Skip to content

fix: skip raw on open, validate folders, decode cached subjects, map move conflicts - #55

Merged
TheGreatAxios merged 1 commit into
cl-9436-mailbox-harden-the-send-route-recipient-injection-displayfrom
cl-9437-mailbox-stop-loading-raw-bytes-on-open-validate-folders
Sep 27, 2026
Merged

TheGreatAxios merged 1 commit into
cl-9436-mailbox-harden-the-send-route-recipient-injection-displayfrom
cl-9437-mailbox-stop-loading-raw-bytes-on-open-validate-folders

Conversation

@TheGreatAxios

@TheGreatAxios TheGreatAxios commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Stacked on fix(routes): harden POST /me/inbox/send #54.
  • openNativeMailboxStore no longer selects raw. readRaw fetches it when needed, so a list or mark-read no longer loads every frame in the folder.
  • POST /me/inbox/:uid/read and /unread return 400 for a ?folder= outside INBOX, Sent, Archive and Trash, so an unknown folder never creates a mailbox_state row. restore returns 400 for any source except Archive or Trash (the README says so).
  • persist decodes RFC 2047 encoded-words (B and Q) in the Subject it caches. @intx/mime has no decoder, so decodeEncodedWords lives in frame.ts. A word that does not decode (invalid base64, bytes invalid in its charset, an unknown charset) is left as written, and whitespace is dropped only between two encoded-words that both decode, never after a literal ?= or before an undecodable word.
  • moveNativeMailboxMessage runs in one transaction, so a failed move burns no uid. It locks both folders' mailbox_state rows up front in folder order, so opposite-direction moves queue instead of deadlocking. The archive/trash/restore routes return 404 only when the uid is missing, 409 when the destination already holds the Message-ID from the same sender (Postgres 23505), and 500 for anything else, such as a database outage.

Verification

  • e2e/mount-native.test.ts: restore?folder=INBOX|Sent|junk is 400; read/unread?folder=junk is 400 with no mailbox_state row; archiving onto a Message-ID Archive already holds is 409 with both folders' uid_next unchanged; a move against a closed connection is 500. 8 archive and 8 restore moves run interleaved return only 200/404/409 and leave 16 distinct rows with distinct (folder, uid); on fix(routes): harden POST /me/inbox/send #54 it gets deadlock 500s.
  • e2e/persist.test.ts: =?UTF-8?B?w6nDqcOp?= is cached as ééé.
  • src/frame.test.ts unit-tests decodeEncodedWords, including =?UTF-8?B?!!!!?= and a truncated UTF-8 sequence staying as written, and plain?= =?UTF-8?Q?b?= keeping its space, and =?UTF-8?Q?a?= =?UTF-8?B?!!!!?= keeping the space before the undecodable word.
  • These tests fail on fix(routes): harden POST /me/inbox/send #54. Nothing tests the dropped raw column directly; the readRaw tests cover it.
  • bun run check, build, test:e2e and the pack smoke pass locally.

Closes CL-9437

@TheGreatAxios
TheGreatAxios added this pull request to stack #50 September 27, 2026 00:56
@TheGreatAxios
TheGreatAxios force-pushed the cl-9437-mailbox-stop-loading-raw-bytes-on-open-validate-folders branch from e9377ab to b1a1a03 Compare September 27, 2026 01:23
@TheGreatAxios TheGreatAxios changed the title fix: skip raw on open, validate folders, decode cached subjects, scope dedupe fix: skip raw on open, validate folders, decode cached subjects, map move conflicts Sep 27, 2026
…move conflicts

openNativeMailboxStore no longer selects raw, since readRaw fetches it
on demand, so a list or mark-read does not load every frame in the
folder. POST /me/inbox/:uid/read and /unread 400 on a ?folder= outside
INBOX, Sent, Archive and Trash instead of creating a mailbox_state row
for it, and restore 400s on any source but Archive or Trash.

persist caches the Subject with its RFC 2047 encoded-words decoded
(@intx/mime has no decoder). A word that does not decode (bad base64,
bytes invalid in its charset, an unknown charset) stays as written, and
whitespace is dropped only between two encoded-words.

moveNativeMailboxMessage runs in one transaction, so a failed move
burns no uid. The move routes answer 404 only when the uid is missing,
409 when the destination already holds the Message-ID from the same
sender, and 500 on anything else, such as a database outage.
@TheGreatAxios
TheGreatAxios force-pushed the cl-9437-mailbox-stop-loading-raw-bytes-on-open-validate-folders branch from b1a1a03 to 0bb3dbe Compare September 27, 2026 01:39
@TheGreatAxios TheGreatAxios reopened this Sep 27, 2026
@TheGreatAxios
TheGreatAxios merged commit c0b6044 into main Sep 27, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant