Repository navigation
Feather Mail 0.2.0
A stability release driven by a full audit of the client. No new account types; the fixes below cover
reading, syncing, searching, composing and the MCP server.
Reading mail
- A
<style>element with any attribute no longer bypasses the CSS allowlist, and>/&inside author
CSS no longer break the stylesheet. - MIME parts whose boundary line carries trailing whitespace (RFC 2046 transport padding) now render instead
of showing an empty body. - Attachment names encoded per RFC 2231 (
filename*=) are decoded, so they keep their real file names. - Replying to an HTML-only message now quotes its text.
- The folder chip next to an open message names the real folder instead of always saying "Inbox"; list rows
in Starred, Snoozed and All accounts now carry a folder chip too. - Times in the list and reading pane are computed from the real clock. Previously every message newer than
May 2024 showed a time of day instead of a date. - Folder names are decoded consistently in the sidebar, the list header and the message view; sender names
in thread cards are RFC 2047-decoded. - Secondary and tertiary text colours were darkened in both themes to clear WCAG AA contrast.
Sync and folders
- Mail deleted on the server is now removed locally. On CONDSTORE servers a sliding walk reconciles the whole
mailbox, one 200-UID batch per pass, and resumes after a restart. - CONDSTORE is actually enabled on SELECT, so flag changes from other clients arrive incrementally.
- A date header with a non-ASCII month name no longer panics the sync thread.
- Deleting an account no longer leaves a stale backoff record that spun the sync worker.
- A cancelled sync pass is no longer recorded as a completed one.
- Creating and renaming folders with non-ASCII names sends modified UTF-7 to the server, and renaming under
a non-ASCII parent no longer double-encodes the prefix. - Removing vanished messages also removes their cached bodies from disk, and "Clear cache" really deletes
the files. - The OAuth reauthorisation flow keeps the refreshed refresh token, and a
%before a multi-byte character
in a redirect no longer panics.
Queue and drafts
- Repeating a command after an identical one was acknowledged is queued again instead of being silently
dropped. - Queued operations replay in the order you issued them, even when one was retried later.
- Permanent delete acts on the messages that were in the thread when you asked, not whatever arrived since.
- Deleting a thread that a reply draft points to no longer fails with a foreign-key error and stalls sync.
- Drafts: a failed sequence lookup no longer overwrites an existing draft; discarding a draft while
autosave is in flight no longer resurrects it; edits made just before closing the compose window are kept. - Reply and forward from All accounts save and send through the draft's own account.
- Opening a search hit from All accounts switches to the hit's account instead of an empty list.
- Star, search history, folder create/rename/delete, account rename/removal and move all run off the UI
thread; the interface never blocks on SQLite.
Search
- Words inside Japanese and Chinese text are found (e.g. "東京" inside a sentence), and "ё" matches "е"
in both directions. Existing profiles reindex in the background after the upgrade.
Notifications
- A burst of more than 20 new messages is announced as one summary notification instead of losing
everything below the cut. - A mailbox added in the current session starts its notification watermark at its newest message, so the
first sync does not announce the whole history.
Add account
- The "Other IMAP" form looks up IMAP/SMTP settings (Thunderbird ISPDB and DNS SRV) when you leave the
email field, filling only the fields you have not typed into.
MCP server
send_emailno longer bumps the draft revision on every call for bodies with surrounding whitespace.create_draft/update_draftno longer accept an arbitraryfromaddress;update_draftwithout a
draft_idis rejected instead of creating a new draft.- Waiting for a UI confirmation no longer floods the audit log.
- The permissions and tools documentation matches the registered tool set and the real
limitbehaviour.
Storage
- The database uses
IMMEDIATEtransactions for read-then-write paths, so a concurrent writer waits instead
of failing withSQLITE_BUSY_SNAPSHOT. - Cached bodies and attachments are written with owner-only permissions.
- Schema upgraded to v29.