Files
LibreMail/secrets.properties.example
T
JMR-devandClaude Opus 4.8 038cfd6153 Fix correctness, security, and concurrency issues from code review
Addresses findings from a full-repo review across the mail, sync, persistence,
auth, and UI layers.

Send / outbox:
- Stop the Graph->SMTP fallback from duplicating a message when a Graph send may
  already have been accepted; leave indeterminate sends queued for the user.
- Parse RFC822 display-name recipients on the Graph path.
- Preserve attachment order (staged in indexed subdirectories).

Data safety (schema v7):
- Disable cloud/device backup of the Keystore-encrypted credential DB.
- Add the missing v1->v2 migration and drop the destructive migration fallback.
- Normalize the messages.isHtml default and add an attachments->messages
  ON DELETE CASCADE foreign key (no more orphaned attachment rows).

Concurrency:
- Serialize syncing and per-account OAuth token refresh; cache tokens by expiry.
- Synchronize Android Keystore key creation.
- Make a sync's persist+notify non-cancellable so an IDLE renewal can't drop it.

Notifications / UI:
- Per-message notifications under a group + summary instead of one overwriting id.
- Wire the "load remote images" and "allow STARTTLS" settings.
- Harden the reader WebView (scheme allowlist + user gesture; no reload on
  recomposition); refresh headers without reverting optimistic read/star flags.
- Persist draft attachments; keep server-search hits out of the inbox; encode
  the reader navigation argument.

Build / test:
- Export Room schemas; support a real release keystore; add unit/db tests.
- Remove dead Gmail account-setup code left after the sign-in removal.

Verified: debug + release (R8) + androidTest compile; unit tests pass;
MIGRATION_6_7 matches the generated v7 schema.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-29 18:15:53 -05:00

19 lines
860 B
Plaintext

# Copy this file to `secrets.properties` (which is git-ignored) and fill in the value.
#
# Gmail OAuth 2.0 *Android* client ID created in Google Cloud Console.
# See the README ("Gmail account setup") for the exact steps. Used by the app for
# the Authorization Code + PKCE login flow; no client secret is required for an
# installed Android app.
GMAIL_OAUTH_CLIENT_ID=
# Optional: Microsoft (Outlook) OAuth public client id. A working default ships with the build;
# set this only to use your own Azure app registration.
#OUTLOOK_OAUTH_CLIENT_ID=
# Optional: release signing. When these are set, release builds are signed with this keystore;
# otherwise they fall back to the debug key (installable for testing, but not publishable).
#RELEASE_STORE_FILE=/absolute/path/to/release.keystore
#RELEASE_STORE_PASSWORD=
#RELEASE_KEY_ALIAS=
#RELEASE_KEY_PASSWORD=