KamoCRM

Confidential thread markers and EMAIL_THREAD labels — PUT …/thread-confidential on member and shared mailboxes, one audited writer, threadKey and threadConfidential on both message GETs, POST **************** the org graph (KamoCollab CP05 Task 20)

FeatureEmailService
Shipped
October 11, 2026 at 8:45 AM UTC
Author
Kamo
Commit
410359c

EmailThreadKeys is the one thread-naming rule **************** now calls it): root Message-ID, UUIDv5 thread id, and the EMAIL_THREAD key without angle brackets. email_thread_labels is JDBC-only (EmailThreadLabelStore): a set is a conditional upsert, a clear a conditional delete, keyed by (org_id, thread_key); a lost race is 409 MARKER_CHANGED. ThreadMarkerWriter writes the marker and its system_access_logs row in one @Transactional @RetryOnDbConflict transaction. ThreadMarkers decides with ConfidentialMarkerRule on the session org's graph: holders of the mailbox read from (own, assignees, shared-mailbox accessors) or members the From/To/Cc reach are participants; an all-mailboxes reader is not. EmailThreadLabelResolver labels a thread from the index (holders in the org, search-index addresses, company addresses excluded from externals, leads by root and thread id, the marker) and forMessage labels a loaded original for the mail-forward check. OrgGraphBeanConfig and OrgGraphEventListener follow CP02.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing