Open locked accounts handed to you, beside your own mail

When the server hands a locked account to the reader (urn:inbuxa:jmap
delegation), the account popover offers it. Only mail follows the switch;
the reader's own settings, push and notifications stay theirs. A red bar,
a red wordmark with a padlock and the tab title say which account is in
view. Read delegates can't change anything, organize delegates can't
delete, and writing needs send-as. A delegation taken away drops back to
the reader's own mail.

14 new strings in all nine catalogs, unreviewed (inbuxa AL-7, AL-8).
This commit is contained in:
jcoffey-dev committed 2026-09-27 14:32:10 -07:00
1 parent ffe1a898f5
commit 8674b70f62
22 files changed
+679 -25

No files matched your search

@@ -0,0 +1,127 @@
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest";
import { CAP, client } from "@/jmap/client";
import type { JmapSession } from "@/jmap/types";
import { useSession } from "@/store/session";
import { useMail } from "@/store/mail";
import { composeBlocked, useCompose } from "@/store/compose";
import { delegatedAccounts, delegationOf, mayDestroy, mayWrite } from "@/lib/delegation";
/**
* inbuxa AL-7: a locked account handed to the reader shows in place of their
* own mail, and only mail follows it; the reader never loses their own
* account, and a delegation taken away takes them back.
*/
const delegated = (access: string, sendAs = false) => ({
name: "[email protected]",
isPersonal: false,
isReadOnly: access === "read",
accountCapabilities: {
[CAP.mail]: {},
"urn:inbuxa:jmap": { delegation: { locked: true, access, sendAs, until: null } },
},
});
const sessionWith = (locked: Record<string, unknown> | null) =>
({
capabilities: { [CAP.core]: { maxCallsInRequest: 16, maxObjectsInGet: 500 }, [CAP.mail]: {} },
accounts: {
own: { name: "[email protected]", isPersonal: true, accountCapabilities: { [CAP.mail]: {} } },
shared: { name: "[email protected]", isPersonal: false, accountCapabilities: { [CAP.mail]: {} } },
...(locked ? { locked } : {}),
},
primaryAccounts: { [CAP.mail]: "own" },
state: "s",
}) as unknown as JmapSession;
let nextSession: JmapSession;
beforeEach(() => {
nextSession = sessionWith(delegated("read"));
vi.stubGlobal(
"fetch",
vi.fn(async (url: string, init?: RequestInit) => {
if (String(url).includes("/api/auth/session")) {
return { ok: true, status: 200, json: async () => nextSession } as Response;
}
const { methodCalls } = JSON.parse((init?.body as string) ?? "{}") as { methodCalls: [string, Record<string, unknown>, string][] };
const methodResponses = methodCalls.map(([name, args, id]) => [name, { accountId: args.accountId, state: "1", list: [], notFound: [] }, id]);
return { ok: true, status: 200, json: async () => ({ methodResponses, sessionState: "s" }) } as Response;
}),
);
const session = sessionWith(delegated("read"));
client.session = session;
useSession.setState({ status: "authenticated", session, accountId: "own", viewing: null, delegationEnded: null });
useCompose.setState({ drafts: [] });
});
afterEach(() => {
useSession.setState({ viewing: null });
vi.unstubAllGlobals();
});
describe("delegation", () => {
it("is read only from the session's mark, never from a shared account's capabilities", () => {
const session = sessionWith(delegated("organize", true));
expect(delegationOf(session, "locked")).toEqual({ locked: true, access: "organize", sendAs: true, until: null });
expect(delegationOf(session, "shared")).toBeNull();
expect(delegationOf(session, "own")).toBeNull();
expect(delegatedAccounts(session).map((a) => a.id)).toEqual(["locked"]);
});
it("never lets a read delegate send, whatever the server says", () => {
const session = sessionWith(delegated("read", true));
expect(delegationOf(session, "locked")?.sendAs).toBe(false);
});
it("says what each level may do", () => {
const read = delegationOf(sessionWith(delegated("read")), "locked");
const organize = delegationOf(sessionWith(delegated("organize")), "locked");
expect(mayWrite(read)).toBe(false);
expect(mayWrite(organize)).toBe(true);
expect(mayDestroy(organize)).toBe(false);
expect(mayWrite(null) && mayDestroy(null)).toBe(true);
});
});
describe("viewing a locked account", () => {
it("moves only the mail store; the session's own account stays", () => {
useSession.getState().view("locked");
expect(useMail.getState().accountId).toBe("locked");
expect(useSession.getState().accountId).toBe("own");
expect(useSession.getState().ownAccountFor(CAP.mail)).toBe("own");
useSession.getState().view(null);
expect(useMail.getState().accountId).toBe("own");
});
it("refuses an account that isn't delegated", () => {
useSession.getState().view("shared");
expect(useSession.getState().viewing).toBeNull();
expect(useMail.getState().accountId).toBe("own");
});
it("goes back to the reader's own mail when the delegation ends", async () => {
useSession.getState().view("locked");
nextSession = sessionWith(null);
await useSession.getState().refresh();
expect(useSession.getState().viewing).toBeNull();
expect(useSession.getState().delegationEnded).toBe("[email protected]");
expect(useMail.getState().accountId).toBe("own");
});
it("blocks writing mail where the delegate can't send", () => {
expect(composeBlocked()).toBeNull();
useSession.getState().view("locked");
expect(composeBlocked()).toMatch(/[email protected]/);
expect(useCompose.getState().open()).toBe("");
expect(useCompose.getState().drafts).toHaveLength(0);
});
it("lets a send-as delegate write", () => {
const session = sessionWith(delegated("full", true));
client.session = session;
useSession.setState({ session });
useSession.getState().view("locked");
expect(composeBlocked()).toBeNull();
});
});