ross ad8fd1e24f Merge main into feat-177-draft-autosave 2026-07-03 00:45:19 -05:00
JMR-devandClaude Opus 4.8 071034de65 feat(compose): add a font family picker with bundled open-source fonts
Bundle four SIL OFL 1.1 fonts in res/font (no build-time downloads, F-Droid
safe): Inter, Lora, and JetBrains Mono as weight-variable TTFs plus a static
Merriweather Regular cut (its variable font is 4.4 MB) — ~1.5 MB total. Each
family's OFL license text is committed under THIRD_PARTY_LICENSES/, and *.ttf/
*.otf are marked binary in .gitattributes so the bytes commit intact.

Add FontRegistry: display name <-> email-safe CSS stack <-> Compose FontFamily,
with three generic Sans/Serif/Monospace entries that need no bundled file. Each
bundled stack names the family first then falls back to a generic (e.g.
'Lora', Georgia, serif), so a recipient whose client lacks the face still gets
a sensible one. resolveFontFamily maps a stored CSS stack back to a FontFamily
for in-editor rendering, and is now passed into RichTextBodyField from
ComposeScreen so styled runs actually render in their font.

Add FontPicker (ui/compose/format): a toolbar dropdown applying
RichStyle.FontFamily(css) via the generalized applyStyle/clearStyle path, with a
leading "Default" entry that clears it; each menu entry previews itself in its
own face. Appended at the END of the toolbar (with the size/alignment controls),
after the block and link buttons — per the #73/#76 lesson, nothing may shift the
bullet/numbered/quote buttons that the compose E2E taps without scrolling.

Tests: FontRegistryTest (JVM) proves every CSS stack survives an html
round-trip, the resolver maps known/unknown stacks, and bundled stacks end in a
generic fallback; a compile-only FontPickerTest drives the picker in isolation
(default label, current-font label, menu lists every font, picking reports the
css / Default clears).

Closes #72

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-03 00:31:09 -05:00
JMR-devandClaude Opus 4.8 bbc0715666 feat(compose): debounced periodic draft autosave
Adds a debounced periodic draft save alongside the existing exit-time
save, so an in-progress compose survives a background-kill without going
through the back gesture. Observes the persisted body/recipient/subject/
attachment fields, coalescing rapid keystrokes into one write after a
~1.5s idle window (viewModelScope), and flushes immediately on ON_STOP
from ComposeScreen so the last keystrokes within the window aren't lost.

Prerequisite bug fix: draftId was a nullable val, so
saveOrDeleteDraft()'s `id = draftId ?: UUID.randomUUID()` minted a fresh
id on every call. Harmless when it ran only once at exit, but periodic
autosave would insert a new duplicate draft row per tick. The persist id
is now generated once (persistedDraftId) and reused for every save this
session; a draftPersisted flag drives delete-on-empty and delete-on-send
so an autosaved new draft is never orphaned.

onExit()'s save-or-delete-on-back behavior and the "don't save mid-send"
guard are unchanged; autosave mirrors the same guard (plus a navigated
guard so a post-send tick can't re-create a sent message's draft).

Closes #177

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-03 00:22:42 -05:00
Jason Ross 6fff3fcf02 Merge main into feat-76-paragraph-alignment 2026-07-02 23:55:54 -05:00
JMR-devandClaude Opus 4.8 df5c1aa2f9 feat(compose): add paragraph alignment to the formatting toolbar
Add setAlignment(content, start, end, align) and alignmentAt(...) ops to
RichTextEditing with paragraph-range bookkeeping (mirroring toggleBlock).
setAlignment marks every line the selection touches, leaves untouched
paragraphs alone, and stores START as "no alignment" (dropping the range) so
an otherwise-plain paragraph stays plaintext-only; CENTER/END become explicit
ranges. It emits the same canonical form RichTextHtml.fromHtml returns — one
merged range per run of adjacent same-aligned lines, and blank paragraphs
anchor no range (the HTML model can't pin text-align to an empty <p>) — so the
model, its HTML, and the editor's ParagraphStyle rendering never drift.
alignmentAt returns the shared alignment (START default for plain paragraphs,
null when mixed), driving a three-state control directly.

Add ParagraphAlignmentControl (start/center/end glyph buttons) and append it —
plus the existing FontSizePicker — at the END of the toolbar, after the block
and link buttons. Per the #73 lesson, nothing may shift the bullet/numbered/
quote buttons rightward or the compose E2E's no-scroll performClick on "•" (and
siblings) misses.

Editor renders alignment via the existing ParagraphStyle(textAlign) path
(applyAlignment routes through it, preserving the selection since alignment
never changes the text).

Tests: setAlignment/alignmentAt covered thoroughly at the JVM layer (caret,
multi-paragraph merge, mid-block split, untouched paragraphs, blank lines,
empty document, mixed selections) plus a serialize->parse round-trip fixpoint
on setAlignment output; applyAlignment covered in RichTextEditorTest; a
compile-only androidTest drives the control in isolation.

Closes #76

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 23:51:50 -05:00
Jason Ross 2df6b0f82a Merge main into feat-78-remember-font-size 2026-07-02 23:41:19 -05:00
JMR-devandClaude Opus 4.8 5e5116cbca feat(compose): remember last-used font and size
Persists the font family/size from a sent formatted message to the
settings DataStore (SettingsRepository.setLastFont), taking the
message-wide base style if set, else the last FontFamily/FontSize
span. Brand-new compositions (draftId == null) seed a RichBaseStyle
from the remembered preference so the whole message defaults to it;
resumed drafts and replies/forwards are untouched, and messages with
no remembered font stay plaintext-only.

Closes #78

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 23:32:58 -05:00
Jason Ross d9cfff80ec Merge main into feat-160-app-password-disclaimer 2026-07-02 23:28:26 -05:00
JMR-devandClaude Opus 4.8 9c6a969c17 fix(compose): keep the bullet button tappable by appending the font-size control last
The font-size dropdown was inserted before the block-marker buttons, and its
wide "Default"/"N pt" anchor pushed the "•" bullet button past the right edge
of the horizontally-scrolling toolbar on the Pixel 2 E2E device (411dp wide,
minus the compose column's 16dp padding = 379dp usable). ComposeScreenTest's
formattingToolbar_bulletButtonMarksTheLineAndSendsItAsHtml taps the bullet
without scrolling first, so performClick targeted a center that was clipped
off-screen and the tap silently missed — the line was never marked, failing
all 8 instrumented legs deterministically (expected "• Buy milk", got "Buy milk").

The block-toggle logic was never touched; this was pure toolbar overflow. Move
FontSizePicker to the end of the toolbar (after the link button) so every
pre-existing glyph button keeps the exact position it has on main and the
bullet stays within the initial viewport. Add a comment recording the ordering
constraint for future toolbar tickets.

Also add a JVM unit test (RichTextEditorTest) that drives the same bullet-tap
flow through applyBlock + RichTextHtml.toHtml, pinning "• Buy milk" and
<ul><li>Buy milk</li></ul> so a regression in that block/HTML path is caught
by testDebugUnitTest without an emulator.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 23:13:59 -05:00
Jason Ross b7c7415fef Merge main into feat-160-app-password-disclaimer 2026-07-02 23:09:17 -05:00
Jason Ross 1634c57837 Merge main into feat-73-font-size-control 2026-07-02 23:09:16 -05:00
JMR-devandClaude Opus 4.8 bae25b20f3 feat(onboarding): require GPL-3.0 license agreement as the first screen
Inserts a new LicenseScreen ahead of OnboardingWelcomeScreen as the
onboarding graph's start destination: the user must scroll the full
GPL-3.0 text and tap Agree before reaching anything else, or Decline
to exit the app outright. Acceptance is persisted
(SettingsRepository.licenseAccepted) so a user who agrees but exits
before adding an account isn't asked again, and the
NotificationPermissionEffect() request (#151) stays scoped to
OnboardingWelcomeScreen so it never fires on the license screen.

Closes #172

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 22:56:34 -05:00
JMR-devandClaude Opus 4.8 23fa389c0a feat(compose): add font size control to the formatting toolbar
Add a preset-size dropdown (10/12/14/18/24pt, plus Default to clear) to the
compose FormattingToolbar via a new FontSizePicker composable, applying
RichStyle.FontSize over the selection through the existing generalized
applyStyle/clearStyle toggle path (no font-size-specific branching needed).
The anchor button shows the selection's current size, or "Default" when
unset/mixed. The rich-text foundation already provided RichStyle.FontSize,
its pt/px-tolerant HTML round-trip, and pt->sp mapping for in-editor
rendering; this ticket wires up the missing UI control.

Closes #73

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 22:38:22 -05:00
JMR-devandClaude Opus 4.8 c3cd567da2 feat(accountsetup): warn against using account password for app password
New users unfamiliar with app passwords commonly try their regular
account password first and get a confusing auth failure. Add a
disclaimer as supporting text directly under the "App password" field
on AppPasswordSetupScreen (shared by every preset provider), instead
of leaving the warning only in the intro InfoCards above.

Closes #160

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 22:29:53 -05:00
Jason Ross af22467817 Merge main into feat-156-154-aol-provider 2026-07-02 21:26:33 -05:00
Jason Ross fd80bded67 Merge main into feat-156-154-aol-provider 2026-07-02 21:15:15 -05:00
Jason Ross 2ce2cb39d2 Merge main into feat-74-75-compose-color-highlight 2026-07-02 21:15:14 -05:00
Jason Ross 4f588b8fd1 Merge main into feat-74-75-compose-color-highlight 2026-07-02 21:03:12 -05:00
Jason Ross 4dd2c20053 Merge main into feat-156-154-aol-provider 2026-07-02 21:03:11 -05:00
Jason Ross cf274781bd Merge main into test-53-sync-concurrency 2026-07-02 21:03:10 -05:00
JMR-devandClaude Opus 4.8 b4a450a8b8 test(sync): interleaving tests for the ungated sync↔backfill and sync↔prune pairs
MailMaintenanceGate serializes only the backfill↔prune pair. The other two
pairs — sync↔backfill and sync↔prune — are deliberately ungated (foreground
sync uses its own syncMutex to stay UI-responsive) and rely on a disjoint-by-UID
argument for safety, with no test covering it (issue #53).

Add MailSyncConcurrencyTest: a real MailSyncer and a real MailBackfiller/
MailPruner wired to one shared in-memory message store, with CompletableDeferred
gates (mirroring MailMaintenanceGateTest) that park one actor mid-critical-
section while the other's whole critical section runs. Each interleaving is
driven to the boundary (window edge / count floor) where an overlap would
surface as a lost, duplicated, or wrongly-deleted row:

- sync's windowed reconcile runs while a backfill is parked mid-paging just
  below the window (tightest edge: lowestSyncedUid == minWindowUid);
- a backfill's below-window page lands after a concurrent full sync of the
  window (stale-boundary ordering);
- a count-retention prune runs while a foreground sync is parked in its fetch;
- a full foreground sync runs while a prune is parked inside its critical
  section, before it touches the message table.

All four pass: the disjointness invariant holds unlocked. No production code
changed.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 21:00:23 -05:00
JMR-devandClaude Opus 4.8 ef43dc9a79 feat(accountsetup): add AOL provider with app-password help and IMAP/SMTP presets
Adds MailProvider.AOL as a guided app-password provider (after iCloud, before
Other), closing the coupled pair of #156 (app-password help content) and #154
(IMAP/SMTP presets):

- appPasswordHelpUrl points at AOL's "Create and manage 3rd-party app
  passwords" article. No twoFactorHelpUrl: verified against both AOL's
  app-password article and its separate two-step-verification article that
  neither treats 2FA as a prerequisite for generating an app password (AOL
  mirrors Yahoo here, not Gmail/iCloud).
- IMAP imap.aol.com:993 (SSL/TLS); SMTP smtp.aol.com:465 (SSL/TLS) — AOL's
  official docs and the Thunderbird ISPDB autoconfig only document implicit
  TLS on 465 for submission, with no STARTTLS/587 alternative, so this
  follows Yahoo's rationale rather than Gmail/iCloud's STARTTLS preset.

AppPasswordSetupScreen's two exhaustive `when` blocks (providerIntro,
twoFactorHelpLabel) gain an AOL branch; AccountPickerScreen already lists
providers generically via MailProvider.entries. Test coverage mirrors the
Yahoo/iCloud assertions: presets, help URLs, no twoFactorHelpUrl, fromKey,
forImapHost, and brandFor resolving a manually-configured imap.aol.com
account to the AOL brand.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 20:59:17 -05:00
JMR-devandClaude Opus 4.8 5120d65793 feat(compose): add font color and text highlight to the formatting toolbar
Wire the previously-unused ColorSwatchRow into the compose FormattingToolbar
with two new controls: a font-color button applying RichStyle.FontColor and a
highlight button applying RichStyle.Highlight over the selection. Each opens a
ColorPickerDialog built on the shared ColorSwatchRow (~8 font colors; yellow /
green / cyan / pink highlighter markers), with a "no color"/"none" entry that
clears the style outright via a new clearStyle op. Buttons reflect the current
selection's color and carry accessible onClickLabels; swatches carry their own
contentDescriptions.

Closes #74
Closes #75

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 20:52:09 -05:00
Jason Ross 92c97a386b Merge main into perf-186-message-open 2026-07-02 20:43:31 -05:00
JMR-devandClaude Opus 4.8 aafb4f8f6a perf(reader): render message body once, move openMessage IO off-main, drop wasted work
Follow-up to #148: opening an already-cached message was still slow. Three fixes
on the cached-open critical path (issue #186).

Fix 1 - WebView renders once. The reader resolved cid: inline images AFTER the
first render, so the AndroidView update key (which included inlineImages.keys)
changed and reloaded the whole document a second time for any inline-image email.
ReaderViewModel now resolves inline images and folds them into the SAME state
update as the body, and HtmlBody drops inline images from the reload key, so the
WebView loads exactly once and a late inline-image change never reloads. The
WebView is also destroyed onRelease so it (and its Context) is not leaked.
Pool/pre-warm is left as a TODO (leak-prone; single-render is the dominant win).

Fix 2 - openMessage does no wasted work for a cached, already-read message. Added
a body-less MessageRouting projection (mirrors MessageSummary, no migration);
the routing/flag callers (openMessage's first read, downloadAttachment, setStarred,
deleteMessage, expunge, moveByRole/moveToFolder, buildReplyDraft, prefetchMessage)
route on it, and getById (SELECT *) is reserved for the single read that returns
the body. imapParamsFor (Keystore decrypt + DataStore read) is resolved lazily,
only in the fetch / SEEN-push branches; the cached+read path also skips the
account lookup. De-duped the inlineImages attachment N+1 via a shared
ensureAttachmentFile helper that takes the already-resolved account/folder.

Fix 3 - repository IO off the main thread. openMessage, inlineImages,
downloadedAttachmentParts, and downloadAttachment now run in
withContext(Dispatchers.IO), so their DB/file/crypto work no longer runs on the
Main.immediate viewModelScope during the open animation.

Reader behavior (content, read/SEEN semantics) is unchanged; does not touch the
async SEEN network push handled separately by #170.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 20:33:07 -05:00
Jason Ross 046c21cdaa Merge main into feat-155-yahoo-app-password 2026-07-02 20:32:49 -05:00
Jason Ross ec88548f25 Merge main into feat-71-strikethrough 2026-07-02 20:21:11 -05:00
Jason Ross ecbc052389 Merge main into fix-148-async-seen-flag 2026-07-02 20:08:15 -05:00
Jason Ross 455948774d Merge main into feat-155-yahoo-app-password 2026-07-02 20:08:14 -05:00
Jason Ross 0d0bb0d8fe Merge main into feat-71-strikethrough 2026-07-02 20:08:13 -05:00
Jason Ross 31771e3a4e Merge main into feat-71-strikethrough 2026-07-02 19:56:24 -05:00
Jason Ross 49e22d1873 Merge main into feat-155-yahoo-app-password 2026-07-02 19:56:22 -05:00
Jason Ross 228ea83288 Merge main into feat-162-advanced-settings-hierarchy 2026-07-02 19:56:22 -05:00
Jason Ross d3f0ca46dd Merge main into feat-155-yahoo-app-password 2026-07-02 19:44:32 -05:00
Jason Ross 73f69c5326 Merge main into feat-150-battery-deeplink 2026-07-02 19:44:32 -05:00
Jason Ross aff7133bbb Merge main into feat-162-advanced-settings-hierarchy 2026-07-02 19:44:31 -05:00
Jason Ross 47b7efade7 Merge main into fix-148-async-seen-flag 2026-07-02 19:44:29 -05:00
Jason Ross 6a3b3d5a92 Merge main into feat-71-strikethrough 2026-07-02 19:44:29 -05:00
Jason Ross bd1f09fc06 Merge main into feat-71-strikethrough 2026-07-02 19:33:18 -05:00
Jason Ross 565a4ebfa8 Merge main into fix-148-async-seen-flag 2026-07-02 19:33:17 -05:00
Jason Ross d6100462a7 Merge main into feat-163-default-account 2026-07-02 19:33:16 -05:00
Jason Ross 56a6776f67 Merge main into feat-162-advanced-settings-hierarchy 2026-07-02 19:33:15 -05:00
Jason Ross 96fb91ce8c Merge main into feat-150-battery-deeplink 2026-07-02 19:33:13 -05:00
Jason Ross 7b2bef32fc Merge main into feat-155-yahoo-app-password 2026-07-02 19:33:12 -05:00
JMR-devandClaude Opus 4.8 6ff988aaec feat(accountsetup): add Yahoo app-password/2FA help in onboarding
Yahoo's guided app-password setup pointed appPasswordHelpUrl at the
generic account-security sign-in page, which assumes the user already
knows to hunt for "Create app password" once there. Point it instead at
Yahoo's own step-by-step "Generate and manage 3rd-party app passwords"
article, mirroring what #153 did for iCloud.

Yahoo does NOT gate app-password creation behind two-step verification
(verified against Yahoo's live help docs, which never list it as a
prerequisite), so — unlike Gmail and iCloud — it keeps twoFactorHelpUrl
null and shows no 2FA button. AppPasswordSetupScreen already renders the
help buttons generically from these provider fields, so no screen change
is needed; the existing PR #152 ordering (2FA link before the
app-password link) is preserved for the providers that have both.

Add a MailProviderTest assertion pinning Yahoo's new app-password URL
(mirroring the iCloud test) and extend the onboarding
yahooSetup_hasNoTwoFactorHelpLink coverage note for #155.

Closes #155

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 19:25:24 -05:00
Jason Ross 52d99d2bf9 Merge main into feat-150-battery-deeplink 2026-07-02 19:21:15 -05:00
Jason Ross 41d06c5c77 Merge main into fix-157-notification-open-message 2026-07-02 19:21:13 -05:00
Jason Ross 5eebe2e2b1 Merge main into feat-162-advanced-settings-hierarchy 2026-07-02 19:21:12 -05:00