This release adds 5 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+4 more
Summary
AI summaryUpdates 1.7.3, 2026-06-04, and robots across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Medium |
Discovers OIDC metadata server‑side to avoid CORS failures during authentication. Discovers OIDC metadata server‑side to avoid CORS failures during authentication. Source: granite4.1:30b@2026-06-04-audit Confidence: low |
— |
| Feature | Low |
Adds inline attachment preview with reliable MIME detection for PDFs on desktop and mobile. Adds inline attachment preview with reliable MIME detection for PDFs on desktop and mobile. Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Feature | Low |
Adds inline preview of composer attachments (click to open). Adds inline preview of composer attachments (click to open). Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Feature | Low |
Adds preview of `.eml` (`message/rfc822`) attachments as emails. Adds preview of `.eml` (`message/rfc822`) attachments as emails. Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Feature | Low |
Adds read receipts (MDN, RFC 8098) support. Adds read receipts (MDN, RFC 8098) support. Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Feature | Low |
Adds editable, layout‑preserving quote island when replying to emails. Adds editable, layout‑preserving quote island when replying to emails. Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Feature | Low |
Surfaces the most severe SPF result and hides the "via" badge on spoofed mail. Surfaces the most severe SPF result and hides the "via" badge on spoofed mail. Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Feature | Low |
Adds per‑viewer colors for shared calendars (issue #345). Adds per‑viewer colors for shared calendars (issue #345). Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Feature | Low |
Extends filter rules with attachment field and multi‑value conditions. Extends filter rules with attachment field and multi‑value conditions. Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Feature | Low |
Introduces built‑in themes Aurora Glass and Elastic. Introduces built‑in themes Aurora Glass and Elastic. Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Feature | Low |
Renders theme cards as mini mailbox mockups with light/dark variant chips. Renders theme cards as mini mailbox mockups with light/dark variant chips. Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Feature | Low |
Enables localizable sandboxed plugins via manifest locales and api.i18n.t. Enables localizable sandboxed plugins via manifest locales and api.i18n.t. Source: granite4.1:30b@2026-06-04-audit Confidence: low |
— |
| Feature | Low |
Exposes /api/translate proxy and email body to plugins. Exposes /api/translate proxy and email body to plugins. Source: granite4.1:30b@2026-06-04-audit Confidence: low |
— |
| Feature | Low |
Adds toggle for search‑engine indexing (robots) in admin settings. Adds toggle for search‑engine indexing (robots) in admin settings. Source: granite4.1:30b@2026-06-04-audit Confidence: low |
— |
| Feature | Low |
Supports file‑based secrets passwordHashFile, sessionSecretFile, and oauthClientSecretFile in admin.json. Supports file‑based secrets passwordHashFile, sessionSecretFile, and oauthClientSecretFile in admin.json. Source: granite4.1:30b@2026-06-04-audit Confidence: low |
— |
| Feature | Low |
Allows configurable install screenshots per domain for PWA. Allows configurable install screenshots per domain for PWA. Source: granite4.1:30b@2026-06-04-audit Confidence: low |
— |
| Feature | Low |
Adds Hungarian locale support. Adds Hungarian locale support. Source: granite4.1:30b@2026-06-04-audit Confidence: low |
— |
| Feature | Low |
Localizes PWA install prompt, reply/forward quote header (including sender address), html lang attribute, and per‑locale head description; adds missing settings.folders.role_memos key. Localizes PWA install prompt, reply/forward quote header (including sender address), html lang attribute, and per‑locale head description; adds missing settings.folders.role_memos key. Source: granite4.1:30b@2026-06-04-audit Confidence: low |
— |
| Feature | Low |
Gates preview "open in new tab" action on inline‑safe MIME types. Gates preview "open in new tab" action on inline‑safe MIME types. Source: granite4.1:30b@2026-06-04-audit Confidence: low |
— |
| Bugfix | Medium |
Migrates legacy flat‑named files to real FileNode hierarchy and makes folders visible via FileNode/get API. Migrates legacy flat‑named files to real FileNode hierarchy and makes folders visible via FileNode/get API. Source: granite4.1:30b@2026-06-04-audit Confidence: low |
— |
| Bugfix | Medium |
Treats blob‑less FileNode as folder signal and migrates legacy directory markers. Treats blob‑less FileNode as folder signal and migrates legacy directory markers. Source: granite4.1:30b@2026-06-04-audit Confidence: low |
— |
| Bugfix | Low |
Empties Trash for shared and group folders. Empties Trash for shared and group folders. Source: granite4.1:30b@2026-06-04-audit Confidence: low |
— |
| Bugfix | Low |
Allows moving mail from a shared group inbox to a personal inbox. Allows moving mail from a shared group inbox to a personal inbox. Source: granite4.1:30b@2026-06-04-audit Confidence: low |
— |
| Bugfix | Low |
Preserves HTML signature when sending a quick reply. Preserves HTML signature when sending a quick reply. Source: granite4.1:30b@2026-06-04-audit Confidence: low |
— |
| Bugfix | Low |
Prevents body clipping under the fold for emails setting html/body height: 100%. Prevents body clipping under the fold for emails setting html/body height: 100%. Source: granite4.1:30b@2026-06-04-audit Confidence: low |
— |
| Bugfix | Low |
Drops single‑letter R:/I: subject prefix tokens and deduplicates localized reply/forward prefixes. Drops single‑letter R:/I: subject prefix tokens and deduplicates localized reply/forward prefixes. Source: granite4.1:30b@2026-06-04-audit Confidence: low |
— |
| Bugfix | Low |
Eliminates 404 console spam for missing sender favicons. Eliminates 404 console spam for missing sender favicons. Source: granite4.1:30b@2026-06-04-audit Confidence: low |
— |
| Bugfix | Low |
Routes the Sent copy to the shared‑mailbox account on per‑identity send. Routes the Sent copy to the shared‑mailbox account on per‑identity send. Source: granite4.1:30b@2026-06-04-audit Confidence: low |
— |
| Bugfix | Low |
Honours basePath in plugin sandbox, http.post proxy, and branding routing. Honours basePath in plugin sandbox, http.post proxy, and branding routing. Source: granite4.1:30b@2026-06-04-audit Confidence: low |
— |
| Bugfix | Low |
Makes plugin slot iframes inherit host font and color tokens. Makes plugin slot iframes inherit host font and color tokens. Source: granite4.1:30b@2026-06-04-audit Confidence: low |
— |
Full changelog
1.7.3 (2026-06-04)
Features
- Mail: Inline attachment preview — reliable MIME detection with inline PDF on desktop and mobile
- Mail: Preview composer attachments inline (click to open)
- Mail: Preview
.eml(message/rfc822) attachments like an email - Mail: Read receipts (MDN, RFC 8098)
- Mail: Editable, layout-preserving quote island when replying
- Mail: Surface the most severe SPF result and hide the "via" badge on spoofed mail
- Calendar: Per-viewer colors for shared calendars (#345)
- Filters: Extended filter rules — attachment field and multi-value conditions
- Settings: New built-in themes — Aurora Glass and Elastic
- Settings: Theme cards render as a mini mailbox mockup from theme colors, with light/dark variant chips
- Plugins: Localizable sandboxed plugins (manifest locales +
api.i18n.t) - Plugins:
/api/translateproxy and email body exposed to plugins - Admin: Toggle for search-engine indexing (robots)
- Admin:
passwordHashFileinadmin.json - Admin:
sessionSecretFileandoauthClientSecretFilefor file-based secrets in JSON config - PWA: Configurable install screenshots (per-domain)
- i18n: Hungarian locale support
Fixes
- Files: Store Files as real
FileNodehierarchy, migrate legacy flat-named files on load, and list folders viaFileNode/getso they are visible (#379) - Files: Treat a blob-less
FileNodeas the only folder signal and migrate legacy dir-markers - Mail: Empty Trash for shared and group folders (#387)
- Mail: Move mail from a shared group inbox to a personal inbox (#375)
- Mail: Preserve the HTML signature when sending a quick reply
- Mail: Stop body clipping under the fold when the email sets
html/bodyheight: 100% - Mail: Drop single-letter
R:/I:subject prefix tokens and deduplicate localized reply/forward prefixes - Mail: No more 404 console spam for missing sender favicons
- Auth: Discover OIDC metadata server-side to avoid CORS failures (#382)
- Send: Route the Sent copy to the shared-mailbox account on per-identity send
- Routing: Honour
basePathin the plugin sandbox,http.postproxy, and branding - i18n: Localize the PWA install prompt, reply/forward quote header (incl. sender address),
<html lang>, and per-locale<head>description; add missingsettings.folders.role_memoskey - Themes: Plugin slot iframes inherit host font and color tokens
- Theme: Gate preview "open in new tab" on inline-safe MIME types
- Appearance: Move Themes settings into the Appearance category with a distinct tab icon; clicking the active theme is a no-op
- UI: Fix invisible dark-mode borders (border token collided with secondary)
- UI: Remove the 16px empty strip beside the collapsed sidebar
- UI: Align top bars to a uniform
h-14height and the account selector header to the search/reply toolbars - UI: Close pane gaps by centering the resize handle on the seam
- Settings: Fix section gears permanently hijacking the active tab
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About webmail
Webmail built for the 21st Century. A modern, self-hosted email client for Stalwart Mail Server powered by the JMAP protocol. Email, calendar, contacts and files. Fast, private, and open source.
Related context
Earlier breaking changes
- v1.7.0 Server‑managed plugin bundles must be Ed25519‑signed and admin‑approved before loading.
- v1.7.0 Bundle hash is now full SHA-256; legacy hashes auto-migrated.
- v1.7.0 Server-managed bundles require Ed25519 signature verification.
- v1.7.0 Plugins run in sandboxed iframe with postMessage RPC bridge.
Beta — feedback welcome: [email protected]