You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Provide an encrypted, account-partitioned GRDB cache for a 90-day mail window, offline reads, pending actions, drafts, migrations, eviction, and safe rebuild.
Scope
Model cached accounts, folders, threads, messages, body variants, attachment metadata, draft revisions, action queue, event cursor, and sync metadata.
Define Swift 6 models, actors, storage, API, and UI boundaries for this scope.
Implement the smallest complete native capability.
Add XCTest, Swift Concurrency, migration, UI, accessibility, and device tests where applicable.
Update generated clients, translations, privacy declarations, and distribution documentation.
Acceptance criteria
Cached inbox, search subset, and opened conversations remain usable offline.
Removing an account erases its rows and keys.
Corruption or migration failure offers safe rebuild without remote mutation.
Reconnect reconciles server events, local drafts, and pending actions deterministically.
Account isolation, data protection, accessibility, EN default, and ES completeness match the web and macOS contracts.
Tokens, credentials, message content, recipients, and personal data never enter logs, crash reports, screenshots, fixtures, URLs, or notification defaults.
The capability is independently reviewable and rollback-safe.
Validation
Run GRDB migration, encryption, observation, offline, reconnect, conflict, eviction, corruption, and large-cache performance tests.
Run Swift build, XCTest, strict concurrency checks, generated-client diff, and the affected simulator and physical-device UI tests.
Use sanitized fixtures and protected accounts only for final manual provider validation.
Offline state, background execution, notification privacy, generated contracts, and device credentials can diverge from server truth. Use actors, Keychain, bounded caches, explicit conflict states, and real-device validation.
Out of scope
Full historical archive, provider authority, and shared database with macOS.
Plan reference
Post-1.0 — iPhone and iPad: local cache.
Objective
Provide an encrypted, account-partitioned GRDB cache for a 90-day mail window, offline reads, pending actions, drafts, migrations, eviction, and safe rebuild.
Scope
Tasks
Acceptance criteria
Cached inbox, search subset, and opened conversations remain usable offline.
Removing an account erases its rows and keys.
Corruption or migration failure offers safe rebuild without remote mutation.
Reconnect reconciles server events, local drafts, and pending actions deterministically.
Account isolation, data protection, accessibility, EN default, and ES completeness match the web and macOS contracts.
Tokens, credentials, message content, recipients, and personal data never enter logs, crash reports, screenshots, fixtures, URLs, or notification defaults.
The capability is independently reviewable and rollback-safe.
Validation
Run GRDB migration, encryption, observation, offline, reconnect, conflict, eviction, corruption, and large-cache performance tests.
Run Swift build, XCTest, strict concurrency checks, generated-client diff, and the affected simulator and physical-device UI tests.
Use sanitized fixtures and protected accounts only for final manual provider validation.
Dependencies
Post-1.0 work. Blocked until Mailflow 1.0.0 is released: https://github.com/Tutitoos/mailflow/milestone/9
Risks
Offline state, background execution, notification privacy, generated contracts, and device credentials can diverge from server truth. Use actors, Keychain, bounded caches, explicit conflict states, and real-device validation.
Out of scope