APPS: App Password creation starts from 'what do you want to connect?' in plain words, not protocol presets #412
Open
opened 2026-09-29 08:07:21 +00:00 by kayg
·
35 comments
No Branch/Tag specified
dev
wip/importhang-1121
wip/hiderev-1153
wip/hide4-1153
wip/hide3-1153
wip/hide2-1153
wip/hide-1153
wip/editreg-1132
wip/editorrail3-1113
wip/editorrail2-1113
wip/editorrail-1113
wip/e2e-b2-1071
wip/e2e-b-1071
wip/draw4-1101
wip/draw3-1101
wip/draw2-1101
wip/draw-1101
wip/directory-1199
wip/delete-1119
wip/collabloss-1197
wip/cards2-1083
wip/cards-1083
wip/canvas-visual
wip/canvasvis2-976
wip/calhdr-1112
wip/calcards-1115
wip/browserfix
wip/blocks-1125
wip/allday-1107
wip/agenda-decks
wip/agenda-1086
wip/adv7c-1105
wip/txentry-1198
wip/trayicons2-1095
wip/trayicons-1095
wip/tagperf-1186
wip/sidebar3-1094
wip/segmented-1200
wip/rev2-webperf
wip/rev2-money-ident
wip/previewcard-1098
job/collabloss-1197
wip/palette2-1123
wip/palette-1093
wip/onboard2-1141
job/restyle-settings
wip/onboard-1141.aborted-early
wip/onboard-1141
wip/notifloop-1194
wip/nlpchip-1127
wip/morph-1104
wip/merge-round-7c5
wip/merge-round-7c4
wip/merge-round-7c3
wip/merge-round-7c2
wip/merge-round-7c
wip/mchrome-1084
wip/mailghost2-1094
wip/mailghost-1094
wip/kbpreview2-1118
job/restyle-files
wip/kbpreview-1118
wip/kanban-1092
job/tagdnd-1187
job/merge30
job/perf-1124
job/tocrail-1191
job/cards-1179
wip/cards2-1179
wip/cards-1179
job/segmented-1200
wip/tocrail-1191
job/hide-1153
wip/tagdnd-1187
wip/restyle-files
wip/perf-1124
wip/merge30j
job/onboard-1141
job/restyle-notes
wip/restyle-notes
job/wizchoices-1140
job/adv-1202
job/notifloop-1194
wip/wizchoices-1140
wip/restyle-1190
job/moneyfmt-1180
job/txentry-1198
wip/moneyfmt2-1180
wip/moneyfmt-1180-r
wip/moneyfmt-1180
job/tagperf-1186
job/pillglass-1189
job/flags-1181
wip/flags-1181
job/restyle-1190
job/restyle-mailmoney
job/restyle-search
job/settingsreg-1195
job/wizard-1140
site/website
wip/wizardrev2-1140
wip/wizardrev-1140
wip/wizard5-1140
wip/wizard4-1140
wip/wizard3-1140
wip/wizard2-1140
wip/wizard-1140
wip/pillglass-1189
wip/settingsreg-1195
job/merge29
job/fu-1171
wip/merge29j
wip/fu-1171
job/fu-1166
job/directory-1199
job/txresearch-1188
wip/fu-1166
job/merge28
job/search-1066
wip/search-1066
wip/merge28j
job/gateslot-1182
job/bulkimport-1157
job/mailnet-1160
wip/mailnetrev-1160
wip/mailnet-1160
wip/bulkrev-1157
wip/bulkimport-1157
job/startup-1161
wip/startup-1161
job/merge27
job/linkcards-1151
wip/linkcards3-1151
wip/linkcards2-1151
wip/linkcards-1151
job/traydate-1144
wip/traydate3-1144
wip/traydate2-1144
wip/traydate-1144
job/draw-1101
wip/merge27j
job/blockpill-1152
wip/blockpill3-1152
wip/blockpill2-1152
wip/blockpill-1152
job/minihover-1149
wip/minihover2-1149
wip/minihover-1149
job/merge25
wip/merge25-r
wip/merge25b
wip/merge25
job/inspector-1129
job/tags-1110
wip/inspector3-1129
wip/inspector2-1129
wip/inspector-1129
wip/tagsrev-1110
wip/tags2-1110
wip/tags-1110
job/dates-1148
wip/datesrev-1148
wip/dates2-1148
wip/dates-1148
job/licence-1145
wip/licence2-1145
wip/licence-1145
job/selfhost-1156
job/merge23
wip/merge23
job/tagfilter-1109
wip/tagfilter2-1109
wip/tagfilter-1109
job/kbd-1134
wip/kbd2-1134
wip/kbd-1134
job/palfoot-1137
wip/selfhost-1156
wip/palfoot2-1137
wip/palfoot-1137
job/toggle-1158
wip/toggle-1158
job/kbpreview-1118
job/docratchet-1155
job/perflint-1133
job/devtests-1159
wip/docratchet-1155
wip/devtests-1159
job/segv-1136
wip/toast-1142
wip/segv-1136
job/toast-1142
job/blockreload-1147
wip/blockreload-1147
job/font-1150
wip/font-1150
job/importui-1120
job/minimonth-1149
wip/importui-1120
wip/minimonth-1149
job/depcheck-1146
wip/perflint-1133
wip/depcheck-1146
job/calcards-1115
job/blocks-1125
job/plus-1128
job/shift-1138
wip/plus2-1128
wip/plus-1128
wip/shift-1138
job/moneyfid-1130
job/editorrail-1113
wip/moneyrev-1130
wip/moneyfid-1130
job/noext-851
wip/noext-851
wip/noext3-851
wip/noext2-851
job/week-1135
wip/week-1135
job/editreg-1132
job/smoke-1122
wip/smoke-1122
job/docs-1143
job/palette2-1123
job/calhdr-1112
job/nlpchip-1127
job/mailghost-1094
job/reconnect-1131
wip/reconnect-1131
job/trayicons-1095
job/delete-1119
job/importhang-1121
job/cards-1083
job/palette-1093
job/mchrome-1084
job/e2e-a-1071
job/canvas-visual
job/previewcard-1098
job/allday-1107
wip/e2e-a2-1071
wip/e2e-a-1071
job/e2e-b-1071
job/adv7c-1105
job/kanban-1092
job/agenda-1086
job/merge-round-7c
job/morph-1104
wip/surfaces-p2
job/merge-round-9
wip/merge-round-9
job/7cfix-small
wip/7cfix-small
job/mailui-1078
job/merge-round-8
wip/merge-round-8
wip/mailui-1078
job/mailround-1038
job/applemail-accept
wip/settitle-1068
wip/mailround2-1038
wip/mailround-1038
wip/e2e-7b
job/crash-1069
wip/crash-1069
job/searchlost-1066
wip/searchlost-1066
job/7b-reconcile
job/flake-1065
wip/flake-1065
wip/merge-round-7b7
wip/merge-round-7b6
wip/merge-round-7b5
wip/merge-round-7b4
wip/7b-reconcile
job/appupdate-1059
job/nfd-1044
wip/appupdate-1059
job/e2e-7b
job/loop-1062
wip/loop-1062
job/pdfprev-1045
job/invtoggle-1053
wip/pdfprev-1045
wip/nfd-1044
wip/invtoggle-1053
job/7bfix-e2e
job/mailstress-b
wip/7bfix-e2e
wip/mailstress-b
job/7bfix-adv
wip/7bfix-adv
job/mailstress-a
job/stack-1054
wip/stack-1054
wip/mailstress-a
job/mailstress-1038
wip/mailstress-1038
job/upload500-1051
wip/upload500-1051
job/share-1034
wip/share-1034
job/syncerr-1037
job/7bfix-photos
wip/7bfix-photos
job/paste-1036
job/setside-1039
wip/setside-1039
wip/paste-1036
job/lease-1042
wip/syncerr-1037
wip/lease-1042
job/7bfix-data
job/passkeybind-1043
wip/apprevoke-1041
job/invite-1035
wip/invite-1035
job/merge-round-7b2
wip/merge-round-7b2
job/mailproxy-486
job/apprevoke-1041
job/rebuild-1033
job/pillborder-1029
wip/pillborder-1029
wip/mailproxy-486
wip/applemail-486
job/headless-998
wip/headless-998
job/groups-1028
wip/groups-1028
job/rebuildwarn-1016
wip/rebuildwarn-1016
job/startup-1011
wip/startup-1011
job/monthpill-1009
job/bgthumb-1025
job/sharetitle-1012
wip/monthpill-1009
wip/bgthumb-1025
wip/sharetitle-1012
job/canvas-cards-977
wip/canvas-cards-977
job/canvas-pencil-978
job/canvas-sketch-990
wip/canvas-sketch-990
wip/canvas-pencil-978
job/canvas-files-989
wip/canvas-files-989
job/canvas-collab-991
wip/canvas-collab-991
job/weekscroll-1018
wip/weekscroll-1018
wip/canvas-core-976
job/canvas-core-976
job/round-drag
wip/round-drag
job/round-settings
job/browserfix
wip/oapi-974
job/oapi-974
job/hist2-integrate
job/mailhtml-726
wip/mailhtml-726
wip/hist2-integrate
job/moneyfu-984
job/drag-1015
wip/drag-1015
job/rename-1017
wip/rename-1017
job/hist2-api
wip/hist2-api
job/oneacct-1014
wip/oneacct-1014
wip/moneyfu-984
job/hist2-bench
job/hist2-restore
wip/hist2-bench
job/hist2-write
job/hotfix-724
wip/hotfix-724
wip/hist2-write
wip/hist2-restore
job/hist2-store
job/hist2-ui
wip/hist2-ui
wip/hist2-store
job/searchstarve-965
job/shutdown-963
wip/shutdown-963
wip/pubedit-981
job/pubedit-981
job/analytics-973
wip/searchstarve-965
job/authflash-850
job/weeklane-969
job/pvtitle-1004
job/hist-975
wip/authflash-850
job/voicepill-617
wip/pvtitle-1004
job/headring-1003
wip/weeklane-969
wip/voicepill-617
wip/headring-1003
wip/analytics-973
job/agentscope-980
wip/thumbsandbox-988
job/thumbsandbox-988
wip/hist-975
job/links-856
wip/links-856
job/davetag-966
wip/davetag-966
job/filesstorm-1000
job/hoverpad-725
wip/filesstorm-1000
job/ffmpegblas-993
job/merge-round-7a
wip/hoverpad-725
wip/ffmpegblas-993
job/nowdot-1002
wip/verify-7a
job/noteid-857
wip/nowdot-1002
wip/noteid-857
wip/merge-round-7a
wip/agentscope-980
job/imapedge
job/a11yfix2
wip/imapedge-941
wip/imapedge
wip/a11yfix2
job/notetask-986
job/logheading
wip/logheading-998
job/textthumb-652
job/photolive-987
wip/photolive-987
job/davactive-983
job/savefix-985
job/tabicons-607
wip/davactive-983
wip/tabicons-607
wip/notetask-986
wip/savefix-985
job/dirid-627
job/buildspeed-1007
wip/dirid-627
job/agenda-decks
job/perfguards-impl
job/undo-a11y
wip/undo-a11y
job/mailperf
job/wal-824
wip/settings-50
job/settings-50
job/notesfilter-606
wip/notesfilter-606
job/surfaces-p2
wip/wal-824
job/maillayouts
wip/mailperf
wip/maillayouts
job/taskmeta-659
job/money-ident
wip/money-ident
wip/taskmeta-659
job/errstates
wip/perfguards-impl
job/headings-881
wip/headings-881
wip/errstates
job/voice-619
job/gaps-827
job/notesperf
wip/notesperf
wip/voice-619
job/hddsql-549
job/perf-stream-668
wip/perf-stream-668
wip/deeplinks-fix
job/deeplinks-fix
job/authfix
job/docsfix-rust
wip/docsfix-rust
job/webperf
job/docsfix-web
job/datafix2
job/webdav-lock-476
job/copyfix
wip/copyfix
wip/webperf
job/focus-658
wip/protofix
job/mediafix
job/protofix
wip/mediafix
job/agentfix
job/hhmm-724
wip/agentfix
job/undo-722
job/reuse
wip/webdav-lock-476
wip/reuse
job/scopefix
job/datafix
wip/hhmm-724
wip/undo-722
job/surfaces-p1
wip/hddsql-549
job/voicememos-618
wip/datafix2
wip/surfaces-p1
job/fix-940
wip/fix-940
job/blaze-surfaces
wip/datafix
wip/blaze-surfaces
job/taskday-655
job/linknav-639
wip/linknav-639
wip/gaps-827
job/isolation-707
job/audiophotos-720
wip/audiophotos-720
job/advfind-664
wip/voicememos-618
wip/taskday-655
wip/isolation-707
wip/advfind-664
wip/scopefix
wip/focus-658
job/testgaps
wip/testgaps
job/overscroll-718
wip/authfix
job/deps
wip/overscroll-718
job/rev2-agentfix
job/rev2-money-ident
job/rev2-mailperf
wip/deps
job/hardening-728
wip/hardening-728
job/searchgen-832
wip/searchgen-832
job/photopw-849
job/mailsql-825
wip/photopw-849
job/sharefix
wip/sharefix
job/rev2-mailhtml-726
job/rev2-perfguards
job/copyval-723
job/lightglass-r2
wip/lightglass-r2
wip/docsfix-web
job/copy-audit
job/macinterop-staging-r2
job/design-sync
job/rev2-taskmeta-659
job/rev2-webperf
job/docs-audit
job/rev2-advfind-664
job/rev2-mailproxy-486
job/states-audit
job/rev2-datafix
job/design-drift
job/test-gaps
job/rev2-voicememos-618
job/rev2-mediafix
job/rev2-deps
job/rev2-datafix2
job/licence-audit
job/issue-hygiene
job/rev2-protofix
job/rev2-voice-619
job/rev2-isolation-707
job/rev2-surfaces-p1
job/deeplink-audit2
job/rev2-audiophotos-720
wip/test-gaps
job/rev2-overscroll-718
job/rev2-undo-722
wip/states-audit
job/rev2-dropmd-719
job/rev2-linknav-639
job/merge-7b-plan
wip/merge-7b-plan
job/rev2-taskday-655
wip/mailsql-825
job/rev2-webdav-lock-476
job/rev2-browserfix
wip/design-drift
job/rev2-hddsql-549
wip/deeplink-audit2
job/rev2-scopefix
job/rev2-authfix
job/rev2-hardening-728
job/rev2-wal-824
job/rev2-sharefix
job/calsidebar-638
job/chrome-audit
job/ioperf
wip/ioperf
wip/chrome-audit
wip/calsidebar-638
job/dropmd-719
wip/dropmd-719
job/ocr-build
wip/ocr-build
job/blaze-settings
wip/copyval-723
job/toastring-721
wip/toastring-721
job/deployfix-732
wip/deployfix-732
wip/blaze-settings
job/money-import-recheck
job/rev-a11y
job/perf-arch-db
job/rev-7b-data
wip/textthumb-652
wip/perf-arch-db
job/sec-protocols
job/sidehdr-660
job/rev-7b-security
job/research-surfaces
job/rev-design-gaps
job/rev-mcp-api
wip/sidehdr-660
job/perf-arch-memory
wip/sec-protocols
job/perf-arch-bundle
job/snapedge-714
wip/rev-mcp-api
job/sec-supplychain
wip/research-surfaces
job/perf-arch-sync
job/rev-consistency
job/perf-arch-server
wip/perf-arch-server
wip/perf-arch-memory
job/perf-arch-io
job/perf-arch-client
job/sec-fs
job/sec-mcp-scopes
job/sec-sharing
job/perf-guards
job/sec-browser
job/sec-admin-deploy
job/sec-auth
wip/snapedge-714
job/bgpicker-717
wip/perf-arch-bundle
wip/money-import-recheck
job/advsetup-654
wip/bgpicker-717
wip/advsetup-654
job/burst-709
job/kbdcaps-710
job/app-pw-chooser
wip/burst-709
wip/app-pw-chooser
job/imaptest-625
wip/kbdcaps-710
job/fix-499
wip/fix-499
job/perf-mut-667
job/calimg-589
job/perf-snap-666
wip/calimg-589
wip/perf-snap-666
wip/perf-mut-667
job/perf-cache-665
wip/perf-cache-665
job/voicefiles-620
wip/voicefiles-620
job/admin-burst-705
wip/admin-burst-705
job/voicememos-review
wip/voicememos-review
wip/ryw-653
job/ryw-653
job/writeonopen-661
job/instant-663
wip/writeonopen-661
job/money-import-review
wip/money-import-review
wip/importjs-610
review/integrations-407-round6
wip/integrations-review
job/dragghost-612
wip/dragghost-612
job/integrations
wip/integrations
job/decider-656
job/merge-round-6
job/perf-rerun
wip/merge-round-6
job/integrations-review-round5
job/selalign-576
wip/selalign-576
job/mcp-events-491
job/files-631
job/cal-e2e-569
wip/cal-e2e-569
job/reload-423
wip/reload-423
wip/mcp-events-491
wip/files-631
job/notesbridge-644
wip/notesbridge-644
job/editor-series
job/calcard-series
wip/calcard-series
job/mcp-events-review-491
wip/mcp-events-review
wip/editor-series
job/quirks-546
job/integrations-recheck
job/tocrail-636
wip/tocrail-636
wip/quirks-546
wip/reminders-643
job/reminders-643
wip/davscale-573
job/davscale-573
job/integrations-review
wip/ocr-eval-584
job/ocr-eval-584
job/esc-537
wip/esc-537
job/toastname-586
wip/toastname-586
job/submenu-579
wip/submenu-579
job/tasks-mode
wip/tasks-mode
job/agentdocs-630
job/dupwrite-634
wip/agentdocs-630
wip/dupwrite-634
job/lightglass-588
wip/lightglass-588
job/tabswitch-549
job/ghosttask-623
wip/ghosttask-623
job/toaststack-616
job/weekstate-609
job/mailsync-613
wip/mailsync-613
wip/weekstate-609
job/maildup-626
wip/tabswitch-549
wip/maildup-626
wip/toaststack-616
job/motion-611
wip/motion-611
job/tlstest-601
wip/tlstest-601
job/perf-495
job/floating-sheet
wip/floating-sheet
job/remdup-585
wip/remdup-585
job/fix-502
wip/fix-502
job/attachplay-622
job/perf-batch
wip/perf-batch-563
wip/perf-495
hotfix/mail-sync-diag
job/mail-m3
wip/mail-m3
job/attach-poof-603
job/calhover-608
job/editorbar-604
job/mentions-605
job/merge-round-4
job/allday-514
wip/merge-round-4
wip/allday-514
job/merge-round-4a
wip/merge-round-4a
job/sharestack-580
job/fix-501
wip/sharestack-580
wip/fix-501
job/perf-batch-563
job/apw-cache-review
wip/apw-cache-review
job/probe-520
wip/probe-520
job/mac-393
wip/mac-393
job/header-571
job/flake-513
wip/flake-513
job/docs-thumb-547
wip/header-571
job/webcal-572
wip/webcal-572
wip/shortcuts-542
job/shortcuts-542
wip/docs-thumb-547
job/caldav-stress
wip/caldav-stress
wip/sweep-478
job/apw-cache-512
wip/apw-cache-512
job/money-empty-540
wip/restart-505
wip/money-empty-540
wip/fix-510
job/restart-505
job/fix-503
job/perf-496
wip/perf-496
job/fix-498
wip/fix-498
job/info-inspector-465
wip/info-inspector-465
job/fix-510
job/fix-507
wip/fix-507
wip/fix-503
job/fix-493
job/money-kinds
wip/money-kinds
job/hygiene-548
job/merge-round-3
wip/fix-493
job/drag-snap-536
wip/merge-round-3
wip/merge-round-0930
wip/drag-snap-536
job/align-538
wip/align-538
job/bg-flash
wip/bg-flash
job/money-import
job/search-count-544
wip/search-count-544
wip/money-import
job/settings-key-541
wip/settings-key-541
job/toast-539
job/preview-421
wip/preview-421
wip/toast-539
job/tasks-500-531
job/title-plain-526
wip/title-plain-526
wip/tasks-500-531
job/notes-bridge
wip/parity-484
job/parity-484
job/files-slow
job/crash-525
wip/notes-bridge
wip/files-slow
wip/crash-525
job/kbd-motion-527
wip/bg-422
job/analytics-504
wip/analytics-504
wip/kbd-motion-527
job/upload-pill-523
wip/upload-pill-523
wip/tray-order
job/tray-order
wip/overflow-mid
wip/merge-round-2
job/perf-494
wip/perf-494
wip/mcp-fast-492
wip/motion-477
wip/asr-ab-489
wip/theme-variants-506
wip/overflow-511
wip/week-header-508
wip/attach-427
job/dav-delete-471
job/iso-435
wip/iso-435
wip/files-sel-keys
wip/dav-delete-471
job/align-253
job/siwc-490
wip/siwc-490
job/money-kinds-review
wip/align-253
wip/money-kinds-review
job/small-bugs-3
wip/overlay-title-487
wip/multiget-500
wip/hidden-420
wip/webcal-ui
wip/webcal-431
job/perf-367
job/location
wip/small-bugs-3
wip/location
wip/perf-367
wip/admin-deny-483
job/tag-unicode-473
wip/tag-unicode-473
job/blur-436
wip/photos-470
wip/blur-436
wip/small-bugs-4
wip/hunt-20260930
wip/settings-hdr-482
wip/chips-416
job/dedup-375
wip/dedup-375
job/doc-stack
wip/doc-stack
job/tokens-literals
wip/tokens-literals
job/jobs-leftovers
wip/send-fast
wip/paste-467
wip/money-numbers
job/money-plugin
wip/money-plugin
job/break-dav
wip/merge-batch
wip/crossday-469
wip/mac-verify
wip/mail-m2
wip/break-dav
wip/money-review2
job/money-md
job/modes-424
wip/money-md
wip/jobs-leftovers
job/agenda-413
wip/agenda-413
wip/modes-424
job/recog-417
wip/recog-417
wip/bounce-425
wip/ab-384-luna
job/webdav-perf
wip/webdav-perf
job/toast-ring
wip/toast-ring
job/money-review
wip/money-review
wip/micro-motion
wip/settings-card
wip/minical
job/notes-imap-428
job/least-priv
wip/ui-small-2
wip/flaky-426
wip/drag-end-418
job/jank
wip/jank
wip/least-priv
wip/docs-site
job/agenda
job/sec-batch
wip/sec-batch
wip/per-user-index
job/area-calendars
wip/area-calendars
job/parity
wip/parity
job/documents-research
wip/documents-research
job/test-infra
job/reminders-sync
wip/small-bugs-2
wip/reminders-sync
wip/gestures
job/google-oauth
wip/tags-merge
wip/tags
job/e2e-theme
wip/e2e-theme
job/icon-align
wip/test-infra
wip/select-align
wip/editor-385
job/voice
wip/webdav
job/webdav
job/app-pw-ui
job/editor-integrity
wip/editor-integrity
wip/voice
wip/quota
wip/cal-followups
wip/icon-align
job/composer-scale
wip/composer-scale
job/jobs-page
wip/jobs-page
job/hig-type
wip/hig-type
wip/app-pw-ui
job/motion-spring
job/mcp
wip/motion-spring
wip/mcp
job/small-bugs
wip/push-hosts
job/profile-sign
wip/touch-369
wip/profile-sign
job/mobile-focus
wip/mobile-focus
wip/ui-polish-354
wip/small-bugs
wip/dup-task
job/toast-polish
job/app-pw-scopes
wip/toast-polish
wip/app-pw-scopes
wip/cli-agent
wip/selection-pills
job/preview-attach
wip/preview-attach
job/dav-proppatch
wip/dav-proppatch
wip/cal-switcher
job/atomic-race
wip/atomic-race
job/photos-shared
wip/photos-shared
wip/cal-grid
wip/note-rewrite
wip/search-rebuild
job/mail-m1
job/paperless-import
wip/paperless-import
wip/mail-m1
wip/hidden-activity
wip/search-d
wip/pricing-research
wip/cursors
wip/auto-scheme
job/single-pills
wip/single-pills
wip/xuser-matrix
wip/money-format
wip/app-pw-setup
wip/purge-dos
wip/vault-health
wip/caldav-apple
wip/xuser-audit
wip/e2e-green
wip/tabbar
wip/adv-harness
wip/maple-mono
job/search-fix
wip/search-fix
wip/search-perf-c
job/adv-harness
wip/sidebar-headers
job/glass
wip/temp-index
job/polish
wip/polish
wip/file-protocols
wip/money-research
wip/glass
wip/voice-models
wip/collab-redo
job/voice-research
wip/hunt-20260928
wip/notes-actions-research
wip/search-pad
wip/search-perf
wip/search-sticky
wip/editor-undo
wip/chrome-rules
wip/motion
wip/appearance-research
wip/appearance
wip/audit-bugs
wip/cal-glass
wip/block-actions
wip/authz-order
wip/event-stripes
wip/chrome-sidebar
wip/auth-flaky
wip/robust-2
wip/gate-fix
wip/menu-blur
wip/import-calternaljs
wip/tray-fix
job/import-calternaljs
wip/index-order
wip/audit-fixes
wip/search-chevrons
research/mail
wip/phone-chrome
wip/dedup-break
wip/csp
wip/ui-audit
wip/select-toast
wip/perf
wip/flat-layout
wip/fonts
wip/event-tint
wip/sync-converge
wip/data-split
wip/glass-audit
wip/robustness
wip/sync-chaos
wip/search-thumbs
wip/fuzz
wip/menu-icons
wip/search-pill
wip/sync-changing
wip/heading-links
wip/date-formats
wip/a11y
wip/break-editor
wip/e2e-fix
wip/settings-sections
wip/sync-root-guard
wip/search-palette
wip/share-edit
job/toasts
wip/toasts
wip/cont-analytics
wip/authz-review
wip/popovers
wip/overlay-glass
wip/change-feed
wip/editor-modes
wip/composer-align
wip/cont-agenda
wip/agenda-merge
job/agent-conventions
wip/agent-conventions
wip/backend-misc
job/route-audit
wip/route-audit
wip/ui-batch
wip/heif-hardening
wip/grid-resize
wip/ask-page
wip/webmcp
job/deeplink-audit
wip/deeplinks
wip/shortcuts
wip/cont-tz-days
main
No results found.
Labels
Clear labels
No items
No labels
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
kayg/calternal#412
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Request (owner, 2026-09-29)
"we need to make this way more user friendly!" — the App Password "Scope preset" menu lists technical labels ("Calendar apps · CalDAV", "Files / WebDAV", "Photo upload · PhotoSync", "Automation · API", "AI assistant · MCP (read only)", "Custom scopes").
Direction (Claude proposal; owner reviews the screenshots)
Evidence: screenshots of the chooser and each flow at 390/820/1440, light and dark.
Added (found by the docs-site job, #415):
AppPasswordsGroup.svelte:393,426,428always says the Apple profile is unsigned ("Not Verified", "author is unknown"). On calternal.cloud, profile signing is configured and verified (the admin config reports enabled: true, macOS reports GoodSignature). Drive this copy from the server's profile-signing status (ProfileSigningStatusin the OpenAPI contract): when signed, show the signer name ("Signed by ") and drop the unknown-author steps. Show the unsigned guidance only when signing is not configured. Add an e2e for both states.Starting #412 on job/app-pw-chooser from
dfb5964a2f(dev). I’m tracing the existing App Password flows and profile-signing contract before changing the chooser.Finding: carries , but it is an admin-only route. App Passwords are available to non-admin Users too. I’ll return the signing status alongside the one-use profile links, from the same signer operation that creates the profile bytes, so the UI reports the status of the profile it will deliver.
Correction: the status is in GET /api/v1/admin/config as the ProfileSigningStatus field, and that route is admin-only. Since ordinary Users can create App Passwords, I will return the status beside the one-use profile links from the same signer operation that creates the profile bytes.
Finding: the first
bun run testreportedshared-components.guard.test.tsatAppPasswordsGroup.svelte: <Cardbecause the guard treats every Card as a private Settings card. The chooser uses the shared@calternal/uiCard from #402, so I updated the guard to allow that import while keepingSettingsCardfor the Settings surface. The same run had 875/877 tests pass; the unrelated ThemePicker test hit its 5-second timeout with jsdomscrollTo()warnings. I left that timeout and its expectations unchanged and will report the final suite result after the merge.Finding: the bearer-token reveal showed the token and scope but no server endpoint for API, MCP, or PhotoSync clients. The reveal now shows a copyable
/api/v1/URL for API grants and/mcpfor MCP grants. The real-server e2e flow checks the displayed API URL.Finding: the profile-links response did not report whether its one-use profile bytes were signed, and the admin configuration status is not available to regular Users. The response now carries
ProfileSigningStatusfrom the same sign-or-unsigned operation that creates the queued bytes. Evidence:cargo test -p calternal-authfinished withtest result: ok. 63 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 115.14s; clippy passed. Commit:cffbcdcc2.The chooser UI slice is committed as
0293cd5cf(feat(web): add plain-language app password presets). It adds eight preset choices with scope explanations, real Home folder selection for Files and PhotoSync, one-time secret and endpoint copy, and signer-aware Apple setup copy. The production-server E2E script now checks Notes/Mail plugin isolation, PhotoSync restrictions, and captures chooser, API, and Apple setup states at the requested device widths and themes.bun run checkpassed with 0 errors and 0 warnings; the focused shared-component guard test passed (2 tests). Server clippy is still running before the final post-merge gates.Owner decisions (2026-09-30):
Server verification finding:
cargo clippy -p calternal-server --all-targets -- -D warningspassed.cargo test -p calternal-serverran 87 tests: 84 passed, 2 ignored, and the process-isolatedlive_apps_run_in_separate_processestest failed because its nestedfull_app_setup_session_config_and_backuptest timed out withElapsed(())after 40.41s. The test expectation is unchanged. This appeared during heavy shared-host Rust activity. I will preserve it in the final report.Post-merge auth gates: clippy passed (
Finished dev profile ... in 1m 50s).cargo test -p calternal-authreported 53 passed and 10 failed. All 10 failures returnedErr(Unavailable)from test database setup (oidc.rs:463orstore.rs:2957); the same auth crate passed all 63 tests earlier in this job. No test expectation was changed. This run occurred during heavy shared-host Rust activity.Final report for #412. The job passed the four-hour cap, so I stopped with a clean worktree and recorded the remaining gates below. No screenshots were produced.
Built and committed:
cffbcdcc2feat(auth): report profile signer status with setup links0293cd5cffeat(web): add plain-language app password presetsorigin/devonce; merge commit07899dc59.07899dc599.Implemented the chooser presets, scope explanations, real Home folder choices, one-time token and endpoint copy, and signer-aware Apple profile instructions. The E2E script covers Photosync restrictions, Notes/Mail plugin isolation, signed/unsigned profile copy branches, and production screenshots. Those browser probes and captures were not run before the time cap.
Gate output:
cargo fmt --check: passed with no output.cargo clippy -p calternal-auth --all-targets -- -D warnings:Finished dev profile [unoptimized + debuginfo] target(s) in 1m 50s(post-merge).cargo test -p calternal-auth:test result: FAILED. 53 passed; 10 failed; 0 ignored; 0 measured; 0 filtered out; finished in 56.57s. Each failure returnedErr(Unavailable)while setting up the test database. The same crate passed all 63 tests earlier in this job. Test expectations were not changed.cargo clippy -p calternal-server --all-targets -- -D warnings:Finished dev profile [unoptimized + debuginfo] target(s) in 9m 58s(post-merge).cargo test -p calternal-server:test result: FAILED. 84 passed; 1 failed; 2 ignored; 0 measured; 0 filtered out; finished in 51.79s. The nested live-app setup test timed out withElapsed(())after 40.41s. Expectations were not changed.bun run check:svelte-check found 0 errors and 0 warnings. Focused shared-component test passed:Test Files 1 passed (1); Tests 2 passed (2).bun run testhad an earlier run with 2 failures among 877 tests (the shared-card guard, since fixed, and an unrelated ThemePicker timeout). It was not rerun after the guard fix or after the merge.Decisions not specified in DESIGN: Notes and Mail use existing API credentials with a fixed plugin scope, so each token is limited to its named plugin. Files and PhotoSync select real visible Home folders. API, MCP, DAV and Files endpoints are shown with their matching transport URLs. Apple setup copy uses the signing status returned with the profile links so it describes the delivered profile.
Resuming #412 in
/home/kayg/Developer/calternal-wt/app-pw-chooserat07899dc599a5cad7508b2b24fe17377216977d9c(job/app-pw-chooser). I have read the current owner decisions from 2026-09-30 and will apply the single “Sync with Your Devices” preset, the Apple/Other Devices disclosure layout, deep links, and QR contrast. First I am updating fromorigin/devas requested, then I will rerun the auth tests alone and continue the UI verification.E2E finding: Chromium timed out at
apps/web/e2e/app-passwords.mjs:45when the helper calledradio.check()for PhotoSync. The radio is intentionally clipped to a 1px hit box; Playwright attempted that hidden hit target and reported that.preset-gridintercepted the click. The visible wrapping label remains the intended pointer target. I am updating the E2E helper to exercise the visible label and keyboard selection separately; this is a test interaction mismatch, not evidence of a UI failure.E2E finding: after fixing pointer selection, the chooser reached PhotoSync and the assertion
getByText('Protocol').count() === 0found the label inside the collapsed Custom access panel.Disclosure.svelteretains its panel in the DOM withhidden/display: noneso itsaria-controlstarget remains stable. The visible UI still keeps protocol choices closed. I am narrowing this assertion to the visible custom-access panel so it checks the original user-facing requirement rather than counting hidden DOM text.E2E finding: the first Sync password POST returned HTTP 200. The flow then failed before checking manual instructions because the non-exact
getByRole('button', { name: 'Manual' })matched both the Manual disclosure and its newCopy link to Manualaction. I am scoping that locator to the exact accessible name so the test addresses the disclosure while retaining the copy-link check.E2E finding: the Sync flow reached Manual and rendered the expected headings (
iPhone / iPad,Mac). The check failed becauseassert.equalcomparesallTextContents()arrays by object identity, even when their contents match. The updated App Password and Calendar E2E flows have this assertion pattern; I am usingdeepEqualwhile keeping both expected arrays unchanged.E2E finding: both Sync creation requests returned HTTP 200. The shared ready-state matcher then timed out because its regex accidentally required the words
secretandpasswordtogether, while the UI has two valid messages: “Copy this password now” for Sync and “Copy the secret now” for other grants. I am correcting the matcher to accept those two exact message forms; the UI text and expectation remain unchanged.E2E finding: the Sync Manual panel renders the same server URL for both iPhone/iPad and Mac, as required by the two setup sections. The test used a strict exact-text locator that expected one match and failed with two matches. I am asserting that both manual instructions contain the server URL and waiting on the first rendered value; the UI and expected setup content remain unchanged.
E2E finding: the Sync setup exposes the same one-time password in six locations: the reveal, two Manual instructions, and three Other Devices instructions. A strict single-match locator failed when the test read it. I am reading all rendered secret fields, asserting they carry the same value, and retaining the first value for the existing checks without logging it.
E2E finding: the second Sync password has the same scope summary as the first, so the list contains two identical scope strings. The strict text locator then failed despite the new credential row being present. I am locating the row by its unique password name and checking the expected scope within that row.
E2E finding: the uniquely named password row was present.
SettingsRowcombines the scope summary with created, last-used, and expiry text in one metadata span, so an exact-text query for only the scope cannot match. I am retaining the same expected scope and matching it as text within that named row.E2E finding: the full
apps/web/e2e/calendar.mjsrun stopped at line 579, before its App Passwords section. The existing assertionthe send startedreceivednullwhere it expectstrue. I did not alter that existing expectation because this issue does not change send behavior. The dedicated App Passwords E2E passed and covers the profile setup flow independently.Benchmark profile finding: the first temporary App Password POST returned HTTP 200, but the seed wait timed out. The ready paragraph also contains the credential name, so an exact text query for only the copy sentence did not match. I am matching the unchanged ready sentence within the paragraph before continuing the 50-row profile.
Performance probe finding: selecting Photos from
/filesleft the shell at/fileswithOpening Photos…after 5 seconds, despite HTTP 200 from/api/v1/photos/timeline/buckets; the existing route probe timed out at 30 seconds. I filed this unrelated navigation issue as #528. I am running the #412 profile in isolation so its measurements cover App Passwords only.Finished report — #412 App Password chooser
Branch:
job/app-pw-chooserHead:
8f774059f5ab2668f742522c10d615ca08c3ffafBuilt the single Sync with Your Devices preset with the approved subtitle, plus Files, PhotoSync, AI assistant and automation choices. Setup now uses shared disclosures and stable section links. Apple setup opens on Apple Devices → Automatic, with a dark-on-light QR code and Install Profile action; Manual and Other Devices start collapsed and show copyable credentials. Mail and Notes are not separate choices. Existing Notes/Mail records remain supported and are summarized as “Synced data.”
Attached 12 production-build screenshots to this issue: chooser and ready states at 390, 820 and 1440 px in light and dark themes. The dedicated App Password production E2E flow passed, including grant checks, one-use profile links, QR contrast, deep links and actual clipboard copies.
Changed files:
apps/web/src/routes/settings/account/AppPasswordsGroup.sveltepackages/ui/src/components/Disclosure.svelte,CopyControl.svelte, andpackages/ui/src/index.tsapps/web/e2e/app-passwords.mjs,calendar.mjs, androute-perf.mjsbench/run.sh,bench/record.py, andbench/test_record.pydocs/perf/runs/2026-09-30-issue-412-app-passwords.mdand2026-09-30T1514Z-issue-412-app-passwords.jsonGates
cargo fmt --check: exit 0; no output.cargo test -p calternal-auth(run alone):bun run check:bun run test:The web tests also printed existing jsdom
Window's scrollTo()and CSS parse warnings.python3 -m unittest bench.test_record:cargo cleancompleted:Removed 8535 files, 5.4GiB total. Webbuild/and.svelte-kit/outputs were removed.Performance
The #412 profile used 50 real credentials, three runs at 390/1440 px and a 24-client burst. App Password data-ready p50/p95 was 2973/3020 ms at 390 px and 7355/10040 ms at 1440 px. Chooser open p50/p95 was 443/909 ms. The server sample recorded idle RSS 215.7 MiB, idle CPU 0.5%, peak RSS 215.9 MiB, and peak CPU 427.94%.
The 12-second list burst made 17,398 requests: 102 HTTP 200 and 17,296 HTTP 429. Its latency percentiles mostly describe rate-limit responses, not successful list reads.
docs/perf/baseline.jsonhas no App Password route. Its nearest Settings route was Appearance; its 24-client storm returned only 200s. The current host load average ranged from 26.29 to 34.80, and the routes and workloads differ, so the report records these numbers as diagnostic rather than a direct regression comparison.Known gaps and decisions
The broader
bun e2e/calendar.mjsrun stopped before its App Password section at the existing “the send started” assertion (line 579; actualnull, expectedtrue). I kept that expectation unchanged; the dedicated App Password E2E passed. The performance probe also found Photos navigation stuck at “Opening Photos…” while its bucket API returned 200; that separate finding is filed as #528.Decision not specified in DESIGN: the new Sync choice maps to the existing full CalDAV grant and
/dav/setup path; existing per-service Notes/Mail credentials remain supported but are shown generically. No Rust source crate changed. The auth crate test was rerun alone and passed.Owner, 2026-09-30 night: the instruction sections in the App Password setup must be plain headings / sub-sections / sub-cards, with no expand/collapse pills or disclosures. The queued polish round (job/app-pw-chooser) is updated with this rule.
Starting polish round 2 on branch job/app-pw-chooser. Current HEAD:
8f774059f5; branch base (merge-base with origin/dev):ec917c7f19. I’m updating the ready/setup layout, heading Copy link controls, responsive sheet surface, and #412 browser coverage.Finding after the origin/dev merge: stopped in the new motion-token guard at AppPasswordsGroup.svelte:863 because the Copy link animation used a literal 140ms ease. I am switching that transition to the shared token and will rerun the web gates.
Finding after origin/dev merge: the new motion-token checker rejected AppPasswordsGroup.svelte's literal 140ms ease transition. I replaced it with --dur-brief and --ease-standard. The rerun completed with: svelte-check found 0 errors and 0 warnings.
Finding from the 390 px light capture: the App Passwords SettingsCard painted an inset panel inside the phone's glass sheet. I removed that wrapper surface and padding only on the phone sheet. Its content now uses the sheet's standard 16 px inset, and the three setup sub-cards keep their shared card role. The dedicated E2E asserts this rule and completed the 12 screenshot captures.
Evidence:
svelte-check found 0 errors and 0 warnings;app password e2e: one sync choice, Apple profiles, other devices, retained grants, and QR contrast passed.The focused live adversarial round for App Password profile issuance and delivery completed with 0 findings. It checked malformed and oversized requests, cross-user and mismatched IDs, signed CMS delivery, expiry, replay, a 20-request one-use race, and a 200-request burst. It reported one SLOW-only result: signing took 1.2 s (HTTP 200) on the shared local host. No 5xx or accepted hostile input was reported.
Finished: App Password chooser polish round 2
Built: static Apple setup headings; Manual and Other Devices sub-cards; in-row Copy link actions with the warm tooltip; centred 200 px QR, caption and content-sized Install Profile action; footnotes after the action; and a trailing Done action. The phone sheet owns the outer surface, and the app-password content uses its 16 px inset. The E2E asserts this and masks both the one-time secret and QR in every ready screenshot.
Files:
apps/web/src/routes/settings/account/AppPasswordsGroup.svelte,apps/web/e2e/app-passwords.mjs,apps/web/e2e/calendar.mjs,apps/web/e2e/route-perf.mjs,apps/web/src/routes/settings/shared-components.guard.test.tspackages/ui/src/components/CopyControl.svelte,CopyLink.svelte,Disclosure.svelte,LinkedHeading.svelte,packages/ui/src/index.tscrates/calternal-auth/src/api.rs,profile_signing.rs,contracts/openapi.json,packages/api-client/src/generated.tsbench/record.py,bench/run.sh,bench/test_record.py, anddocs/perf/runs/2026-09-30-issue-412-app-passwords.md,2026-09-30T1514Z-issue-412-app-passwords.json,2026-10-01-issue-412-polish-round2.mdScreenshots: all 12 sanitized screenshots are attached here.
Head SHA:
e2cf6ef0700f9bd4cf594f5ce0e4a89f1d27ed6bGates (verbatim excerpts)
cargo fmt --check: exit 0; no output.bun run check:bun run test:bun run test:e2e:app-passwords:Rust gates:
Production SPA build:
Performance: local
calternal-dev, 50 credentials, one route sample per viewport, load average 24.43–26.68. Chooser visible p50/p95 was 197/427 ms; API list read was 8.1/22.9 ms over 50 successful samples. The 24-client, 12 s list burst made 11715 requests: 49 HTTP 200 and 11666 HTTP 429, p50/p95 21.2/49.9 ms; peak RSS 231.3 MiB.docs/perf/baseline.jsonhas no App Password route, so the report records the nearest Appearance values as context only. The local profile is diagnostic under this load.Adversarial round: 0 findings. One SLOW-only result: profile signing took 1.2 s (HTTP 200) on the shared host. No 5xx or accepted hostile input was reported. Three
calternal-servertests remain ignored by their existing process-isolation annotations.Decisions: for phone sheet presentation only, the SettingsCard wrapper is a transparent, zero-padding layout container so the sheet remains the single outer surface; its three shared instruction sub-cards remain intact. This follows the owner’s 390 px requirement and leaves desktop card styling unchanged.
Copy audit evidence for the current Settings → Apps → App Passwords screen
The current screen still exposes the protocol-first labels that this issue aims to remove:
apps/web/src/routes/settings/account/AppPasswordsGroup.svelte:45,56-60:CalDAV,Notes · IMAP,WebDAV,API,MCPin protocol names and custom-access choices. Use app tasks such asCalendar,Files,Automation, andAI helper; keep protocol names out of the normal flow.:48-52:Calendar apps · CalDAV,Files / WebDAV,Photo upload · PhotoSync,Automation · API,AI assistant · MCP (read only). Use plain choices that describe the app and what it can do. The 2026-10-02 owner rule also says not to name third-party products in the UI.:335:Give each external app its own password. Choose its protocol and access, set an optional Home folder or expiry, and revoke it without changing other passwords.Replaceprotocolandaccesswith plain task words.:403,:441-462: setup steps name platform Settings paths, CalDAV, Thunderbird and DAVx⁵. Use plain steps for adding a calendar account and copy-ready fields. Do not name third-party products in the instructions.:495-499:Bearer token,Authorization header, andscopetell people how to send the secret. Use a plain label and one short setup sentence.:509-510:scopeSummary(...)shows protocol, access and resource details in each row. Show what the password can do in plain words.:532-546:Scope preset,protocol, andaccesslabels. UseWhat do you want to connect?, then show extra technical choices only under a clearly named advanced section.:559-569:Plugin ID,Plugin access,Resource IDandHome folder prefix. Use app name, allowed actions, and folder names.:164,177,198-212: validation errors and last-used summaries can exposeAPI,plugin ID, and protocol names. Keep those messages in plain words too.Test idea: review the create, setup, detail and revoke flows at phone, tablet and desktop widths. Check visible labels, help text, errors, screen-reader names and saved-row summaries. The normal flow must not show protocol names or third-party product names.
More App Passwords wording from setup and validation
apps/web/src/routes/settings/account/AppPasswordsGroup.svelte:161:Upload-only access needs a Home folder.→Choose a folder for uploads.:177:Use lowercase letters, numbers, hyphens, or underscores for the plugin ID.→Use lowercase letters, numbers, hyphens, or underscores for the feature name.:180:Enter a valid resource ID or leave it empty.→Enter a valid item name or leave it empty.:389:Install within 8 minutes. Apple removes a downloaded profile that is not installed in time.→Install the downloaded profile within 8 minutes. It is removed after that.:393:The profile is unsigned. Apple may show “Not Verified”; HTTPS protects the download.→Your device may show “Not verified” for this profile. The download uses a secure connection.:422:If Safari asks to allow downloads from this site, choose Allow.→If your browser asks to allow downloads from this site, choose Allow.:428:The profile is unsigned. macOS labels it “Not Signed” and warns that the author is unknown. This is expected until profile signing is configured.→Your Mac may say it cannot verify who made this profile. This is expected.:535:The selected protocol and access are enforced for every request. The calendar preset keeps its existing QR and profile setup.→This password keeps the access you chose. The calendar choice also gives setup steps and a QR code.:541:This credential can list names and upload new files in this folder. It cannot download or replace files.→This password can show file names and upload files in this folder. It cannot download or replace files.Test idea: check each custom-access validation error and both setup paths. Check the copy on a Mac and on other devices. Keep the same secure profile installation steps.