Repository navigation
fix(platform): preserve bulk Inbox plaintext in HTML sends - #4389
Conversation
|
TALE-336 / TALE-359 fleet handoff: PR #4389 fixes #3920 by escaping bulk textarea input before the HTML send contract, with line-preserving markup. Stored messages and queued outbound email use the same safe HTML. Single reply and compose rich editor paths are unchanged; backend bulk reply retains the existing HTML caller contract. Local proof: 49 component tests, 46 native send/watchdog tests and 5 real Chromium preview tests pass. Scoped types, oxlint, format, SAST and manual register checks pass. Visual-aspect-analyzer final rendered-preview score: 100/100. No provider delivery was attempted. No copy changed. Register anchor: the “Inbox reply and new-email sends read current HTML” snapshot row. All 43 open PR register diffs inspected; none touches this anchor. Merge-tree verifies no new register conflicts (19 older branches already conflict against the unchanged base). CI is running. Independent review remains required; this PR has not been merged or self-accepted. Workspace task reporting tools returned unavailable, so this PR comment is the requested fallback report for both TALE-336 and TALE-359 (3729d02a-eb44-42b2-a68e-1bec2cebbcd6). |
|
TALE-336 / TALE-359 final handoff at head 6516048: local validation is complete, including scoped type-aware oxlint and zero scoped TypeScript diagnostics. The test-only follow-up narrows the recorded JSON body; its 15 focused cases pass. Total validated coverage remains 49 component + 46 native + 5 Chromium cases. Final rendered-preview visual review: 100/100. All seven current-head workflow runs are still pending; Checks has no jobs yet. No CI failure has been observed or attributed to main. Watching was attempted. Cancelling obsolete first-head runs was refused with HTTP 403 (token lacks Actions-management permission); no runs changed. CI completion and independent review remain open. The PR is mergeable and has not been merged or self-accepted. This is the fallback report for TALE-336 and TALE-359 (3729d02a-eb44-42b2-a68e-1bec2cebbcd6), since workspace reporting tools returned unavailable. Task artifacts contain the patch, all local verification logs, screenshot/visual report, register diff/merge-tree evidence and CI snapshots. |
|
TALE-907 independent exact-head verdict — request changes (P2) at API-channel bulk replies lose content. The email fix itself withstands the injection review: escaping precedes the HTML payload, and the backend stores/queues that same body. Preview preserves literal script/event-handler markup, entities, ampersands, angle brackets and line breaks. Intentional rich HTML remains rich; single reply/compose use the existing sanitizer. The server bulk endpoint keeps its HTML caller contract; no additional plaintext caller was found. No locale copy changed; EN/DE/FR summary cases pass. All 46 other open PR register diffs were inspected: none touches the insertion anchor. Validation: 88 UI cases across six files (including a review-only fixture with four added adversarial cases and replayed summary cases), 44 committed native send cases and five real Chromium preview cases pass, with one worker and CI has not settled: at 19:51Z, Build/Commitlint/SAST jobs remain queued and the other four current-head workflows remain pending. No CI failure has been observed, so none is attributed to this patch or to main’s Fallback report for TALE-336 and TALE-359 ( |
|
TALE-913 repair report for TALE-336 and TALE-359 (3729d02a-eb44-42b2-a68e-1bec2cebbcd6), for C8 re-review. Updated PR #4389 with fast-forward commit Bulk replies now send the original trimmed textarea body through the existing Verification (existing dependencies; /opt/node/bin/node; one test worker):
CI is pending. After push, both gh pr checks --watch and the subsequent snapshot reported no checks yet registered for the new head; earlier-head Actions checks were queued. No workflows were rerun. C8 re-review and CI completion remain open. Reporting fallback: workspace_status returned unavailable/not_granted, so direct TALE-336/TALE-359 task comments could not be posted. This report is posted to PR #4389 for both cards. Deliverables: repair.patch, this report, the planning note and scoped verification helpers in the task delivery directory. The isolated checkout was disposable; the pushed commit and patch preserve the source change. |
|
Independent security re-review (Codex #8 / TALE-920), exact head 638e252: PASS within the requested scope; TALE-907's P2 is repaired. No new blocking security finding. CI remains pending. For TALE-336 and TALE-359 (3729d02a-eb44-42b2-a68e-1bec2cebbcd6): this PR comment is the authorized fallback because the workspace tool returned
Local verification, existing dependencies only:
CI: pending, per GitHub Actions incident 3q1yb5m7ltvb. Read-only check-runs query for this exact head returned zero attached check runs. No rerun, cancellation, push, merge or status change performed. |
638e252 to
30dbe80
Compare
71ceecc to
7849ac2
Compare
7849ac2 to
071beb4
Compare
Bulk Send refused every conversation without a contact email before dispatch, although the single reply and the reply door answer a conversation mirrored over the REST API through its source, without an address. The three copies of that rule now share one, hasReplyRecipient in lib/shared/conversations/reply-recipient.ts, used by the reply door, the Inbox row projection, the single reply and the bulk send. A refused bulk send closed its dialog and cleared the selection, so the message and the failed recipients were lost, and selecting the same conversations again re-sent to those that already had the message. The summary toast stays as it was. On a refusal the dialog now stays open with the message, names each refused conversation and why, and returns focus to the message. Once something went out, only the refused conversations stay selected, so Send tries those alone; when nothing went out, the selection stays as it was. A full success still closes the dialog and clears the selection. The plain-text escaping from #4389 is kept and is now also covered for an API conversation without an address. Closes #3912 Closes #3924 Refs #3920
Bulk Inbox messages came from a plain textarea but were sent through the HTML reply contract unchanged, losing literal tags and collapsing line breaks. Escape the textarea text with the existing
helibrary and serialize newlines as<br>inside a paragraph before the real reply mutation. Stored messages and queued HTML emails receive that same safe body; rich editor sends retain their existing behavior.Validation:
Sweep: single replies and compose use the Milkdown snapshot serialized/sanitized by
toOutboundHtml; backend bulk reply forwards the caller's existing HTML contract. Only the plain bulk textarea boundary changes. No user-visible copy changed.Register insertion anchor: the existing “Inbox reply and new-email sends read current HTML” editor-snapshot row. Inspected
gh pr difffor every open PR touching this register (43); none touches that anchor.git merge-treefound no newly introduced register conflicts: 24 merge cleanly; 19 older PRs already conflict in that file against the unchanged base. Evidence is retained in task artifacts.Closes #3920
Current-main rebase
Replayed the previously accepted source
71ceecc9fe72fdc7fedbd8f894909bd6962a0476onto maind1373d84cd56972501403f62145ec52e6f65d44a, including the merged shared CI repair in #4625. The accepted feature payload and all current-main changes are preserved in one atomic commit. Configured commit and conflict checks pass; earlier behavioral proof remains recorded above. All seven native required checks and full merge-group validation remain required for this new source.Maintenance replay: preserves the accepted feature payload on current main 7d178ca. Includes the merged #4649 Knip cleanup and the exact independently accepted one-line shared CLI inventory repair from #4654 (252f0df), which is still pending native merge on main. The fixed suite inventory keeps its discovery and source/compiled phase guards. Existing feature proof is retained; no fresh full-feature/full-workspace test or hosted-green claim. Native required checks remain mandatory.