Phase-3 review — below-the-cut findings (Backlog, for review):
Dormant conn-retry double-apply (ImapConnectionCache.kt:57): the rebuild-and-retry re-executes mutations (expunge/copy) on a fresh socket — double-applies if the server committed before the connection dropped. Dormant (reuseConnections off, #125) but a landmine to fix before that flag ships; restrict retry to idempotent reads.
Email in logcat (SendWorker.kt:146, IdleService.kt:167): Log.w writes account.email to logcat (not the debug report). Prefer a non-identifying account id.
Subject CRLF (SmtpSender.kt:65, GraphSender.kt:97): strip CR/LF from subject before setSubject (header-injection defense-in-depth).
Charset fallback (ImapClient.kt:486): part.content.toString() throws on unsupported/mislabeled charset → whole body fetch fails; fall back to raw-bytes best-effort.
https-enforce endpoint (ReportUploadWorker.kt:54): reject non-httpsDEBUG_REPORT_ENDPOINT (cleartext report POST if ever configured http).
Link URL scheme allow-list (RichText.kt:36/RichTextHtmlParser.kt:277): allow-list http/https/mailto/tel on link create+parse (outgoing-mail defense-in-depth).
Phase-3 review — below-the-cut findings (Backlog, for review):
- **Dormant conn-retry double-apply** (`ImapConnectionCache.kt:57`): the rebuild-and-retry re-executes mutations (expunge/copy) on a fresh socket — double-applies if the server committed before the connection dropped. Dormant (reuseConnections off, #125) but a landmine to fix before that flag ships; restrict retry to idempotent reads.
- **Email in logcat** (`SendWorker.kt:146`, `IdleService.kt:167`): `Log.w` writes `account.email` to logcat (not the debug report). Prefer a non-identifying account id.
- **Subject CRLF** (`SmtpSender.kt:65`, `GraphSender.kt:97`): strip CR/LF from subject before `setSubject` (header-injection defense-in-depth).
- **Charset fallback** (`ImapClient.kt:486`): `part.content.toString()` throws on unsupported/mislabeled charset → whole body fetch fails; fall back to raw-bytes best-effort.
- **https-enforce endpoint** (`ReportUploadWorker.kt:54`): reject non-`https` `DEBUG_REPORT_ENDPOINT` (cleartext report POST if ever configured http).
- **Link URL scheme allow-list** (`RichText.kt:36`/`RichTextHtmlParser.kt:277`): allow-list http/https/mailto/tel on link create+parse (outgoing-mail defense-in-depth).
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Phase-3 review — below-the-cut findings (Backlog, for review):
ImapConnectionCache.kt:57): the rebuild-and-retry re-executes mutations (expunge/copy) on a fresh socket — double-applies if the server committed before the connection dropped. Dormant (reuseConnections off, #125) but a landmine to fix before that flag ships; restrict retry to idempotent reads.SendWorker.kt:146,IdleService.kt:167):Log.wwritesaccount.emailto logcat (not the debug report). Prefer a non-identifying account id.SmtpSender.kt:65,GraphSender.kt:97): strip CR/LF from subject beforesetSubject(header-injection defense-in-depth).ImapClient.kt:486):part.content.toString()throws on unsupported/mislabeled charset → whole body fetch fails; fall back to raw-bytes best-effort.ReportUploadWorker.kt:54): reject non-httpsDEBUG_REPORT_ENDPOINT(cleartext report POST if ever configured http).RichText.kt:36/RichTextHtmlParser.kt:277): allow-list http/https/mailto/tel on link create+parse (outgoing-mail defense-in-depth).