SendWorker.kt:71: runCatching{…}.fold swallows CancellationException (routes it to onFailure); rethrow it (mirror sendOutlook).
DatabaseProvisioner.kt:117+AccountDatabaseModule.kt:48: opening the plaintext AccountDatabase awaits the full cache-encryption+app-lock passphrase sequence it doesn't need — latent pre-auth coupling; split so accounts-open awaits only wipe+migrator.
DatabaseKeyStore.kt:68: resolvePassphrase(MASTER) ignores appLockEnabled — if seal-state and the app-lock setting diverge, cache opens without auth while EncryptedCacheGuard disagrees; add a defense-in-depth assertion/log.
MailRepositoryImpl.copyAttachments (:456): swallows copy failures → message can send missing an attachment silently; fail/flag the enqueue instead.
MailSyncer.kt:115: empty fetchRecent deletes the whole folder cache (incl. backfilled history); require corroboration (server EXISTS==0) before whole-folder delete.
DatabaseEncryption.kt:42/DatabaseFiles.kt:39: stale .migrate temp file not removed by the wipe path; delete it in DatabaseFiles.clear.
MailRepositoryImpl.inlineImages/ensureAttachmentFile: large inline images/attachments fully materialized in memory (OOM risk); stream/cap.
Phase-3 review — below-the-cut LOW findings (Backlog):
- `SendWorker.kt:71`: `runCatching{…}.fold` swallows `CancellationException` (routes it to onFailure); rethrow it (mirror `sendOutlook`).
- `DatabaseProvisioner.kt:117`+`AccountDatabaseModule.kt:48`: opening the plaintext AccountDatabase awaits the full cache-encryption+app-lock passphrase sequence it doesn't need — latent pre-auth coupling; split so accounts-open awaits only wipe+migrator.
- `DatabaseKeyStore.kt:68`: `resolvePassphrase(MASTER)` ignores `appLockEnabled` — if seal-state and the app-lock setting diverge, cache opens without auth while `EncryptedCacheGuard` disagrees; add a defense-in-depth assertion/log.
- `MailRepositoryImpl.copyAttachments` (:456): swallows copy failures → message can send missing an attachment silently; fail/flag the enqueue instead.
- `MailSyncer.kt:115`: empty `fetchRecent` deletes the whole folder cache (incl. backfilled history); require corroboration (server EXISTS==0) before whole-folder delete.
- `AesGcmKeystoreCipher.kt:86`: truncated/invalid-Base64 ciphertext throws unwrapped IOoB/IllegalArgument instead of `GeneralSecurityException`; length/format-guard + wrap.
- `DatabaseEncryption.kt:42`/`DatabaseFiles.kt:39`: stale `.migrate` temp file not removed by the wipe path; delete it in `DatabaseFiles.clear`.
- `MailRepositoryImpl.inlineImages`/`ensureAttachmentFile`: large inline images/attachments fully materialized in memory (OOM risk); stream/cap.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Phase-3 review — below-the-cut LOW findings (Backlog):
SendWorker.kt:71:runCatching{…}.foldswallowsCancellationException(routes it to onFailure); rethrow it (mirrorsendOutlook).DatabaseProvisioner.kt:117+AccountDatabaseModule.kt:48: opening the plaintext AccountDatabase awaits the full cache-encryption+app-lock passphrase sequence it doesn't need — latent pre-auth coupling; split so accounts-open awaits only wipe+migrator.DatabaseKeyStore.kt:68:resolvePassphrase(MASTER)ignoresappLockEnabled— if seal-state and the app-lock setting diverge, cache opens without auth whileEncryptedCacheGuarddisagrees; add a defense-in-depth assertion/log.MailRepositoryImpl.copyAttachments(:456): swallows copy failures → message can send missing an attachment silently; fail/flag the enqueue instead.MailSyncer.kt:115: emptyfetchRecentdeletes the whole folder cache (incl. backfilled history); require corroboration (server EXISTS==0) before whole-folder delete.AesGcmKeystoreCipher.kt:86: truncated/invalid-Base64 ciphertext throws unwrapped IOoB/IllegalArgument instead ofGeneralSecurityException; length/format-guard + wrap.DatabaseEncryption.kt:42/DatabaseFiles.kt:39: stale.migratetemp file not removed by the wipe path; delete it inDatabaseFiles.clear.MailRepositoryImpl.inlineImages/ensureAttachmentFile: large inline images/attachments fully materialized in memory (OOM risk); stream/cap.