fix(onboarding): enforce GPL license gate for upgrade users #202
Closed
JMR-dev wants to merge 1 commits from
fix-172-license-gate-upgrade-users into main
pull from: fix-172-license-gate-upgrade-users
merge into: :main
:main
:feat-362-yahoo-imap-limits
:feat-34-debug-ingest
:spike-359-sqlcipher-ondevice
:build-290-jacoco-scope
:fix-172-license-gate-upgrade-users
No Reviewers
Labels
Clear labels
Compliance
Infrastructure
P0
P1
P2
P3
P4
P5
P6
P7
P8
P9
Release
broken
bug
dequeued
documentation
donotmerge
duplicate
enhancement
good first issue
help wanted
invalid
question
queued
wontfix
Priority P0 (P0=highest for CI runners, P9=lowest)
Priority P1 (P0=highest for CI runners, P9=lowest)
Priority P2 (P0=highest for CI runners, P9=lowest)
Priority P3 (P0=highest for CI runners, P9=lowest)
Priority P4 (P0=highest for CI runners, P9=lowest)
Priority P5 (P0=highest for CI runners, P9=lowest)
Priority P6 (P0=highest for CI runners, P9=lowest)
Priority P7 (P0=highest for CI runners, P9=lowest)
Priority P8 (P0=highest for CI runners, P9=lowest)
Priority P9 (P0=highest for CI runners, P9=lowest)
Deprioritize below all P-levels; higher-priority PRs may preempt it. Coordinator/owner only.
Something isn't working
Improvements or additions to documentation
This issue or pull request already exists
New feature or request
Good for newcomers
Extra attention is needed
This doesn't seem right
Further information is requested
This will not be worked on
No labels
Milestone
No items
No Milestone
Projects
Clear projects
No projects
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: JMR-dev/LibreMail#202
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Finding (from the post-batch security review, refs #172)
Low severity. The GPL-3.0 license gate added in #172 is skipped for upgrade users. The license screen (
ONBOARDING_LICENSE) is only the onboarding graph's start destination, butAppViewModel.startDestinationchose mailbox-vs-onboarding purely by account count. So a user upgrading from a pre-#172 install (accounts present,licenseAccepted = false) went straight toMAILBOXand never saw the license — contradicting #172's own intent (theAppSettingsTestcomment: pre-#172 installs should route throughONBOARDING_LICENSE).Separately, the
pendingComposemailto/share deep-link navigated unconditionally, unlikependingOpenMessageIdwhich already guards onstart != Routes.ONBOARDING— so a deep-link could also jump past the gate.Fix
AppViewModel.startDestinationnowcombines account presence with the (already-resolved from #172)licenseAccepted: it returnsONBOARDINGwhenever the license is unaccepted, even when accounts exist. Only a user who has both accepted the license and has an account lands onMAILBOX. Same hold-until-known +take(1)"resolve once at launch" contract as before.pendingComposenow carries the sameif (start != Routes.ONBOARDING)guard aspendingOpenMessageId(still consumes the request either way so it isn't replayed).LicenseScreen'sonAgreesent everyone toONBOARDING_WELCOME("add your first account"), which has no path forward for a user who already has accounts.AppViewModelnow also exposeshasAccounts, andonboardingGraph'sonAgreeuses it — an upgrade user (has accounts) goes straight to their inbox via the existingfinishOnboarding(null)(which pops the whole onboarding graph, leaving the one-time gate behind); a fresh install (no accounts) continues into the welcome/add-account flow exactly as before. Without this, the fix would trade "skips the license" for "trapped after accepting it."Tests
AppViewModelTestupdated/extended to cover the full 2x2 of (accounts × licenseAccepted):ONBOARDINGMAILBOXONBOARDING(the regression this fixes — the upgrade license gate)hasAccountsreflects account presenceThe post-accept nav wiring (agree → mailbox for upgrade users) is graph-level; it's left to CI's E2E rather than an emulator run here.
Preflight (JDK 21,
--max-workers=8, no emulator) — all green:app:assembleDebug:app:testDebugUnitTest(AppViewModelTest: 6 pass):app:lintDebug:app:ktlintCheck :app:detekt:app:compileDebugAndroidTestKotlin🤖 Generated with Claude Code
Pull request closed