Detailed code review/audit #15

Open
opened 2026-07-01 03:11:11 +00:00 by JMR-dev · 0 comments
JMR-dev commented 2026-07-01 03:11:11 +00:00 (Migrated from github.com)

Context

Final pre-release read-through of the whole codebase for correctness, security, and
consistency before a production release.

Scope (checklist)

  • Security: credential/token storage (data/security/*), TLS/STARTTLS enforcement,
    WebView hardening (reader), Outlook OAuth flow, the opt-in SQLCipher path.
  • Correctness: sync/IDLE concurrency, outbox retry, Room migrations (schemas), error
    handling.
  • Privacy: no PII/tokens in release logs; debug-pipeline data flow (#10/#11).
  • Consistency: SPDX headers on every file, ktlint/detekt clean, dependency licenses
    GPL-compatible.
  • Run /security-review and /code-review (or ultra) over the release branch; triage
    findings.

Acceptance criteria

  • A documented audit pass with findings triaged (fixed or ticketed); lint + tests clean.

Dependencies

Run after feature work lands; gates store compliance (#16/#17/#18) and release (#19).

## Context Final pre-release read-through of the whole codebase for correctness, security, and consistency before a production release. ## Scope (checklist) - [ ] **Security:** credential/token storage (`data/security/*`), TLS/STARTTLS enforcement, WebView hardening (reader), Outlook OAuth flow, the opt-in SQLCipher path. - [ ] **Correctness:** sync/IDLE concurrency, outbox retry, Room migrations (schemas), error handling. - [ ] **Privacy:** no PII/tokens in release logs; debug-pipeline data flow (#10/#11). - [ ] **Consistency:** SPDX headers on every file, ktlint/detekt clean, dependency licenses GPL-compatible. - [ ] Run `/security-review` and `/code-review` (or ultra) over the release branch; triage findings. ## Acceptance criteria - A documented audit pass with findings triaged (fixed or ticketed); lint + tests clean. ## Dependencies Run after feature work lands; gates store compliance (#16/#17/#18) and release (#19).
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: JMR-dev/LibreMail#15