feat(unified-mailbox): account-bounded Unified Mailbox with opt-in cross-account

Rework the sidebar "All accounts" section into a "Unified Mailbox" that, by
default, stays within the active login account and its shared/group folders.
Merging across multiple logged-in accounts becomes an opt-in sub-option instead
of the default, and the standalone per-account "All Mail" virtual folder is
folded into the unified All mail / Unread / Starred entries (its folder selection
now narrows those lists).

Scope:
- lib/unified-mailbox.ts: UnifiedAccountClient.crossIncludedMailboxIds; the cross
  views honor the per-account folder selection (union across accounts = the sum
  of each account's selection), falling back to inbox+custom when unset.
- stores/email-store.ts: buildUnifiedAccountClients gains scopeToClientAccountId
  (the account boundary) and populates crossIncludedMailboxIds from
  allMailFolderIds; remove the standalone __all_mail__ fetch/search/load-more
  branches.
- page.tsx: scope to the active account unless cross-account is active (per-user
  opt-in AND admin gate); the per-role unified mailboxes obey the same scope.

Folding:
- Drop ALL_MAIL_MAILBOX_ID (lib/jmap/types.ts); thread-list source-folder column
  now keys on isUnifiedView only; settings folder picker moves under the unified
  group and shows once any unified entry is enabled.

Config:
- User: new unifiedCrossAccount (default false); includeGroupInUnified default
  flips to true; enableAllMailView retired; the three cross-view toggles now gate
  the unified Unread/Starred/All mail entries.
- Admin: new unifiedCrossAccountEnabled gate, default FALSE (cross-account is an
  admin opt-in; when off the per-user toggle is hidden and the scope is forced
  account-bounded at runtime). allMailViewEnabled deprecated and normalized
  forward into crossAllViewEnabled on policy load; cross-view gate labels reworded
  to "Unified Mailbox: ...".

Header: the sidebar section shows "All accounts" when cross-account is active
(opt-in AND admin gate AND >1 connected account), else "Unified Mailbox".

Migration:
- Settings persist v5 -> v6 (exported migrateSettings) - cross-active users keep
  cross-account; All-Mail-only users get the account-bounded unified All mail
  entry with folder ids preserved; includeGroupInUnified enabled for every
  migrated config; fresh installs are account-bounded.
- Admin policy: one-shot, marker-guarded migratePolicyUnifiedMailbox (run before
  configManager.load) enables unifiedCrossAccountEnabled when a cross view was
  active, so existing cross-account installs keep the behaviour despite the
  default-false gate. Skipped on read-only config dirs.

Locales: sidebar all_accounts (original label) + unified_mailbox (translated, per
locale) keys; dead standalone all_mail strings removed across all 20 locales.

Docs: FEATURES.md updated to the account-bounded model, the cross-account gate,
and the folder-narrowed aggregate entries.

Verification: tsc clean, eslint clean, full vitest suite green (incl. translations
completeness, cross-view/migration coverage, and the admin policy migration test).
This commit is contained in:
Stefan Hildebrandt
2026-07-11 21:14:34 +02:00
parent 38a396d150
commit 7c221c4a4a
37 changed files with 541 additions and 257 deletions
+22 -2
View File
@@ -22,6 +22,18 @@ export interface UnifiedAccountClient {
// must use the mailbox's `originalId` and explicitly target this accountId
// so the server routes to the owner's data.
isShared?: boolean;
// Store-side mailbox ids that make up THIS account's contribution to the
// cross views (All mail / Unread / Starred). It is intentionally per-account,
// not a global list: mailbox ids are account-scoped, so an id from one account
// is meaningless in another. The effective folder set of a cross view is the
// UNION across every account's entry (one UnifiedAccountClient per account),
// i.e. the sum of the respective per-account selections.
//
// For personal accounts this is the user's folder selection
// (`allMailFolderIds[accountId]`); shared/group accounts are not individually
// configurable and leave this undefined. When undefined, getCrossIncludedMailboxes
// falls back to the role-exclusion default (inbox + custom folders).
crossIncludedMailboxIds?: string[];
}
export interface UnifiedFetchResult {
@@ -313,10 +325,18 @@ export function fetchUnifiedMailboxCounts(
// filter is built from each account's included-mailbox ids.
/**
* Mailboxes of an account included in the cross-account views: everything whose
* role is not excluded (inbox + custom/no-role folders).
* Mailboxes of an account included in the cross views (All mail / Unread /
* Starred). When the account carries an explicit `crossIncludedMailboxIds`
* selection (personal accounts honor the user's folder picker, shared accounts
* include everything), only those mailboxes are used. Otherwise it falls back
* to the role-exclusion default: everything whose role is not excluded (inbox +
* custom/no-role folders).
*/
export function getCrossIncludedMailboxes(account: UnifiedAccountClient): Mailbox[] {
if (account.crossIncludedMailboxIds) {
const selected = new Set(account.crossIncludedMailboxIds);
return account.mailboxes.filter((m) => selected.has(m.id));
}
return account.mailboxes.filter((m) => !CROSS_EXCLUDED_ROLES.has(m.role ?? ''));
}