- Add __version__ = "0.1.0" to src/server.py
- Add release.yml workflow to create GitHub Releases on v* tags
- Refactor start.sh OTA to use GitHub Releases API instead of commit SHAs
Emails forwarded to Poke are no longer marked as read by default,
so users can continue using read/unread status to organize their
inbox. Set mark_as_read: true (global or per-account) to restore
the previous behavior.
Closes#5
imapclient.DRAFTS does not exist (only imapclient.DRAFT, which is a
message flag, not a folder attribute). Replaced with direct list_folders
iteration checking for the \Drafts special-use flag, matching the
approach used by detect_archive_folder.
- Add DropNonMCPRoutes middleware to return empty 404 for non-MCP paths
- Add per-IP sliding window rate limiter with separate GET/POST buckets
- Include account_id and from_address in webhook forwarding payload
- Fix IDLE watcher to always check UNSEEN instead of filtering by EXISTS
- Track seen UIDs to avoid re-forwarding on subsequent IDLE cycles
- Switch to uvicorn.run() with Starlette middleware stack
- start.sh: detect POKE_TUNNEL env var; skip MCP_API_KEY requirement and
auth when running via poke tunnel (server.py reads the same var)
- start.sh: pass POKE_TOKEN into Python via env var + use json.dumps to
safely escape quotes/backslashes in YAML (fixes shell-interpolation
injection risk, Copilot issue #5 / start.sh:72)
- start.sh: anchor MCP_API_KEY guard to non-commented line-start
assignments and also detect empty value (Copilot issues #1, #8 /
start.sh:104)
- start.sh: anchor re.sub pattern with re.MULTILINE so only the actual
assignment line is rewritten, not mid-line occurrences (Copilot
issue #2)
- start.sh: check re.sub replacement count, warn when poke_api_key key
is missing from config.yml (Copilot issue #6)
- start.sh: guard npm/npx usage with command -v check; fall back to npx
poke instead of hard-failing (Copilot issue #3)
- start.sh: use python3 consistently for server.py (Copilot issue #9 /
start.sh:134)
- start.sh: prefer npx poke tunnel; check command -v poke and fall back
gracefully (Copilot issue #10 / start.sh:135)
- server.py: honour POKE_TUNNEL=1 — skip bearer-token auth so the poke
tunnel handles identity; MCP_API_KEY becomes optional in that mode
- README.md: add Node.js/npm prerequisite note (Copilot issue #4)
- README.md: clarify server starts on first run; update AI agent prompt
(Copilot issue #11 / README.md:48)
Add a custom GET /mcp health route so health checks and client polling
return 200 instead of flooding logs with 405. Also allow resolve_account
to match by email address (from_address, imap_username, smtp_username)
in addition to account ID.
Adds a copy-pasteable prompt for non-technical users to set up poke-mail
via their AI coding agent, a start.sh script that loads .env, activates
the virtualenv, starts the server, and tunnels to Poke, and recommended
container resource limits for orchestrators.