User can able to delete from bin #670
Conversation
|
@Adarsh9977 is attempting to deploy a commit to the Zero Team on Vercel. A member of the Team first needs to authorize it. |
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the You can disable this status message by setting the WalkthroughA new asynchronous function for deleting email threads has been added to the mail actions. The thread context menu now includes an option to delete threads from the Bin folder, invoking this new deletion logic and providing user feedback via toast notifications. The Google OAuth provider's scope has been expanded to include both mail modification and full mail access. Additionally, new English localization strings have been introduced to support the deletion action and related UI elements. Changes
Sequence Diagram(s)sequenceDiagram
participant User
participant UI (ThreadContextMenu)
participant Actions (deleteThread)
participant Driver
participant Toast
User->>UI (ThreadContextMenu): Clicks "Delete from Bin"
UI->>Toast: Show "Deleting mail..."
UI->>Actions (deleteThread): Calls handleDelete with threadId
Actions->>Driver: driver.delete(threadId)
alt Success
Actions->>UI: Return { success: true }
UI->>Toast: Show "Mail deleted"
UI->>UI: mutate() to refresh threads
else Error
Actions->>UI: Throw error
UI->>Toast: Show "Failed to delete mail"
end
Suggested reviewers
Poem
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
There was a problem hiding this comment.
Actionable comments posted: 1
🧹 Nitpick comments (3)
apps/mail/lib/auth-providers.ts (1)
51-51:Details
❓ Verification inconclusive
Scope expansion should follow principle of least privilege.
The Google OAuth scope has been expanded to include both
"https://www.googleapis.com/auth/gmail.modify"and"https://mail.google.com". However, using both scopes appears redundant since"https://mail.google.com"already provides full access to Gmail, which includes all permissions from the more limited"gmail.modify"scope.Consider using only the minimum scope required for the application's functionality. If the delete operation requires full access, you could simplify to:
- scope: ["https://www.googleapis.com/auth/gmail.modify", 'https://mail.google.com'], + scope: ["https://mail.google.com"],
🌐 Web query:
What's the difference between Gmail API scopes "https://www.googleapis.com/auth/gmail.modify" and "https://mail.google.com"?💡 Result:
The primary difference between the Gmail API scopes
https://www.googleapis.com/auth/gmail.modifyandhttps://mail.google.comlies in their levels of access and use cases:1. Scope:
https://www.googleapis.com/auth/gmail.modify
- Access Level: This is a more restricted scope. It allows applications to read, send, and modify emails in the user's Gmail account but does not grant full control or other advanced permissions like account settings management.
- Capabilities:
- Reading emails.
- Sending emails.
- Modifying emails (e.g., marking messages as read/unread or applying labels).
- Limitations: This scope cannot perform non-email functions like managing Gmail settings or accessing certain advanced features.
- Use Case: Ideal for apps that need to perform basic email tasks while maintaining a narrower security profile[1][3][5].
2. Scope:
https://mail.google.com
- Access Level: This is a significantly broader scope that grants full access to the Gmail account, including all emails, labels, settings, and metadata.
- Capabilities:
- Everything possible with the
gmail.modifyscope, plus:
- Access to Gmail settings (e.g., filters and forwarding).
- Viewing and managing additional account configurations.
- Essentially provides complete control over the Gmail mailbox and associated data.
- Limitations: Due to the high level of access, this scope requires a higher level of security review from Google to ensure proper use.
- Use Case: Best suited for applications that need extensive control over a Gmail account, such as email backup and migration tools or apps requiring deep Gmail integration[1][3][4][6].
Key Differences in Summary:
Feature https://www.googleapis.com/auth/gmail.modifyhttps://mail.google.comLevel of Access Moderate - Focused on email modification Full - Broad access and control Email Modification Yes Yes Settings Management No Yes Metadata & Advanced Access Limited Full Review Requirement Standard High (due to greater permissions) In conclusion,
https://www.googleapis.com/auth/gmail.modifyis a more secure, limited scope designed for basic email functionality, whereashttps://mail.google.comprovides full access, making it more versatile but also riskier and requiring stricter compliance measures.Citations:
- 1: https://developers.google.com/gmail/api/auth/scopes
- 2: https://developers.google.com/identity/protocols/oauth2/scopes
- 3: https://apidog.com/blog/gmail-api-guide/
- 4: https://docs.umbrella.com/cloudlock-documentation/docs/google-scope-categories
- 5: https://www.unipile.com/gmail-api-integration-made-easy-a-comprehensive-guide/
- 6: https://workspace.google.com/blog/product-announcements/elevating-user-trust-in-our-api-ecosystems
- 7: https://cloud.google.com/apigee/docs/api-platform/security/oauth/working-scopes
Action: Revisit the OAuth Scope Selection
The current implementation in
apps/mail/lib/auth-providers.ts(line 51) includes both
"https://www.googleapis.com/auth/gmail.modify"and"https://mail.google.com". Since"https://mail.google.com"already provides full access—including all capabilities granted by"gmail.modify"—this dual inclusion is redundant. In line with the principle of least privilege, please confirm which level of access is truly needed:
If only email modifications (including deletion) are required:
Use the more restricted scope"https://www.googleapis.com/auth/gmail.modify"to minimize access.If full mailbox access is required:
Keep only"https://mail.google.com".Example diff (if full access is intended):
- scope: ["https://www.googleapis.com/auth/gmail.modify", "https://mail.google.com"], + scope: ["https://mail.google.com"],apps/mail/actions/mail.ts (1)
158-169: The deleteThread implementation looks good.The function correctly obtains the active mail driver, performs the deletion operation, and handles errors appropriately. It follows the same error handling pattern used throughout the file.
For consistency with other functions:
- console.log("Deleting thread:", id); + console.log(`Server: Deleting thread ${id}`);apps/mail/components/context/thread-context.tsx (1)
259-265: Context menu item for deleting from bin implemented correctly.The menu item is properly placed in the bin-specific actions and uses appropriate icons and labels.
For consistency with the bulk selection handling in other actions, consider modifying handleDelete to support bulk deletion:
const handleDelete = async () => { try { + const targets = mail.bulkSelected.length ? mail.bulkSelected : [threadId]; + - const promise = deleteThread({ id: threadId }).then(() => { + // Since deleteThread only accepts one ID at a time, we need to process them sequentially + const promise = Promise.all( + targets.map(id => deleteThread({ id })) + ).then(() => { setMail(prev => ({ ...prev, bulkSelected: [] })); return mutate(); }); toast.promise(promise, { loading: t('common.actions.deletingMail'), success: t('common.actions.deletedMail'), error: t('common.actions.failedToDeleteMail'), }); } catch (error) { - console.error(`Error deleting ${threadId ? 'email' : 'thread'}:`, error); + console.error('Error deleting emails:', error); } };
📜 Review details
Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro
📒 Files selected for processing (4)
apps/mail/actions/mail.ts(1 hunks)apps/mail/components/context/thread-context.tsx(3 hunks)apps/mail/lib/auth-providers.ts(1 hunks)apps/mail/locales/en.json(2 hunks)
🧰 Additional context used
🧬 Code Graph Analysis (2)
apps/mail/actions/mail.ts (2)
apps/mail/app/api/driver/google.ts (1)
driver(85-823)apps/mail/actions/utils.ts (3)
getActiveDriver(29-60)FatalErrors(9-9)deleteActiveConnection(11-27)
apps/mail/components/context/thread-context.tsx (1)
apps/mail/actions/mail.ts (1)
deleteThread(158-169)
🔇 Additional comments (3)
apps/mail/locales/en.json (2)
22-24: Good addition of required localization strings for deletion operations.The added strings for deletion operations follow the existing pattern and will enable proper user feedback during mail deletion operations.
251-251: Appropriately added "Delete from Bin" menu label.This label is correctly added to support the new context menu item implemented in the thread-context component.
apps/mail/components/context/thread-context.tsx (1)
38-38: Correctly added import for the deleteThread function.The import statement has been properly updated to include the new deleteThread function from mail actions.
|
Changing the scopes requires a whole thing with google, putting this on hold |
|
@MrgSub got it |
|
The latest updates on your projects. Learn more about Vercel for Git ↗︎
|
apps/mail/lib/auth-providers.ts
Outdated
| prompt: "consent", | ||
| accessType: "offline", | ||
| scope: ["https://www.googleapis.com/auth/gmail.modify"], | ||
| scope: ["https://www.googleapis.com/auth/gmail.modify", 'https://mail.google.com'], |
There was a problem hiding this comment.
Let's not change the scopes, our scope should be enough
There was a problem hiding this comment.
should I close his PR or left it for future
There was a problem hiding this comment.
we just don't need that scope. remove it and we can merge
|
@Adarsh9977 is this ready now? |
|
@ahmetskilinc yes ready |
|
@ahmetskilinc on hold from many days ! |
* draft fixes: - added cc and bcc when saving drafts - save drafts less aggresively * some fixes for saving attachments to draft * fix for empty draft loading * fix draft list recipient name/address * also show 'No Recipient' if empty * remove comments * switch to mimetext for draft saving to keep formatting consistent * add message title to draft list * feat: single api for oauth connections * fix: add extra error handling * chore: simplify and fix the dev env * Ai generate security (#706) * Create prompts with XML formatting * Include XML formatted prompts in generate func * remove unused regex and add helper functions/warnings * error handling * Update apps/mail/lib/prompts.ts Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * lint issues * Update prompts.ts * #706 (comment) Coderabbit fix 1 * erabbitai bot 3 days ago⚠️ Potential issue errorOccurred state is stale inside finally React state setters (setErrorOccurred) are asynchronous; the errorOccurred value captured at render time will not yet reflect changes made earlier in the same event loop. Consequently, the logic deciding whether to collapse/expand may run with an outdated flag. - } finally { - setIsLoading(false); - if (!errorOccurred || isAskingQuestion) { - setIsExpanded(true); - } else { - setIsExpanded(false); // Collapse on errors - } - } + } finally { + setIsLoading(false); + // Use a local flag to track errors deterministically + const hadError = isAskingQuestion ? false : !!errorFlagRef.current; + setIsExpanded(!hadError); + } You can create const errorFlagRef = useRef(false); and update errorFlagRef.current = true every time an error is detected, ensuring reliable behaviour irrespective of React batching. Committable suggestion skipped: line range outside the PR's diff. * #706 (comment) * #706 (comment) * #706 (comment) --------- Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * Add a new Vietnamese translation file to support Vietnamese language users (#726) * feat(i18n): add Vietnamese language support Add Vietnamese ('vi') to the list of supported languages in the i18n configuration and JSON file to expand language options. * Add a new Vietnamese translation file to support Vietnamese language users. * Clear Vietnamese translation strings * Update es.json (#710) Co-authored-by: needle <122770437+needleXO@users.noreply.github.com> * Update app manifest and add new icons for PWA (#739) * feat: allow sending from email aliases added through gmail (#743) * Refactor IP handling in early-access routes * Add unauthorized error handling in sign out function * Redirect from Home Page on Session (#701) * Updated lockfile * Updated home page session validation --------- Co-authored-by: Adam <x_1337@outlook.com> * Refactor settings handling and golden ticket logic * Feat: og:image Generation on /compose route (#730) * Create route og image * resolve coderabbit nitpicks --------- Co-authored-by: Adam <x_1337@outlook.com> * Update session check to include user id before redirecting * Fix unauthorized error handling in multiple actions * Enable shortcuts settings in navigation * Refactor error handling to return unauthorized gracefully * Update Hero component with new imports and link adjustments * Update redirect URL to use hostname from req object * Fix redirect URL formatting and add log for missing user ID * Fix error handling in API routes for unauthorized requests * Refactor throwUnauthorizedGracefully function for readability * Fix error handling in driver routes * Handle unauthorized gracefully when getting connections * Refactor mail actions for better error handling * Refactor deleteActiveConnection function for readability * fixed (#752) * Refactor error handling in mail actions to return null or specific error messages instead of throwing unauthorized errors. This improves readability and maintains functionality across various actions. * Update Google auth provider configuration * Delete connection and update hero text * Refactor error handling to use StandardizedError class * Refactor error handling for Google API driver * Add labels to sidebar, labels settings and useLabels hook (#746) * Adds labels from the provider: - labels page in settings - labels page translations - added labels for google provider * useLabels and labels in sidebar * fix rate limit parts of labels route * Added labels to mail-list * - add rate limiting - move useThreadsLabel --------- Co-authored-by: Adam <x_1337@outlook.com> * bin count of unread messages * dixes drafts not saving persistently * dont show from field is no aliases * limited height of attachment dialog * added delete page * correct way to delete accounts * - adds new revokeRefreshToken method to Google driver - updates lib/auth.ts to use the new method - updates actions/user.ts - updates app/(routes)/settings/danger-zone/page.tsx * Add posthog-js dependency and implement label filtering in NavMain component - Added posthog-js version 1.236.6 to package.json and bun.lock. - Introduced search functionality by implementing handleFilterByLabel in NavMain component. - Updated NavItem to trigger label filtering on click. * Enhance NavItem component to support onClick event handling - Updated NavItem to include an onClick prop for the Link component, allowing for custom click behavior. - Maintained existing functionality with prefetch and target attributes. * fix: add missing dompurify dep (#765) * user can edit enail after selecting (#760) * User can able to delete from bin (#670) * delete mails permanently from bin * add English translations for delete mail actions * update the call handleDelete * fixed handle delete function * handleDelete call * enhance handledelete to reset bulk selection after deletion * removed the scope * delete mails permanently from bin * add English translations for delete mail actions * update the call handleDelete * handleDelete call * enhance handledelete to reset bulk selection after deletion * removed the scope --------- Co-authored-by: Ahmet Kilinc <akx9@icloud.com> Co-authored-by: Adam <x_1337@outlook.com> * send draft instead of new message (#767) * Add sendDraft method to Gmail driver and MailManager interface * fix sendDraft method * Add support for sending draft emails and clear draftId after sending --------- Co-authored-by: Adam <x_1337@outlook.com> * Add Chinese language support for mail app * Update email addresses in send function * Add import statement for deleteActiveConnection function --------- Co-authored-by: Ahmet Kilinc <akx9@icloud.com> Co-authored-by: BlankParticle <blankparticle@gmail.com> Co-authored-by: grim <75869731+ripgrim@users.noreply.github.com> Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> Co-authored-by: Chánh Đại <dai@chanhdai.com> Co-authored-by: Dani B. <danibaldomirm@gmail.com> Co-authored-by: needle <122770437+needleXO@users.noreply.github.com> Co-authored-by: Humber Nieto <56887259+humbernieto@users.noreply.github.com> Co-authored-by: Atharva Deosthale <atharva.deosthale17@gmail.com> Co-authored-by: Nikita Drokin <86173808+nikitadrokin@users.noreply.github.com> Co-authored-by: Adarsh Tiwari <adarshtiwari797023@gmail.com> Co-authored-by: Adarsh Tiwari <134617221+Adarsh9977@users.noreply.github.com>
Description
User now able to delete his mails permanently from bin
Type of Change
Please delete options that are not relevant.
Present workflow
Screen.Recording.2025-04-15.at.5.12.38.PM.mov
Upgraded workflow
Screen.Recording.2025-04-15.at.5.14.13.PM.mov
By submitting this pull request, I confirm that my contribution is made under the terms of the project's license.
Summary by CodeRabbit