Keep each contribution focused on one problem. Read PRODUCT.md for scope, DESIGN.md for interface behavior and AGENTS.md for engineering and mail privacy safeguards. These guidelines apply to people and AI contributors.
Use Node 24 or newer and npm. Install the locked dependencies from the repository root:
| 1 | npm ci |
npm run dev launches Electron with React and CSS hot reload. Restart it after
desktop or server changes. Development and packaged desktop builds share app
data by default. Use an isolated temporary profile for checks; follow
the verification recipes before launching against saved accounts.
The earlier browser development target is optional. The installed desktop app needs no separate browser, mail-service process or Node installation.
docs/adr/ without replacing accepted history.For application changes:
| 1 | npm test |
| 2 | npm run build |
Tests use Node's test runner through tsx and cover server/*.test.ts,
desktop/*.test.ts, src/*.test.tsx and scripts/*.test.mjs. The build checks
strict TypeScript, builds the renderer into dist/ and bundles Electron code into
.desktop/.
| Changed area | Additional proof |
|---|---|
| MCP | node scripts/check-mcp.mjs for the isolated handshake and access check |
| Electron, preload, storage or packaging | Isolated npm run check:desktop from docs/KB.md |
| Native Windows or macOS behavior | Startup on the affected OS and architecture |
| Documentation only | Relative links, command and source review, git diff --check |
Keep live account sign-in, mailbox changes, sending, interactive UI and downloaded-app acceptance separate from automated test results. State which checks were run and which remain unverified. Preserve the current restriction on live browser tests in PRODUCT.md.
npm run package creates the Windows NSIS installer. On a Mac,
npm run package:mac creates unsigned DMG and ZIP files, and
npm run package:mac:dir creates the app bundle only. Output goes to release/.
See README.md for architecture selection and installation limits,
and ADR 0001 for the signing decision.
Packaging does not publish a release. Release tags, the release script and workflow dispatch can publish artifacts; use them only within explicit release authorization. Do not include generated output or local app data in a source PR.