summaryrefslogtreecommitdiffstats
path: root/docs/manual-verification.md
AgeCommit message (Collapse)AuthorFilesLines
23 hoursdocs: record manual verification items 4, 6-11Danilo M.1-6/+96
Items 4, 6, 7, 8, 9, 10 pass. Item 11 failed and was fixed in 9d13346. Two findings worth keeping beyond the pass/fail: The blank message pane (items 6, 9, 10) is exactly what this checklist existed for. Every layer was correct in isolation and the pane still showed nothing, because setHtml() does not navigate to the base URL it is given. No unit test would have caught it; the first click did. Item 7's initial failure was the checklist's fault, not the code's. The suggested query term came from the thread's subject line, so notmuch correctly matched all 22 messages and expanding them all was right. A test query has to partition on something that varies per message. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
23 hoursfix: render the message pane at allDanilo M.1-1/+11
Clicking a thread left the pane blank. Two independent bugs, both from the same false premise: that setHtml() navigates to the base URL it is given. It does not. setHtml() navigates to a data: URL carrying the markup and applies the base URL afterwards, purely as the document's origin. Verified empirically on Qt 6.11. Built on that wrong assumption were: - MessagePage::acceptNavigationRequest compared the navigation's URL against documentUrl() and rejected everything else, so the document load was refused. It now accepts a typed main-frame navigation, which is one we initiated ourselves. - RequestInterceptor exempted exactly the qtmaildir: base URL and denied everything else, so the data: document load was blocked too. The interceptor fix is scoped to ResourceTypeMainFrame rather than allowing the data: scheme outright. A blanket allow would have been a real hole: a message body can write <img src="data:..."> or an iframe, and the existing dataSchemeBlocked test in test_interceptor.cpp was right to fail when that was tried. Sub-resource data: URLs remain denied. Note this was never working. The drafted version had the same defect in a different spelling (it compared url.scheme() rather than the whole URL, and would have rejected the data: navigation just the same), and task 11 shipped with no runtime test to catch it. test_messageview.cpp now pins all three facts: the document loads, its text reaches the page, and a data: image inside a hostile body stays blocked. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
24 hoursdocs: record manual verification resultsDanilo M.1-0/+124
Covers the items verifiable without a person at the screen. Items 4, 6-15 need eyes on the rendering, 16-18 write to the live index and wait for the maintainer, and 19-20 need a sync script that does not exist on this machine yet. Item 5's premise turned out to be wrong rather than the code: notmuch accepts `tag:` and returns 1,917 threads, so there is no error to report. The CLI agrees exactly, as it does on tag:inbox. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>