github kimusan/Tachyon v4.3.0
4.3.0: The Extension That Had Never Once Run

2 hours ago

Your other mailboxes can use OAuth2 now

Adding a second Gmail account used to mean an app password, which means switching on 2-step verification to get one. That's a lot of ceremony to read a second inbox. Now Gmail, Office 365 and the generic OAuth2 extension can all authenticate an extra account properly: Add account, press the provider button, approve, done.

Two confessions came out of building it.

The Office 365 extension looked like it already did this. It couldn't. Its security check compared a token against one taken from a cookie, and the provider sends you back through a redirect that deliberately withholds that cookie. So it compared against a freshly invented value and never matched, which also broke ordinary o365 login on a default install. Upstream hit the same wall and left a branch titled "fails due to missing cookies". They weren't wrong.

The generic OAuth2 extension, meanwhile, had never run. Not once, not for anybody. It called a class that doesn't exist on its only live code path, and three more faults sat quietly behind that one because nothing ever got far enough to reach them. It works now, and it's finally generic: point it at any provider that speaks the standard.

Setup for all three is in the FAQ.

false.length is politely undefined

Encrypt a message without signing it and nothing was sent, nothing was saved, just TypeError: e.findIndex is not a function.

The compose window keeps a list of ways it can sign. With signing off, that list isn't empty, it's false. SnappyMail got away with this for years because nothing ever did more than ask its length, and JavaScript answers that question with a shrug. Then I taught it to reorder the list by your preferred method, and false has no opinion about ordering.

Exchange was right and we were rude about it

S/MIME wouldn't decrypt on Exchange. We asked for the headers belonging to part 1; Exchange said NIL. Correct of it: the message isn't a container with an encrypted part inside, it is the encrypted blob, and a single-part message has no part-level header to give. We took that truthful "nothing", pasted it onto the body, and handed openssl a bare base64 lump.

Installed as an app, links stopped working

View original, Download original and attachment downloads all failed from the Chrome app shortcut. Installed, Tachyon has its own browsing context, so opening a link in a tab lands it in the browser, which counts as somewhere else, so the session cookie stays behind. Fetched inside the app now.

Also

Swipe left and right on a phone to move between messages. Delivery receipts ask for delay notifications, which servers will often send even when they refuse success ones, and they stop pretending to work on domains using php mail(), which cannot request them at all. Release tarballs finally carry real timestamps instead of claiming 1 January 1970.

Upgrading

If you run the o365 or generic OAuth2 extension, recheck the configuration rather than assuming this is transparent. One was broken by default and the other never worked.

Thank you

@lvarnava, a fortnight of patient testing across three issues, and for finding the cause of one himself after I sent him down two blind alleys.

@reaisinc, whose IMAP trace corrected my diagnosis instead of confirming it.

@sir-andreas, for a report so precise it needed no follow-up.

@dreamawake, for the Chinese translation.

Don't miss a new Tachyon release

NewReleases is sending notifications on new releases.