You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Post-1.0 — iPhone and iPad: secure native identity.
Objective
Implement server discovery, bootstrap when permitted, email and password, passkeys, recovery code, short JWT refresh, per-device revocation, Keychain storage, logout, and protected-screen behavior.
Define Swift 6 models, actors, storage, API, and UI boundaries for this scope.
Implement the smallest complete native capability.
Add XCTest, Swift Concurrency, migration, UI, accessibility, and device tests where applicable.
Update generated clients, translations, privacy declarations, and distribution documentation.
Acceptance criteria
Refresh credentials never enter GRDB, preferences, logs, URLs, crash events, or backups outside Keychain policy.
Concurrent requests perform one refresh and correctly replay authorized operations.
Revoked devices cannot refresh and return to a safe sign-in state.
Logout clears credentials, cached mail, notifications, and background work.
Account isolation, data protection, accessibility, EN default, and ES completeness match the web and macOS contracts.
Tokens, credentials, message content, recipients, and personal data never enter logs, crash reports, screenshots, fixtures, URLs, or notification defaults.
The capability is independently reviewable and rollback-safe.
Validation
Run passkey, password, recovery, refresh race, locked device, Keychain failure, revocation, logout, reinstall, and physical-device tests.
Run Swift build, XCTest, strict concurrency checks, generated-client diff, and the affected simulator and physical-device UI tests.
Use sanitized fixtures and protected accounts only for final manual provider validation.
Offline state, background execution, notification privacy, generated contracts, and device credentials can diverge from server truth. Use actors, Keychain, bounded caches, explicit conflict states, and real-device validation.
Out of scope
Social sign-in, multi-user instances, enterprise SSO, and credential synchronization between devices.
Plan reference
Post-1.0 — iPhone and iPad: secure native identity.
Objective
Implement server discovery, bootstrap when permitted, email and password, passkeys, recovery code, short JWT refresh, per-device revocation, Keychain storage, logout, and protected-screen behavior.
Scope
Tasks
Acceptance criteria
Refresh credentials never enter GRDB, preferences, logs, URLs, crash events, or backups outside Keychain policy.
Concurrent requests perform one refresh and correctly replay authorized operations.
Revoked devices cannot refresh and return to a safe sign-in state.
Logout clears credentials, cached mail, notifications, and background work.
Account isolation, data protection, accessibility, EN default, and ES completeness match the web and macOS contracts.
Tokens, credentials, message content, recipients, and personal data never enter logs, crash reports, screenshots, fixtures, URLs, or notification defaults.
The capability is independently reviewable and rollback-safe.
Validation
Run passkey, password, recovery, refresh race, locked device, Keychain failure, revocation, logout, reinstall, and physical-device tests.
Run Swift build, XCTest, strict concurrency checks, generated-client diff, and the affected simulator and physical-device UI tests.
Use sanitized fixtures and protected accounts only for final manual provider validation.
Dependencies
Post-1.0 work. Blocked until Mailflow 1.0.0 is released: https://github.com/Tutitoos/mailflow/milestone/9
Risks
Offline state, background execution, notification privacy, generated contracts, and device credentials can diverge from server truth. Use actors, Keychain, bounded caches, explicit conflict states, and real-device validation.
Out of scope