1.1.4
2026-08-28
Third marketplace review round: hardening of the broker's local boundary.
Security
- Broker API is now read-only (
recentonly; theselftestdiagnostic was
removed) and client authorization goes beyondSO_PEERCRED: the peer
process must be the Python interpreter running exactly this plugin's
installed client script. The broker docstring states the residual same-uid
exposure honestly (truncated metadata of the last N messages; no bodies,
no session, no JS execution). - The broker refuses to start without a trusted per-user
XDG_RUNTIME_DIR
(no/tmpfallback) and creates/opens its subdirectory, lock and socket
relative to a validated directory descriptor withO_NOFOLLOW. hyprctl clients -joutput is capped at 256 KiB on the producer side (and
time-bounded) in bothomarchy-protonmail-unreadand
omarchy-protonmail-focus-or-launch.omarchy-protonmail-recentcaps broker replies at 64 KiB and normalizes
the exact schema, record count and field lengths before QML parses them.