Skip to content

fix(mail): say so when the password saved for Gmail is not an app password - #72

Merged
JOhnsonKC201 merged 1 commit into
mainfrom
fix/gmail-password-hint
Oct 9, 2026
Merged

JOhnsonKC201 merged 1 commit into
mainfrom
fix/gmail-password-hint

Conversation

@JOhnsonKC201

Copy link
Copy Markdown
Owner

What this fixes

Settings > Feeds showed saved with a tick for any mail password of eight characters or more. With a Gmail address that is misleading. Gmail accepts only a 16-letter app password over IMAP, so someone who pastes their normal Google password sees a tick, the poll fails quietly, and the alerts never come with nothing to explain why.

Now, when the account resolves to imap.gmail.com and the saved password is not 16 characters:

  • next to the field: saved, but 19 characters, not 16
  • in the status line, on saving: what that usually means, and where to make an app password

How

  • passwordAdvice(len, email, host) in src/mail.js is pure and tested. It reuses imapHostFor, so a @googlemail.com address or a mistyped www.gmail.com host is still recognised.
  • email:passwordInfo now hands main the config, since the advice depends on the address and the server.
  • Only the length is used. The password is not compared, logged or sent anywhere. The one new thing crossing to the Settings window is a single word of advice, on a channel that already carried the length.

Known limits (from review, not fixed here)

  • The sentence is worded as likely, not certain. A Google Workspace account on a custom domain is flagged the same way, and its admin may have app passwords turned off, in which case the link does not help. The wording says so.
  • The sentence in the status line is advisory and is not cleared if the address is later changed to another provider; the next Test, save or toggle replaces it. The short note beside the field does update on every render.
  • Pressing Test saves the address without waiting, so the note can briefly reflect the previous address.
  • The Settings wiring is covered by a source-text test. passwordAdvice itself has a real unit test; passwordInfo(cfg) end to end would need Electron mocked.

Test plan

  • npm test: 514 pass, 0 fail, 4 skipped (POSIX only)
  • npx eslint . clean
  • In the running app: open Settings > Feeds with a non-app password saved for a Gmail address and confirm the note beside the field. Not checked live.
  • Save a real 16-letter app password and confirm the tick returns and Test connects.

…sword

Settings showed a tick for any saved password of eight characters
or more. With a Gmail address that misleads: Gmail accepts only a
16-letter app password over IMAP, so someone who pastes their
normal Google password sees saved, the poll fails quietly, and the
alerts never come with nothing to say why.

passwordAdvice in mail.js looks at the saved length and whether the
account resolves to imap.gmail.com. Settings then shows the length
next to the field and, when the password is saved, a sentence on
what that usually means and where to make an app password. It is
worded as likely, since a work or school account can be set up
differently by its admin.

Only the length is used. The password is not compared, logged or
sent anywhere, and nothing new leaves the main process beyond one
word of advice on the existing Settings channel.
@vercel

vercel Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
pixelcat Ready Ready Preview Oct 9, 2026 5:04am UTC

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown

CI for f47e157: all jobs passed

Job Result Log
test passed open
packaged-boot (windows-latest) passed open
boot (macos-latest) passed open
packaged-boot (macos-latest) passed open
boot (windows-latest) passed open

Tests: 518 passed, 0 failed, 0 skipped, 518 total.

This comment updates itself on every push. Full run.

@JOhnsonKC201
JOhnsonKC201 merged commit 602bcfa into main Oct 9, 2026
9 checks passed
@JOhnsonKC201
JOhnsonKC201 deleted the fix/gmail-password-hint branch October 9, 2026 05:07

This branch was successfully deployed

1 active deployment
Preview — f47e1577 Deployed Oct 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant