Change the Yahoo/AOL proactive auth circuit-breaker's after-threshold
behaviour from a silent, self-clearing 30-min open-circuit window to a
fail-loud, permanent stop that surfaces to the user.
- AuthThrottleGate: past circuitOpenThreshold the circuit now LATCHES
(blockedUntilMillis = Long.MAX_VALUE) instead of opening a self-clearing
window. onAuthSuccess never clears a latch; only onAccountReadded does.
The 1-4 spaced-retry ramp and all thresholds/timings are unchanged, and
only genuine AuthenticationFailedExceptions still count.
- Persistent, user-visible error state: new nullable AccountEntity.authError
(AccountDatabase migration v2 -> v3 + exported schema) + Account domain
field + mappers + AccountDao.setAuthError (idempotent conditional write).
markAccountErroredIfLatched bridges the in-memory latch to the row from
MailSyncer/MailBackfiller (which hold the Account), keeping the DAO out of
the mail layer. Both loops also skip a latched/errored account entirely
(durable across restarts), and a re-add clears the latch + the row error.
- UI: a persistent red indicator + the message on the Settings account row
(AccountReorderList) and the drawer switcher (FolderDrawer), plus a
persistent banner atop the mailbox for the shown account (MailboxScreen +
MailboxViewModel.accountAuthError). String: "Please remove and re-add this
account with valid credentials".
- All AppLog breadcrumbs stay PII-free (hashed accountLogRef only).
Also merges origin/main, composing authGate with #469's GmailBandwidthTracker
in MailBackfiller/MailSyncer constructors and every test construction site.
Tests: gate latch (no self-clear / success can't clear / re-add clears),
markAccountErroredIfLatched, MailSyncer/MailBackfiller errored+latched skips,
repository reset-on-re-add, mapper round-trip, v2->v3 migration, DAO
set/clear, the mailbox banner + Settings-row Compose renders, and the
on-device gate latch. Full fast gate green (JDK 21).