Move Mail account and message projection to per-User files #441

Open
opened 2026-09-29 12:50:52 +00:00 by kayg · 0 comments
Owner

Follow-up from #435 and docs/audits/cross-user-inventory.md. DESIGN §48 requires physical separation of each User's Derived data.

Current state: plugins/mail/migrations/0001_mail.sql: accounts, folders, messages, memberships, sync generations; include attachment cache and Mail Search. Shared User-keyed rows can expose message content and credentials.

Acceptance: use a separate User Index file under .system/index/users/<User ID>/; open from a validated, authenticated User context; bound open handles; migrate rows once with count verification before deleting old rows; resume after a crash at each step; keep reads on the old store until the new file is verified. Test that removing an owner predicate still cannot expose another User's data. Extend tests/adversarial/xuser_matrix.py for each affected API and run the per-crate gates. Do not change shared security state.

Follow-up from #435 and docs/audits/cross-user-inventory.md. DESIGN §48 requires physical separation of each User's Derived data. Current state: plugins/mail/migrations/0001_mail.sql: accounts, folders, messages, memberships, sync generations; include attachment cache and Mail Search. Shared User-keyed rows can expose message content and credentials. Acceptance: use a separate User Index file under `.system/index/users/<User ID>/`; open from a validated, authenticated User context; bound open handles; migrate rows once with count verification before deleting old rows; resume after a crash at each step; keep reads on the old store until the new file is verified. Test that removing an owner predicate still cannot expose another User's data. Extend tests/adversarial/xuser_matrix.py for each affected API and run the per-crate gates. Do not change shared security state.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#441
No description provided.