feat(unified-mailbox): account-bounded Unified Mailbox with opt-in cross-account
Rework the sidebar "All accounts" section into a "Unified Mailbox" that, by default, stays within the active login account and its shared/group folders. Merging across multiple logged-in accounts becomes an opt-in sub-option instead of the default, and the standalone per-account "All Mail" virtual folder is folded into the unified All mail / Unread / Starred entries (its folder selection now narrows those lists). Scope: - lib/unified-mailbox.ts: UnifiedAccountClient.crossIncludedMailboxIds; the cross views honor the per-account folder selection (union across accounts = the sum of each account's selection), falling back to inbox+custom when unset. - stores/email-store.ts: buildUnifiedAccountClients gains scopeToClientAccountId (the account boundary) and populates crossIncludedMailboxIds from allMailFolderIds; remove the standalone __all_mail__ fetch/search/load-more branches. - page.tsx: scope to the active account unless cross-account is active (per-user opt-in AND admin gate); the per-role unified mailboxes obey the same scope. Folding: - Drop ALL_MAIL_MAILBOX_ID (lib/jmap/types.ts); thread-list source-folder column now keys on isUnifiedView only; settings folder picker moves under the unified group and shows once any unified entry is enabled. Config: - User: new unifiedCrossAccount (default false); includeGroupInUnified default flips to true; enableAllMailView retired; the three cross-view toggles now gate the unified Unread/Starred/All mail entries. - Admin: new unifiedCrossAccountEnabled gate, default FALSE (cross-account is an admin opt-in; when off the per-user toggle is hidden and the scope is forced account-bounded at runtime). allMailViewEnabled deprecated and normalized forward into crossAllViewEnabled on policy load; cross-view gate labels reworded to "Unified Mailbox: ...". Header: the sidebar section shows "All accounts" when cross-account is active (opt-in AND admin gate AND >1 connected account), else "Unified Mailbox". Migration: - Settings persist v5 -> v6 (exported migrateSettings) - cross-active users keep cross-account; All-Mail-only users get the account-bounded unified All mail entry with folder ids preserved; includeGroupInUnified enabled for every migrated config; fresh installs are account-bounded. - Admin policy: one-shot, marker-guarded migratePolicyUnifiedMailbox (run before configManager.load) enables unifiedCrossAccountEnabled when a cross view was active, so existing cross-account installs keep the behaviour despite the default-false gate. Skipped on read-only config dirs. Locales: sidebar all_accounts (original label) + unified_mailbox (translated, per locale) keys; dead standalone all_mail strings removed across all 20 locales. Docs: FEATURES.md updated to the account-bounded model, the cross-account gate, and the folder-narrowed aggregate entries. Verification: tsc clean, eslint clean, full vitest suite green (incl. translations completeness, cross-view/migration coverage, and the admin policy migration test).
This commit is contained in:
@@ -11,6 +11,7 @@ import {
|
||||
import type { AdminConfigData, AdminStateData } from './types';
|
||||
|
||||
const MIGRATION_MARKER = '.migrated-v2';
|
||||
const POLICY_UNIFIED_MARKER = '.migrated-unified-mailbox';
|
||||
|
||||
interface LegacyAdminData {
|
||||
passwordHash: string;
|
||||
@@ -59,6 +60,65 @@ export async function migrateLegacyAdminLayout(): Promise<void> {
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* One-shot policy migration for the Unified Mailbox rework. Before it, the
|
||||
* cross views (crossUnread/crossStarred/crossAll) merged across every logged-in
|
||||
* account, so an admin who had any of them enabled was already permitting
|
||||
* cross-account aggregation. The new `unifiedCrossAccountEnabled` gate (default
|
||||
* false) controls that capability, so enable it whenever a cross view was active
|
||||
* - otherwise existing cross-account installs would silently lose the behaviour
|
||||
* on upgrade (the per-user `unifiedCrossAccount` is AND-ed with this gate).
|
||||
*
|
||||
* Persisted + marker-guarded (not a per-load normalization) so a later admin
|
||||
* decision to disable the gate survives restarts. Skipped on read-only config
|
||||
* dirs - operators who locked their config must migrate manually (mirrors
|
||||
* migrateLegacyAdminLayout). The deprecated `allMailViewEnabled` (a single-account
|
||||
* view, never cross-account) deliberately does NOT trigger this.
|
||||
*/
|
||||
export async function migratePolicyUnifiedMailbox(): Promise<void> {
|
||||
if (isConfigReadOnly()) return;
|
||||
|
||||
const markerPath = getConfigPath(POLICY_UNIFIED_MARKER);
|
||||
if (existsSync(markerPath)) return;
|
||||
|
||||
try {
|
||||
const policyPath = getConfigPath('policy.json');
|
||||
if (existsSync(policyPath)) {
|
||||
let parsed: Record<string, unknown> | null = null;
|
||||
try {
|
||||
parsed = JSON.parse(await readFile(policyPath, 'utf-8')) as Record<string, unknown>;
|
||||
} catch {
|
||||
logger.warn('policy.json is not valid JSON; skipping Unified Mailbox policy migration');
|
||||
}
|
||||
const features =
|
||||
parsed && typeof parsed.features === 'object' && parsed.features
|
||||
? (parsed.features as Record<string, unknown>)
|
||||
: null;
|
||||
if (features) {
|
||||
const hadCrossAccount = !!(
|
||||
features.crossUnreadViewEnabled ||
|
||||
features.crossStarredViewEnabled ||
|
||||
features.crossAllViewEnabled
|
||||
);
|
||||
if (hadCrossAccount && features.unifiedCrossAccountEnabled !== true) {
|
||||
features.unifiedCrossAccountEnabled = true;
|
||||
const tmp = policyPath + '.tmp';
|
||||
await writeFile(tmp, JSON.stringify(parsed, null, 2), 'utf-8');
|
||||
await rename(tmp, policyPath);
|
||||
logger.info('Migrated policy: enabled unifiedCrossAccountEnabled (cross-account views were active)');
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
await ensureConfigDir();
|
||||
await writeFile(markerPath, new Date().toISOString(), 'utf-8');
|
||||
} catch (error) {
|
||||
logger.warn('Unified Mailbox policy migration failed; will retry on next boot', {
|
||||
error: error instanceof Error ? error.message : 'Unknown error',
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* If the existing admin.json carries timestamp fields (legacy mixed layout),
|
||||
* split them into admin-state.json and rewrite admin.json without them.
|
||||
|
||||
Reference in New Issue
Block a user