Releases: mojoaar/icloud-mailflow
Releases · mojoaar/icloud-mailflow
Release list
v0.13.0 — nested rules, safer imports, polished UI
[0.13.0] - 2026-09-21
Added
- Nested AND/OR condition groups in the rule editor (preserved through export, backup, and MCP)
- Failure alerts: POST a webhook when the poller goes unhealthy or recovers, or a scheduled backup fails
- Rule import is validated and previewed — invalid files are rejected and duplicate names skipped; MCP
import_rulessupportsdry_run - "Run rules" on an activity row to dry-run the current rules against that message
- Metrics:
mailflow_rules_total,mailflow_contacts_total,mailflow_db_size_bytes,mailflow_build_info;/healthreports DB size, build info, and the poller's last error - Build commit injectable via
-ldflags -X main.commit=… - Activity log bulk selection and delete (
POST /activity/delete-selected) alongside the existing clear-all - Stats CSV export (
GET /stats/export.csv?days=…,category,name,countrows) - Settings in-page section navigation (sticky anchor chips), a loading indicator for htmx-swapped regions, a print stylesheet (hides chrome, forces list view over charts), and consistent empty states across Activity, Rules, Stats, and Contacts
Changed
- MCP
run_pollreports "poll already in progress" instead of a false success - Accessibility: form labels are associated with their inputs, toasts announce via
role, the nav marks the current page witharia-current, links/buttons get a shared focus ring,prefers-reduced-motionis honoured, andcolor-scheme+ thin scrollbars match the theme - Responsive: the mobile stylesheet no longer forces every button full-width, form-control widths moved from inline styles to classes so they flow on small screens, and the nav collapses behind a toggle
- CSS cleanup: removed duplicate
method-*rules, stopped blanket table-cell truncation, added utility classes and migrated many inline styles, and htmx actions now show a loading state (aria-busy) - Extracted the remaining static inline styles into utility/component classes (spacing/typography tokens,
.hint,.empty-state,.chart-grid,.bar,.snippet,.code-block, …); only template-interpolated values stay inline, and JS visibility toggles use.hidden
v0.12.2 — Strict CSP, self-hosted assets, and performance
[0.12.2] - 2026-09-21
Changed
Content-Security-Policyis now strict:script-src 'self' 'nonce-…'with nounsafe-inline/unsafe-eval; inline event handlers were replaced with delegated listeners and inline scripts carry a per-request nonce- HTMX, Lucide and Chart.js are self-hosted under
/staticinstead of loaded from CDNs (no third-party script origins); the keyboard-modal and Docs styles moved from inline<style>blocks intostyle.css - Performance:
RulesRepo.Listloads rules with four fixed queries instead of per-rule lookups; the message body/headers are fetched once per message and shared across rules; folder sync diffs by path (stable IDs) instead of rewriting the table; file-backed databases allow concurrent readers (WAL); the catch-all rule is no longer rewritten on every rule change - The auto-reply throttle log is pruned after 7 days
Fixed
- The CSRF token is now stable across page renders, so submissions from other open tabs keep validating
v0.12.1 — Security & reliability fixes
[0.12.1] - 2026-09-21
Added
Content-Security-Policyon all responses (object-src 'none',base-uri 'self',form-action 'self',frame-ancestors 'none', allowlisted CDN/font origins) andStrict-Transport-Securityover HTTPS
Security
- The IMAP password is no longer written to
config.json— it is stored only in the encrypted database. A legacy plaintext value is migrated into the encrypted store on startup and theimap_passwordfield is removed from the file X-Forwarded-Foris only trusted whenTRUST_PROXY=true, so the login and MCP rate limits can no longer be bypassed by spoofing the header- Changing the admin password now invalidates all other sessions
Changed
- Theme families are now listed alphabetically in Settings, the docs, and the README (Mailflow, the default, stays first)
config.jsonis written atomically (temp file + rename) and serialized, so a crash mid-write can no longer leave it corrupt- IMAP/SMTP credentials are read from the encrypted store at use time, so changing the password takes effect without a restart
- The auto-reply daily throttle is consumed only after a successful send
Fixed
- Polling settings (interval, messages per poll, log retention) are validated before saving — an invalid interval can no longer be persisted and block startup; an invalid legacy interval self-heals to the default
Run Poll Now,Backup Now, andApply to Folderno longer panic when IMAP is not configured- The poller could execute a matched rule's actions repeatedly within a single tick, and could crash after processing a full batch (
atomic.Value.Store(nil)) — both fixed - IMAP session access is serialized across the poller, bulk apply, rule test, folder refresh, and contact seeding, removing data races on the shared connection
- Stats backfill runs again on upgrade (it was dead code), and folder sync no longer aborts on duplicate folder paths
- Schedules can cross midnight (e.g.
22:00–06:00), and zero/negative day counts are rejected - Activity pagination URL-encodes the search/filter values; auto-reply-throttled actions show a distinct
skippedbadge instead oferror - Rule reorder ignores non-rule rows and invalid ids; a blank priority on edit no longer resets to 0; the built-in catch-all rule can no longer be deleted
- Apply-to-folder job status is mutex-guarded and HTML-escaped
- MCP tools validate their arguments instead of panicking on unexpected types; activity
per_pageis capped - CardDAV credentials are only sent to the configured iCloud host; SMTP multipart writes are error-checked
- MOVE on a server without UIDPLUS now reports an error and stops remaining actions for that message, instead of addressing the wrong UID
- Rule export and the scheduled-backup email now include schedules, priority, and enabled state; the backup attachment uses the same envelope as import and can be restored
v0.12.0 — Five new themes, theme-aware charts, WCAG AA
[0.12.0] - 2026-09-20
Added
- Five new theme families — Tokyo Night, One Dark, Gruvbox, Dracula, and Ayu — each with a dark and light variant (nine families in total)
- Theme-aware Stats doughnut palette via a new
--chart-seriestoken defined per theme /docs"Themes & Appearance" section (with sidebar link) documenting the families, picker, nav toggle, OS-preference fallback, and per-browser storage
Changed
- Brand wordmark now derives from the active theme accent instead of a hardcoded blue gradient
- Tuned colours in Catppuccin Light, Nord Dark, Nord Light, and Cyberpunk Light to meet WCAG AA contrast (4.5:1 text, 3:1 status/inverse); all themes are now covered by an automated contrast test
- README and the
/docsSettings reference updated for the nine theme families - Regenerated the README screenshots to reflect the current UI (Stats range selector and Poller card, theme-derived brand wordmark)
Fixed
/docsinlinecodetext now uses a contrast-safe background instead of--accenton--border- Removed a duplicated
POST /rules/{id}/testentry and made the/healthexample version accurate in/docs
v0.11.0 — Theming, timezone-aware stats, and a smarter Stats page
[0.11.0] - 2026-09-20
Added
- Theme system — Mailflow, Catppuccin, Nord, and Cyberpunk, each with a dark and light variant; theme chosen in Settings → Regional, quick dark/light toggle in the nav, syntax highlighting follows the mode
/statsrange selector (7/30/90 days) scoping the daily and weekly volume charts/statsPoller card showing last run time, duration, health, and consecutive failures
Changed
- Replaced hardcoded UI colours with theme tokens (buttons, badges, toasts, method badges, focus ring, charts) so all themes apply consistently
/statsstatus totals (success/error/skipped) are now shown as a labelled breakdown under the all-time processed count/statscharts recolor live when the theme changes (no reload)- Refreshed README screenshots and added
scripts/screenshots.sh(Playwright) to regenerate them from the demo dataset - Timezone picker now accepts any IANA zone (searchable field with suggestions) instead of a fixed 10-zone list; validated on save and via MCP
update_settings
Fixed
/statsdaily and weekly volume charts were plotted newest-first (reversed); they are now returned in ascending time order/statsdaily/weekly buckets and runtime-metric time axis now follow the configured timezone instead of UTC/server-local time
v0.10.0 — Prometheus instrumentation, light-mode header fix & docs refresh
[0.10.0] - 2026-09-19
Added
- Prometheus metrics are now instrumented — messages processed, rule matches, actions, errors, poller ticks, tick duration, and CPU/memory/uptime gauges
Changed
- Documentation and README refreshed: MCP now lists 26 tools, corrected
/healthendpoint description, documented rule scheduling, regex capture, webhook settings, and the dry-run/bulk-apply features, and added Prometheus + Chart.js to credits/stack
Fixed
- Header wordmark rendered as a flat blue block in light mode — the
backgroundshorthand was resettingbackground-clip: text - Data race between the metrics collector and router initialization (
startTime) caught by-racein CI — collector now starts after the router is built
v0.9.6 — favicon, brand header, dashboard uptime & fixes
[0.9.6] - 2026-09-19
Changed
- New favicon: blue gradient tile with a white "M" monogram
- Dashboard status now shows uptime
- Header brand now shows the logo mark beside a gradient "iCloud Mailflow" wordmark with a soft glow
Fixed
/statsRefresh now reloads the page instead of doing an htmx partial swap — fixes charts reverting to list mode after refresh/activityRefresh now shows a spinner and a "Activity refreshed" toast on completion
v0.9.5 — UI fixes, regex validation, Docker healthcheck
[0.9.5] - 2026-09-19
Changed
- Footer now reads "Crafted with ❤️ & 🤖 by Morten Johansen"
- Docker image now ships a
/health-based HEALTHCHECK
Fixed
/statsRefresh button desyncing chart/list toggle state — switched from full-body HTMX swap to a partial#stats-contentswap that only re-runs the stats init script- Buttons with Lucide icons rendered taller than text-only buttons (icons defaulted to 24px) — icon size now matches button font, most visible on
/settings - Rule dry-run PASS/FAIL colors referenced undefined
--success/--dangerCSS variables — now use--green/--red - Bulk-apply result toasts used
toast error/toast successclasses — nowtoast-error/toast-success - Theme-toggle icon now reflects the active theme (was hardcoded to
sunand never updated after Lucide replaced the<i>element) matches_regexconditions are now validated on save (web and MCP) — invalid regex returns an error instead of silently never matching- MCP rate limiter now periodically evicts expired entries (previously grew unbounded)
v0.9.4 — uptime days & weekly volume cap
[0.9.4] - 2026-09-15
Changed
- Stats page Weekly Volume now displays the latest 8 weeks instead of 24
- Settings Uptime now includes days (e.g.
9d 6h 1m 36s) instead of rolling all hours into a single value
v0.9.3 — button consistency & CPU/memory fixes
[0.9.3] - 2026-08-03
Changed
- Settings page button consistency: Refresh folders inherits standard button sizing, webhook Save/Generate use flex layout, icons added to Generate/Copy/Regenerate/Import/Wipe buttons
Fixed
- Runtime Metrics CPU and memory charts showing empty after v0.9.3 migration — fixed chart initialization path and added "No data yet" fallback
- CPU % chart resetting on every container restart due to a migration that re-ran
DELETE FROM stats WHERE category='cpu'on each startup - CPU % exceeding 100% on multi-core systems — now normalized by dividing by
runtime.NumCPU()