MAIL M3: send and actions (DESIGN §45) — after M2 #397

Open
opened 2026-09-29 04:40:51 +00:00 by kayg · 49 comments
Owner

MAIL M3: send and actions (DESIGN §45) — after M2

Composer for mail (the shared Composer: desktop overlay, phone sheet, draft deck, commit-freeze, Cmd/Ctrl+Enter sends; From/To/Cc/Bcc), HTML + text/plain alternative, plain-text with format=flowed, SMTP with the account's app password, Sent folder sync, reply/reply-all/forward, the first-release actions list in §45 (archive, delete, move, mark, snooze if decided, Share…), iMIP invitation replies (never automatic). Parity (#395). Gates as §45. Start after M2 merges (shared reader and routes).

## MAIL M3: send and actions (DESIGN §45) — after M2 Composer for mail (the shared Composer: desktop overlay, phone sheet, draft deck, commit-freeze, Cmd/Ctrl+Enter sends; From/To/Cc/Bcc), HTML + text/plain alternative, plain-text with format=flowed, SMTP with the account's app password, Sent folder sync, reply/reply-all/forward, the first-release actions list in §45 (archive, delete, move, mark, snooze if decided, Share…), iMIP invitation replies (never automatic). Parity (#395). Gates as §45. Start after M2 merges (shared reader and routes).
Author
Owner

Starting Mail M3 on job/mail-m3, based on dfb5964a2fcf13dc8b9a50a319eee09bc386f322 (origin/dev). I am reading #396 and the merged M2 routes/components before implementing the send and actions slice from #397 and DESIGN §45.

Starting Mail M3 on `job/mail-m3`, based on `dfb5964a2fcf13dc8b9a50a319eee09bc386f322` (`origin/dev`). I am reading #396 and the merged M2 routes/components before implementing the send and actions slice from #397 and DESIGN §45.
Author
Owner

Finding: M1 stores the SMTP endpoint and app password in each encrypted Mail account, but Mail currently has no SMTP send route. The existing IMAP connection code also pins a validated public DNS result; SMTP must use the same host policy and pin one resolved address so a user-configured server cannot redirect a send to a private network. I am reusing the account credential boundary and adding a bounded idempotent send operation.

Finding: M1 stores the SMTP endpoint and app password in each encrypted Mail account, but Mail currently has no SMTP send route. The existing IMAP connection code also pins a validated public DNS result; SMTP must use the same host policy and pin one resolved address so a user-configured server cannot redirect a send to a private network. I am reusing the account credential boundary and adding a bounded idempotent send operation.
Author
Owner

Backend send slice committed as 779312c82.

Added owner-scoped POST /accounts/{id}/send with MIME construction, TLS SMTP over the validated pinned IP, Bcc-only envelope handling, a bounded provider protocol, durable idempotency metadata, and a queued normal account sync after acceptance. The database stores a payload digest and SMTP state; it does not store recipients, message bodies, or credentials. A Mail route test proves cross-User 404, retry returns the original Message-ID without a second transport call, and reusing a key for changed content returns 409.

Gates for this slice:

  • cargo fmt --check: passed.
  • cargo test -p calternal-plugin-mail: 41 passed; 0 failed.
  • cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings: passed.

Decisions: raw SMTP is used so connection setup can reuse the IMAP public-DNS validation and pinning policy. mail-builder 1.0.0 builds MIME. If SMTP ends with an uncertain result, the request is not retried automatically; the User checks Sent before starting a new request.

Remaining in #397: shared Composer integration, Sent sync/UI actions, iMIP invitation replies, adversarial probe, generated contract, parity, and production screenshots.

Backend send slice committed as 779312c82. Added owner-scoped POST /accounts/{id}/send with MIME construction, TLS SMTP over the validated pinned IP, Bcc-only envelope handling, a bounded provider protocol, durable idempotency metadata, and a queued normal account sync after acceptance. The database stores a payload digest and SMTP state; it does not store recipients, message bodies, or credentials. A Mail route test proves cross-User 404, retry returns the original Message-ID without a second transport call, and reusing a key for changed content returns 409. Gates for this slice: - `cargo fmt --check`: passed. - `cargo test -p calternal-plugin-mail`: `41 passed; 0 failed`. - `cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings`: passed. Decisions: raw SMTP is used so connection setup can reuse the IMAP public-DNS validation and pinning policy. `mail-builder` 1.0.0 builds MIME. If SMTP ends with an uncertain result, the request is not retried automatically; the User checks Sent before starting a new request. Remaining in #397: shared Composer integration, Sent sync/UI actions, iMIP invitation replies, adversarial probe, generated contract, parity, and production screenshots.
Author
Owner

M3 finding: the M2 Mail API had no provider Drafts write route. I added owner-scoped save and delete routes. They resolve the synchronized Drafts special-use folder and replace only messages with the draft UUID marker; removal uses UID EXPUNGE and does not expunge unrelated mailbox messages. Offline edits remain in the bounded User-scoped local deck.

M3 finding: the M2 Mail API had no provider Drafts write route. I added owner-scoped save and delete routes. They resolve the synchronized Drafts special-use folder and replace only messages with the draft UUID marker; removal uses UID EXPUNGE and does not expunge unrelated mailbox messages. Offline edits remain in the bounded User-scoped local deck.
Author
Owner

M3 progress at 063afe7c1: Mail sends now keep Bcc on the SMTP envelope only, and provider Drafts use owner-scoped save/delete routes. Draft replacement uses a stable UUID header, accepts only the synchronized Drafts special-use folder, and UID EXPUNGE removes only matching provider copies. Mail gates at this commit: cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings passed; cargo test -p calternal-plugin-mail passed 43 tests, 0 failed. I also added anonymous/foreign-owner and malformed/oversized send/draft probes, and classified the new OpenAPI routes in the cross-user matrix.

M3 progress at `063afe7c1`: Mail sends now keep Bcc on the SMTP envelope only, and provider Drafts use owner-scoped save/delete routes. Draft replacement uses a stable UUID header, accepts only the synchronized Drafts special-use folder, and UID EXPUNGE removes only matching provider copies. Mail gates at this commit: `cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings` passed; `cargo test -p calternal-plugin-mail` passed 43 tests, 0 failed. I also added anonymous/foreign-owner and malformed/oversized send/draft probes, and classified the new OpenAPI routes in the cross-user matrix.
Author
Owner

M3 UI progress at 109de69c4: Compose, Reply, Reply all, and Forward now use the shared app Composer and Mail editor profile. The composer has From/To/Cc/Bcc, address chips, rich/plain editing, a bounded User-scoped offline deck, and provider autosave. I chose /mail?draft=<uuid> because DESIGN §33 does not define a composer-draft route; this restores the User's local draft deck. Remote draft retrieval for a link opened on another device is still missing. The production web build passed; type and API gates remain pending the generated contract.

M3 UI progress at `109de69c4`: Compose, Reply, Reply all, and Forward now use the shared app Composer and Mail editor profile. The composer has From/To/Cc/Bcc, address chips, rich/plain editing, a bounded User-scoped offline deck, and provider autosave. I chose `/mail?draft=<uuid>` because DESIGN §33 does not define a composer-draft route; this restores the User's local draft deck. Remote draft retrieval for a link opened on another device is still missing. The production web build passed; type and API gates remain pending the generated contract.
Author
Owner

Web test finding for #397: bun run test in apps/web is still running. Vitest has reported failures in src/lib/components/analytics/widgets/StatRow.svelte.test.ts (uses the shared type roles and never mono) and src/lib/components/SidebarSectionHeader.svelte.test.ts (uses the next shared type step and semibold weight for section labels). Neither file is part of the Mail changes. I will report the completed suite output with the final gates.

Web test finding for #397: `bun run test` in `apps/web` is still running. Vitest has reported failures in `src/lib/components/analytics/widgets/StatRow.svelte.test.ts` (`uses the shared type roles and never mono`) and `src/lib/components/SidebarSectionHeader.svelte.test.ts` (`uses the next shared type step and semibold weight for section labels`). Neither file is part of the Mail changes. I will report the completed suite output with the final gates.
Author
Owner

Mail M3 time-boxed report

Head: 44335f10dba9753d5db856a6eda6fb98b311f400 (Use shared shape tokens in Mail composer). origin/dev was fetched and merged once at 2030bbafd; the merge was clean. Mail migration 0009_send_requests.sql remains the next number after origin/dev's 0008_reader_actions.sql.

Built

  • Authenticated SMTP send with request-idempotency, bounded MIME construction, TLS and pinned public DNS; send results do not expose provider replies or message content.
  • Owner-scoped provider Drafts save/delete, UUID-marked replacement, safe UID EXPUNGE, and append-before-delete ordering so an APPEND failure preserves the existing draft.
  • Shared Mail composer and recipient chips, plain/rich body editing with the portable editor profile, offline draft deck, provider autosave, reply/reply-all/forward, send, and copy-link action.
  • OpenAPI and generated TypeScript contract for send and Drafts. The Mail routes are classified in the xuser matrix and the adversarial Mail probe covers send/Drafts inputs and ownership.
  • The draft deep link uses /mail?draft=<uuid> and restores the signed-in User's local deck. This is the simplest stable identity compatible with the existing query-based Mail subviews; DESIGN §33 does not define a composer URL grammar.

Commits: 779312c82, c31387c97, 063afe7c1, 109de69c4, 3ce6ba5cf, d0add2429, 44335f10d.

Gate results

  • cargo fmt --check: exit 0, no output.
  • bun run build: passed on the merged tree. Output:
    ✓ built in 3m 15s
    
    Run npm run preview to preview your production build locally.
    
    > Using @sveltejs/adapter-static
      Wrote site to "build"
      ✔ done
    
  • bun run check: first run found the two Mail shape literals, which were changed to --radius-none and --radius-circle. The rerun printed Text sizes and UI shape values use shared role tokens. and continued into svelte-check, but did not finish before the four-hour cap.
  • bun run test: 135 test files passed and 2 failed; 877 tests passed and 2 failed. Both failures were Vitest 5-second timeouts in SidebarSectionHeader.svelte.test.ts and analytics/widgets/StatRow.svelte.test.ts after the origin/dev merge. The exact output ended:
    Test Files  2 failed | 135 passed (137)
         Tests  2 failed | 877 passed (879)
    error: script "test" exited with code 1
    
  • Before the last IMAP ordering fix and the origin/dev merge, cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings passed and cargo test -p calternal-plugin-mail passed 43 tests. The post-merge test command started compiling the Mail crate but did not finish before the cap. Post-merge server Clippy/tests were not completed.
  • OpenAPI and packages/api-client/src/generated.ts were regenerated and committed. packages/api-client/check-generated.sh did not finish within the cap. The parity check was not run.
  • python3 -m py_compile tests/adversarial/xuser_matrix.py, node --check tests/adversarial/mail_api.mjs, and git diff --check passed earlier. The real-server adversarial round was not run.
  • The production build completed, but no screenshot matrix was captured or attached. The 390/820/1440 light/dark captures remain outstanding.

Known M3 gaps

Archive/move/trash, flag/junk, undo and offline action queue, linked reminder tasks, invite clash checks and iMIP, save/print/export actions, signatures, and provider Draft retrieval across devices are not implemented in this slice. CLI, MCP and WebMCP parity for send and Drafts also remains open. A copied provider draft link on another device cannot load the provider draft because no provider GET/list route exists yet.

The four-hour cap stopped the remaining checks; this report records that state without treating the issue as fully verified.

## Mail M3 time-boxed report Head: `44335f10dba9753d5db856a6eda6fb98b311f400` (`Use shared shape tokens in Mail composer`). `origin/dev` was fetched and merged once at `2030bbafd`; the merge was clean. Mail migration `0009_send_requests.sql` remains the next number after `origin/dev`'s `0008_reader_actions.sql`. ### Built - Authenticated SMTP send with request-idempotency, bounded MIME construction, TLS and pinned public DNS; send results do not expose provider replies or message content. - Owner-scoped provider Drafts save/delete, UUID-marked replacement, safe UID EXPUNGE, and append-before-delete ordering so an APPEND failure preserves the existing draft. - Shared Mail composer and recipient chips, plain/rich body editing with the portable editor profile, offline draft deck, provider autosave, reply/reply-all/forward, send, and copy-link action. - OpenAPI and generated TypeScript contract for send and Drafts. The Mail routes are classified in the xuser matrix and the adversarial Mail probe covers send/Drafts inputs and ownership. - The draft deep link uses `/mail?draft=<uuid>` and restores the signed-in User's local deck. This is the simplest stable identity compatible with the existing query-based Mail subviews; DESIGN §33 does not define a composer URL grammar. Commits: `779312c82`, `c31387c97`, `063afe7c1`, `109de69c4`, `3ce6ba5cf`, `d0add2429`, `44335f10d`. ### Gate results - `cargo fmt --check`: exit 0, no output. - `bun run build`: passed on the merged tree. Output: ``` ✓ built in 3m 15s Run npm run preview to preview your production build locally. > Using @sveltejs/adapter-static Wrote site to "build" ✔ done ``` - `bun run check`: first run found the two Mail shape literals, which were changed to `--radius-none` and `--radius-circle`. The rerun printed `Text sizes and UI shape values use shared role tokens.` and continued into `svelte-check`, but did not finish before the four-hour cap. - `bun run test`: 135 test files passed and 2 failed; 877 tests passed and 2 failed. Both failures were Vitest 5-second timeouts in `SidebarSectionHeader.svelte.test.ts` and `analytics/widgets/StatRow.svelte.test.ts` after the origin/dev merge. The exact output ended: ``` Test Files 2 failed | 135 passed (137) Tests 2 failed | 877 passed (879) error: script "test" exited with code 1 ``` - Before the last IMAP ordering fix and the origin/dev merge, `cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings` passed and `cargo test -p calternal-plugin-mail` passed 43 tests. The post-merge test command started compiling the Mail crate but did not finish before the cap. Post-merge server Clippy/tests were not completed. - OpenAPI and `packages/api-client/src/generated.ts` were regenerated and committed. `packages/api-client/check-generated.sh` did not finish within the cap. The parity check was not run. - `python3 -m py_compile tests/adversarial/xuser_matrix.py`, `node --check tests/adversarial/mail_api.mjs`, and `git diff --check` passed earlier. The real-server adversarial round was not run. - The production build completed, but no screenshot matrix was captured or attached. The 390/820/1440 light/dark captures remain outstanding. ### Known M3 gaps Archive/move/trash, flag/junk, undo and offline action queue, linked reminder tasks, invite clash checks and iMIP, save/print/export actions, signatures, and provider Draft retrieval across devices are not implemented in this slice. CLI, MCP and WebMCP parity for send and Drafts also remains open. A copied provider draft link on another device cannot load the provider draft because no provider GET/list route exists yet. The four-hour cap stopped the remaining checks; this report records that state without treating the issue as fully verified.
Author
Owner

Resuming Mail M3 on job/mail-m3 at base/head 44335f10dba9753d5db856a6eda6fb98b311f400. I read the prior time-boxed report and am completing the pending gates and adversarial probes first, then continuing the remaining M3 actions in DESIGN §45 order. No uncommitted changes were present at resume.

Resuming Mail M3 on `job/mail-m3` at base/head `44335f10dba9753d5db856a6eda6fb98b311f400`. I read the prior time-boxed report and am completing the pending gates and adversarial probes first, then continuing the remaining M3 actions in DESIGN §45 order. No uncommitted changes were present at resume.
Author
Owner

M3 finding: the composer has the one-action rich/plain switch, and Mail thread/message queries are newest-first by received_ms DESC. The composer and Settings → Mail do not have the §45 per-app signature-note library, per-account default assignment, or draft signature switch. I am recording this explicit gap as requested; the current M3 worktree has no signature API or note-library connection to extend.

M3 finding: the composer has the one-action rich/plain switch, and Mail thread/message queries are newest-first by `received_ms DESC`. The composer and Settings → Mail do not have the §45 per-app signature-note library, per-account default assignment, or draft signature switch. I am recording this explicit gap as requested; the current M3 worktree has no signature API or note-library connection to extend.
Author
Owner

Gate finding on the resumed merged tree: bun run test completed in 389.54 s with 137 files passed and 1 failed (888 tests passed, 1 failed). The only failure was src/lib/components/ThemePicker.svelte.test.ts → “opens dark variants as a keyboard submenu and checks the selected variant”, timed out at 5000 ms. SidebarSectionHeader.svelte.test.ts and analytics/widgets/StatRow.svelte.test.ts both passed in this full run; I am running those two files alone now as requested.

Gate finding on the resumed merged tree: `bun run test` completed in 389.54 s with 137 files passed and 1 failed (888 tests passed, 1 failed). The only failure was `src/lib/components/ThemePicker.svelte.test.ts` → “opens dark variants as a keyboard submenu and checks the selected variant”, timed out at 5000 ms. `SidebarSectionHeader.svelte.test.ts` and `analytics/widgets/StatRow.svelte.test.ts` both passed in this full run; I am running those two files alone now as requested.
Author
Owner

Isolated rerun completed for the two files named in the prior time-boxed report:

$ bun run test -- src/lib/components/SidebarSectionHeader.svelte.test.ts src/lib/components/analytics/widgets/StatRow.svelte.test.ts
Could not parse CSS stylesheet

 Test Files  2 passed (2)
      Tests  17 passed (17)
   Start at  10:08:01
   Duration  76.94s (transform 88%, import 4%, tests 3%, environment 2%, setup 2%)

Both earlier timeout candidates pass when run alone. The full-suite ThemePicker timeout is separate and was not rerun yet.

Isolated rerun completed for the two files named in the prior time-boxed report: ``` $ bun run test -- src/lib/components/SidebarSectionHeader.svelte.test.ts src/lib/components/analytics/widgets/StatRow.svelte.test.ts Could not parse CSS stylesheet Test Files 2 passed (2) Tests 17 passed (17) Start at 10:08:01 Duration 76.94s (transform 88%, import 4%, tests 3%, environment 2%, setup 2%) ``` Both earlier timeout candidates pass when run alone. The full-suite ThemePicker timeout is separate and was not rerun yet.
Author
Owner

Gate finding: after the direct Mail Editor import removed the first TypeScript diagnostic, bun run check reported five errors in packages/editor/src/extensions.ts. Three are from unchecked Range.getClientRects()[0] access; two are from assuming heading and paragraph nodes exist in every ProseMirror schema. I am adding bounds/node-presence handling at those two call sites and will rerun the full check.

Gate finding: after the direct Mail Editor import removed the first TypeScript diagnostic, `bun run check` reported five errors in `packages/editor/src/extensions.ts`. Three are from unchecked `Range.getClientRects()[0]` access; two are from assuming `heading` and `paragraph` nodes exist in every ProseMirror schema. I am adding bounds/node-presence handling at those two call sites and will rerun the full check.
Author
Owner

Slice committed as 1f5dc75ee (Fix Mail editor type checking). Mail now imports the shared editor from its explicit Svelte component export so the mail profile prop is typed. The editor uses the first range rect through item(0) and leaves setext input unchanged when a partial schema lacks heading or paragraph nodes.

Verification:

  • bun run check: svelte-check found 0 errors and 0 warnings.
  • Focused editor test: Test Files 1 passed (1); Tests 1 passed (1).
  • Full web suite: Test Files 1 failed | 137 passed (138); Tests 1 failed | 888 passed (889), one 5 s ThemePicker timeout. Focused rerun: ThemePicker 2 passed; the two previously reported timeout files 17 passed.
Slice committed as `1f5dc75ee` (`Fix Mail editor type checking`). Mail now imports the shared editor from its explicit Svelte component export so the `mail` profile prop is typed. The editor uses the first range rect through `item(0)` and leaves setext input unchanged when a partial schema lacks heading or paragraph nodes. Verification: - `bun run check`: `svelte-check found 0 errors and 0 warnings`. - Focused editor test: `Test Files 1 passed (1); Tests 1 passed (1)`. - Full web suite: `Test Files 1 failed | 137 passed (138); Tests 1 failed | 888 passed (889)`, one 5 s ThemePicker timeout. Focused rerun: ThemePicker `2 passed`; the two previously reported timeout files `17 passed`.
Author
Owner

Server gates passed on the merged tree:

  • cargo clippy -p calternal-server --all-targets -- -D warnings: exit 0; Finished dev profile [unoptimized + debuginfo] target(s) in 46m 51s.
  • cargo test -p calternal-server: test result: ok. 85 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 39.95s (test-profile compile took 22m 07s).
Server gates passed on the merged tree: - `cargo clippy -p calternal-server --all-targets -- -D warnings`: exit 0; `Finished `dev` profile [unoptimized + debuginfo] target(s) in 46m 51s`. - `cargo test -p calternal-server`: `test result: ok. 85 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 39.95s` (test-profile compile took 22m 07s).
Author
Owner

Parity finding on the resumed tree: python3 scripts/parity_matrix.py --check returned Parity gaps changed; review them and run --accept-current-gaps. The composer’s send and provider-Drafts calls add web API operations whose CLI/MCP/WebMCP adapters were already recorded as open in the prior time-boxed report. I am regenerating the source-backed inventory so the exact route gaps are visible and checked rather than omitted.

Parity finding on the resumed tree: `python3 scripts/parity_matrix.py --check` returned `Parity gaps changed; review them and run --accept-current-gaps`. The composer’s send and provider-Drafts calls add web API operations whose CLI/MCP/WebMCP adapters were already recorded as open in the prior time-boxed report. I am regenerating the source-backed inventory so the exact route gaps are visible and checked rather than omitted.
Author
Owner

Contract/parity slice committed as 7ddf9537c (Record Mail composer parity gaps).

  • packages/api-client/check-generated.sh: exit 0. The server OpenAPI command completed; openapi-typescript 7.13.0 regenerated packages/api-client/src/generated.ts; the contract diff check passed with no generated source changes.
  • python3 scripts/parity_matrix.py --check: passed. Output: Parity matrix: 190 web API actions, 113 shortcuts, 2 static commands, 135 menu actions, 30 settings groups, 172 actions with adapter gaps.
  • The reviewed inventory records mail_send, mail_save_draft, and mail_delete_draft as missing from CLI, MCP and WebMCP. This parity work remains open; the matrix makes the gap visible rather than counting the web-only routes as parity.
Contract/parity slice committed as `7ddf9537c` (`Record Mail composer parity gaps`). - `packages/api-client/check-generated.sh`: exit 0. The server OpenAPI command completed; `openapi-typescript 7.13.0` regenerated `packages/api-client/src/generated.ts`; the contract diff check passed with no generated source changes. - `python3 scripts/parity_matrix.py --check`: passed. Output: `Parity matrix: 190 web API actions, 113 shortcuts, 2 static commands, 135 menu actions, 30 settings groups, 172 actions with adapter gaps`. - The reviewed inventory records `mail_send`, `mail_save_draft`, and `mail_delete_draft` as missing from CLI, MCP and WebMCP. This parity work remains open; the matrix makes the gap visible rather than counting the web-only routes as parity.
Author
Owner

Finding and fix: an accepted SMTP retry looked up its idempotency row only after credential decryption, so retrying with a rotated or unavailable credential returned HTTP 500 instead of the stored result. I reproduced this with the Mail route test after corrupting the stored ciphertext; it failed 500 vs 200. The route now checks the owner-scoped payload digest before provider work, while checking that the account remains enabled first. The regression test now passes and confirms the mock sender is called once.

Commit: 7db2b0b057. Gates: cargo fmt --check, cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings, and cargo test -p calternal-plugin-mail passed; 43 passed, 0 failed.

Finding and fix: an accepted SMTP retry looked up its idempotency row only after credential decryption, so retrying with a rotated or unavailable credential returned HTTP 500 instead of the stored result. I reproduced this with the Mail route test after corrupting the stored ciphertext; it failed 500 vs 200. The route now checks the owner-scoped payload digest before provider work, while checking that the account remains enabled first. The regression test now passes and confirms the mock sender is called once. Commit: 7db2b0b05758642cefa32308fe0265d0ad2d3a7b. Gates: `cargo fmt --check`, `cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings`, and `cargo test -p calternal-plugin-mail` passed; 43 passed, 0 failed.
Author
Owner

Finding: the production build crashes when the lazy Mail composer opens. Playwright reports ReferenceError: Cannot access 'Q' before initialization in the composer chunk; the visible Compose action leaves no composer mounted. The instance creates its initial draft before initializing the derived enabled-account list, but the draft factory reads that list for its default account. I am moving the derived list before the initial draft state and will use the production screenshot flow as the regression check.

Finding: the production build crashes when the lazy Mail composer opens. Playwright reports `ReferenceError: Cannot access 'Q' before initialization` in the composer chunk; the visible Compose action leaves no composer mounted. The instance creates its initial draft before initializing the derived enabled-account list, but the draft factory reads that list for its default account. I am moving the derived list before the initial draft state and will use the production screenshot flow as the regression check.
Author
Owner

Follow-up finding: once the composer mounted, autosave raised DataCloneError because structuredClone received Svelte $state proxy arrays. This interrupted the form before recipient inputs became available. I replaced the structured clone with a small explicit copy of the draft and its recipient records; the production capture flow checks that the fields render and remain editable.

Follow-up finding: once the composer mounted, autosave raised `DataCloneError` because `structuredClone` received Svelte `$state` proxy arrays. This interrupted the form before recipient inputs became available. I replaced the structured clone with a small explicit copy of the draft and its recipient records; the production capture flow checks that the fields render and remain editable.
Author
Owner

Composer runtime fixes are committed as dd4d720dc.

  • Fixed the lazy-open TDZ by initializing the enabled-account derived list before creating the default draft.
  • Replaced structuredClone on Svelte state with explicit plain copies for recipient arrays and quote data; this preserves autosave and recipient entry.
  • Put the desktop Composer in the dialog surface and the phone Composer in the sheet surface so the content stays within the surface.

bun run check passed with 0 errors and 0 warnings before this comment-only follow-up. The production Mail probe captured all requested Composer states at 390, 820 and 1440 px in light and dark themes. The run later stopped in the new-message screenshot helper on a duplicate title locator; I am correcting the probe separately.

Composer runtime fixes are committed as `dd4d720dc`. - Fixed the lazy-open TDZ by initializing the enabled-account derived list before creating the default draft. - Replaced `structuredClone` on Svelte state with explicit plain copies for recipient arrays and quote data; this preserves autosave and recipient entry. - Put the desktop Composer in the dialog surface and the phone Composer in the sheet surface so the content stays within the surface. `bun run check` passed with 0 errors and 0 warnings before this comment-only follow-up. The production Mail probe captured all requested Composer states at 390, 820 and 1440 px in light and dark themes. The run later stopped in the new-message screenshot helper on a duplicate title locator; I am correcting the probe separately.
Author
Owner

The real-server Mail adversarial round passed on the production web build. Commit: 2cbefa7da.

The exact probe summary was:

Mail API probe: remote-content isolation, hostile IDs and headers, accepted send replay, disabled-account send, oversized attachment rejection, cross-User message/thread/draft isolation, safe attachment names and 24 parallel account/Inbox reads passed

Attached production screenshots cover 390, 820 and 1440 px in light and dark themes:

The real-server Mail adversarial round passed on the production web build. Commit: `2cbefa7da`. The exact probe summary was: > Mail API probe: remote-content isolation, hostile IDs and headers, accepted send replay, disabled-account send, oversized attachment rejection, cross-User message/thread/draft isolation, safe attachment names and 24 parallel account/Inbox reads passed Attached production screenshots cover 390, 820 and 1440 px in light and dark themes: - New: [390 light](https://git.kayg.org/attachments/95b2ee44-12d6-42f4-958a-5c58fc2b9715), [390 dark](https://git.kayg.org/attachments/c2c78b9f-65d3-4903-ba0b-de2e9c97d12b), [820 light](https://git.kayg.org/attachments/ee9534f4-ceb1-40ce-aa1f-364fa7c4d41e), [820 dark](https://git.kayg.org/attachments/cda22883-dfb2-4fd0-9e61-ceaf4a819091), [1440 light](https://git.kayg.org/attachments/9799e7fd-6bb3-496c-896b-6a1ab40df3af), [1440 dark](https://git.kayg.org/attachments/76ecbf0d-5465-4424-8247-8eef3ca2cd33) - Reply: [390 light](https://git.kayg.org/attachments/76f5e7b6-7aec-4a9f-ab92-814d07cc8eb9), [390 dark](https://git.kayg.org/attachments/cf411226-913c-48a0-8385-84adb1b0f438), [820 light](https://git.kayg.org/attachments/8799aa64-5e98-426f-a468-93d08cbc9fc1), [820 dark](https://git.kayg.org/attachments/bf21e051-79dc-4cce-b98b-8d6550bfdd72), [1440 light](https://git.kayg.org/attachments/f9d57633-78a7-48fb-b3ad-e062d2d62832), [1440 dark](https://git.kayg.org/attachments/a38ccdb8-3039-4a22-a70a-6d90fbd9497a) - Forward: [390 light](https://git.kayg.org/attachments/e631c985-965a-4c4e-88ed-70ea36f32c66), [390 dark](https://git.kayg.org/attachments/9844dc93-8799-4053-b034-2a5852af64cb), [820 light](https://git.kayg.org/attachments/ef911a69-e7b2-44aa-a610-a862b2bb32a5), [820 dark](https://git.kayg.org/attachments/c0b404c0-019c-4383-bd59-a222eb5ed72b), [1440 light](https://git.kayg.org/attachments/b679a0fc-ba3c-4ad7-acdd-65a0cab18919), [1440 dark](https://git.kayg.org/attachments/368c0d0f-3675-40da-908b-1d1487bd5ee3) - Recipient chips: [390 light](https://git.kayg.org/attachments/337a5082-5eb4-4334-9eac-0b0265ea96bc), [390 dark](https://git.kayg.org/attachments/b38b222b-b76a-441b-844b-fbe7e018305b), [820 light](https://git.kayg.org/attachments/e3197912-9dcf-4218-a3e2-267c5ca6d6b8), [820 dark](https://git.kayg.org/attachments/3bcae3c6-cb46-4afb-9c86-9cd00e3d34fa), [1440 light](https://git.kayg.org/attachments/614eefc8-3ee7-4620-a435-e61e819b2f26), [1440 dark](https://git.kayg.org/attachments/2ab5c583-cfdc-43b6-a59d-61dfa72c0cbc) - Saved draft: [390 light](https://git.kayg.org/attachments/039d6537-8b80-4473-8e73-94016d8bca98), [390 dark](https://git.kayg.org/attachments/37adba73-bfa4-4b54-bf85-81abe3a54e65), [820 light](https://git.kayg.org/attachments/0fddfeb9-c8e4-4e71-8f28-698049579e40), [820 dark](https://git.kayg.org/attachments/9f51cf43-d242-4cd0-977d-0194afc65f48), [1440 light](https://git.kayg.org/attachments/e5dc8bb6-b9f1-4f46-aa7a-f26b1f6c1983), [1440 dark](https://git.kayg.org/attachments/eadb4f28-3c3b-4f88-bca2-60458d633d01) - Send error: [390 light](https://git.kayg.org/attachments/145546b2-f5ce-4a1e-b7b5-67ef9995b0fc), [390 dark](https://git.kayg.org/attachments/66b34a19-b89c-4e77-8553-3e3dfef2398b), [820 light](https://git.kayg.org/attachments/321eac5d-35ad-4de4-874b-a426973a94a2), [820 dark](https://git.kayg.org/attachments/056ebed2-96d8-4c88-8ef0-5aac2bb60f64), [1440 light](https://git.kayg.org/attachments/16ac5504-488a-4de0-84e6-09ca52300106), [1440 dark](https://git.kayg.org/attachments/03960a01-0eba-4a97-8020-cad9ed66e612)
Author
Owner

M3 action API slice is implemented on job/mail-m3: owner-scoped Archive, Move and Trash requests now capture live UID identity, persist idempotency state and run through the JobQueue. The route tests cover queue/replay, changed-payload conflict, foreign-User status and stale-generation rejection. Mail plugin gates: cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings passed; cargo test -p calternal-plugin-mail passed (47 tests).

Decision not specified in DESIGN: the worker uses IMAP UID MOVE as the only provider mutation. If the server does not advertise MOVE, the durable action becomes failed. I chose this because a COPY+EXPUNGE fallback cannot make replay safe after an interrupted request.

M3 action API slice is implemented on `job/mail-m3`: owner-scoped Archive, Move and Trash requests now capture live UID identity, persist idempotency state and run through the JobQueue. The route tests cover queue/replay, changed-payload conflict, foreign-User status and stale-generation rejection. Mail plugin gates: `cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings` passed; `cargo test -p calternal-plugin-mail` passed (47 tests). Decision not specified in DESIGN: the worker uses IMAP `UID MOVE` as the only provider mutation. If the server does not advertise MOVE, the durable action becomes failed. I chose this because a COPY+EXPUNGE fallback cannot make replay safe after an interrupted request.
Author
Owner

Action API slice committed: 9932353d5120c7bb3c85d99b846e1e77968a4171 (feat(mail): queue idempotent folder actions). The Mail plugin clippy gate passed and all 47 Mail plugin tests passed. The action request row captures owner, source generation, UIDVALIDITY and UID; the worker rechecks them under the shared per-account sync lock before atomic UID MOVE.

Action API slice committed: `9932353d5120c7bb3c85d99b846e1e77968a4171` (`feat(mail): queue idempotent folder actions`). The Mail plugin clippy gate passed and all 47 Mail plugin tests passed. The action request row captures owner, source generation, UIDVALIDITY and UID; the worker rechecks them under the shared per-account sync lock before atomic UID MOVE.
Author
Owner

Per-message Archive, Move to, and Move to Trash are now exposed in both the message overflow menu and the page action menu. Move destinations come from selectable folders on the message's account. Touch/pen swipes archive left and copy the stable message link right. The UI polls the durable action state and refreshes only after completion.

Commit: 06aba445334ca5f0aa82f484229ac35d1597ba74 (feat(mail): expose per-message folder actions). Web check passed with 0 errors and 0 warnings. Full Vitest run: 138 files and 889 tests passed. Isolated SidebarSectionHeader and StatRow: 2 files and 17 tests passed. The action menu and destination submenu are added to the 390/820/1440 light/dark production capture flow; final real-server captures are pending.

Per-message Archive, Move to, and Move to Trash are now exposed in both the message overflow menu and the page action menu. Move destinations come from selectable folders on the message's account. Touch/pen swipes archive left and copy the stable message link right. The UI polls the durable action state and refreshes only after completion. Commit: `06aba445334ca5f0aa82f484229ac35d1597ba74` (`feat(mail): expose per-message folder actions`). Web check passed with 0 errors and 0 warnings. Full Vitest run: 138 files and 889 tests passed. Isolated `SidebarSectionHeader` and `StatRow`: 2 files and 17 tests passed. The action menu and destination submenu are added to the 390/820/1440 light/dark production capture flow; final real-server captures are pending.
Author
Owner

Flag/Unflag and Junk/Not junk are committed: 7028263e9c9f6a2d638e432b8362730f045ba8d9 (feat(mail): queue flag and junk actions). The action table accepts these variants. Flag changes use idempotent UID STORE and update the live projection; Junk moves to the selectable Junk folder, and Not junk is available only for a message in Junk and moves it to Inbox. The action menu and destination submenu captures now include these actions.

Mail plugin gates: cargo fmt --check passed; cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings passed; cargo test -p calternal-plugin-mail passed (49 tests). The new route test confirmed Flag queues against the existing source folder. The IMAP test confirmed the provider command is UID STORE 17 +FLAGS.SILENT (\\Flagged).

Flag/Unflag and Junk/Not junk are committed: `7028263e9c9f6a2d638e432b8362730f045ba8d9` (`feat(mail): queue flag and junk actions`). The action table accepts these variants. Flag changes use idempotent UID STORE and update the live projection; Junk moves to the selectable Junk folder, and Not junk is available only for a message in Junk and moves it to Inbox. The action menu and destination submenu captures now include these actions. Mail plugin gates: `cargo fmt --check` passed; `cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings` passed; `cargo test -p calternal-plugin-mail` passed (49 tests). The new route test confirmed Flag queues against the existing source folder. The IMAP test confirmed the provider command is `UID STORE 17 +FLAGS.SILENT (\\Flagged)`.
Author
Owner

Action backend slice committed as d143c3de1 (feat(mail): queue reversible provider actions).

  • Archive, Move, Trash, Flag/Unflag, Junk/Not junk, and manual Mark read/unread now use the durable provider action queue.
  • Added owner-scoped POST /actions/{request_id}/undo, one inverse per original action, replay-safe request IDs, and generation/UID capture after sync confirms the current folder membership.
  • Queued provider actions use u32::MAX attempts so transient provider outages do not dead-letter accepted work. An Undo submitted while its original is pending waits for that action and sync to finish.
  • The branch-local 0011_action_undo.sql migration stores the inverse identity. The private-action probe fixture now seeds a second User's request.

Gate output:

  • cargo fmt --check: exit 0, no output.
  • cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings: exit 0; Finished dev profile [unoptimized + debuginfo] target(s) in 2m 36s.
  • cargo test -p calternal-plugin-mail: test result: ok. 51 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.80s.

Decision not stated in DESIGN §45: Undo remains a queued inverse when the original action is still pending; the worker resolves the message's current provider UID after sync. One original action can have one Undo request. OpenAPI generation and the web contract/UI commit are in progress; final merged-tree gates, screenshots, and the adversarial round remain pending.

Action backend slice committed as `d143c3de1` (`feat(mail): queue reversible provider actions`). - Archive, Move, Trash, Flag/Unflag, Junk/Not junk, and manual Mark read/unread now use the durable provider action queue. - Added owner-scoped `POST /actions/{request_id}/undo`, one inverse per original action, replay-safe request IDs, and generation/UID capture after sync confirms the current folder membership. - Queued provider actions use `u32::MAX` attempts so transient provider outages do not dead-letter accepted work. An Undo submitted while its original is pending waits for that action and sync to finish. - The branch-local `0011_action_undo.sql` migration stores the inverse identity. The private-action probe fixture now seeds a second User's request. Gate output: - `cargo fmt --check`: exit 0, no output. - `cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings`: exit 0; `Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 36s`. - `cargo test -p calternal-plugin-mail`: `test result: ok. 51 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.80s`. Decision not stated in DESIGN §45: Undo remains a queued inverse when the original action is still pending; the worker resolves the message's current provider UID after sync. One original action can have one Undo request. OpenAPI generation and the web contract/UI commit are in progress; final merged-tree gates, screenshots, and the adversarial round remain pending.
Author
Owner

The API contract and Mail UI are committed:

  • 578d00a2b (build(api-client): expose reversible Mail actions) adds the Undo endpoint and Mark read/unread enum variants to OpenAPI and the generated client.
  • 9db34a83f (feat(mail): add undo controls to message actions) adds Undo toast actions for reversible message operations and extends the real-server probe and production capture harness.

Web check output:

$ bun run check
$ node scripts/check-type-tokens.mjs && svelte-kit sync && svelte-check --tsconfig ./tsconfig.json
Text sizes and UI shape values use shared role tokens.
Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/mail-m3/apps/web
Getting Svelte diagnostics...

svelte-check found 0 errors and 0 warnings

The production screenshots for the action menus and Undo toast, final merged-tree gates, and the one real-server adversarial round remain pending. The composer, recipient, saved draft and send-error screenshots were attached earlier and are not being repeated.

The API contract and Mail UI are committed: - `578d00a2b` (`build(api-client): expose reversible Mail actions`) adds the Undo endpoint and Mark read/unread enum variants to OpenAPI and the generated client. - `9db34a83f` (`feat(mail): add undo controls to message actions`) adds Undo toast actions for reversible message operations and extends the real-server probe and production capture harness. Web check output: ``` $ bun run check $ node scripts/check-type-tokens.mjs && svelte-kit sync && svelte-check --tsconfig ./tsconfig.json Text sizes and UI shape values use shared role tokens. Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/mail-m3/apps/web Getting Svelte diagnostics... svelte-check found 0 errors and 0 warnings ``` The production screenshots for the action menus and Undo toast, final merged-tree gates, and the one real-server adversarial round remain pending. The composer, recipient, saved draft and send-error screenshots were attached earlier and are not being repeated.
Author
Owner

Mail M3 parity inventory follow-up (#397): committed 60eea6254cb5d55c6262e764d8bab6eb8041dacc after the origin/dev merge. The matrix now records the web-only gaps for folder actions, undo and action status. Check output:

Parity matrix: 193 web API actions, 113 shortcuts, 2 static commands, 138 menu actions, 30 settings groups, 175 actions with adapter gaps

The check passes. The generated contract check also exits 0 on the merged tree. Rust gates, isolated timeout reruns, production screenshots and the single real-server adversarial round are still in progress.

Mail M3 parity inventory follow-up (#397): committed `60eea6254cb5d55c6262e764d8bab6eb8041dacc` after the `origin/dev` merge. The matrix now records the web-only gaps for folder actions, undo and action status. Check output: ``` Parity matrix: 193 web API actions, 113 shortcuts, 2 static commands, 138 menu actions, 30 settings groups, 175 actions with adapter gaps ``` The check passes. The generated contract check also exits 0 on the merged tree. Rust gates, isolated timeout reruns, production screenshots and the single real-server adversarial round are still in progress.
Author
Owner

Production screenshot evidence from the merged Mail M3 tree. Each full-resolution sheet keeps the 10 captured states at the viewport's native width: new, reply and forward composer; recipient chips; saved draft; send error; message actions; move destinations; Undo; and Not junk. Captures use the production web build and the real local API with test fixtures.

390 px, light:
Mail M3 390 px light

390 px, dark:
Mail M3 390 px dark

820 px, light:
Mail M3 820 px light

820 px, dark:
Mail M3 820 px dark

1440 px, light:
Mail M3 1440 px light

1440 px, dark:
Mail M3 1440 px dark

Production screenshot evidence from the merged Mail M3 tree. Each full-resolution sheet keeps the 10 captured states at the viewport's native width: new, reply and forward composer; recipient chips; saved draft; send error; message actions; move destinations; Undo; and Not junk. Captures use the production web build and the real local API with test fixtures. 390 px, light: ![Mail M3 390 px light](https://git.kayg.org/attachments/fd28eb54-f45d-4c78-9f67-8853b384d729) 390 px, dark: ![Mail M3 390 px dark](https://git.kayg.org/attachments/87ec597b-4dc6-416e-851f-151cb9f36da6) 820 px, light: ![Mail M3 820 px light](https://git.kayg.org/attachments/cb3ab6d9-e458-4e50-8004-58300715df52) 820 px, dark: ![Mail M3 820 px dark](https://git.kayg.org/attachments/225ef97c-db4d-467e-b53a-b251dc408839) 1440 px, light: ![Mail M3 1440 px light](https://git.kayg.org/attachments/3ce3a84f-c9ed-4900-9531-eebfff24eec5) 1440 px, dark: ![Mail M3 1440 px dark](https://git.kayg.org/attachments/2da25219-2ea2-403b-9630-462987742b72)
Author
Owner

Mail M3 continuation — final report

Branch: job/mail-m3
Head: 60eea6254cb5d55c6262e764d8bab6eb8041dacc (docs(parity): record Mail action gaps)

Built

  • Durable, owner-scoped Archive, Move, Trash, Flag/Unflag, Junk/Not junk and manual Mark read/unread actions. Actions are idempotent, generation-scoped, and retried by the server queue.
  • One queued Undo per original action. An Undo waits for the original and sync to resolve the message's current provider UID.
  • Undo controls in the Mail action toast, generated API contract updates, and parity entries for the remaining CLI/MCP adapter gaps.
  • Six full-resolution screenshot sheets are attached in the screenshot comment. Each sheet covers new/reply/forward, recipient chips, saved draft, send error, message actions, destinations, Undo and Not junk at its native viewport size. Together they cover 390/820/1440 px in light and dark themes.

Gates

cargo fmt --check: exit 0, no output.

cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings:

Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 19s

cargo test -p calternal-plugin-mail:

test result: ok. 51 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.99s

test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-server --all-targets -- -D warnings:

Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 58s

cargo test -p calternal-server:

test result: ok. 85 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 21.22s

bash packages/api-client/check-generated.sh exited 0 with no diff:

$ bunx --package openapi-typescript@7.13.0 openapi-typescript ../../contracts/openapi.json -o src/generated.ts
✨ openapi-typescript 7.13.0
🚀 ../../contracts/openapi.json → src/generated.ts [4s]

python3 scripts/parity_matrix.py --check:

Parity matrix: 193 web API actions, 113 shortcuts, 2 static commands, 138 menu actions, 30 settings groups, 175 actions with adapter gaps

bun run check:

Text sizes and UI shape values use shared role tokens.
Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/mail-m3/apps/web
Getting Svelte diagnostics...

svelte-check found 0 errors and 0 warnings

Full bun run test:

Error: Test timed out in 5000ms.

Test Files  1 failed | 137 passed (138)
      Tests  1 failed | 900 passed (901)
   Duration  254.51s
error: script "test" exited with code 1

The timed-out test was MailSection.svelte.test.ts (“keeps provider connection details behind Advanced”). Isolated reruns:

SidebarSectionHeader: Test Files 1 passed (1); Tests 4 passed (4); Duration 25.24s
StatRow: Test Files 1 passed (1); Tests 13 passed (13); Duration 17.50s
MailSection: Test Files 1 passed (1); Tests 4 passed (4); Duration 23.08s

The production bun run build exited 0 (✓ built in 1m 5s). It emitted existing module-level "use client" bundler warnings. The real-server Mail adversarial round passed:

Mail API probe: remote-content isolation, hostile IDs and headers, accepted send replay, disabled-account send, oversized attachment rejection, cross-User message/thread/draft/action isolation, idempotent Undo replay, unique Undo, safe attachment names and 24 parallel account/Inbox reads passed

The probe also asserted 413 for oversized draft and send bodies. The fixture uses fake provider credentials and does not contact an external IMAP/SMTP server.

cargo clean output:

Removed 15258 files, 8.5GiB total

The web build output was deleted. The worktree is clean.

Known gaps

The job has passed its four-hour time box, so I stopped after the ordered action slice. The next decided DESIGN §45 slices are Remind me (linked Task and due notification), invite clash checks and explicit iMIP replies, Save as formats, and Share. The provider Drafts save path is present; fetching provider-created or cross-device Drafts remains incomplete. Per-app Notes signatures with account defaults and per-draft switching are also still missing; that gap was recorded earlier on #397. Reply branches/forks remain OPEN in DESIGN and were not built.

The action-state adapters remain Web-only; the parity matrix records the CLI/MCP gaps.

Decisions not stated in DESIGN

  • Provider moves use atomic IMAP UID MOVE only. There is no COPY/EXPUNGE fallback because an interrupted fallback cannot be replayed safely; a provider without UID MOVE fails that action.
  • Each original action accepts at most one Undo. If the original is pending, Undo stays queued until the original and sync finish, then captures a live UID.
  • Accepted provider actions retry with u32::MAX attempts so a transient provider outage does not dead-letter the user's request.

No push, deploy or merge was performed.

## Mail M3 continuation — final report Branch: `job/mail-m3` Head: `60eea6254cb5d55c6262e764d8bab6eb8041dacc` (`docs(parity): record Mail action gaps`) ### Built - Durable, owner-scoped Archive, Move, Trash, Flag/Unflag, Junk/Not junk and manual Mark read/unread actions. Actions are idempotent, generation-scoped, and retried by the server queue. - One queued Undo per original action. An Undo waits for the original and sync to resolve the message's current provider UID. - Undo controls in the Mail action toast, generated API contract updates, and parity entries for the remaining CLI/MCP adapter gaps. - Six full-resolution screenshot sheets are attached in [the screenshot comment](https://git.kayg.org/kayg/calternal/issues/397#issuecomment-14831). Each sheet covers new/reply/forward, recipient chips, saved draft, send error, message actions, destinations, Undo and Not junk at its native viewport size. Together they cover 390/820/1440 px in light and dark themes. ### Gates `cargo fmt --check`: exit 0, no output. `cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings`: ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 19s ``` `cargo test -p calternal-plugin-mail`: ``` test result: ok. 51 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.99s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo clippy -p calternal-server --all-targets -- -D warnings`: ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 58s ``` `cargo test -p calternal-server`: ``` test result: ok. 85 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 21.22s ``` `bash packages/api-client/check-generated.sh` exited 0 with no diff: ``` $ bunx --package openapi-typescript@7.13.0 openapi-typescript ../../contracts/openapi.json -o src/generated.ts ✨ openapi-typescript 7.13.0 🚀 ../../contracts/openapi.json → src/generated.ts [4s] ``` `python3 scripts/parity_matrix.py --check`: ``` Parity matrix: 193 web API actions, 113 shortcuts, 2 static commands, 138 menu actions, 30 settings groups, 175 actions with adapter gaps ``` `bun run check`: ``` Text sizes and UI shape values use shared role tokens. Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/mail-m3/apps/web Getting Svelte diagnostics... svelte-check found 0 errors and 0 warnings ``` Full `bun run test`: ``` Error: Test timed out in 5000ms. Test Files 1 failed | 137 passed (138) Tests 1 failed | 900 passed (901) Duration 254.51s error: script "test" exited with code 1 ``` The timed-out test was `MailSection.svelte.test.ts` (“keeps provider connection details behind Advanced”). Isolated reruns: ``` SidebarSectionHeader: Test Files 1 passed (1); Tests 4 passed (4); Duration 25.24s StatRow: Test Files 1 passed (1); Tests 13 passed (13); Duration 17.50s MailSection: Test Files 1 passed (1); Tests 4 passed (4); Duration 23.08s ``` The production `bun run build` exited 0 (`✓ built in 1m 5s`). It emitted existing module-level `"use client"` bundler warnings. The real-server Mail adversarial round passed: ``` Mail API probe: remote-content isolation, hostile IDs and headers, accepted send replay, disabled-account send, oversized attachment rejection, cross-User message/thread/draft/action isolation, idempotent Undo replay, unique Undo, safe attachment names and 24 parallel account/Inbox reads passed ``` The probe also asserted 413 for oversized draft and send bodies. The fixture uses fake provider credentials and does not contact an external IMAP/SMTP server. `cargo clean` output: ``` Removed 15258 files, 8.5GiB total ``` The web build output was deleted. The worktree is clean. ### Known gaps The job has passed its four-hour time box, so I stopped after the ordered action slice. The next decided DESIGN §45 slices are Remind me (linked Task and due notification), invite clash checks and explicit iMIP replies, Save as formats, and Share. The provider Drafts save path is present; fetching provider-created or cross-device Drafts remains incomplete. Per-app Notes signatures with account defaults and per-draft switching are also still missing; that gap was recorded earlier on #397. Reply branches/forks remain OPEN in DESIGN and were not built. The action-state adapters remain Web-only; the parity matrix records the CLI/MCP gaps. ### Decisions not stated in DESIGN - Provider moves use atomic IMAP UID MOVE only. There is no COPY/EXPUNGE fallback because an interrupted fallback cannot be replayed safely; a provider without UID MOVE fails that action. - Each original action accepts at most one Undo. If the original is pending, Undo stays queued until the original and sync finish, then captures a live UID. - Accepted provider actions retry with `u32::MAX` attempts so a transient provider outage does not dead-letter the user's request. No push, deploy or merge was performed.
Author
Owner

Starting the #397 composer polish round on job/mail-m3, at base 60eea6254cb5d55c6262e764d8bab6eb8041dacc. I am reading the Mail and Chrome design decisions, then I will update the composer and verify the real production build at 390, 820 and 1440 px in both themes.

Starting the #397 composer polish round on `job/mail-m3`, at base `60eea6254cb5d55c6262e764d8bab6eb8041dacc`. I am reading the Mail and Chrome design decisions, then I will update the composer and verify the real production build at 390, 820 and 1440 px in both themes.
Author
Owner

Finding: the current composer uses a native From select, always shows empty Cc and Bcc rows, wraps the Mail editor in a bordered grey frame, and renders text pills for format and discard. Its existing correspondent list comes from recent indexed Mail messages and feeds a native address datalist. The Mail preferences API currently stores only read marking; this repository has no Contacts API. I will use the shared Select, keep the existing correspondent data, and add cross-Installation account preferences for compose format and signature Note identity through the existing owner-scoped Mail preferences boundary. Contacts suggestions will join when that service exists.

Finding: the current composer uses a native From select, always shows empty Cc and Bcc rows, wraps the Mail editor in a bordered grey frame, and renders text pills for format and discard. Its existing correspondent list comes from recent indexed Mail messages and feeds a native address datalist. The Mail preferences API currently stores only read marking; this repository has no Contacts API. I will use the shared Select, keep the existing correspondent data, and add cross-Installation account preferences for compose format and signature Note identity through the existing owner-scoped Mail preferences boundary. Contacts suggestions will join when that service exists.
Author
Owner

Finding while completing #397: the Mail send and provider-draft contracts have no attachment field, and the SMTP builder only sends text/HTML alternatives under its current size cap. I kept the paperclip action visible with a warm “Attachments are not available yet” tooltip and aria-disabled, instead of opening a file picker whose selection could not be saved or sent. This job does not expand Mail attachment transport.

Choices not stated by DESIGN §45: new accounts start in rich mode; later rich/plain choices are stored per account. Mail stores the owner-scoped Signature Note ID and reads the Note body through Notes; the draft stores a copy of that body so its sent text stays stable if the Note changes later.

Finding while completing #397: the Mail send and provider-draft contracts have no attachment field, and the SMTP builder only sends text/HTML alternatives under its current size cap. I kept the paperclip action visible with a warm “Attachments are not available yet” tooltip and `aria-disabled`, instead of opening a file picker whose selection could not be saved or sent. This job does not expand Mail attachment transport. Choices not stated by DESIGN §45: new accounts start in rich mode; later rich/plain choices are stored per account. Mail stores the owner-scoped Signature Note ID and reads the Note body through Notes; the draft stores a copy of that body so its sent text stays stable if the Note changes later.
Author
Owner

#397 finished: Mail composer polish

Branch: job/mail-m3
Head: 79069a69cb9a9349ac713644e556032389626629

Built

  • The From control uses the shared Select and shows the provider/account address.
  • To, Cc and Bcc use recipient chips. To suggestions use recent Mail Index correspondents. Cc and Bcc stay collapsed until requested.
  • Subject is a single-line field. The message body reuses the Notes Editor without an inset box and fills the sheet.
  • Rich/plain format and default signature Note are remembered per account. The composer uses the shared Notes menu and shared phone OverlaySurface.
  • The toolbar uses icon controls with warm tooltips. Send shows Ctrl and Enter keycaps in its tooltip.
  • Added the account-scoped preference route and migration, generated contract, performance profile integration, and hostile-input coverage for the preference API.

Decisions where DESIGN §45 was silent

  • New accounts start in rich format. A saved plain/rich value is account-scoped.
  • Mail stores the selected signature Note ID. Applying a Note copies its current text into the draft so later Note edits do not change an existing draft.
  • The Contacts API is not available, so To suggestions come from up to 40 unique recent correspondents from the Mail Index.
  • Mail has no attachment send contract. The Paperclip stays visible with aria-disabled and an availability tooltip until that contract exists.

Known gaps

  • Contacts are not included in autocomplete until a Contacts API exists.
  • Attachments cannot be sent until the Mail send contract supports them.

Performance

The perf VM was unreachable, so this is a local run on calternal-dev, at 4× CPU throttle. Host load was 35.32, 37.45, 32.02 before and 35.10, 36.34, 32.26 after. The nearest baseline row is open_composer: p50 185 ms, p95 349 ms over 15 samples on perf-test, whose load before the run was 0.15, 0.39, 1.03. That baseline is not Mail-specific and the host load differs, so these results do not establish a regression.

  • Composer open: 390px p50/p95 1890.1/2765.1 ms, browser CPU 109%, RSS 508,248,064 B; 1440px 582.9/3539.6 ms, CPU 197.8%, RSS 610,934,784 B.
  • First 100-Note page: 972.5 ms. Signature menu average p50/p95 672.7/2922.5 ms, CPU 203.3%, RSS 656,478,208 B.
  • 10-open, 100-Note menu burst p50/p95 1979.2/4754.5 ms, CPU 121.1%, peak browser RSS 703,508,480 B.
  • Server during profile: mean CPU 4.11%, peak CPU 92.54%, peak RSS 216,539,136 B.

Production screenshots

Width Light Dark
390px 390 light 390 dark
820px 820 light 820 dark
1440px 1440 light 1440 dark

Send shortcut tooltip: Send tooltip with keycaps

The icon/label pair and recipient chip were zoom-checked. Screenshots use the production SPA and authenticated local server with E2E Mail and Notes fixtures. Screenshots are attached here and are not committed.

Gates

cargo fmt --check passed with exit 0 and no output.

cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings:

Checking calternal-fs v0.1.0 (/home/kayg/Developer/calternal-wt/mail-m3/crates/calternal-fs)
Checking calternal-plugin v0.0.1 (/home/kayg/Developer/calternal-wt/mail-m3/crates/calternal-plugin)
Checking calternal-plugin-mail v0.0.1 (/home/kayg/Developer/calternal-wt/mail-m3/crates/plugins/mail)
    Finished `dev` profile [unoptimized + debuginfo] target(s) in 36.12s

cargo test -p calternal-plugin-mail:

test result: ok. 51 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 1.03s

   Doc-tests calternal_plugin_mail

running 0 tests

test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-server --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 29m 06s

cargo test -p calternal-server:

test result: ok. 93 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 22.23s

bun run check:

$ node scripts/check-type-tokens.mjs && node scripts/check-motion-tokens.mjs && svelte-kit sync && svelte-check --tsconfig ./tsconfig.json
Text sizes and UI shape values use shared role tokens.
UI transitions and animation options use shared motion tokens or documented exceptions.
Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/mail-m3/apps/web
Getting Svelte diagnostics...

svelte-check found 0 errors and 0 warnings

bun run test:

 Test Files  141 passed (141)
      Tests  916 passed (916)
   Start at  20:24:41
   Duration  120.75s (transform 49%, environment 19%, import 16%, tests 12%, setup 4%)

Requested timed-out file rerun alone, bun run test -- src/routes/settings/mail/MailSection.svelte.test.ts:

 Test Files  1 passed (1)
      Tests  4 passed (4)
   Start at  20:27:01
   Duration  16.02s (transform 73%, environment 9%, tests 9%, import 6%, setup 2%)

bash packages/api-client/check-generated.sh passed with exit 0 and no output. PYTHONDONTWRITEBYTECODE=1 python3 -m unittest bench.test_record:

.......
----------------------------------------------------------------------
Ran 7 tests in 0.438s

OK

Production build:

✓ built in 46.02s

Run npm run preview to preview your production build locally.

> Using @sveltejs/adapter-static
  Wrote site to "build"
  ✔ done

Real-server adversarial probe:

Mail API probe: remote-content isolation, hostile IDs and headers, accepted send replay, disabled-account send, oversized attachment rejection, cross-User message/thread/draft/action isolation, idempotent Undo replay, unique Undo, safe attachment names and 24 parallel account/Inbox reads passed

cargo clean completed:

     Removed 15481 files, 8.4GiB total

The web build output was removed after verification. No push, deploy, merge into dev, or issue close was performed.

# #397 finished: Mail composer polish Branch: `job/mail-m3` Head: `79069a69cb9a9349ac713644e556032389626629` ## Built - The From control uses the shared Select and shows the provider/account address. - To, Cc and Bcc use recipient chips. To suggestions use recent Mail Index correspondents. Cc and Bcc stay collapsed until requested. - Subject is a single-line field. The message body reuses the Notes Editor without an inset box and fills the sheet. - Rich/plain format and default signature Note are remembered per account. The composer uses the shared Notes menu and shared phone OverlaySurface. - The toolbar uses icon controls with warm tooltips. Send shows `Ctrl` and `Enter` keycaps in its tooltip. - Added the account-scoped preference route and migration, generated contract, performance profile integration, and hostile-input coverage for the preference API. ## Decisions where DESIGN §45 was silent - New accounts start in rich format. A saved plain/rich value is account-scoped. - Mail stores the selected signature Note ID. Applying a Note copies its current text into the draft so later Note edits do not change an existing draft. - The Contacts API is not available, so To suggestions come from up to 40 unique recent correspondents from the Mail Index. - Mail has no attachment send contract. The Paperclip stays visible with `aria-disabled` and an availability tooltip until that contract exists. ## Known gaps - Contacts are not included in autocomplete until a Contacts API exists. - Attachments cannot be sent until the Mail send contract supports them. ## Performance The perf VM was unreachable, so this is a local run on `calternal-dev`, at 4× CPU throttle. Host load was `35.32, 37.45, 32.02` before and `35.10, 36.34, 32.26` after. The nearest baseline row is `open_composer`: p50 `185 ms`, p95 `349 ms` over 15 samples on `perf-test`, whose load before the run was `0.15, 0.39, 1.03`. That baseline is not Mail-specific and the host load differs, so these results do not establish a regression. - Composer open: 390px p50/p95 `1890.1/2765.1 ms`, browser CPU `109%`, RSS `508,248,064 B`; 1440px `582.9/3539.6 ms`, CPU `197.8%`, RSS `610,934,784 B`. - First 100-Note page: `972.5 ms`. Signature menu average p50/p95 `672.7/2922.5 ms`, CPU `203.3%`, RSS `656,478,208 B`. - 10-open, 100-Note menu burst p50/p95 `1979.2/4754.5 ms`, CPU `121.1%`, peak browser RSS `703,508,480 B`. - Server during profile: mean CPU `4.11%`, peak CPU `92.54%`, peak RSS `216,539,136 B`. ## Production screenshots | Width | Light | Dark | |---|---|---| | 390px | ![390 light](https://git.kayg.org/attachments/3d451e1b-738b-497d-ae9d-9c39804b3293) | ![390 dark](https://git.kayg.org/attachments/e4288eed-0eac-4a28-97d8-71ee5aefb69a) | | 820px | ![820 light](https://git.kayg.org/attachments/bbbf0933-dafa-4546-8f50-0defb35a7b3f) | ![820 dark](https://git.kayg.org/attachments/4bf86483-f6bd-460a-94ef-122f6c56e08f) | | 1440px | ![1440 light](https://git.kayg.org/attachments/2cbd82da-7565-4e9d-8b0e-90f63dd9ba12) | ![1440 dark](https://git.kayg.org/attachments/73ea0d99-ba52-47ad-a241-1512c1dcb012) | Send shortcut tooltip: ![Send tooltip with keycaps](https://git.kayg.org/attachments/8bba48b1-8508-479a-bd45-ae6af3d3cada) The icon/label pair and recipient chip were zoom-checked. Screenshots use the production SPA and authenticated local server with E2E Mail and Notes fixtures. Screenshots are attached here and are not committed. ## Gates `cargo fmt --check` passed with exit 0 and no output. `cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings`: ```text Checking calternal-fs v0.1.0 (/home/kayg/Developer/calternal-wt/mail-m3/crates/calternal-fs) Checking calternal-plugin v0.0.1 (/home/kayg/Developer/calternal-wt/mail-m3/crates/calternal-plugin) Checking calternal-plugin-mail v0.0.1 (/home/kayg/Developer/calternal-wt/mail-m3/crates/plugins/mail) Finished `dev` profile [unoptimized + debuginfo] target(s) in 36.12s ``` `cargo test -p calternal-plugin-mail`: ```text test result: ok. 51 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 1.03s Doc-tests calternal_plugin_mail running 0 tests test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo clippy -p calternal-server --all-targets -- -D warnings`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 29m 06s ``` `cargo test -p calternal-server`: ```text test result: ok. 93 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 22.23s ``` `bun run check`: ```text $ node scripts/check-type-tokens.mjs && node scripts/check-motion-tokens.mjs && svelte-kit sync && svelte-check --tsconfig ./tsconfig.json Text sizes and UI shape values use shared role tokens. UI transitions and animation options use shared motion tokens or documented exceptions. Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/mail-m3/apps/web Getting Svelte diagnostics... svelte-check found 0 errors and 0 warnings ``` `bun run test`: ```text Test Files 141 passed (141) Tests 916 passed (916) Start at 20:24:41 Duration 120.75s (transform 49%, environment 19%, import 16%, tests 12%, setup 4%) ``` Requested timed-out file rerun alone, `bun run test -- src/routes/settings/mail/MailSection.svelte.test.ts`: ```text Test Files 1 passed (1) Tests 4 passed (4) Start at 20:27:01 Duration 16.02s (transform 73%, environment 9%, tests 9%, import 6%, setup 2%) ``` `bash packages/api-client/check-generated.sh` passed with exit 0 and no output. `PYTHONDONTWRITEBYTECODE=1 python3 -m unittest bench.test_record`: ```text ....... ---------------------------------------------------------------------- Ran 7 tests in 0.438s OK ``` Production build: ```text ✓ built in 46.02s Run npm run preview to preview your production build locally. > Using @sveltejs/adapter-static Wrote site to "build" ✔ done ``` Real-server adversarial probe: ```text Mail API probe: remote-content isolation, hostile IDs and headers, accepted send replay, disabled-account send, oversized attachment rejection, cross-User message/thread/draft/action isolation, idempotent Undo replay, unique Undo, safe attachment names and 24 parallel account/Inbox reads passed ``` `cargo clean` completed: ```text Removed 15481 files, 8.4GiB total ``` The web build output was removed after verification. No push, deploy, merge into `dev`, or issue close was performed.
Author
Owner

Starting the #397 polish pass on branch job/mail-m3.

Base SHA: aa372eef6c9312403f59a65d5b90cb3648ff52ed (origin/dev). Current HEAD: 79069a69cb9a9349ac713644e556032389626629.

Starting the #397 polish pass on branch `job/mail-m3`. Base SHA: `aa372eef6c9312403f59a65d5b90cb3648ff52ed` (`origin/dev`). Current HEAD: `79069a69cb9a9349ac713644e556032389626629`.
Author
Owner

Evidence for #397: the first production E2E found that the blank Mail editor rendered <p><br class="ProseMirror-trailingBreak"></p> without .is-editor-empty. The Mail profile returned its own extension list and omitted EmptyBlockHints, even though the shared profile registered it. Added that existing presentation-only extension to the Mail profile; this preserves the portable message schema and enables the requested body placeholder. The E2E now checks the actual pseudo-element content.

Evidence for #397: the first production E2E found that the blank Mail editor rendered `<p><br class="ProseMirror-trailingBreak"></p>` without `.is-editor-empty`. The Mail profile returned its own extension list and omitted `EmptyBlockHints`, even though the shared profile registered it. Added that existing presentation-only extension to the Mail profile; this preserves the portable message schema and enables the requested body placeholder. The E2E now checks the actual pseudo-element content.
Author
Owner

Evidence for #397: the production E2E's phone geometry check found that the title box shifted left when the title and long offline status were centered as one flex group. The shared sheet header now centers the title in its own grid track and keeps the status directly beside it. The production E2E verifies the title center within one CSS pixel at 390 px.

Evidence for #397: the production E2E's phone geometry check found that the title box shifted left when the title and long offline status were centered as one flex group. The shared sheet header now centers the title in its own grid track and keeps the status directly beside it. The production E2E verifies the title center within one CSS pixel at 390 px.
Author
Owner

Finding: the offline reconnect handler returned early when the draft already had a provider copy. After an offline period, the UI therefore kept showing “Saved on this device” even though provider Drafts still contained the saved copy. The handler now restores “Saved” for that case, and the composer E2E exercises both local-to-provider save and a second offline/online cycle. The phone sheet title also uses an independent centered heading track while its save status sits beside it, preserving the shared sticky title geometry.

Finding: the offline reconnect handler returned early when the draft already had a provider copy. After an offline period, the UI therefore kept showing “Saved on this device” even though provider Drafts still contained the saved copy. The handler now restores “Saved” for that case, and the composer E2E exercises both local-to-provider save and a second offline/online cycle. The phone sheet title also uses an independent centered heading track while its save status sits beside it, preserving the shared sticky title geometry.
Author
Owner

Gate finding: the final bun run test run had 140/141 files and 915/916 tests pass. The unrelated src/lib/date-formatting.test.ts recursive source scan exceeded its 5s test timeout (Vitest reported 9.85s); its assertions did not report a formatting violation. The host load average after that run was 28.65 / 26.65 / 26.81. I did not change the test or its timeout. I am recording this as an environment-sensitive gate failure.

Gate finding: the final `bun run test` run had 140/141 files and 915/916 tests pass. The unrelated `src/lib/date-formatting.test.ts` recursive source scan exceeded its 5s test timeout (Vitest reported 9.85s); its assertions did not report a formatting violation. The host load average after that run was 28.65 / 26.65 / 26.81. I did not change the test or its timeout. I am recording this as an environment-sensitive gate failure.
Author
Owner

Finished #397 polish on job/mail-m3.

Head SHA: 73aa6705d (merge of origin/dev is included; no push or deploy).

Built

  • Removed the explanatory subtitle and header plus. Draft save state now appears beside the title as “Saved”, “Saving…” or “Saved on this device”. The phone sheet has a centered title, leading Cancel and trailing Send; Copy link stays in the saved-draft actions.
  • Removed the Message label and added the “Write your message” placeholder while retaining the editor accessible name.
  • Reused the shared Pill Send action with its icon-label gap and control height.
  • Named recipient chips show the name only; the address remains in the token title and focused remove control. Field labels share one label column and baseline alignment.
  • Fixed reconnect state for drafts already present in provider Drafts, and added E2E coverage for saving and offline/reconnect cycles.

Files: apps/web/src/lib/mail/MailComposer.svelte, apps/web/src/lib/mail/MailRecipients.svelte, packages/editor/src/extensions.ts, packages/ui/src/components/OverlaySurface.svelte, apps/web/e2e/mail-composer-397-perf.mjs.

Decisions

  • Added an accessory slot to shared OverlaySurface so Mail can place save state beside the phone heading without shifting its center.
  • Kept Copy link reachable on phones by placing it with the saved-draft actions after removing the unclear header plus.
  • A synced draft returns to “Saved” after reconnect; an offline draft says “Saved on this device”.

Screenshots attached

Full production screenshots:

Native 3× crops of the header and field rows:

Gates

cargo fmt --check exited 0 with no output.

cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 47s

cargo test -p calternal-plugin-mail:

test result: ok. 51 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 1.93s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

bun run check:

Text sizes and UI shape values use shared role tokens.
UI transitions and animation options use shared motion tokens or documented exceptions.
Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/mail-m3/apps/web
Getting Svelte diagnostics...

svelte-check found 0 errors and 0 warnings

bun run test exited 1. Exact summary:

 FAIL  |unit| src/lib/date-formatting.test.ts > shared date formatter reuse gate > keeps direct date and locale formatting inside packages/ui/src/time.ts
Error: Test timed out in 5000ms.
 Test Files  1 failed | 140 passed (141)
      Tests  1 failed | 915 passed (916)
   Duration  150.38s (transform 60%, environment 14%, import 14%, tests 8%, setup 3%)

The timed-out test is an unrelated recursive source scan; it reported no formatting violation. The host load average after the run was 28.65 / 26.65 / 26.81. I did not change its expectation or timeout.

Production build completed with Wrote site to "build" and ✔ done.

The mail-composer-397-perf.mjs production E2E exited 0. Verbatim run summary:

Mail composer profile: 390px open samples
Mail composer profile: 1440px open samples
Mail composer profile: 6 signature-menu samples
Mail composer profile: 10-open signature-menu burst
Mail composer screenshots: /home/kayg/Developer/calternal-wt/mail-m3/artifacts/mail-m3

cargo clean: Removed 10742 files, 5.6GiB total. Web build output was removed.

Performance

Local calternal-dev, CPU throttle 4, 50 inbox rows, 40 correspondents and 100 signature Notes; load average moved from 24.93 / 26.06 / 26.59 to 31.24 / 27.56 / 27.04.

Scenario Current p50 / p95 Browser CPU RSS Available baseline
Composer open, 390×844, 6 samples 971.8 / 1807.8 ms 11.09 s (153.5%) 508,350,464 B generic open_composer: 185 / 349 ms, 15 samples
Composer open, 1440×900, 6 samples 1318.9 / 4019.4 ms 14.67 s (138.2%) 599,482,368 B same generic baseline
Signature menu, 6 opens 1184.6 / 3562.8 ms 16.96 s (180.8%) 652,017,664 B no matching profile in baseline
Signature menu burst, 10 opens 904.7 / 2283.1 ms 25.09 s (238%) peak 699,441,152 B no matching profile in baseline

The baseline is from quiet perf-test (load_average_before 0.15 / 0.39 / 1.03); this local run was heavily loaded, and its composer workload is not a direct match. Treat the timing comparison as directional only.

Known gap: one unrelated bun run test timeout remains; all other requested gates and the production E2E passed.

Finished #397 polish on `job/mail-m3`. Head SHA: `73aa6705d` (merge of `origin/dev` is included; no push or deploy). ### Built - Removed the explanatory subtitle and header plus. Draft save state now appears beside the title as “Saved”, “Saving…” or “Saved on this device”. The phone sheet has a centered title, leading Cancel and trailing Send; Copy link stays in the saved-draft actions. - Removed the Message label and added the “Write your message” placeholder while retaining the editor accessible name. - Reused the shared Pill Send action with its icon-label gap and control height. - Named recipient chips show the name only; the address remains in the token title and focused remove control. Field labels share one label column and baseline alignment. - Fixed reconnect state for drafts already present in provider Drafts, and added E2E coverage for saving and offline/reconnect cycles. Files: `apps/web/src/lib/mail/MailComposer.svelte`, `apps/web/src/lib/mail/MailRecipients.svelte`, `packages/editor/src/extensions.ts`, `packages/ui/src/components/OverlaySurface.svelte`, `apps/web/e2e/mail-composer-397-perf.mjs`. ### Decisions - Added an accessory slot to shared `OverlaySurface` so Mail can place save state beside the phone heading without shifting its center. - Kept Copy link reachable on phones by placing it with the saved-draft actions after removing the unclear header plus. - A synced draft returns to “Saved” after reconnect; an offline draft says “Saved on this device”. ### Screenshots attached Full production screenshots: - 390px: [light](https://git.kayg.org/attachments/76595136-aac3-4cd8-88e8-53bafb4c1a45) · [dark](https://git.kayg.org/attachments/b734563d-171c-4f0f-9304-20ae6f715de3) - 820px: [light](https://git.kayg.org/attachments/815866c2-a52d-4dec-8b7a-de146182cdce) · [dark](https://git.kayg.org/attachments/03d2d905-a23f-4805-b25c-f2441c5aaa51) - 1440px: [light](https://git.kayg.org/attachments/c35668d0-84fd-4265-bd15-0c568247daf5) · [dark](https://git.kayg.org/attachments/7db94094-7e71-4afe-b0fd-598dce0d9520) Native 3× crops of the header and field rows: - 390px paper: [header](https://git.kayg.org/attachments/24a4df61-4764-4a20-9bf5-e83429ffdb3f) · [field rows](https://git.kayg.org/attachments/4d4ccd31-d4aa-42eb-93de-e35f083dc2c8) - 390px midnight: [header](https://git.kayg.org/attachments/c4743be2-0a36-4530-88c9-5b1e2e5dec12) · [field rows](https://git.kayg.org/attachments/cd6138c8-ad59-4109-9d2a-19a07566226b) - 1440px paper: [header](https://git.kayg.org/attachments/a6c7b4ed-d48e-4129-8f8b-1f3fe6b804f0) · [field rows](https://git.kayg.org/attachments/5747babc-6bb1-48f8-815d-6546c94abfbf) - 1440px midnight: [header](https://git.kayg.org/attachments/c54fc2f5-3b5f-4689-a5ea-f300b5d62f33) · [field rows](https://git.kayg.org/attachments/a883b36a-c231-4df8-b185-a23f5e4ffb25) ### Gates `cargo fmt --check` exited 0 with no output. `cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 47s ``` `cargo test -p calternal-plugin-mail`: ```text test result: ok. 51 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 1.93s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `bun run check`: ```text Text sizes and UI shape values use shared role tokens. UI transitions and animation options use shared motion tokens or documented exceptions. Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/mail-m3/apps/web Getting Svelte diagnostics... svelte-check found 0 errors and 0 warnings ``` `bun run test` exited 1. Exact summary: ```text FAIL |unit| src/lib/date-formatting.test.ts > shared date formatter reuse gate > keeps direct date and locale formatting inside packages/ui/src/time.ts Error: Test timed out in 5000ms. Test Files 1 failed | 140 passed (141) Tests 1 failed | 915 passed (916) Duration 150.38s (transform 60%, environment 14%, import 14%, tests 8%, setup 3%) ``` The timed-out test is an unrelated recursive source scan; it reported no formatting violation. The host load average after the run was `28.65 / 26.65 / 26.81`. I did not change its expectation or timeout. Production build completed with `Wrote site to "build"` and `✔ done`. The `mail-composer-397-perf.mjs` production E2E exited 0. Verbatim run summary: ```text Mail composer profile: 390px open samples Mail composer profile: 1440px open samples Mail composer profile: 6 signature-menu samples Mail composer profile: 10-open signature-menu burst Mail composer screenshots: /home/kayg/Developer/calternal-wt/mail-m3/artifacts/mail-m3 ``` `cargo clean`: `Removed 10742 files, 5.6GiB total`. Web build output was removed. ### Performance Local `calternal-dev`, CPU throttle 4, 50 inbox rows, 40 correspondents and 100 signature Notes; load average moved from `24.93 / 26.06 / 26.59` to `31.24 / 27.56 / 27.04`. | Scenario | Current p50 / p95 | Browser CPU | RSS | Available baseline | |---|---:|---:|---:|---:| | Composer open, 390×844, 6 samples | 971.8 / 1807.8 ms | 11.09 s (153.5%) | 508,350,464 B | generic `open_composer`: 185 / 349 ms, 15 samples | | Composer open, 1440×900, 6 samples | 1318.9 / 4019.4 ms | 14.67 s (138.2%) | 599,482,368 B | same generic baseline | | Signature menu, 6 opens | 1184.6 / 3562.8 ms | 16.96 s (180.8%) | 652,017,664 B | no matching profile in baseline | | Signature menu burst, 10 opens | 904.7 / 2283.1 ms | 25.09 s (238%) | peak 699,441,152 B | no matching profile in baseline | The baseline is from quiet `perf-test` (`load_average_before` `0.15 / 0.39 / 1.03`); this local run was heavily loaded, and its composer workload is not a direct match. Treat the timing comparison as directional only. Known gap: one unrelated `bun run test` timeout remains; all other requested gates and the production E2E passed.
Author
Owner

Starting polish round 3 for #397 on branch job/mail-m3.

Starting HEAD: 73aa6705d4ed59599db618abe3612ac8a7374a44
Base (origin/dev merge base): 15e17aeafc8ea160c109e62fba57f6961c39d21f

I am tracing the Mail composer header and shared sheet header before making the requested fixes.

Starting polish round 3 for #397 on branch `job/mail-m3`. Starting HEAD: `73aa6705d4ed59599db618abe3612ac8a7374a44` Base (`origin/dev` merge base): `15e17aeafc8ea160c109e62fba57f6961c39d21f` I am tracing the Mail composer header and shared sheet header before making the requested fixes.
Author
Owner

Finding from the pre-fix production e2e: CALTERNAL_SERVER_BIN="$CARGO_TARGET_DIR/debug/calternal-server" bun e2e/mail-composer-397-perf.mjs failed at 1440 px with AssertionError: 1440px puts draft actions in the trailing header.

The cause is in apps/web/src/lib/mail/MailComposer.svelte: Copy link has a separate desktop button, while New draft and phone Copy link are rendered in .draft-deck-actions above the From field. The phone title accessory also receives the long draftSaveLabel in the shared header's side slot. I will keep OverlaySurface as the shared sheet header and make the focused composer changes there.

Finding from the pre-fix production e2e: `CALTERNAL_SERVER_BIN="$CARGO_TARGET_DIR/debug/calternal-server" bun e2e/mail-composer-397-perf.mjs` failed at 1440 px with `AssertionError: 1440px puts draft actions in the trailing header`. The cause is in `apps/web/src/lib/mail/MailComposer.svelte`: Copy link has a separate desktop button, while New draft and phone Copy link are rendered in `.draft-deck-actions` above the From field. The phone title accessory also receives the long `draftSaveLabel` in the shared header's side slot. I will keep `OverlaySurface` as the shared sheet header and make the focused composer changes there.
Author
Owner

Correction to my previous e2e note: its first menu assertion ran on an untouched blank draft, where draft actions are correctly absent. I fixed the fixture to create local draft content before checking these actions.

The corrected production e2e now gives two valid pre-fix failures:

  • At 390 px, a populated offline draft shows Saved on this device instead of the required Offline · saved here.
  • With the same populated draft, the phone header has no Draft actions menu beside Send.

Both follow the source layout recorded above. I am proceeding with the focused composer change.

Correction to my previous e2e note: its first menu assertion ran on an untouched blank draft, where draft actions are correctly absent. I fixed the fixture to create local draft content before checking these actions. The corrected production e2e now gives two valid pre-fix failures: - At 390 px, a populated offline draft shows `Saved on this device` instead of the required `Offline · saved here`. - With the same populated draft, the phone header has no Draft actions menu beside Send. Both follow the source layout recorded above. I am proceeding with the focused composer change.
Author
Owner

Finished — Mail M3 polish round 3

Built

  • Phone draft status now shows Saved, Saving…, or Offline · saved here as a centred, non-clipping footnote below the title.
  • Removed the separate New draft / Copy link action row. The existing actions are in a ⋯ menu beside Send in the phone header and at the trailing edge of the desktop header.
  • The composer uses the shared OverlaySurface sheet header. Its shared sticky chrome and ProgressiveBlur remain owned by that component, so the composer inherits the #530 fix when it merges.
  • Extended the production E2E profile to assert save-status layout, action placement, and six screen captures at 390/820/1440 in both themes. It also captures both 3× phone header crops.

Issue attachments

Capture File
Phone · 390 · light mail-composer-390-paper.png
Phone · 390 · dark mail-composer-390-midnight.png
Tablet · 820 · light mail-composer-820-paper.png
Tablet · 820 · dark mail-composer-820-midnight.png
Desktop · 1440 · light mail-composer-1440-paper.png
Desktop · 1440 · dark mail-composer-1440-midnight.png
Phone header · 390 · light · 3× mail-composer-header-390-paper-3x.png
Phone header · 390 · dark · 3× mail-composer-header-390-midnight-3x.png

Files and commit

  • apps/web/src/lib/mail/MailComposer.svelte
  • apps/web/e2e/mail-composer-397-perf.mjs
  • Head: a1fd501db9659fb3eb35c3a4c8025c58c99fab09 (Move Mail draft actions into header menu)

Gates

bun run check output:

$ node scripts/check-type-tokens.mjs && node scripts/check-motion-tokens.mjs && svelte-kit sync && svelte-check --tsconfig ./tsconfig.json
Text sizes and UI shape values use shared role tokens.
UI transitions and animation options use shared motion tokens or documented exceptions.
Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/mail-m3/apps/web
Getting Svelte diagnostics...

svelte-check found 0 errors and 0 warnings

bun run test final output:

 Test Files  141 passed (141)
      Tests  932 passed (932)
   Start at  04:33:03
   Duration  213.33s (transform 56%, environment 16%, import 14%, tests 9%, setup 3%)

Environment  |component| jsdom was created 43 times · 191.07s total, 26% of tracked time
             create it once per worker with pool: 'vmThreads' (keeps per-file isolation) or isolate: false (shares it across files)
             learn more: https://vitest.dev/guide/improving-performance#caching-between-reruns

The Vitest run also printed these non-failing JSDOM messages (the scroll message repeated):

Could not parse CSS stylesheet
Not implemented: Window's scrollTo() method

The #397 production E2E profile exited 0 and saved captures under artifacts/mail-m3-round3. It checked 390, 820, and 1440 px, light and dark, and the phone save-state transitions. The current local profile measured 390 px composer open at p50/p95 2109.3/3599.9 ms (browser CPU 96.7%, RSS 478,060,544 B) and 1440 px at 2463.7/3642.2 ms (CPU 108.5%, RSS 600,358,912 B). The 100-note signature-menu 10-open burst measured p50/p95 2563.5/4455.5 ms, CPU 136.1%, peak browser RSS 711,208,960 B.

For comparison, docs/perf/baseline.json has the generic open_composer.visible_ms baseline at p50/p95 185/349 ms (15 samples), not this profile's 4× CPU-throttled workload. This local run had load average 35.66/32.53/30.28 before and 47.02/42.26/34.93 after; treat the figures as noisy local evidence, not a direct regression delta. The repo Playwright harness was used because the Browser plugin was not available.

Known gaps and decisions

  • There is no directly comparable Mail composer profile in the baseline yet; the E2E profile now records this hot path for follow-up comparison.
  • I used OverlaySurface for the shared sheet header and only adjusted the composer accessory's phone grid placement. I did not fork the shared header or its ProgressiveBlur treatment.
  • The short phone labels and menu placement follow #397. Draft actions is the accessible menu name; the menu keeps the prior action availability conditions.

Cargo outputs were cleaned and apps/web/build plus .svelte-kit/output were removed after verification. No Rust files changed, so Rust crate gates were not applicable.

## Finished — Mail M3 polish round 3 ### Built - Phone draft status now shows **Saved**, **Saving…**, or **Offline · saved here** as a centred, non-clipping footnote below the title. - Removed the separate **New draft / Copy link** action row. The existing actions are in a **⋯** menu beside Send in the phone header and at the trailing edge of the desktop header. - The composer uses the shared `OverlaySurface` sheet header. Its shared sticky chrome and `ProgressiveBlur` remain owned by that component, so the composer inherits the #530 fix when it merges. - Extended the production E2E profile to assert save-status layout, action placement, and six screen captures at 390/820/1440 in both themes. It also captures both 3× phone header crops. ### Issue attachments | Capture | File | |---|---| | Phone · 390 · light | [mail-composer-390-paper.png](https://git.kayg.org/attachments/b0a11593-c379-4d8f-a194-546d464d7d8c) | | Phone · 390 · dark | [mail-composer-390-midnight.png](https://git.kayg.org/attachments/d5a6d2a1-403d-418f-a51f-bede1115d265) | | Tablet · 820 · light | [mail-composer-820-paper.png](https://git.kayg.org/attachments/f0caa277-2b9f-4c87-a059-be3189657de9) | | Tablet · 820 · dark | [mail-composer-820-midnight.png](https://git.kayg.org/attachments/c13094d8-bec1-4480-b856-a496de79214a) | | Desktop · 1440 · light | [mail-composer-1440-paper.png](https://git.kayg.org/attachments/44479909-7c06-467e-b8b4-e1573b2086fc) | | Desktop · 1440 · dark | [mail-composer-1440-midnight.png](https://git.kayg.org/attachments/b8ecbc81-49c8-4e57-899b-814bc898ab65) | | Phone header · 390 · light · 3× | [mail-composer-header-390-paper-3x.png](https://git.kayg.org/attachments/c4727545-dca4-485d-8e84-7f0e526e1fa1) | | Phone header · 390 · dark · 3× | [mail-composer-header-390-midnight-3x.png](https://git.kayg.org/attachments/647422ab-3216-4448-9b56-b146f7cf5260) | ### Files and commit - `apps/web/src/lib/mail/MailComposer.svelte` - `apps/web/e2e/mail-composer-397-perf.mjs` - Head: `a1fd501db9659fb3eb35c3a4c8025c58c99fab09` (`Move Mail draft actions into header menu`) ### Gates `bun run check` output: ```text $ node scripts/check-type-tokens.mjs && node scripts/check-motion-tokens.mjs && svelte-kit sync && svelte-check --tsconfig ./tsconfig.json Text sizes and UI shape values use shared role tokens. UI transitions and animation options use shared motion tokens or documented exceptions. Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/mail-m3/apps/web Getting Svelte diagnostics... svelte-check found 0 errors and 0 warnings ``` `bun run test` final output: ```text Test Files 141 passed (141) Tests 932 passed (932) Start at 04:33:03 Duration 213.33s (transform 56%, environment 16%, import 14%, tests 9%, setup 3%) Environment |component| jsdom was created 43 times · 191.07s total, 26% of tracked time create it once per worker with pool: 'vmThreads' (keeps per-file isolation) or isolate: false (shares it across files) learn more: https://vitest.dev/guide/improving-performance#caching-between-reruns ``` The Vitest run also printed these non-failing JSDOM messages (the scroll message repeated): ```text Could not parse CSS stylesheet Not implemented: Window's scrollTo() method ``` The #397 production E2E profile exited 0 and saved captures under `artifacts/mail-m3-round3`. It checked 390, 820, and 1440 px, light and dark, and the phone save-state transitions. The current local profile measured 390 px composer open at p50/p95 **2109.3/3599.9 ms** (browser CPU **96.7%**, RSS **478,060,544 B**) and 1440 px at **2463.7/3642.2 ms** (CPU **108.5%**, RSS **600,358,912 B**). The 100-note signature-menu 10-open burst measured p50/p95 **2563.5/4455.5 ms**, CPU **136.1%**, peak browser RSS **711,208,960 B**. For comparison, `docs/perf/baseline.json` has the generic `open_composer.visible_ms` baseline at p50/p95 **185/349 ms** (15 samples), not this profile's 4× CPU-throttled workload. This local run had load average **35.66/32.53/30.28** before and **47.02/42.26/34.93** after; treat the figures as noisy local evidence, not a direct regression delta. The repo Playwright harness was used because the Browser plugin was not available. ### Known gaps and decisions - There is no directly comparable Mail composer profile in the baseline yet; the E2E profile now records this hot path for follow-up comparison. - I used `OverlaySurface` for the shared sheet header and only adjusted the composer accessory's phone grid placement. I did not fork the shared header or its `ProgressiveBlur` treatment. - The short phone labels and menu placement follow #397. `Draft actions` is the accessible menu name; the menu keeps the prior action availability conditions. Cargo outputs were cleaned and `apps/web/build` plus `.svelte-kit/output` were removed after verification. No Rust files changed, so Rust crate gates were not applicable.
Author
Owner

Round 4 started on branch job/mail-m3, based at cc25c441b7a974185622a1dee853cf38686d2b67 (current head at start: a1fd501db9659fb3eb35c3a4c8025c58c99fab09). I am tracing the composer profile chip and phone header menu before making the small fixes.

Round 4 started on branch `job/mail-m3`, based at `cc25c441b7a974185622a1dee853cf38686d2b67` (current head at start: `a1fd501db9659fb3eb35c3a4c8025c58c99fab09`). I am tracing the composer profile chip and phone header menu before making the small fixes.
Author
Owner

Finding from Round 4 inspection: the “Mail composer profile / morgan0@example.test” card came from the e2e profile’s persisted draft. captureVisualEvidence copied that Mail draft in Playwright storageState, so the screenshot session rendered it as a Saved drafts card. It is a test fixture leak, not a linked profile/contact card or pasted-link preview; the Mail draft deck in DESIGN §45 remains unchanged. The screenshot clone now removes only the profile’s calternal.mail-drafts.v1: local-storage entries.

The phone ⋯ action was hidden when the draft was blank because the trigger depended on draft content. The header now keeps the action visible; the menu always offers New draft. The e2e checks the blank composer at 390 px, the warm tooltip, and a 44 px touch target.

Finding from Round 4 inspection: the “Mail composer profile / morgan0@example.test” card came from the e2e profile’s persisted draft. `captureVisualEvidence` copied that Mail draft in Playwright `storageState`, so the screenshot session rendered it as a Saved drafts card. It is a test fixture leak, not a linked profile/contact card or pasted-link preview; the Mail draft deck in DESIGN §45 remains unchanged. The screenshot clone now removes only the profile’s `calternal.mail-drafts.v1:` local-storage entries. The phone ⋯ action was hidden when the draft was blank because the trigger depended on draft content. The header now keeps the action visible; the menu always offers New draft. The e2e checks the blank composer at 390 px, the warm tooltip, and a 44 px touch target.
Author
Owner

Round 4 e2e visual evidence (2026-10-01). Full production screenshots cover 390, 820, and 1440 px in light (paper) and dark (midnight). Header and field crops use native 3× device scale. The attached profile JSON records the local performance run.

Full composer views

390 px

390 px, light
390 px, dark

820 px

820 px, light
820 px, dark

1440 px

1440 px, light
1440 px, dark

Native 3× crops

Phone header: light, dark. Phone fields: light, dark.

Desktop header: light, dark. Desktop fields: light, dark.

Performance profile JSON

Round 4 e2e visual evidence (2026-10-01). Full production screenshots cover 390, 820, and 1440 px in light (`paper`) and dark (`midnight`). Header and field crops use native 3× device scale. The attached profile JSON records the local performance run. ### Full composer views 390 px ![390 px, light](https://git.kayg.org/attachments/4eff2eba-3479-4c35-b819-790e57310057) ![390 px, dark](https://git.kayg.org/attachments/7f5bf1a8-84da-47e1-b248-a0338c62f904) 820 px ![820 px, light](https://git.kayg.org/attachments/e9600ca9-1300-414e-b5ed-fd6ca1e7d577) ![820 px, dark](https://git.kayg.org/attachments/7ac7f29a-c8e9-4f57-b028-518bd35306bd) 1440 px ![1440 px, light](https://git.kayg.org/attachments/ed24a51f-2d58-4e5b-a591-e5e7cf7a57ff) ![1440 px, dark](https://git.kayg.org/attachments/c9948fcd-d1fd-42a3-a19d-fccb116902f9) ### Native 3× crops Phone header: [light](https://git.kayg.org/attachments/4aa4ac17-8ea2-4948-80ad-09c8a0ca81a9), [dark](https://git.kayg.org/attachments/93015a35-aaff-409d-8e85-fa0b935d5ed8). Phone fields: [light](https://git.kayg.org/attachments/59aeaad7-6132-4d38-aacd-a37919d56a07), [dark](https://git.kayg.org/attachments/bf81ae32-ee74-4713-bd49-81b43ce2c61d). Desktop header: [light](https://git.kayg.org/attachments/b93bd88d-f09c-464f-8a87-81d752694c2a), [dark](https://git.kayg.org/attachments/c40c8686-8a71-4031-a952-bfa1736078ba). Desktop fields: [light](https://git.kayg.org/attachments/11eb93c8-9fe5-4c38-af55-3e9f24fe0a29), [dark](https://git.kayg.org/attachments/ddc5b8ae-6ebf-4229-9c20-cfab2b01eed7). [Performance profile JSON](https://git.kayg.org/attachments/aa12d4b8-bfaa-4a3a-980d-2232cb5cc457)
Author
Owner

Round 4 complete — Forgejo #397

Branch: job/mail-m3
Head: 8922a129b49a1dd71bf7009ed1147694c1ff7c05
Feature commit: 8922a129b49a1dd71bf7009ed1147694c1ff7c05 — Keep Mail draft actions available on phones.

Changes

  • The phone and desktop composer headers keep the existing ⋯ action beside Send. The icon button uses the warm “More actions” tooltip and passes the 44 px coarse-pointer target check. New draft is available for a blank draft; Copy link appears when the current draft has content.
  • The e2e now checks the blank phone menu, tooltip, touch target and menu actions. It removes this e2e owner's calternal.mail-drafts.v1: entries only from the cloned screenshot session and checks that no unrelated Saved drafts card appears there.
  • The “Mail composer profile / morgan0@example.test” card was the persisted e2e profile draft copied into the visual session by Playwright storageState. It was test fixture leakage, not a contact/profile card or pasted-link preview. DESIGN §45 names the Composer's draft deck as the place for saved drafts; that deck remains available for real saved drafts. The leaked fixture card is absent from the new screenshots.
  • The screenshot set and profile.json are attached in the Round 4 artifact comment. Local copies are in artifacts/mail-m3-round4/ (six full views for 390/820/1440 px in paper/midnight, eight native 3× crops, and the profile JSON). The stale artifacts/mail-m3/mail-composer-* files were removed.

Files

  • apps/web/src/lib/mail/MailComposer.svelte
  • apps/web/e2e/mail-composer-397-perf.mjs
  • crates/plugins/mail/src/imap.rs — conflict resolution while syncing origin/dev; this preserves the upstream explicit rustls provider selection and the branch's pub(crate) helper needed by smtp.rs.

Performance profile

The existing Mail composer profile ran once locally on calternal-dev with 4× CPU throttling. Load average was 28.56/26.16/27.99 before and 19.91/24.01/27.00 after. Composer-open results were 390 px p50/p95 715.2/902.5 ms and 1440 px 454.4/3056.8 ms (six samples each). The baseline in docs/perf/baseline.json is 185/349 ms (15 samples) on perf-test at 4× throttle, with load average 0.15/0.39/1.03 before and 3.34/1.93/1.51 after. The local run had much higher host load, so it is inconclusive as a regression comparison. The 100-note signature menu measured p50/p95 1013.3/1531.2 ms over six opens and 621.9/1370 ms over the ten-open burst; there is no signature-menu baseline.

Gates

cargo fmt --check exited 0 with empty output.

cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings:

Finished `dev` profile [unoptimized + debuginfo] target(s) in 5m 33s

cargo test -p calternal-plugin-mail:

test result: ok. 52 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 2.35s

test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-server --all-targets -- -D warnings:

Finished `dev` profile [unoptimized + debuginfo] target(s) in 8m 33s

cargo test -p calternal-server had one timeout failure:

---- wire::tests::full_app_setup_session_config_and_backup stdout ----
thread 'wire::tests::full_app_setup_session_config_and_backup' (2405640) panicked at crates/calternal-server/src/wire.rs:7505:10:
called `Result::unwrap()` on an `Err` value: Elapsed(())

test result: FAILED. 92 passed; 1 failed; 3 ignored; 0 measured; 0 filtered out; finished in 43.93s
error: test failed, to rerun pass `-p calternal-server --bin calternal-server`

The nested wire test timed out waiting for the archival worker after the delete endpoint returned 202 Accepted; I did not change the expectation or rerun it. The shared host had load average 24.52 during the slow server link.

bun run check:

Text sizes and UI shape values use shared role tokens.
UI transitions and animation options use shared motion tokens or documented exceptions.
Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/mail-m3/apps/web
Getting Svelte diagnostics...

svelte-check found 0 errors and 0 warnings

bun run test:

Not implemented: Window's scrollTo() method
Not implemented: Window's scrollTo() method

 Test Files  141 passed (141)
      Tests  932 passed (932)
   Start at  11:39:38
   Duration  84.74s (transform 51%, environment 17%, import 16%, tests 10%, setup 4%)

The #397 e2e exited 0. It captured all requested widths and themes and passed the fixture-card and phone-menu assertions. cargo clean removed 15,412 files (7.8 GiB); apps/web/build and apps/web/.svelte-kit were removed.

Decisions and sync note

DESIGN §45 does not state whether the ⋯ menu stays visible for an empty draft. I kept the menu visible and made New draft unconditional; Copy link remains conditional on draft content. The visual-session storage filter is limited to Mail draft keys for the e2e profile.

I fetched and merged origin/dev once before the gates in merge commit 56f716706ea797477118b8555580f26e8c604d52 (the merged tip was 4dc9ca394dfef2587b0833a1a59e256349591bed). The shared local origin/dev tracking ref has since advanced to 9c50871eda199ed69ef2fe3af8b44bec1bc5ebd5; status now shows 36 ahead and 318 behind. I did not repeat the fetch/merge. No push or deploy was made.

## Round 4 complete — Forgejo #397 **Branch:** `job/mail-m3` **Head:** `8922a129b49a1dd71bf7009ed1147694c1ff7c05` **Feature commit:** `8922a129b49a1dd71bf7009ed1147694c1ff7c05` — Keep Mail draft actions available on phones. ### Changes - The phone and desktop composer headers keep the existing ⋯ action beside Send. The icon button uses the warm “More actions” tooltip and passes the 44 px coarse-pointer target check. New draft is available for a blank draft; Copy link appears when the current draft has content. - The e2e now checks the blank phone menu, tooltip, touch target and menu actions. It removes this e2e owner's `calternal.mail-drafts.v1:` entries only from the cloned screenshot session and checks that no unrelated Saved drafts card appears there. - The “Mail composer profile / morgan0@example.test” card was the persisted e2e profile draft copied into the visual session by Playwright `storageState`. It was test fixture leakage, not a contact/profile card or pasted-link preview. DESIGN §45 names the Composer's draft deck as the place for saved drafts; that deck remains available for real saved drafts. The leaked fixture card is absent from the new screenshots. - The screenshot set and `profile.json` are attached in [the Round 4 artifact comment](https://git.kayg.org/kayg/calternal/issues/397#issuecomment-16282). Local copies are in `artifacts/mail-m3-round4/` (six full views for 390/820/1440 px in paper/midnight, eight native 3× crops, and the profile JSON). The stale `artifacts/mail-m3/mail-composer-*` files were removed. ### Files - `apps/web/src/lib/mail/MailComposer.svelte` - `apps/web/e2e/mail-composer-397-perf.mjs` - `crates/plugins/mail/src/imap.rs` — conflict resolution while syncing `origin/dev`; this preserves the upstream explicit rustls provider selection and the branch's `pub(crate)` helper needed by `smtp.rs`. ### Performance profile The existing Mail composer profile ran once locally on `calternal-dev` with 4× CPU throttling. Load average was 28.56/26.16/27.99 before and 19.91/24.01/27.00 after. Composer-open results were 390 px p50/p95 715.2/902.5 ms and 1440 px 454.4/3056.8 ms (six samples each). The baseline in `docs/perf/baseline.json` is 185/349 ms (15 samples) on `perf-test` at 4× throttle, with load average 0.15/0.39/1.03 before and 3.34/1.93/1.51 after. The local run had much higher host load, so it is inconclusive as a regression comparison. The 100-note signature menu measured p50/p95 1013.3/1531.2 ms over six opens and 621.9/1370 ms over the ten-open burst; there is no signature-menu baseline. ### Gates `cargo fmt --check` exited 0 with empty output. `cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 5m 33s ``` `cargo test -p calternal-plugin-mail`: ```text test result: ok. 52 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 2.35s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo clippy -p calternal-server --all-targets -- -D warnings`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 8m 33s ``` `cargo test -p calternal-server` had one timeout failure: ```text ---- wire::tests::full_app_setup_session_config_and_backup stdout ---- thread 'wire::tests::full_app_setup_session_config_and_backup' (2405640) panicked at crates/calternal-server/src/wire.rs:7505:10: called `Result::unwrap()` on an `Err` value: Elapsed(()) test result: FAILED. 92 passed; 1 failed; 3 ignored; 0 measured; 0 filtered out; finished in 43.93s error: test failed, to rerun pass `-p calternal-server --bin calternal-server` ``` The nested wire test timed out waiting for the archival worker after the delete endpoint returned `202 Accepted`; I did not change the expectation or rerun it. The shared host had load average 24.52 during the slow server link. `bun run check`: ```text Text sizes and UI shape values use shared role tokens. UI transitions and animation options use shared motion tokens or documented exceptions. Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/mail-m3/apps/web Getting Svelte diagnostics... svelte-check found 0 errors and 0 warnings ``` `bun run test`: ```text Not implemented: Window's scrollTo() method Not implemented: Window's scrollTo() method Test Files 141 passed (141) Tests 932 passed (932) Start at 11:39:38 Duration 84.74s (transform 51%, environment 17%, import 16%, tests 10%, setup 4%) ``` The #397 e2e exited 0. It captured all requested widths and themes and passed the fixture-card and phone-menu assertions. `cargo clean` removed 15,412 files (7.8 GiB); `apps/web/build` and `apps/web/.svelte-kit` were removed. ### Decisions and sync note DESIGN §45 does not state whether the ⋯ menu stays visible for an empty draft. I kept the menu visible and made New draft unconditional; Copy link remains conditional on draft content. The visual-session storage filter is limited to Mail draft keys for the e2e profile. I fetched and merged `origin/dev` once before the gates in merge commit `56f716706ea797477118b8555580f26e8c604d52` (the merged tip was `4dc9ca394dfef2587b0833a1a59e256349591bed`). The shared local `origin/dev` tracking ref has since advanced to `9c50871eda199ed69ef2fe3af8b44bec1bc5ebd5`; status now shows 36 ahead and 318 behind. I did not repeat the fetch/merge. No push or deploy was made.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#397
No description provided.