Skip to content

fix(view): block SSRF in remote images - #1693

Open
kawacukennedy wants to merge 83 commits into
floatpane:masterfrom
kawacukennedy:fix/view-html-ssrf
Open

kawacukennedy wants to merge 83 commits into
floatpane:masterfrom
kawacukennedy:fix/view-html-ssrf

Conversation

@kawacukennedy

@kawacukennedy kawacukennedy commented Jul 20, 2026 •

Copy link
Copy Markdown
Contributor

What?

Block remote image fetches to private/internal IP addresses and cap redirect chains to 5 hops. Reuse a single HTTP client per image fetch instead of creating one per call.

Why?

A malicious HTML email could embed images pointing at internal services (e.g. cloud metadata at 169.254.169.254, or 127.0.0.1). Viewing such an email triggered an outbound request to the attacker-controlled URL, enabling SSRF.

The default HTTP client also followed up to 10 redirects, allowing SSRF via redirect chains.

andrinoff and others added 30 commits June 1, 2026 23:20
## What?

Adds a v1 release backporting, merge queue behaivor, e.t.c.

## Why?

We are ready to start working on v1 of matcha. v0 will still be
maintained and supplied security updates, bug fixes, QoL features

---------

Signed-off-by: drew <me@andrinoff.com>
## What?

Uses [`go-keybind`](https://github.com/floatpane/go-keybind).

## Why?

Easier to maintain/expand

Signed-off-by: drew <me@andrinoff.com>
## What?

Implements a complete test suite for the `encryption.go`.

## Why?

The previous implementation had no test coverage for the
`encryption.go`.

Closes floatpane#886
## What?

Deduplicate unread badge counting across `emailsByAcct` and
`folderEmails` by tracking seen emails with `AccountID + UID`.

Added a regression test for the case where the same unread email exists
in both stores.

<img width="595" height="652" alt="image"
src="https://github.com/user-attachments/assets/8c837fb8-017c-4c7c-aa2c-052f244288b2"
/>

## Why?

Closes floatpane#1107

`syncUnreadBadge` counted unread emails from both stores independently,
but the stores can contain the same fetched messages. This could make
the macOS unread badge show roughly double the real unread count.

<img width="598" height="647" alt="image"
src="https://github.com/user-attachments/assets/f2b1c267-29bc-4d4c-a116-4c91af789722"
/>
## What?

Updates `flake.lock` to the latest revisions of all flake inputs
(`nixpkgs`, `flake-utils`, etc.).

## Why?

Keeps Nix inputs current so contributors and CI build against fresh
`nixpkgs`. Picks up upstream security and toolchain fixes. Generated
automatically by the flake-lock update workflow on changes to `go.sum`.
## What?

Regenerates `gomod2nix.toml` to reflect the current `go.mod` / `go.sum`.

## Why?

Keeps the Nix build in sync with Go module changes. Without this, `nix
build` fails when new or upgraded Go deps are missing from
`gomod2nix.toml`. Generated automatically by the gomod2nix sync
workflow.
## What?

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[charm.land/bubbletea/v2](https://redirect.github.com/charmbracelet/bubbletea)
| `v2.0.6` → `v2.0.7` |
![age](https://developer.mend.io/api/mc/badges/age/go/charm.land%2fbubbletea%2fv2/v2.0.7?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/charm.land%2fbubbletea%2fv2/v2.0.6/v2.0.7?slim=true)
|

---

### Release Notes

<details>
<summary>charmbracelet/bubbletea (charm.land/bubbletea/v2)</summary>

###
[`v2.0.7`](https://redirect.github.com/charmbracelet/bubbletea/releases/tag/v2.0.7)

[Compare
Source](https://redirect.github.com/charmbracelet/bubbletea/compare/v2.0.6...v2.0.7)

### A few lil’ stability patches

Hi! This is a patch release with a few solid improvements around
stability and correctness.

- [@&#8203;lrstanley](https://redirect.github.com/lrstanley), one of our
faves, fixed a race condition around mice in the Cursed Renderer
- [@&#8203;lawrence3699](https://redirect.github.com/lawrence3699) fixed
a panic that could happen when input's not available
- We fixed a correctness issue with regard to mouse releases when Kitty
Keyboard was active (thanks,
[@&#8203;mitchellh](https://redirect.github.com/mitchellh))

Thanks for using Bubble Tea, and if you see anything awry please do let
us know!

—Charm 👋

#### Changelog

##### Fixed

-
[`c60f0c5`](https://redirect.github.com/charmbracelet/bubbletea/commit/c60f0c53042238305ec13b486326588f12aea0ec):
fix: prevent data race with cursedRenderer.onMouse
([#&#8203;1691](https://redirect.github.com/charmbracelet/bubbletea/issues/1691))
([@&#8203;lrstanley](https://redirect.github.com/lrstanley))
-
[`074596e`](https://redirect.github.com/charmbracelet/bubbletea/commit/074596e14e2f5ca5e3986ee72e7c08f1569c4178):
fix: skip input reader restore when input is disabled
([#&#8203;1680](https://redirect.github.com/charmbracelet/bubbletea/issues/1680))
([@&#8203;lawrence3699](https://redirect.github.com/lawrence3699))
-
[`878d7df`](https://redirect.github.com/charmbracelet/bubbletea/commit/878d7df2f2b02f3ca8db177fa8553834bc35ea7c):
fix(deps): bump ultraviolet for kitty keyboard fix
([@&#8203;meowgorithm](https://redirect.github.com/meowgorithm))

***

<a href="https://charm.land/"><img alt="The Charm logo"
src="https://stuff.charm.sh/charm-banner-next.jpg" width="400"></a>

Thoughts? Questions? We love hearing from you. Feel free to reach out on
[X](https://x.com/charmcli), [Discord](https://charm.land/discord),
[Slack](https://charm.land/slack), [The
Fediverse](https://mastodon.social/@&#8203;charmcli),
[Bluesky](https://bsky.app/profile/charm.land).

</details>

## Why?

Automated dependency update via Renovate.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend
Renovate](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMDcuNCIsInVwZGF0ZWRJblZlciI6IjQzLjIwNy40IiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
## What?

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [react](https://react.dev/)
([source](https://redirect.github.com/facebook/react/tree/HEAD/packages/react))
| [`19.2.6` →
`19.2.7`](https://renovatebot.com/diffs/npm/react/19.2.6/19.2.7) |
![age](https://developer.mend.io/api/mc/badges/age/npm/react/19.2.7?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/react/19.2.6/19.2.7?slim=true)
|
| [react-dom](https://react.dev/)
([source](https://redirect.github.com/facebook/react/tree/HEAD/packages/react-dom))
| [`19.2.6` →
`19.2.7`](https://renovatebot.com/diffs/npm/react-dom/19.2.6/19.2.7) |
![age](https://developer.mend.io/api/mc/badges/age/npm/react-dom/19.2.7?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/react-dom/19.2.6/19.2.7?slim=true)
|

---

### Release Notes

<details>
<summary>facebook/react (react)</summary>

###
[`v19.2.7`](https://redirect.github.com/facebook/react/releases/tag/v19.2.7):
19.2.7 (June 1st, 2026)

[Compare
Source](https://redirect.github.com/facebook/react/compare/v19.2.6...v19.2.7)

##### React Server Components

- Fixed missing `FormData` entries in Server Actions which regressed in
19.2.6
([#&#8203;36566](https://redirect.github.com/facebook/react/pull/36566)
by [@&#8203;unstubbable](https://redirect.github.com/unstubbable))

</details>

## Why?

Automated dependency update via Renovate.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.

---

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend
Renovate](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMDcuNCIsInVwZGF0ZWRJblZlciI6IjQzLjIwNy40IiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
## What?

Regenerates `gomod2nix.toml` to reflect the current `go.mod` / `go.sum`.

## Why?

Keeps the Nix build in sync with Go module changes. Without this, `nix
build` fails when new or upgraded Go deps are missing from
`gomod2nix.toml`. Generated automatically by the gomod2nix sync
workflow.
## What?

Adds a mention about v1 release in the README (master branch

## Why?

So that people know, that, even, if there are no commits on master, we
still are developing

Signed-off-by: drew <me@andrinoff.com>
Signed-off-by: drew <me@andrinoff.com>
## What?

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [go](https://redirect.github.com/actions/go-versions) | uses-with |
patch | `1.26.3` → `1.26.4` |

---

### Release Notes

<details>
<summary>actions/go-versions (go)</summary>

###
[`v1.26.4`](https://redirect.github.com/actions/go-versions/releases/tag/1.26.4-26891772857):
1.26.4

[Compare
Source](https://redirect.github.com/actions/go-versions/compare/1.26.3-25533533231...1.26.4-26891772857)

Go 1.26.4

</details>

## Why?

Automated dependency update via Renovate.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend
Renovate](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMDkuNCIsInVwZGF0ZWRJblZlciI6IjQzLjIwOS40IiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
## What?

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [actions/checkout](https://redirect.github.com/actions/checkout)
([changelog](https://redirect.github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd..df4cb1c069e1874edd31b4311f1884172cec0e10))
| action | digest | `de0fac2` → `df4cb1c` |

## Why?

Automated dependency update via Renovate.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend
Renovate](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMDkuNCIsInVwZGF0ZWRJblZlciI6IjQzLjIwOS40IiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->

Co-authored-by: Drew Smirnoff <drew@floatpane.com>
Co-authored-by: Drew Smirnoff <drew@floatpane.com>
## What?

Gate the `LIST ... RETURN (STATUS (UNSEEN))` request in `FetchFolders`
on the server advertising the LIST-STATUS capability (RFC 5819). When
the server doesn't support it, send a plain `LIST "" "*"` and populate
unread counts with a per-mailbox `STATUS (UNSEEN)` fallback instead.

## Why?

Fixes floatpane#1426

Signed-off-by: drew <me@andrinoff.com>
## What?

Checks if the composer has contents at the moment of interrupt signal
(`ctrl+c`). If so, it saves the draft before quitting

## Why?

It is easy to accidentally quit, and it was unforgiving, without saving
anything. Especially including that the default quit keybind is the same
as "copy" on linux and windows (`ctrl+c`)

Signed-off-by: drew <me@andrinoff.com>
…1437)

## What?

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/floatpane/bubble-overlay](https://redirect.github.com/floatpane/bubble-overlay)
| `v0.0.1` → `v0.1.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2ffloatpane%2fbubble-overlay/v0.1.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2ffloatpane%2fbubble-overlay/v0.0.1/v0.1.0?slim=true)
|

---

### Release Notes

<details>
<summary>floatpane/bubble-overlay
(github.com/floatpane/bubble-overlay)</summary>

###
[`v0.1.0`](https://redirect.github.com/floatpane/bubble-overlay/releases/tag/v0.1.0)

[Compare
Source](https://redirect.github.com/floatpane/bubble-overlay/compare/v0.0.1...v0.1.0)

<!-- Release notes generated using configuration in .github/release.yml
at v0.1.0 -->

#### What's Changed

##### Dependencies

- chore(deps): github.com/charmbracelet/x/ansi ^ v0.11.7 by
[@&#8203;floatpanebot](https://redirect.github.com/floatpanebot) in
[#&#8203;5](https://redirect.github.com/floatpane/bubble-overlay/pull/5)
- chore(deps): go ^ 1.26.4 by
[@&#8203;floatpanebot](https://redirect.github.com/floatpanebot) in
[#&#8203;11](https://redirect.github.com/floatpane/bubble-overlay/pull/11)

#### New Contributors

- [@&#8203;floatpanebot](https://redirect.github.com/floatpanebot) made
their first contribution in
[#&#8203;5](https://redirect.github.com/floatpane/bubble-overlay/pull/5)

**Full Changelog**:
<floatpane/bubble-overlay@v0.0.1...v0.1.0>

***

**Install:**

```bash
go get github.com/floatpane/bubble-overlay@v0.1.0
```

See the [Go
reference](https://pkg.go.dev/github.com/floatpane/bubble-overlay) for
full API documentation.

</details>

## Why?

Automated dependency update via Renovate.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend
Renovate](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMTEuMCIsInVwZGF0ZWRJblZlciI6IjQzLjIxMS4wIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
## What?

Regenerates `gomod2nix.toml` to reflect the current `go.mod` / `go.sum`.

## Why?

Keeps the Nix build in sync with Go module changes. Without this, `nix
build` fails when new or upgraded Go deps are missing from
`gomod2nix.toml`. Generated automatically by the gomod2nix sync
workflow.
## What?

Updates `flake.lock` to the latest revisions of all flake inputs
(`nixpkgs`, `flake-utils`, etc.).

## Why?

Keeps Nix inputs current so contributors and CI build against fresh
`nixpkgs`. Picks up upstream security and toolchain fixes. Generated
automatically by the flake-lock update workflow on changes to `go.sum`.
## What?

Uses `overlay.Center` for the move modal. 

## Why?

The previous version messed with the inbox contents on both sides. Like
in floatpane#1435

Signed-off-by: drew <me@andrinoff.com>
## What?

Makes the protocol selection a "combobox"

## Why?

Closes floatpane#1230

---------

Signed-off-by: drew <me@andrinoff.com>
## What?

Moves the log message for i18n to loglevel `verbose`

## Why?

Each time you used to load matcha in secure mode, these messages would
appear and possibly block the UI

Signed-off-by: drew <me@andrinoff.com>
## What?
The code to support JMAP authentication via API tokens was in place, it
just wasn't wired up correctly. This fixes that.


- JMAP protocol selection ended up getting routed to IMAP code
- no way to specify `token` for `account.AuthMethod`
- `hasBackendProvider` didn't account for/support `jmap`
- modified placeholder when `account.AuthMethod` is `token` to say `API
Token` instead of `Password / App Password`
- modified tip for `inputAuthMethod` when protocol is `jmap`

## Why?
Because I use Fastmail, want to use JMAP, and want to be able to read my
email.

JMAP authentication with Fastmail via API Tokens wasn't working for
multiple reasons. Fastmail is the largest (only?) JMAP supporting email
host and they require API Tokens.

I have manually confirmed that this authenticates just fine with my
Fastmail account via JMAP and the API token.
## What?
in `jmap.go`

- added a `resolveUID` function
- added a `resolveUIDByQuery` function

## Why?
Email body fetch always failed with "jmap: no cached ID"
(backend/jmap/jmap.go)
FetchEmailBody relied on p.idToJMAPID being pre-populated by FetchEmails
on the same Provider instance. However, the fetcher layer creates a
fresh Provider for every call, so the map is always empty when
FetchEmailBody runs.

The fix adds a resolveUID method that checks the in-memory cache first
(fast path when the daemon reuses the same instance), then falls back to
resolveUIDByQuery. The fallback issues an Email/query for the folder,
reads the JMAP string IDs directly from QueryResponse.IDs, hashes each
one with FNV-32a, and returns the match — also warming the cache as a
side effect.
## What?

Messages are held for `N` seconds before delivery, with a recall window.

## Why?

Saves users from sending mistakes, just like Gmail/Outlook.


Closes floatpane#1139
## What?

Makes Background daemon optional in the settings

## Why?

Temporary fix for floatpane#1448, also a good option to have for users to turn
off, if they do not want the daemon on.

---------

Signed-off-by: drew <me@andrinoff.com>
## What?

Refreshes the feature screenshots in `docs/docs/assets/features/`.

### Screenshots included:
- `compose_email.png`
- `compose_empty.png`
- `drafts.png`
- `email_view.png`
- `inbox_view.png`
- `main_menu.png`
- `settings.png`
- `theme_settings.png`
- `threading_demo.png`

## Why?

Keeps documentation visuals aligned with the current TUI. Generated
automatically by the Generate Screenshots workflow on the latest
release.

Co-authored-by: floatpanebot <278062430+floatpanebot@users.noreply.github.com>
## What?

Replaces `public/assets/demo.gif` with a freshly recorded VHS run.

## Why?

Keeps the demo GIF aligned with the latest release so README and docs
reflect current behaviour. Generated automatically by the Update Demo
VHS workflow.

Co-authored-by: floatpanebot <278062430+floatpanebot@users.noreply.github.com>
## What?

Fixes crashes when sending. 

## Why?

Fixes floatpane#1453

Signed-off-by: drew <me@andrinoff.com>
## What?

Improves queue, by making undo non-blocking

## Why?

You had to wait for 5 seconds in order to use Matcha again

Signed-off-by: drew <me@andrinoff.com>
andrinoff and others added 13 commits July 5, 2026 12:33
## What?

Improves threaded view, making the first email (latest) accessible

## Why?

Previously, you could not access the last email

---------

Signed-off-by: drew <me@andrinoff.com>
## What?

All Sent mailbox lookups now resolve via `getMailboxByAttr(c,
imap.MailboxAttrSent)` with fallback to the hardcoded `getSentMailbox`,
matching the existing Trash/Archive pattern.

## Why?

Fixes floatpane#1641

Signed-off-by: drew <me@andrinoff.com>
## What?

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [go](https://redirect.github.com/actions/go-versions) | uses-with |
patch | `1.26.4` → `1.26.5` |

---

### Release Notes

<details>
<summary>actions/go-versions (go)</summary>

###
[`v1.26.5`](https://redirect.github.com/actions/go-versions/releases/tag/1.26.5-28913679792):
1.26.5

[Compare
Source](https://redirect.github.com/actions/go-versions/compare/1.26.4-26891772857...1.26.5-28913679792)

Go 1.26.5

</details>

## Why?

Automated dependency update via Renovate.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend
Renovate](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTUuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI1NS4yIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
## What?

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [go](https://go.dev/)
([source](https://redirect.github.com/golang/go)) | golang | patch |
`1.26.4` → `1.26.5` |

## Why?

Automated dependency update via Renovate.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend
Renovate](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTUuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI1NS4yIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->

Co-authored-by: Drew Smirnoff <drew@floatpane.com>
## What?

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [golang.org/x/text](https://pkg.go.dev/golang.org/x/text) | [`v0.38.0`
→
`v0.40.0`](https://cs.opensource.google/go/x/text/+/refs/tags/v0.38.0...refs/tags/v0.40.0)
|
![age](https://developer.mend.io/api/mc/badges/age/go/golang.org%2fx%2ftext/v0.40.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/golang.org%2fx%2ftext/v0.38.0/v0.40.0?slim=true)
|

## Why?

Automated dependency update via Renovate.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend
Renovate](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTIuNSIsInVwZGF0ZWRJblZlciI6IjQzLjI1Ni4wIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
…1663)

## What?

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[github.com/floatpane/bubble-overlay](https://redirect.github.com/floatpane/bubble-overlay)
| `v0.2.0` → `v0.3.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2ffloatpane%2fbubble-overlay/v0.3.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2ffloatpane%2fbubble-overlay/v0.2.0/v0.3.0?slim=true)
|

---

### Release Notes

<details>
<summary>floatpane/bubble-overlay
(github.com/floatpane/bubble-overlay)</summary>

###
[`v0.3.0`](https://redirect.github.com/floatpane/bubble-overlay/releases/tag/v0.3.0)

[Compare
Source](https://redirect.github.com/floatpane/bubble-overlay/compare/v0.2.0...v0.3.0)

<!-- Release notes generated using configuration in .github/release.yml
at v0.3.0 -->

**Full Changelog**:
<floatpane/bubble-overlay@v0.2.0...v0.3.0>

***

**Install:**

```bash
go get github.com/floatpane/bubble-overlay@v0.3.0
```

See the [Go
reference](https://pkg.go.dev/github.com/floatpane/bubble-overlay) for
full API documentation.

</details>

## Why?

Automated dependency update via Renovate.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend
Renovate](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTUuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI1NS4yIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
## What?

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [golang.org/x/term](https://pkg.go.dev/golang.org/x/term) | [`v0.44.0`
→
`v0.45.0`](https://cs.opensource.google/go/x/term/+/refs/tags/v0.44.0...refs/tags/v0.45.0)
|
![age](https://developer.mend.io/api/mc/badges/age/go/golang.org%2fx%2fterm/v0.45.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/golang.org%2fx%2fterm/v0.44.0/v0.45.0?slim=true)
|

## Why?

Automated dependency update via Renovate.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend
Renovate](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTYuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI1Ny41IiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
## What?

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[cachix/install-nix-action](https://redirect.github.com/cachix/install-nix-action)
([changelog](https://redirect.github.com/cachix/install-nix-action/compare/8aa03977d8d733052d78f4e008a241fd1dbf36b3..a49548c11d9846ad46ecc0115273879b045f001c))
| action | digest | `8aa0397` → `a49548c` |

## Why?

Automated dependency update via Renovate.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend
Renovate](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTYuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI1Ni4yIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
## What?

Adds a Reply-All function (`shift+r`)

## Why?

Closes floatpane#1667

---------

Signed-off-by: drew <me@andrinoff.com>
## What?

Updates `flake.lock` to the latest revisions of all flake inputs
(`nixpkgs`, `flake-utils`, etc.).

## Why?

Keeps Nix inputs current so contributors and CI build against fresh
`nixpkgs`. Picks up upstream security and toolchain fixes. Generated
automatically by the flake-lock update workflow on changes to `go.sum`.
## What?

Regenerates `gomod2nix.toml` to reflect the current `go.mod` / `go.sum`.

## Why?

Keeps the Nix build in sync with Go module changes. Without this, `nix
build` fails when new or upgraded Go deps are missing from
`gomod2nix.toml`. Generated automatically by the gomod2nix sync
workflow.
## What?

Replaces `public/assets/demo.gif` with a freshly recorded VHS run.

## Why?

Keeps the demo GIF aligned with the latest release so README and docs
reflect current behaviour. Generated automatically by the Update Demo
VHS workflow.

Co-authored-by: floatpanebot <278062430+floatpanebot@users.noreply.github.com>
## What?

Refreshes the feature screenshots in `docs/docs/assets/features/`.

### Screenshots included:
- `compose_email.png`
- `compose_empty.png`
- `drafts.png`
- `email_view.png`
- `inbox_view.png`
- `main_menu.png`
- `settings.png`
- `theme_settings.png`
- `threading_demo.png`

## Why?

Keeps documentation visuals aligned with the current TUI. Generated
automatically by the Generate Screenshots workflow on the latest
release.

Co-authored-by: floatpanebot <278062430+floatpanebot@users.noreply.github.com>
@kawacukennedy
kawacukennedy requested a review from a team as a code owner July 20, 2026 01:03
@floatpanebot floatpanebot added area/tui Terminal UI / view layer size/M Diff: 51–200 lines and removed area/tui Terminal UI / view layer labels Jul 20, 2026
…lient

A malicious HTML email could embed images pointing at internal services
(e.g. http://169.254.169.254/latest/meta-data/ on cloud providers, or
http://127.0.0.1:* to reach local applications). Every recipient who
views such an email triggers a request to the attacker-controlled URL,
enabling server-side request forgery.

Add isPrivateHost() DNS resolution check that rejects connections to
loopback (127.0.0.0/8), RFC 1918 (10/172.16-31/192.168), link-local
(169.254.0.0/16), and IPv6 loopback/link-local addresses.

Also limit redirect chains to 5 hops using httpclient.NewWithRedirectCap
to prevent SSRF via open-redirect chains, and reuse a single HTTP client
across calls instead of creating a new one per image fetch.

@floatpanebot floatpanebot left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @kawacukennedy! Please fix the following issues with your PR:

  • Title: Is too long (55 characters). The PR title must be strictly under 40 characters.
  • Body: Missing the ## What? or ## Why? headings required by the PR template.

@floatpanebot floatpanebot added the area/tui Terminal UI / view layer label Jul 20, 2026
@floatpanebot

floatpanebot commented Jul 20, 2026 •

Copy link
Copy Markdown
Member

Benchmark report — no significant change

Metrics worse: 0 · better: 0 (threshold: ±3%).

benchstat output
goos: linux
goarch: amd64
pkg: github.com/floatpane/matcha/backend
cpu: AMD EPYC 9V74 80-Core Processor                
                           │    old.txt    │              new.txt               │
                           │    sec/op     │    sec/op     vs base              │
ParseSearchQuery_Simple-4    2.607µ ± 311%   2.308µ ± 39%       ~ (p=0.394 n=6)
ParseSearchQuery_Complex-4   8.145µ ±  40%   8.445µ ± 87%       ~ (p=0.818 n=6)
TokenizeSearchQuery-4        4.345µ ±  40%   5.263µ ± 35%       ~ (p=0.180 n=6)
geomean                      4.519µ          4.681µ        +3.60%

                           │  old.txt   │              new.txt               │
                           │    B/op    │    B/op     vs base                │
ParseSearchQuery_Simple-4    26.00 ± 0%   26.00 ± 0%       ~ (p=1.000 n=6) ¹
ParseSearchQuery_Complex-4   762.0 ± 0%   762.0 ± 0%       ~ (p=1.000 n=6) ¹
TokenizeSearchQuery-4        176.0 ± 0%   176.0 ± 0%       ~ (p=1.000 n=6) ¹
geomean                      151.6        151.6       +0.00%
¹ all samples are equal

                           │  old.txt   │              new.txt               │
                           │ allocs/op  │ allocs/op   vs base                │
ParseSearchQuery_Simple-4    2.000 ± 0%   2.000 ± 0%       ~ (p=1.000 n=6) ¹
ParseSearchQuery_Complex-4   23.00 ± 0%   23.00 ± 0%       ~ (p=1.000 n=6) ¹
TokenizeSearchQuery-4        9.000 ± 0%   9.000 ± 0%       ~ (p=1.000 n=6) ¹
geomean                      7.453        7.453       +0.00%
¹ all samples are equal

pkg: github.com/floatpane/matcha/tui
                    │   old.txt    │               new.txt                │
                    │    sec/op    │    sec/op      vs base               │
LogPanelView-4        158.6µ ± 10%    168.3µ ± 17%        ~ (p=0.180 n=6)
SearchOverlayView-4   163.9µ ±  8%    181.0µ ± 21%  +10.48% (p=0.009 n=6)
InboxConstruction-4   970.4µ ± 16%   1011.2µ ±  6%        ~ (p=0.093 n=6)
geomean               293.3µ          313.5µ         +6.91%

                    │    old.txt    │               new.txt               │
                    │     B/op      │     B/op       vs base              │
LogPanelView-4        33.23Ki ± 34%   33.23Ki ± 34%       ~ (p=1.000 n=6)
SearchOverlayView-4   33.17Ki ± 69%   33.19Ki ± 69%       ~ (p=0.784 n=6)
InboxConstruction-4   874.3Ki ±  0%   874.3Ki ±  0%       ~ (p=0.818 n=6)
geomean               98.78Ki         98.79Ki        +0.02%

                    │   old.txt   │              new.txt              │
                    │  allocs/op  │  allocs/op   vs base              │
LogPanelView-4         713.0 ± 0%    713.0 ± 0%       ~ (p=1.000 n=6)
SearchOverlayView-4    923.5 ± 0%    924.0 ± 0%       ~ (p=0.913 n=6)
InboxConstruction-4   3.478k ± 0%   3.478k ± 0%       ~ (p=0.634 n=6)
geomean               1.318k        1.318k       +0.02%

auto-generated by benchmarks.yml

@kawacukennedy kawacukennedy changed the title fix(view): add SSRF protection to remote image fetching fix(view): block SSRF in remote images Jul 20, 2026
@floatpanebot
floatpanebot dismissed their stale review July 20, 2026 01:33

Formatting issues have been resolved. Thank you!

@floatpanebot floatpanebot added the stale No activity for extended period label Sep 4, 2026
@floatpanebot

Copy link
Copy Markdown
Member

This has had no activity for 45 days. It will be closed in 21 days unless updated. Comment or remove the stale label to keep it open.

@kawacukennedy

Copy link
Copy Markdown
Contributor Author

Hi @andrinoff — this PR is still open and all CI checks are green; just keeping it off the stale queue. Happy to rebase/adjust if anything needs updating. Thanks!

@floatpanebot floatpanebot removed the stale No activity for extended period label Sep 5, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/tui Terminal UI / view layer size/M Diff: 51–200 lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants