27 Commits
Author SHA1 Message Date
Matthieu MALVACHE fc7b22a74a chore: v1.7.3 - dependency maintenance
Next.js 16.3.5, DOMPurify 3.4.15, React 19.3, next-intl 4.14.5 and
tooling patch releases.
2026-09-20 22:21:56 +02:00
Matthieu MALVACHE 773284e12e fix: restore lock file consistency for npm ci
The 1.7.2 version bump regenerated the lock and left a nested @emnapi
entry unresolved, which broke the Docker image build.
2026-09-19 17:40:03 +02:00
Matthieu MALVACHE 70c5d1a839 fix: v1.7.2 - SSO sessions survive reloads with external identity providers
Request offline_access so the IdP issues a refresh token, and add an
OAUTH_SCOPES override for providers that reject or extend the default
list. Closes #104
2026-09-19 17:35:23 +02:00
Matthieu MALVACHE d682f5fe23 fix: v1.7.1 - OIDC logout with Keycloak, favicon badge on Firefox, settings cleanup 2026-08-28 02:42:32 +02:00
Matthieu MALVACHE c3a79a8bc3 feat: v1.7.0 - unified inbox across accounts, cross-account search, send-as for shared accounts 2026-08-28 01:59:13 +02:00
Matthieu MALVACHE 45f8417846 fix: regenerate lockfile with resolved optional platform packages 2026-07-05 05:08:01 +02:00
Matthieu MALVACHE 21a43d686d fix: restore optional platform deps in lockfile for the Docker image build 2026-07-05 05:01:36 +02:00
Matthieu MALVACHE e6a712f8b8 fix: v1.5.3 - stability and security fixes across send, filters, shared mailboxes and CSP 2026-07-05 04:53:54 +02:00
Matthieu MALVACHE 3ea7441f93 fix: v1.5.2 - patch Next.js WebSocket SSRF (CVE-2026-44578)
Security: upgrade Next.js 16.2.4 -> 16.2.6 to patch CVE-2026-44578
(GHSA-c4j6-fc7j-m34r, CVSS 8.6, unauthenticated WebSocket-upgrade
SSRF on the built-in Node server) and eleven other May 2026
advisories bundled in the same release. next-intl patched for
GHSA-4c35-wcg5-mm9h prototype pollution in the experimental
precompile path. React/react-dom rolled forward to 19.2.6.

Fixes:
- bulk delete now honours the "delete to trash" setting instead of
  always hard-deleting
- favicon repaints the base icon on zero unread so the badge clears
2026-05-14 22:32:20 +02:00
Matthieu MALVACHE f3e84a9549 fix: v1.5.1 - Gmail-origin attachments render, email-to-self delivered
- Attachments from providers that stamp a Content-ID on every part
  (e.g. Gmail) now show in the attachment panel; previously they were
  silently filtered out as "inline" even when the HTML body never
  cited their cid. The viewer now parses the body for actual cid:
  references and treats only those attachments as inline (#58).
- Email-to-self no longer gets discarded as a duplicate by the
  sender's own MTA. The send flow keeps the outgoing message in
  Drafts during submission and uses EmailSubmission.onSuccessUpdate\
Email to move it to Sent only after SMTP has accepted it, so the
  inbound delivery for self-send doesn't match a pre-existing
  Message-ID in the account (#60).

Thanks @melges-morgen and @tamisoft for the reports.
2026-04-17 14:58:11 +02:00
Matthieu MALVACHE 41cc48203c feat: v1.5.0 - print, archive-thread, favicon badge + avatars, ru/uk locales
Community PRs and targeted feature work. Highlights:

Features
- Archive now operates on the whole conversation, matching Gmail (#49)
- Russian and Ukrainian locales, full translation sets (#59 @VsevolodSauta)
- Custom favicon with unread badge painted over the base mail icon;
  also fixes stale sidebar counters on JMAP push (#63 @jabiinfante)
- Optional domain-favicon avatars with a privacy-preserving proxy and
  a freemail denylist so the same provider logo isn't shown for every
  sender on a shared host (#22)

Fixes
- Print (Ctrl+P, button, menu) produces a clean single-column page for
  plain text and HTML emails alike, with actions/reply panels hidden,
  dark-mode overridden, and wide newsletters shrunk to fit A4
- Contacts now load past 500 entries by batching ContactCard/get to
  the server's maxObjectsInGet (#45 @capitanroy, #46)
- Sieve filter destinations use the full Parent/Child folder path so
  Stalwart can resolve them (#62 @travier)
- OIDC over plain HTTP shows a clear HTTPS-required banner instead of
  throwing crypto.subtle is undefined (#23 @jothoma1)
- Missing contacts delete-confirm translation keys added to every
  locale (only Dutch had them before)
- Favicon badge hook stopped tearing out Next.js's managed icon link,
  fixing a parentNode-is-null crash on route changes
- Contact empty-state action buttons fit their container (#56)
- Print layout excludes sidebar/list (#55 @prastowoagungwidodo)

Docs
- README example for OAUTH_ONLY=true to disable Basic Auth (#61
  @travier)

Infrastructure
- Container images also published under jmap-webmail:1 for major-tag
  pinning (#57 @joelpurra, closes #54)
2026-04-17 14:39:50 +02:00
Matthieu MALVACHE cc01b84f46 fix(security): XSS in plain-text linkifier, bump vulnerable dependencies
The plain-text email renderer escaped <, >, and & before building anchor
tags for linkified URLs, but did not escape " or '. A crafted URL
containing a quote broke out of the href attribute and could inject
event handlers into the rendered HTML. Affects both the single-email
viewer and the threaded conversation view.

Fix by extracting a shared plainTextToSafeHtml helper that escapes all
five HTML-significant characters in the correct order before
linkification. Both views route through it. Regression tests parse the
output and assert no event handler lands on the anchor element.

Reported privately by Linus Rath. Thank you for the responsible
disclosure.

Also bumps dependencies flagged by npm audit:
- Next.js 16.1.5 -> 16.2.4 (DoS in Server Components)
- next-intl 4.5.8 -> 4.9.1 (open redirect)
- DOMPurify 3.3.1 -> 3.4.0 (FORBID_TAGS bypass)
- picomatch, vite, brace-expansion resolve transitively

Also carries the Apache JAMES compose fix from the 1.4.0 cycle (explicit
text/plain type on textBody per RFC 8621 section 4.1.4) and the missing
email_viewer.send translation.

Release 1.4.1.
2026-04-16 22:51:58 +02:00
Matthieu MALVACHE 384b757815 feat: v1.4.0 - folder management, mail multi-selection, bug fixes
New features:
- Folder management with context menu, inline editing, drag-and-drop (#44)
- Mail multi-selection with batch move/delete and shift-click (#43)

Bug fixes:
- Health endpoint false-positive restarts (#41, thanks @wrenix and @ClemaX)
- Identity deletion failing (#42, thanks @freddij)
- Inline CID images, email list flicker, dark mode clipboard tint

Feature requests from @dlecourtaltimafr (#43, #44).
Contact pagination fix contributed by @capitanroy (#46).

Dependencies: Next.js 16.2.1, Tailwind 4.2.2, Zustand 5.0.12,
flatted CVE fix (GHSA-rf6f-7fwh-wjgh).
2026-03-23 15:24:46 +01:00
Matthieu MALVACHE f6e188560f chore: release v1.3.3 - security patches, community contributions
Next.js 16.2.0 security update, plus merged PRs #33-#40 from
rensreinders and wrenix (calendar improvements, contacts UX, navigation)
2026-03-20 16:54:09 +01:00
Matthieu MALVACHE 5880120431 fix: calendar crash on missing duration, sieve filter activation, security patches
- Guard parseDuration() against undefined event.duration (#31)
- Use onSuccessActivateScript per RFC 9661 for sieve filter activation (#21)
- Update dompurify, undici, flatted for security fixes
2026-03-16 12:43:37 +01:00
Matthieu MALVACHE 58b9b70871 fix: resolve context menu submenu and move-to-folder issues (#19) 2026-03-02 09:10:03 +01:00
Matthieu MALVACHE 92620fb790 fix: details toggle UX, Edge Runtime warnings, minimatch CVE
- Keep show/hide details button in place when expanded (#18)
- Use i18n translations for details toggle text
- Split instrumentation for Edge Runtime compatibility
- Patch minimatch ReDoS (CVE-2026-27903)
2026-02-28 21:03:02 +01:00
Matthieu MALVACHE a0bb200da4 chore: remove unused dependencies and explicit phantom deps 2026-02-22 23:00:35 +01:00
Matthieu MALVACHE 15c14b1833 chore: update dependencies and fix calendar event hooks
Bump tailwindcss 4.2.0, lucide-react 0.575.0, @typescript-eslint 8.56.0,
tailwind-merge 3.5.0, and patch-level updates across 48 transitive packages.
Fix missing useCallback dependency in calendar event card.
2026-02-22 18:07:30 +01:00
Matthieu MALVACHE fb414bf2c9 feat: add contacts phase 2, advanced search, vacation responder, Docker & TOTP 2FA
- Contact groups/lists, vCard import/export (RFC 6350), bulk operations
- Advanced search with JMAP filter panel, search chips, cross-mailbox queries
- Vacation responder with JMAP VacationResponse, settings tab, sidebar indicator
- TOTP two-factor authentication support
- Docker multi-stage build with standalone output and docker-compose
- CSP Report-Only headers and security headers via proxy middleware
- Virtual scrolling for large email lists
- Structured server-side logger (text/JSON, configurable level)
- 450+ tests (contacts, vCard, threads, headers, identity, components)
- Playwright E2E framework setup
- Updated README and ROADMAP with all new features
2026-02-16 18:51:30 +01:00
Matthieu MALVACHE 8a5bc9b88d feat: add address book, fix email layout, update dependencies
- Address book with JMAP sync and local fallback (contacts CRUD,
  search/filter, composer autocomplete, i18n for 8 languages)
- Fix email layout: remove horizontal scroll, left-side clipping,
  and empty spaces from blocked external images in newsletters
- Update all dependencies to latest compatible versions
- Expand i18n from 3 to 8 languages (added ES, IT, DE, NL, PT)
- Upgrade Next.js to 16.1.6 for security patches
2026-02-16 17:25:20 +01:00
Matthieu MALVACHE 5d60fe5186 fix(security): upgrade Next.js to 16.1.5 — patch CVE-2026-23864, CVE-2025-59471, CVE-2025-59472 2026-02-16 16:22:09 +01:00
Matthieu MALVACHE 5d273e2109 feat: expand internationalization and add identity management
This release significantly expands internationalization support and adds comprehensive identity management features.

Internationalization (i18n):
- Add 5 new languages: Spanish, Italian, German, Dutch, Portuguese
- Expand from 3 to 8 total supported languages
- Redesign language switcher for better scalability (dropdown UI)
- Complete translations for all features across all languages

Identity Management:
- Multiple sender identities with per-identity signatures
- Sub-addressing support (user+tag@domain.com)
- Context-aware tag suggestions for sub-addresses
- Identity badges in email viewer and list
- Full CRUD operations for managing identities

Newsletter Management:
- RFC 2369 List-Unsubscribe support (one-click unsubscribe)
- HTTP and mailto unsubscribe methods
- Security validation prevents XSS attacks
- Two-step confirmation with persistent dismissal

Security & Accessibility:
- Dark mode email readability (intelligent color transformation)
- WCAG 2.0 Level AA color contrast compliance
- Comprehensive XSS prevention with validation utilities
- Unit test coverage for security-critical code (57 validation tests)

Testing:
- Add unit tests for validation utilities
- Add unit tests for email sanitization
- Add unit tests for color transformation
- Full test coverage for XSS attack vectors
2026-01-08 22:15:32 +01:00
Matthieu MALVACHE b2b479359f fix(security): Update preact to fix JSON VNode Injection vulnerability 2026-01-08 02:12:54 +01:00
Matthieu MALVACHE dbffaf2a15 fix(email-viewer): Enable horizontal scroll for wide HTML emails
- Change overflow-hidden to overflow-x-auto on email body container
- Add CSS for email-content-wrapper with inline-block display
- Use width: max-content on email-content to respect intrinsic width
- Prevent tables with width="100%" from shrinking below content

Also updates dependencies:
- next: 16.0.10 -> 16.1.1
- react/react-dom: 19.2.1 -> 19.2.3
- next-intl: 4.5.8 -> 4.6.1
- tailwindcss: 4.1.17 -> 4.1.18
- eslint: 9.39.1 -> 9.39.2
- jmap-jam: 0.11.0 -> 0.13.1
- lucide-react: 0.556.0 -> 0.562.0
2025-12-24 04:05:28 +01:00
Matthieu MALVACHE 4920f7f64f fix(security): Update Next.js to 16.0.10
Patches high severity vulnerabilities:
- Server Actions Source Code Exposure (GHSA-w37m-7fhw-fmv9)
- DoS with Server Components (GHSA-mwv6-3258-q52c)
2025-12-18 03:32:02 +01:00
Matthieu MALVACHE cf21a84263 Initial release: JMAP Webmail Client
A modern, privacy-focused webmail client built with Next.js and the JMAP protocol.
Designed for Stalwart Mail Server.

Features:
- Full email operations (compose, reply, forward, threading)
- Real-time push notifications
- Dark/light theme support
- Mobile responsive design
- Keyboard shortcuts
- Drag-and-drop organization
- i18n (English/French)
- Security-first (external content blocked, HTML sanitization)
2025-12-10 17:54:22 +01:00