fix(data): deleteAccount leaves the account's attachment cache files + draft URI grants on disk #299

Closed
opened 2026-07-04 06:48:14 +00:00 by JMR-dev · 0 comments
JMR-dev commented 2026-07-04 06:48:14 +00:00 (Migrated from github.com)

Phase-3 review finding (MEDIUM/correctness+security). AccountRepositoryImpl.deleteAccount (:74) removes the account row, credential, channel, message rows, folders, and backfill progress — but NOT the on-disk attachment files. Those are written by MailRepositoryImpl.ensureAttachmentFile to attachmentCacheDir(cacheDir, messageId) keyed by message id; the only cleanup paths iterate still-existing accounts. Once the account + its message rows are gone, nothing can enumerate those message ids again → every downloaded/prefetched attachment for the deleted account stays as a plaintext file in cacheDir indefinitely. Drafts + their persistable URI grants are also never released. A user deleting an account to remove their data leaves sensitive attachments behind. Fix: in deleteAccount, before deleting message rows, collect the account's message ids and deleteRecursively() each attachment dir; release the account's draft URI grants (AttachmentUriGrants). Test.

Phase-3 review finding (MEDIUM/correctness+security). `AccountRepositoryImpl.deleteAccount` (:74) removes the account row, credential, channel, message rows, folders, and backfill progress — but NOT the on-disk attachment files. Those are written by `MailRepositoryImpl.ensureAttachmentFile` to `attachmentCacheDir(cacheDir, messageId)` keyed by message id; the only cleanup paths iterate still-existing accounts. Once the account + its message rows are gone, nothing can enumerate those message ids again → every downloaded/prefetched attachment for the deleted account stays as a **plaintext file in cacheDir indefinitely**. Drafts + their persistable URI grants are also never released. A user deleting an account to remove their data leaves sensitive attachments behind. **Fix:** in `deleteAccount`, before deleting message rows, collect the account's message ids and `deleteRecursively()` each attachment dir; release the account's draft URI grants (`AttachmentUriGrants`). Test.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: JMR-dev/LibreMail#299