fix(accounts): normalize (lowercase) email when deriving the account id to prevent duplicate accounts #305

Closed
opened 2026-07-04 06:50:22 +00:00 by JMR-dev · 0 comments
JMR-dev commented 2026-07-04 06:50:22 +00:00 (Migrated from github.com)

Phase-3 review (LOW/correctness, flagged by BOTH domain + UI reviews). Account id is the primary key but is built from a trim-only, non-lowercased email: MailProvider.createAccount id="imap:${email.trim()}" (MailProvider.kt:117), ManualSetupViewModel(:67), AppPasswordViewModel.testAndSave, and Account.outlook id="outlook:$email". So User@Gmail.com then user@gmail.com → two account rows syncing the same mailbox (major providers are case-insensitive). Fix: lowercase the address (at least the domain; whole address for consumer providers) when composing the id, so identity is stable across casing. Outlook path is safer (email comes from the id token) but normalize there too for consistency.

Phase-3 review (LOW/correctness, flagged by BOTH domain + UI reviews). Account id is the primary key but is built from a trim-only, non-lowercased email: `MailProvider.createAccount` `id="imap:${email.trim()}"` (MailProvider.kt:117), `ManualSetupViewModel`(:67), `AppPasswordViewModel.testAndSave`, and `Account.outlook` `id="outlook:$email"`. So `User@Gmail.com` then `user@gmail.com` → two account rows syncing the same mailbox (major providers are case-insensitive). **Fix:** lowercase the address (at least the domain; whole address for consumer providers) when composing the id, so identity is stable across casing. Outlook path is safer (email comes from the id token) but normalize there too for consistency.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: JMR-dev/LibreMail#305