MainActivity.kt:118: exported activity consumes private ACTION_OPEN_MESSAGE without caller verification — any app can drive the NavHost to open an arbitrary message id (limited: renders in-app only, app-lock gates). Accept as inherent to an exported email client, or trust only the app's own PendingIntent.
MailNotifier.kt:129: per-message notification id = messageId.hashCode() can collide → a new-mail notification silently replaces an earlier unacknowledged one. Use a stable collision-free id (persisted per-account counter).
Phase-3 review — below-the-cut LOW findings (Backlog):
- `MainActivity.kt:118`: exported activity consumes private `ACTION_OPEN_MESSAGE` without caller verification — any app can drive the NavHost to open an arbitrary message id (limited: renders in-app only, app-lock gates). Accept as inherent to an exported email client, or trust only the app's own PendingIntent.
- `MailNotifier.kt:129`: per-message notification id = `messageId.hashCode()` can collide → a new-mail notification silently replaces an earlier unacknowledged one. Use a stable collision-free id (persisted per-account counter).
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Phase-3 review — below-the-cut LOW findings (Backlog):
MainActivity.kt:118: exported activity consumes privateACTION_OPEN_MESSAGEwithout caller verification — any app can drive the NavHost to open an arbitrary message id (limited: renders in-app only, app-lock gates). Accept as inherent to an exported email client, or trust only the app's own PendingIntent.MailNotifier.kt:129: per-message notification id =messageId.hashCode()can collide → a new-mail notification silently replaces an earlier unacknowledged one. Use a stable collision-free id (persisted per-account counter).