Skip to content

feat: add server-owned compose sessions - #349

Open
salmonumbrella wants to merge 11 commits into
maathimself:mainfrom
salmonumbrella:feat/compose-session-server
Open

feat: add server-owned compose sessions#349
salmonumbrella wants to merge 11 commits into
maathimself:mainfrom
salmonumbrella:feat/compose-session-server

Conversation

@salmonumbrella

Copy link
Copy Markdown
Contributor

Summary

Adds server-owned compose sessions with nine deterministic slots, revisioned
field-aware updates, durable attachments, REST routes, and content-free
WebSocket invalidations.

This is a cumulative PR on #345 and #321. Their approved dependency commits
are restacked here only to keep the combined migration history monotonic through
0052.

Review the last commit only: c1c0abd (feat: add server-owned compose sessions).

Changes

  • Add the 0053_compose_sessions.sql schema and revisioned session model.
  • Enforce nine user-global slots, UUID/field/media validation, and attachment
    size limits.
  • Add compose-session REST handlers with structured conflict responses.
  • Broadcast content-free session invalidations without draft content or
    attachment metadata.
  • Cover capacity, merge/conflict, idempotency, authorization, and privacy
    boundaries.

Testing

  • Backend: 2,292 passed; 52 environment-dependent tests skipped.
  • Backend lint: clean with zero warnings.
  • Focused compose-session model/service/route suites: green.
  • Diff and privacy scans: clean; synthetic example.com fixtures only.

Contributor License Agreement

By submitting this pull request I confirm that:

  • I have read and agree to the Contributor License Agreement.
  • My contribution is my own original work (or I have identified any
    third-party material and confirmed it is compatible with the CLA).
  • I have the right to submit this contribution under the terms of the CLA.

salmonumbrella and others added 11 commits July 31, 2026 16:21
Results ranked by relevance instead of date-only: subject > sender > body
(setweight A-D + ts_rank_cd), prefix matching as you type, quoted phrases,
served by a GIN index over a trigger-maintained search_fts column. Backfill
runs as a resumable background drainer (fast-DDL migrations 0035-0037, no
boot-blocking rewrite); not-yet-backfilled rows fall back to the previous
query path. Body text is materialized by a provider-gated background IMAP
drainer with circuit breakers, poison-message forward progress, and
progress reporting. Filter-only queries stay date-ordered.

No infrastructure changes - runs on stock postgres:16-alpine.

Split 1/3 of maathimself#283.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…tor)

Explicit opt-in embeddings pipeline against any OpenAI-compatible
/v1/embeddings endpoint (key encrypted at rest, host-validated, masked on
read). Fingerprinted generations (config change => clean rebuild), a
crash-safe fill worker, per-dimension HNSW partial indexes, re-embedding of
late-arriving bodies. Query side adds hybrid BM25+ANN reciprocal-rank
fusion behind an in-input Semantic toggle; lexical stays the default, with
silent fallback while the index builds. Settings UI with explicit privacy
copy and live Test/Build progress, in all 7 locales. Migrations 0038-0039.
Includes the search-eval harness that produced the published quality
numbers, and its explain/total diagnostics seams.

Infra: compose moves postgres:16-alpine -> pgvector/pgvector:pg16 (same
PG16 major). Run REINDEX DATABASE once after the first boot: the
musl -> glibc collation change can misorder existing text btree indexes;
the app logs a loud warning when it detects this.

Split 2/3 of maathimself#283, stacked on the weighted-FTS PR.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Streamable-HTTP /mcp endpoint (SHA-256-hashed tokens minted in Profile,
Origin-validated, rate-limited) exposing 12 tools including
semantic_search_messages and search_in_message. Every call is scoped to
the token owner's accounts; deletion is staged-only. Adds the MCP-only
search seams (trusted account scoping, body-scope FTS leg, strictVector,
loadVector), the chunk-excerpt read path, migrations 0040-0041, and one
new backend dependency: @modelcontextprotocol/sdk.

Split 3/3 of maathimself#283, stacked on the semantic-embeddings PR. The stacked
tree is byte-identical to the reviewed maathimself#283 head (3773150).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…tings

Extends the read-only MCP server (maathimself#296) to the full mail client:

- Token scopes (read/write/send/settings) enforced fail-closed at one dispatch
  choke point; tools/list filtered per token; existing tokens stay read-only.
  Per-class rate limits plus a daily send cap.
- 33 new tools (58 total): drafts, send/reply/reply-all/forward with hard
  alias validation and receipts, unsend via a real outbox (0-120s window,
  SKIP LOCKED worker, race-safe cancel), honest best-effort recall, folders/
  move/archive/trash/flags/spam/snooze/category/GTD with refuse-unbounded
  guards, an inbox-triage loop (triage_inbox / get_triage_context /
  mark_triaged) with embedding-derived signals, and settings tools including
  a staged add_account that never accepts secrets over MCP.
- Undo-send frontend: countdown toast with Undo, user preference (0-120s,
  default off so upgrades never change send behavior).
- Service extractions shared by REST and MCP (send/draft/reply/mailbox),
  fixing real bugs en route: alias silent-fallback, the References chain
  (thread_references was never used by compose), drafts dropping threading
  headers, and a new synchronous account test-connection endpoint.
- Migrations 0042-0046. Every tool def carries MCP annotations.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant