aboutsummaryrefslogtreecommitdiffstats
path: root/src/composecontext.cpp
diff options
context:
space:
mode:
authorDanilo M. <danix@danix.xyz>2026-08-27 13:05:17 +0200
committerDanilo M. <danix@danix.xyz>2026-08-27 13:05:17 +0200
commit5570d0e7495a42a90acf951d396c9185b0319eb9 (patch)
tree4052c9060b6ade33577c9bcb285565a1477bd3eb /src/composecontext.cpp
parent12e841b8e2c4c225ea79de87dc7bb50f0404ee69 (diff)
downloadqtmaildir-5570d0e7495a42a90acf951d396c9185b0319eb9.tar.gz
qtmaildir-5570d0e7495a42a90acf951d396c9185b0319eb9.zip
feat: forward an HTML message with its formattingHEADmaster
Item 171. A forward carried only the plain-text version of the original, so formatting was lost; and an original with no plain-text part at all (30 of 342 sampled inbox messages, ~9%) forwarded as an empty quote with its content silently gone. A forward now sends ONE part chosen by the Send-as-HTML toggle: the original's markup when on, the text quote when off. Not a multipart/alternative, at the user's decision: a forward's shape is already decided by that toggle, and sending both hands the choice to the recipient's client. The toggle is honoured even for an HTML-only original, which then forwards as a text fallback. HtmlSanitiser strips remote content from the forwarded markup, checked by default with a per-forward opt-out. This is the security-critical part: the markup leaves this process and is rendered by the recipient's client, where none of MessageView's protections apply, so forwarding a tracking pixel forwards the tracking. It is an ALLOW-LIST, unlike HtmlBuilder::namespaceCids(), because a missed rewrite is a broken image while a missed strip is a beacon reaching the recipient. An HTML forward does not seed a text quote into the editor. The first build did, then subtracted it when building the HTML part, so the user could edit a quote whose edits were discarded; what the composer shows must be what gets sent. The forwarded message appears in a read-only pane beside the editor instead, a QSplitter at 60/40 with a toggle in the Format menu. A plain forward is unchanged. ComposeContextBuilder::quoteBody() renders htmlBody down to text when there is no plain part, so the plain path never emits an empty quote. Design in docs/superpowers/specs/2026-08-27-forward-html-design.md. Two tests repaired for the splitter: the 60/40 assertion reads stretch factors rather than pixels, since the offscreen platform gives the splitter no width and reports 49/49 whatever the code asks; and theComposerSplitsItsToolbarByScope looked for the body directly in the composer's column. Not yet hand-tested in this arrangement. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AtUzfNjMD8fiYfamDd3ywW
Diffstat (limited to 'src/composecontext.cpp')
-rw-r--r--src/composecontext.cpp21
1 files changed, 20 insertions, 1 deletions
diff --git a/src/composecontext.cpp b/src/composecontext.cpp
index 2dfee53..b02b790 100644
--- a/src/composecontext.cpp
+++ b/src/composecontext.cpp
@@ -30,6 +30,7 @@
#include <QDir>
#include <QSet>
#include <QRegularExpression>
+#include <QTextDocumentFragment>
namespace {
@@ -630,10 +631,28 @@ QString ComposeContextBuilder::quoteBody(const ParsedMessage &message)
.arg(message.date, message.from));
quoted.append(QString());
+ // Item 171's silent half. An HTML-only original has an EMPTY plainBody, so
+ // quoting it produced an attribution line and nothing else: the content
+ // was gone with nothing to say so. Measured 2026-08-27, ~9% of the
+ // developer's inbox declares text/html with no text/plain.
+ //
+ // Only when there is no plain part. Rendering the HTML over a real plain
+ // part would change every ordinary reply, and the sender's own plain text
+ // is what they meant a text reader to see.
+ //
+ // QTextDocumentFragment, not a hand-written stripper: it is already
+ // linked, it decodes entities and collapses whitespace the way a reader
+ // expects, and reaching for a regex here would be re-implementing a parser
+ // badly. This restores the WORDS only; preserving the formatting is the
+ // multipart/alternative half of item 171.
+ QString source = message.plainBody;
+ if (source.isEmpty() && !message.htmlBody.isEmpty())
+ source = QTextDocumentFragment::fromHtml(message.htmlBody).toPlainText();
+
// Normalised to LF first. A CRLF body split on '\n' alone leaves a
// carriage return at the end of every line, which survives into the sent
// message as a stray CR in the middle of a quoted line.
- QString body = message.plainBody;
+ QString body = source;
body.replace(QStringLiteral("\r\n"), QStringLiteral("\n"));
body.replace(QLatin1Char('\r'), QLatin1Char('\n'));