Skip to content

Improve temporary mailbox, languages, and interface design - #588

Draft
ywutian wants to merge 38 commits into
maillab:mainfrom
ywutian:security/mail-boundaries
Draft

ywutian wants to merge 38 commits into
maillab:mainfrom
ywutian:security/mail-boundaries

Conversation

@ywutian

@ywutian ywutian commented Oct 3, 2026 •

Copy link
Copy Markdown

Scope

  • Keep public temporary mail available by address alone. Remove the 10-minute viewing limit for server-retained public messages, attachments, and inline images; page older messages in groups of 20. Registered, owned, and deleted mail remains outside public access.
  • Preserve locally used public addresses, full messages, and eligible attachment copies until manual clear. Queue capture of older pages so a current capture cannot silently skip them. Binary caching remains limited to 10 MiB per file and 100 MiB in total; browser storage pressure or clearing site data can remove local copies.
  • Make saved temporary addresses a visible mailbox switcher, show the selected address in the inbox header, and fix the missing switch handler. Message lists and local copies remain scoped to the selected address.
  • Repair the shared mail list component after a recent variable rename caused a runtime error and blank All Mail view. Guard list observation and administrator refresh while the component mounts. Open All Mail with all message types and ignore stale saved type filters.
  • Publish 16 complete interface dictionaries. Browser preference is the default; manual selection remains available. The registry controls script matching, page direction, dates, server responses, and home-screen manifests. Update historical-mail copy in all published languages.
  • Localize built-in role and notice previews, permission errors, request errors, and account deletion states. Prevent saving a role when its permission tree fails to load; keep selected permissions during language changes and retry.
  • Read account deletion mode and active account state from D1, reject stale or legacy deletion confirmations, and stop duplicate deletion submissions. Propagate attachment storage failures instead of reporting successful deletion; assign independent object keys to new and internally delivered attachments.
  • Add pull-request verification for the application, server, language manifests, production build, and deployment bundle.
  • Record the public mailbox read-budget incident and require production index, query-plan, and rows-read checks for future query or polling changes.
  • Reduce public inbox database reads by using the address index, repair the index on the hourly maintenance run, pause polling in background tabs, and back off after failures, and stop polling rejected addresses. Show service outages separately from invalid or registered addresses and preserve shared links during temporary failures.

Verification

  • Frontend tests: 46/46. Server unit tests: 52/52. Server language tests: 8/8. All 32 localized manifests checked; production build passed.
  • Local tests cover public history pagination, old message content, attachment and inline media access, deletion revocation, registered and owned mailbox isolation, local archive persistence, and language completeness.
  • Production browser: All Mail displays 2,867 messages after a hard refresh. The shared list also renders Inbox, Sent, and Starred without the prior blank page. A public sample mailbox shows seven messages spanning several days; an older message opens with its full body and one PDF attachment listed. Its public attachment endpoint returned HTTP 200 with application/pdf. Production switcher check: the second saved address shows an empty inbox; switching back restores the first address’s seven messages. Layout was checked at 320 and 375 px, including Arabic right-to-left.
  • The current release is deployed to both temp.okkmail.cc and box.okkmail.cc as version dda39527-c7d4-4eb9-9f3c-c2263140f099. The D1 allowance has reset and production queries are responding. The public sample was checked again after this release; authenticated production flows and a complete post-release daily read comparison remain pending.

Release and limits

The requested 100-plus languages are not yet ready to publish: 85 draft dictionaries had incorrect high-impact wording and remain outside the application. The 16 published languages passed structural and targeted semantic checks, but not complete line-by-line native-speaker review. Some editor packages remain in English.

Public mailbox history is visible to anyone who knows an address for as long as the server retains it. The app does not automatically clear local copies. The browser may briefly display a cached older application version until its service worker updates; a hard refresh loads the deployed version. Production PDF downloads completed from administrator and public entry points, with a valid PDF header and 461,882 bytes.

Database and object storage have no shared transaction; failed multi-step delivery may leave partial records or orphaned objects for follow-up cleanup. S3 versioned buckets can retain older object versions under their own retention rules. Token revocation after logout, password change, or rapid account restore can still reflect KV propagation delay; the account-deleted and disabled states themselves are checked directly in D1 on each authenticated request. The verification workflow is awaiting the upstream repository's approval to run on this forked pull request.

All Mail inline-image repair

  • All Mail details now request signed inline-image URLs through a route guarded by all-email:query; personal mail keeps owner-only access. The signed media route permits a deleted message only when the grant was issued from the authorized All Mail route.
  • The message view waits for a complete private URL map, shows a retry action on failure, and renews an old grant when the tab becomes visible again.
  • The production image object and media response were verified: PNG, 290,528 bytes, and successful rendering in a sandboxed Chromium iframe. The production D1 plans use the email primary key and idx_attachments_email_type; the two new per-message queries each read one row for the sample message. The unauthenticated All Mail media route returns an authentication error. Authenticated All Mail list, filtering, body, image and completed attachment download have now been verified. A full post-release daily D1 rows-read comparison remains pending.

Mail stability follow-up

  • Complete each mail page before displaying navigable rows; eliminate silent background detail failures and halve the previous duplicate list requests. Superseded requests cannot replace a newer mailbox or filter.
  • Guard unknown message states, empty persisted details, late image previews, account changes and logout. Private mail state is tied to the account; public local history stays intact.
  • Route All Mail attachments through the existing all-email permission, reject JSON business errors as download bytes, pause hidden-page polling and back off service failures. Retry incomplete inline-image caches without losing saved mail.
  • Add a built-application browser release check covering 1440px Chinese, 375px English, 768px German dark mode, 320px Arabic dark mode, completed PDF downloads, inline PNGs, old request races, HTTP 403 recovery, empty detail recovery, mailbox isolation and offline public mail. All sampled browser scenarios passed with no page errors or overflow.
  • Production shell files match the deployed build. Public lookup returns seven retained messages; unauthenticated admin attachment and media requests return authentication errors. At 22:46 UTC on October 8, D1 reported 103,529 rows read and 7,709 read queries for the partial day. A full post-release day is still unverified.
  • Record confirmed causes, screenshots, release gates and unverified scope in the stability review.

Authenticated production review and compose repair

  • Use the authorized administrator login to verify All Mail, owned mail, public address switching, completed PDF downloads, the previous invalid-address sample, local drafts, mobile language search, login/logout recovery and management page loading. No passwords, tokens or private mail bodies were saved in repository evidence.
  • Repair Enter search and unnamed action icons. Materialize protected inline images before reply/forward, preserve regular forwarded attachments, and handle unreadable media as an explicit error.
  • Restrict legacy send-time object reuse to inline images in undeleted mail owned by the sender. Apply and verify idx_attachments_key_type; the missing-key production sample decreased from 100 rows read to zero.
  • Make compose actions accessible, support Escape inside the editor, retain attachment edits in draft confirmation, and isolate recent recipients by account while preserving each account's records.
  • Production after deployment: quoted image decoded successfully, forwarded PDF present, keyboard search returns the intended message, saved local test draft reopens correctly, and logged-out management navigation returns to login with no private rows.
  • The browser release gate now covers reply image serialization, forward images and attachments, editor Escape and edited-attachment draft confirmation in all four representative viewport/language scenarios.
  • Actual test sending to the administrator's own mailbox remains awaiting explicit recipient authorization; third-party messages and permanent deletion were not performed. Daily D1 reads rose from 123,404 at 23:16 UTC to 123,745 at 23:21 UTC during the short production verification period; full-day load is still unverified.
  • Evidence and limits: authenticated review.

历史图片专项修复与生产验收

  • 修复阅读器误拦截外部HTTPS图片,个人/管理详情与临时邮箱共用规则,保留脚本及页面隔离。
  • 新增实际外部图片解码回归,旧版失败、新版通过。应用46、服务器52、语言8项通过,四种尺寸/语言浏览器检查通过。
  • 生产版本6565275f-8e1b-4aed-bd66-89f9c4ca3893:历史外部图片20/20、临时票据图片7/7、个人与管理原始内嵌图片1259×1295均成功。
  • 按用户最新要求仅使用历史邮件;发信链路不属于本轮验收范围,未发送测试邮件。
  • 记录与发布规则见docs/ui/mail-authenticated-review-2026-10-08.md、AGENTS.md及DEPLOY.md。

ywutian added 16 commits August 28, 2026 23:58
后端
- 新增 /open 免鉴权接口:查最近 10 分钟的信、返回域名列表
- email-service 加 addressList()(按地址聚合)和 claimNoOne()(认领无归属邮件)
- 添加邮箱时自动把该地址的历史邮件收编进收件箱
- temp.* 根路径重定向到 /find

前端
- 新增 /find 公开临时邮箱页(免登录,固定暗色)
- 新增 /addresses 地址记录页
- 收件箱顶部随机地址条,点复制才建号
- email-scroll 加 header slot,修 grid 行数导致的空白
- 移除「关于」区块和 GitHub 版本检查请求

另附 DEPLOY.md 记录部署方式和几个反直觉的默认值
- 新增 /open/mailContent,读正文必须 emailId 和 address 同时匹配,
  否则任何人都能从 1 开始遍历 id 读别人的信
- 正文用 iframe 渲染:sandbox 不给 allow-scripts 和 allow-same-origin,
  脚本、内联事件、javascript: 链接一律不执行,邮件自带的 style 也污染不到本页,
  因此不需要再引一个 sanitize 库
- 清掉「关于」区块留下的三个孤儿变量和空函数
- DEPLOY.md 补上 pnpm 依赖检查和 API token 部署两个坑
@ywutian ywutian changed the title Complete temporary mailbox and multilingual experience Improve temporary mailbox, languages, and interface design Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants