Commit Graph
102 Commits
Author SHA1 Message Date
Matthieu MALVACHE 51660481a0 fix(ci): add path filters to Docker workflow to avoid unnecessary rebuilds 2026-02-21 23:59:31 +01:00
Matthieu MALVACHE 05f339283d feat(docker): add GHCR publish workflow and OCI image labels
Automate multi-arch Docker image builds (amd64+arm64) on push to main
or version tags via GitHub Actions. Add OCI metadata labels for GHCR
discoverability. Update release script to sync infra files to
public-release branch.
2026-02-21 23:28:51 +01:00
Matthieu MALVACHE 40c7fa3649 feat: add UI/UX polish, templates settings, confirm dialog, welcome banner, and navigation rail
- Add ConfirmDialog component with promise-based useConfirmDialog hook
- Add WelcomeBanner onboarding component with localStorage persistence
- Add NavigationRail (desktop icon rail + mobile bottom tab bar)
- Polish login form (shake on error, TOTP slide, password visibility, session expired banner)
- Add inline form validation with shake animation in email composer and contacts
- Add empty state patterns for contacts (no data vs no search results)
- Improve toast system with undo action support and typed durations
- Add template settings tab to settings page
- Refactor sidebar (cleaner code, remove unused imports)
- Add WCAG AA reduced-motion, safe area insets, sr-only live region
- Add shake/slide animations in globals.css
- Update i18n for all 8 locales
2026-02-17 02:30:09 +01:00
Matthieu MALVACHE 7da9fa61e2 feat(templates): add email templates with placeholder variables and composer integration
Local-storage templates with dynamic {{variable}} placeholders that auto-fill
from composer context (recipient, sender, date/time). Includes template manager,
category filtering, quick picker in composer toolbar, and settings tab.
48 tests covering placeholder extraction, filling, and variable suggestions.
2026-02-17 01:34:13 +01:00
Matthieu MALVACHE 5d2f5dcf7e feat(calendar): add participant scheduling with iTIP invitations and inline calendar invitation banner
Add organizer/attendee UI with RSVP buttons (accept/maybe/decline),
contact autocomplete in participant input, scheduling message support
via sendSchedulingMessages flag, and DnD notification for participant
events. Add inline calendar invitation banner in email viewer that
auto-detects .ics attachments, parses event details, and allows RSVP
or import to calendar. Includes cancellation display and 51 tests.
2026-02-17 01:09:03 +01:00
Matthieu MALVACHE 83198d46dc fix(contacts): resolve useMemo dependency warnings
Inline the contact filtering directly in useMemo instead of calling
store selectors, so the dependency array accurately reflects what
triggers recomputation.
2026-02-17 00:40:07 +01:00
Matthieu MALVACHE 613eb6ce84 fix(email): improve dark mode readability and fix long subject overflow
Dark mode color transform had 3 bugs preventing it from working:
- Hook only ran when external content was blocked, not for all emails
- Checked `theme` ('system') instead of `resolvedTheme` ('dark')
- Only transformed CSS style attrs, missing <font color> and bgcolor

Replaced invert+boost algorithm with blend-toward-white for text
(preserves hue, brighter results) and added background darkening
for light email backgrounds. Also handles color/bgcolor HTML attrs.

Fixed long email subjects pushing action buttons off-screen by adding
min-w-0 to the email viewer flex container in the page layout.
2026-02-17 00:38:46 +01:00
Matthieu MALVACHE be78603c48 fix(filters): show hierarchical folder structure in rule mailbox selector
Reuse buildMailboxTree/flattenMailboxTree to display nested folders
with indentation instead of a flat list. Exclude shared folders since
Sieve rules only operate on the user's own mailboxes.
2026-02-17 00:06:52 +01:00
Matthieu MALVACHE e80df576cf fix(scripts): make release.sh non-interactive and more reliable
- Remove interactive read prompt that blocked non-interactive shells
- Exclude .md files and .claude/ directory from Claude reference scan
- Also check for "anthropic" references
- Hard-fail instead of prompting on Claude references found
- Remove fragile final diff grep (was matching harmless content)
- Improve forbidden file check to report all matches before aborting
2026-02-16 23:47:45 +01:00
Matthieu MALVACHE a603ee496b feat(calendar): add event notifications with client-side alert evaluation
Evaluate JMAP CalendarEventAlert triggers client-side and display toast
notifications when alert times are reached. Extracts notification sound
into shared utility and mounts ToastContainer globally (fixes silent
toast failures across all components).

- Pure alert utilities: offset parsing, fire time computation (start/end),
  effective alerts resolution with useDefaultAlerts, pending alert filtering
- Zustand persist store for acknowledged alert deduplication (24h retention)
- Global hook with 60s interval check, proactive 24h event fetch via ref
  (isolated from calendar store), stale closure protection
- Settings: calendarNotificationsEnabled, calendarNotificationSound toggles
- Toast icon customization, CalendarAlertProvider in layout
- i18n: all 8 locales (EN/FR/JA/ES/IT/DE/NL/PT)
- 44 tests (36 alert utils + 8 notification store), 558 total passing
2026-02-16 23:46:12 +01:00
Matthieu MALVACHE 9be02e8dd7 feat(filters): add email filters with Sieve rules, review fixes and hardening
Implement JMAP Sieve Scripts (RFC 9661) with visual rule builder and raw
Sieve editor. Includes post-review fixes: parser validation guards,
generator empty-rule skipping, JMAP client error hardening, focus trap
accessibility, mailbox name fix, toast validation feedback, auto-save with
rollback, and "Reset to visual builder" for opaque scripts. 514 tests pass.
2026-02-16 23:07:06 +01:00
Matthieu MALVACHE b84e543e2e feat(calendar): add drag-and-drop rescheduling and iCalendar import
Calendar phase 2 features with review-driven fixes:
- Drag events in week/day views to reschedule (15-min snap intervals)
- Drag events in month view to change date (preserves time)
- Visual snap indicators with time labels during drag
- iCalendar (.ics) import via JMAP CalendarEvent/parse
- Import modal with file upload, event preview, calendar selector
- File validation (5MB max), bulk import with progress
- i18n: calendar.import.* and event_move_error keys (8 locales)
2026-02-16 21:07:44 +01:00
Matthieu MALVACHE a27196bdeb feat(calendar): add JMAP Calendar integration with full review fixes
Calendar phase 1 with comprehensive review-driven hardening:
- JMAP CalendarEvent CRUD (RFC 8984 types, capability detection)
- Month/week/day/agenda views with multi-day event spanning
- Column-based overlap layout for concurrent events
- Event modal with create/edit/delete, recurrence, reminders
- Mini-calendar sidebar with calendar visibility toggles
- Settings: firstDayOfWeek and timeFormat wired to all views
- Locale-aware date formatting via next-intl useFormatter (8 locales)
- Push notification handling for Calendar/CalendarEvent state changes
- ARIA grid roles, event card labels, focus trap, 44px touch targets
- Input validation, color sanitization, timezone auto-detection
- Error handling with toast feedback, capability page guard
- ICU pluralization for alert translations, debug logger integration
2026-02-16 20:32:06 +01:00
Matthieu MALVACHE 83e01ae551 feat: add contacts phase 2, advanced search, vacation responder, Docker & TOTP 2FA
Contacts:
- Contact groups/lists with JMAP members map and composer expansion
- vCard import/export with RFC 6350 parser and duplicate detection
- Bulk operations (multi-select, delete, group add, export)

Search:
- Advanced search panel with JMAP filter fields
- Search chips for active filters visualization
- Debounced inputs with AbortController deduplication

Vacation:
- JMAP VacationResponse singleton management
- Settings tab with date range and message configuration
- Sidebar indicator when vacation responder is active

Auth:
- TOTP 2FA support with Stalwart-compatible password$totp format

Infrastructure:
- Docker multi-stage build with standalone Next.js output
- Structured server-side logger with text/JSON format
- CSP Report-Only and security headers via proxy middleware
- Layout refactoring (HTML structure in root layout)
- Playwright E2E framework setup

Testing: 450+ tests (identity, contacts, vCard, threads, headers, components)
i18n: All new strings added to all 8 locales
2026-02-16 18:46:33 +01:00
Matthieu MALVACHE 3796119da5 docs: update TODO with email layout fix and dependency upgrade notes 2026-02-16 17:23:25 +01:00
Matthieu MALVACHE 416b0e985e chore(deps): upgrade @types/node 22→25, jsdom 27→28, lucide-react 0.564
Major version bumps for dev dependencies. eslint 10 skipped — ecosystem
plugins (typescript-eslint, eslint-config-next) don't support it yet.
2026-02-16 17:21:59 +01:00
Matthieu MALVACHE 4499c83a37 chore(deps): update all packages to latest compatible versions
Update next 16.1.5→16.1.6, react 19.2.3→19.2.4, next-intl 4.7→4.8.3,
zustand 5.0.9→5.0.11, lucide-react 0.562→0.564, vitest 4.0.16→4.0.18,
typescript-eslint 8.50→8.55, and other minor/patch dependencies.
2026-02-16 17:20:39 +01:00
Matthieu MALVACHE dddbcf75db fix(email): resolve layout overflow and blocked image empty spaces
Remove width: max-content and display: inline-block from email content
CSS that caused horizontal scroll and left-side text clipping. Collapse
empty table cells/containers when external images are blocked to prevent
large blank areas in newsletter emails.
2026-02-16 17:18:38 +01:00
Matthieu MALVACHE 17abe7ff56 feat(contacts): add address book with JMAP sync and local fallback
Implement Phase 1 of contacts support — the biggest missing feature
on the roadmap. Uses RFC 9553 (JSContact) data model and RFC 9610
(JMAP for Contacts) when the server advertises the capability,
falling back to localStorage for servers without contact support.

- JMAP types for ContactCard, AddressBook, NameComponent, etc.
- JMAP client methods: CRUD, search, address book listing
- Refactored request() to accept dynamic `using` capabilities
- Zustand contact store with dual-mode persistence
- Full contacts page with two-column layout (list + detail/edit)
- Contact form with multi-email/phone, context labels, validation
- Composer autocomplete on To/Cc/Bcc with keyboard nav and ARIA
- Sidebar navigation link to contacts
- Auth integration: fetch on login, clear on logout
- i18n: contacts.* namespace across all 8 languages
2026-02-16 17:07:45 +01:00
Matthieu MALVACHE b18906b8fa fix(security): upgrade Next.js to 16.1.5 to patch 3 CVEs
Fixes CVE-2026-23864 (HIGH - RSC deserialization DoS),
CVE-2025-59471 (Image Optimizer DoS), and
CVE-2025-59472 (PPR resume endpoint memory exhaustion).
2026-02-16 16:15:21 +01:00
Matthieu MALVACHE 3fc8ccf116 feat(i18n): expand language support from 3 to 8 languages
Add support for Spanish, Italian, German, Dutch, and Portuguese with complete translations for all features including identity management, newsletter unsubscribe, and accessibility improvements.

Changes:
- Add 5 new locale directories with full translations
- Update IntlProvider to load all 8 language message files
- Redesign language switcher from button group to dropdown for better scalability
- Update routing and request configuration to handle new locales
- Improve Select component with dir="auto" for RTL support
- Reorganize notification keys in translation files for consistency
- Update all documentation to reflect expanded language support
2026-01-08 22:12:13 +01:00
Matthieu MALVACHE cfcf0083f6 feat(i18n): add Japanese language support with complete translations
Add Japanese (ja) as the third supported language alongside English and French. Includes 650+ translation keys covering all UI sections: login, sidebar, email operations, settings (all 8 tabs), context menus, keyboard shortcuts, threads, identity management, and error messages.

Uses formal Japanese (敬語 keigo) appropriate for business email communication. All client and server-side i18n infrastructure updated to load Japanese translations.
2026-01-08 21:40:13 +01:00
Matthieu MALVACHE b0946f5e3f chore: add git hook to prevent AI attribution in commits
Added commit-msg hook that blocks commits containing Claude/Anthropic
references. Hook is excluded from version control via .gitignore.
2026-01-08 20:39:50 +01:00
Matthieu MALVACHE a98b48e7b4 chore: upgrade dependencies to latest stable versions
Remove unused next-auth dependency (zero imports in codebase).
Update minor/patch versions for security fixes and bug improvements:
- dompurify 3.2.7 → 3.3.1 (XSS protection improvements)
- tailwind-merge 3.3.1 → 3.4.0 (bug fixes)
- TypeScript to 5.9.3 (performance and type inference improvements)
- globals 16.5.0 → 17.0.0 (ESLint global definitions)
- @types packages to latest for React 19 compatibility

All tests passing (124/124), no breaking changes.
2026-01-08 19:21:43 +01:00
Matthieu MALVACHE e600cd387d fix(security): prevent global CSS injection from email style tags
Emails containing <style> tags were injecting global CSS rules that
affected the entire application UI. For example, button:hover rules
from emails would override all button hover states app-wide.

Changes:
- Block <style> tags in email sanitization config (security fix)
- Keep inline style attributes for element-specific formatting
- Add explicit bg-transparent to banner buttons (defense in depth)
- Add CSS isolation to banner container
- Fix theme dependency in email content memoization

This prevents malicious or poorly-formatted emails from breaking the
UI or being used for phishing via CSS injection attacks.
2026-01-08 19:18:59 +01:00
Matthieu MALVACHEandClaude Sonnet 4.5 1bca54e5d6 feat(accessibility): improve WCAG AA color contrast compliance
- Replace hardcoded hex colors (#666, #999) with CSS variables in email preview
- Strengthen blockquote text color from #6b7280 to #4b5563 (5.3:1 → 7.8:1 contrast)
- Strengthen quoted email text color to match blockquote improvement
- Add comprehensive accessibility guidelines to CLAUDE.md
- Document color contrast standards, testing requirements, and best practices
- All changes maintain dark mode compatibility

Achieves WCAG 2.0 Level AA compliance for all text elements.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-01-08 18:42:53 +01:00
Matthieu MALVACHEandClaude Sonnet 4.5 395f92c47f feat(email): add newsletter unsubscribe and enhance dark mode
Implement RFC 2369 List-Unsubscribe support with security validation (protocol whitelist, XSS prevention), two-step confirmation UI, and localStorage persistence. Add intelligent color transformation for dark mode to fix unreadable inline email styles using WCAG 2.0 luminance calculation. Complete batch spam undo operations for context menu multi-select. Update documentation with new features and comprehensive test coverage (97 tests).

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-01-08 18:39:27 +01:00
Matthieu MALVACHEandClaude Sonnet 4.5 da9fa4e28a feat(email): add spam reporting with bidirectional handling
Implement comprehensive spam management allowing users to report spam emails and restore false positives. Emails are moved to/from the Junk folder with toast notifications and undo support.

Key features:
- Mark as spam: moves email to Junk folder with 5-second undo
- Mark as not spam: restores email from Junk to inbox
- Batch spam operations via context menu
- Smart toggle based on current folder (Junk vs other folders)
- Keyboard shortcut (Shift+!) for quick spam reporting
- Full i18n support (EN/FR)
- Shared mailbox compatibility

UX improvements:
- Toast notifications with undo action using sonner library
- Auto-deselect email after spam action
- Visual distinction with red destructive styling
- Desktop button + context menu + keyboard shortcuts

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-01-08 17:55:24 +01:00
Matthieu MALVACHE f62f5adf29 refactor(identity): enhance i18n and improve sub-address detection
Complete internationalization coverage for all identity-related UI elements,
including mobile navigation, batch actions, and recipient formatting. Improve
sub-address badge to detect and display tags for emails received at
user+tag@domain.com addresses, not just sent emails. Add contextual recipient
display showing "me" for current user and "Name and X others" for multiple
recipients. Update documentation to reflect completed identity management
implementation.
2026-01-08 17:20:13 +01:00
Matthieu MALVACHEandClaude Sonnet 4.5 b6330642c2 feat(identity): improve accessibility for identity management modal
- Add reusable focus trap hook (use-focus-trap.ts)
  - Traps Tab/Shift+Tab within modal
  - Restores focus on close
  - Handles disabled elements gracefully

- Enhance identity modal with WCAG 2.1 compliance
  - Add role="dialog" and aria-modal="true"
  - Add aria-labelledby linking to modal title
  - Implement focus trap on open

- Add ARIA live regions to identity form
  - Error messages announced to screen readers
  - aria-describedby links inputs to errors
  - aria-invalid state on validation failure

Accessibility: Improves keyboard navigation and screen reader UX
Standards: WCAG 2.1 AA compliant for modal interactions

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-01-08 16:20:15 +01:00
Matthieu MALVACHEandClaude Sonnet 4.5 e8d6e0431f test(identity): add comprehensive unit tests for security utilities
- Setup Vitest testing framework with React Testing Library
- Add 27 test cases for email-sanitization.ts
  - XSS prevention (scripts, event handlers, iframes)
  - Safe HTML preservation (tables, formatting)
  - Signature-specific sanitization rules
  - HTML parsing safety checks

- Add 29 test cases for validation.ts
  - RFC 5322 email validation
  - Header injection prevention
  - Length limit enforcement
  - Email list validation

Coverage: >90% for both security-critical utilities
Zero new runtime dependencies (dev-only)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-01-08 16:19:45 +01:00
Matthieu MALVACHE 040b34977b refactor(identity): improve performance and code quality
- Add useMemo for expensive tag suggestions computation
- Add useCallback for identity CRUD handlers
- Extract magic numbers to constants (MAX_RECENT_TAGS, MAX_TAG_LENGTH)
- Improve JMAP error messages with context

Performance: Reduces unnecessary re-renders in identity modal
Maintainability: Makes limits configurable and self-documenting
UX: Users get clearer error messages when operations fail

No functional changes. All tests passing.
2026-01-08 16:12:53 +01:00
Matthieu MALVACHE d301dd15ff security: fix XSS vulnerabilities in identity management
- Add unified email sanitization utility (lib/email-sanitization.ts)
  - Safe HTML parsing using DOMParser instead of innerHTML
  - Consistent DOMPurify configuration across components
  - Separate signature sanitization with stricter rules

- Add secure email validation (lib/validation.ts)
  - RFC 5322 compliant validation
  - Block header injection attempts (\r\n<>)
  - Validate comma-separated email lists

- Fix HTML signature XSS (identity-form.tsx)
  - Sanitize signatures before storage and rendering
  - Add live preview with safe rendering
  - Input length limits for defense in depth

- Fix innerHTML XSS (email-viewer.tsx, thread-conversation-view.tsx)
  - Replace unsafe innerHTML with DOMParser for format detection
  - Use shared EMAIL_SANITIZE_CONFIG
  - Add <meta>, <link>, <base> to forbidden tags

Security issues resolved:
- H1: Stored XSS in HTML signatures (CVSS 7.1)
- H2: XSS during HTML parsing (CVSS 6.8)
- M1: Email validation bypass (CVSS 4.3)
- M3: Inconsistent sanitization (CVSS 5.0)

Zero new dependencies. All tests passing.
2026-01-08 16:12:53 +01:00
Matthieu MALVACHE 275aa8290f feat(identities): Add identity management and sub-addressing support
Enable users to manage multiple sending identities and organize incoming mail with sub-addressing (user+tag@domain.com format). Provides better email organization, privacy through disposable addresses, and flexibility for users with multiple roles or accounts.
2026-01-08 16:12:53 +01:00
Matthieu MALVACHE a7176fefa0 fix(lint): Add missing tCommon dependency to useEffect
Resolves React hooks exhaustive-deps warning by including tCommon translation function in the dependency array.
2026-01-08 04:25:52 +01:00
Matthieu MALVACHE 91b8a42fdd feat(i18n): Complete internationalization coverage
Replaces all remaining hardcoded strings with translation keys to ensure full localization support across the application. This allows users to experience the entire interface in their preferred language without any English fallbacks.
2026-01-08 04:24:58 +01:00
Matthieu MALVACHEandClaude Sonnet 4.5 5613f66bd7 fix(i18n): Add timezone auto-detection to prevent hydration mismatches
Fixes ENVIRONMENT_FALLBACK warning by detecting user's browser timezone
and passing it to NextIntlClientProvider. This ensures users worldwide
see email timestamps in their local timezone (USA, Europe, Asia, etc.)
without manual configuration.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-01-08 04:11:26 +01:00
Matthieu MALVACHEandClaude Sonnet 4.5 da2fe44f7d feat(deployment): Add health check endpoint for container orchestration
Implements /api/health endpoint for Docker/Kubernetes liveness and readiness probes.
- Basic mode: Returns 200 OK or 503 based on memory usage thresholds
- Detailed mode (?detailed=true): Includes memory stats, uptime, and environment info
- HEAD method support for lightweight polling
- Memory-based health monitoring (85% warning, 95% critical)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-01-08 04:09:18 +01:00
Matthieu MALVACHEandClaude Sonnet 4.5 2f50feb6bb fix(lint): Replace any type with proper Record type in IntlProvider
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-01-08 04:00:43 +01:00
Matthieu MALVACHEandClaude Sonnet 4.5 a4e2fcf81b feat(i18n): Enable instant client-side language switching
Refactored i18n implementation to support seamless language switching
without page reload by pre-loading all translations and using
locale-aware navigation helpers.

Changes:
- Created centralized routing config (i18n/routing.ts) with localePrefix: 'never'
- Added type-safe navigation helpers (i18n/navigation.ts)
- Implemented custom IntlProvider with pre-loaded EN/FR translations
- Updated all pages to use new useRouter from i18n/navigation
- Added language switcher to appearance settings
- Removed URL-based locale routing (no more /en/ or /fr/ prefixes)
- Language preference persisted via Zustand localStorage

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-01-08 03:59:29 +01:00
Matthieu MALVACHE 4032692700 feat(ui): Improve tablet and mobile email viewing experience
- Add tablet list auto-hide: email list collapses when selecting an email
  on tablet (768-1024px), with back button to return to two-pane view
- Make sender info scrollable on mobile/tablet while keeping subject bar
  with action buttons sticky at top for quick access
- Extend overlay sidebar behavior to tablet viewport (768-1024px)
- Add body scroll lock when sidebar is open on mobile/tablet
- Fix backdrop only rendering on mobile/tablet (not desktop)
- Add proper i18n keys for back_to_list, important, close
- Simplify desktop-only CSS classes by removing redundant breakpoint prefixes
2026-01-08 03:10:23 +01:00
Matthieu MALVACHE d6614fa5f7 fix(security): Update preact to fix JSON VNode Injection vulnerability
- preact: 10.28.1 → 10.28.2 (high severity fix)
- next-intl: 4.6.1 → 4.7.0 (minor update)
2026-01-08 02:12:44 +01:00
Matthieu MALVACHE e5cb0305d5 docs: Add instruction to update public docs during release 2026-01-08 02:06:34 +01:00
Matthieu MALVACHE 1306ce56f8 feat(config): Add runtime environment variables for Docker support
Enable post-build configuration by reading env vars at request time
instead of build time. This allows Docker containers to be configured
without rebuilding the image.

- Add /api/config endpoint for runtime config
- Add useConfig hook with caching
- Update login page with proper loading/error states
- Add i18n translations for config errors
- Maintain backwards compatibility with NEXT_PUBLIC_* vars
2026-01-08 02:00:09 +01:00
Matthieu MALVACHE 6cea985396 feat(privacy): Add trusted senders for automatic image loading
Allow users to trust specific senders so their images load automatically
without clicking "Show images" each time. Addresses privacy while
improving UX for known senders.

- Add trustedSenders state to settings store with add/remove/check methods
- Show "Always trust this sender" button in email viewer (ask/block modes)
- Add TrustedSendersModal for managing trusted senders in settings
- Include search, manual add, and avatar display in modal
- Full i18n support (en/fr)

Closes #3
2026-01-08 01:43:24 +01:00
Matthieu MALVACHE e50404cf42 feat(identities): Use JMAP identities for email sender address
- Add getIdentities() method to JMAP client
- Fetch and store identities in auth store on login
- Add From selector in composer (dropdown for multiple identities)
- Pass identity email/ID through send flow instead of using username
- Add translations for From field (en/fr)

This allows proper sender address handling for LDAP and other auth
backends where username differs from email address.

Closes #5
2026-01-08 01:19:09 +01:00
Matthieu MALVACHE 60aff695fe fix(email-composer): Improve readability and add discard button
- Fix textarea colors for proper theme support (light/dark mode)
- Fix modal height to prevent composer from collapsing
- Add explicit "Discard" button in footer for better UX
- Fix hardcoded colors in attachments section for theme support
- Use translations for all user-facing text

Closes #6
2026-01-08 01:01:37 +01:00
Matthieu MALVACHE dbadb38703 chore: Add package.json metadata and improve release script
- Add metadata to master's package.json (description, author, license, etc.)
- Update release script to merge dependencies instead of copying package.json
- Automatically removes 'private' and dev-only scripts for public release
2025-12-24 04:08:03 +01:00
Matthieu MALVACHE 1924c36a2c fix(email-viewer): Enable horizontal scroll for wide HTML emails
- Change overflow-hidden to overflow-x-auto on email body container
- Add CSS for email-content-wrapper with inline-block display
- Use width: max-content on email-content to respect intrinsic width
- Prevent tables with width="100%" from shrinking below content

Also updates dependencies:
- next: 16.0.10 -> 16.1.1
- react/react-dom: 19.2.1 -> 19.2.3
- next-intl: 4.5.8 -> 4.6.1
- tailwindcss: 4.1.17 -> 4.1.18
- eslint: 9.39.1 -> 9.39.2
- jmap-jam: 0.11.0 -> 0.13.1
- lucide-react: 0.556.0 -> 0.562.0

Adds test script for injecting HTML emails via JMAP (dev only)
2025-12-24 04:02:32 +01:00
Matthieu MALVACHE 792f775ad2 fix(security): Update Next.js to 16.0.10
Patches high severity vulnerabilities:
- Server Actions Source Code Exposure (GHSA-w37m-7fhw-fmv9)
- DoS with Server Components (GHSA-mwv6-3258-q52c)
2025-12-18 03:31:25 +01:00