From 2966b4941fcde8041faef4759abafc5c1c6c55fd Mon Sep 17 00:00:00 2001 From: Enes Yilmaz Date: Sat, 8 Aug 2026 21:58:09 -0400 Subject: [PATCH 1/2] docs: answer #3 from the bundle, fix the counter label, add a diagram Three open issues, two of them resolved by reading gmail.end.bundle.js rather than by writing code. #3, whether to drive Mailsuite's own opt-out instead of deleting the node. Answer is no, and the bundle says why. Their Remove handler kA() branches on signatureVirality, the variant the server assigned the account: 17 or 18 -> dialog, then POST /settings/update/signature { signatureEnabled: false }. persists. permanent. 11 to 16 -> strips this one email, and calls the upgrade modal unless the account carries the disableSignature permission. So their button is only a real opt-out on two of the eight variants, and the variant is not ours to pick. Worse, the persisting path is a server call that changes an account setting. An extension quietly flipping that on somebody's Mailsuite account is a far larger action than deleting a node from a draft, and a much ruder surprise. Deleting the div locally does the same visible job on every variant, touches nothing server side, and stops when you switch it off. Documented in the README, including how to check your own variant, since anyone on 17 or 18 should click Remove once and uninstall this. #5, the popup counter. It counts scrub passes, not distinct emails, so the label was a small lie. Relabelled with the caveat rather than faking precision nobody needs. #7, screenshots. Cannot be done from a terminal, it needs a live Gmail session. Added docs/how-it-works.svg instead, which carries the tracker-versus-watermark split and the five-step receipt loop that the ASCII was straining to show. The issue stays open for the real before and after. 15 tests, unchanged and passing. Closes #3 Closes #5 Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_013rTepGiDUe15iPn6XqmKjy --- README.md | 99 ++++++++++++++++++++----------------------- docs/how-it-works.svg | 81 +++++++++++++++++++++++++++++++++++ src/popup.html | 8 +++- 3 files changed, 133 insertions(+), 55 deletions(-) create mode 100644 docs/how-it-works.svg diff --git a/README.md b/README.md index 4e7edfd..4abfd2e 100644 --- a/README.md +++ b/README.md @@ -28,60 +28,16 @@ This, and only this: ## How Mailsuite works, and why deleting this is safe Their extension is a thin client. The tracking happens on **their server**, not -in your browser. When you compose, it slips two separate things into the email: +in your browser, and the watermark plays no part in it. -```text - your email body - ┌──────────────────────────────────────┐ - │ Hi Bob, here's the doc. │ <- you wrote this - │ │ - │ │ invisible, does all the work - │ │ - │
│ <- THE WATERMARK - │ Sent with Mailtrack │ visible, does nothing - │
│ it is an advert - └──────────────────────────────────────┘ -``` - -Then the loop that actually gives you read receipts: - -```text - 1 you hit send - | - v - 2 Gmail mails the HTML, pixel included - | - v - 3 Bob opens it. his mail client loads - that 1x1 image from mailsuite.com - | - v - 4 their server logs "hash a3f9 = opened" - | - v - 5 your Mailsuite extension polls - /trace/2/status and paints the ticks -``` +![How it works](docs/how-it-works.svg) The watermark appears nowhere in that loop. It is an advert sitting in the message body. Removing it changes nothing about steps 1 through 5. -## Where this extension sits - -It does not modify, patch or replace Mailsuite. Both run side by side: - -```text - Mailsuite ──► injects [ pixel ] + [ watermark ] - │ │ - MailSuiteFree ──► deletes ────┼────────────┘ - │ - pixel untouched - tracking loop intact -``` - -Everything of theirs carries on: read receipts, notifications, the dashboard, -campaigns, link tracking. You lose the advert and nothing else. +This extension does not modify, patch or replace Mailsuite. Both run side by +side, and everything of theirs carries on: read receipts, notifications, the +dashboard, campaigns, link tracking. You lose the advert and nothing else. ## Install @@ -185,12 +141,47 @@ test/ fixtures, including real transcribed markup The split exists so the part that decides what gets deleted out of your email can be tested without a browser. -## Before you rely on any of this +## Try their own Remove button first + +Mailsuite renders a Remove control inside the signature. Whether it sticks +depends on which signature variant your account was assigned, which is decided +server side. From `kA()`, the click handler, in `gmail.end.bundle.js`: + +```text + variant 17 or 18 ──► dialog, then on confirm: + POST /settings/update/signature + { signatureEnabled: false } + persists on your account. permanent. + + variant 11 to 16 ──► strips it from this one email only, + and shows the upgrade modal unless your + account carries the disableSignature + permission +``` + +So **if you are on variant 17 or 18, click Remove once and you are done.** You +do not need this extension at all. Check +`document.querySelector('[data-signature-version]')` in the Gmail console to see +which you have. + +If you are on 11 to 16, their button is per-email and may nag, which is what +this extension is for. + +### Why this extension does not just click their button for you + +Considered and rejected, see [#3](../../issues/3): + +- It only truly persists on two of the eight variants, and the variant is not + ours to choose. +- On the others it can trigger the upgrade modal on every send. +- The persisting path is a **server call that changes an account setting**. + A local extension quietly flipping a setting on your Mailsuite account is a + much bigger action than deleting a node from a draft, and a much ruder + surprise if you did not expect it. -Mailsuite already ships its own opt-out, *"Don't add the Mailsuite signature to -my emails"*, in its signature settings. It also renders a Remove button inside -the signature itself. If either sticks for you, you do not need this extension. -Worth thirty seconds to check first. +Deleting the `
` locally does the same visible job, works on every variant, +touches nothing on their servers, and stops the moment you switch the extension +off. ## Licence diff --git a/docs/how-it-works.svg b/docs/how-it-works.svg new file mode 100644 index 0000000..d8cf874 --- /dev/null +++ b/docs/how-it-works.svg @@ -0,0 +1,81 @@ + + + + + + + + + + + + WHAT MAILSUITE PUTS IN YOUR EMAIL + + + Hi Bob, here's the doc. + your text + + + + <img src=".../trace/mail/a3f9.png"> + 1x1, invisible · does all the work + + + + <div id="mt-signature"> + visible · does nothing · an advert + + ● kept + ● deleted by this extension + + + HOW THE READ RECEIPT HAPPENS + + + 1 you hit send + + + + + 2 Gmail mails the HTML, pixel included + + + + + 3 Bob opens it, his mail client + loads that pixel from mailsuite.com + + + + + 4 their server logs "a3f9 = opened" + + + + + 5 Mailsuite polls /trace/2/status + and paints the ticks ✓✓ + + The watermark appears nowhere in this loop. + Deleting it changes nothing about steps 1 to 5. + + + + WHERE THIS EXTENSION SITS + Mailsuite injects both. Nothing of theirs is patched + or replaced. This extension deletes one <div> from + the compose box before send, and leaves the rest. + read receipts, notifications, dashboard, + campaigns, link tracking → all still theirs + diff --git a/src/popup.html b/src/popup.html index c2b5d71..01be186 100644 --- a/src/popup.html +++ b/src/popup.html @@ -79,7 +79,13 @@

Mailsuite Signature Stripper

-
0 signatures removed
+
+ 0 removals + + Counts scrub passes, not distinct emails, so one stubborn draft can + score more than once. + +
From de60ebcbd4deba9dd2c0b251791bfbd9013681fd Mon Sep 17 00:00:00 2001 From: Enes Yilmaz Date: Sat, 8 Aug 2026 22:00:21 -0400 Subject: [PATCH 2/2] harden: inline every SVG attribute instead of a style block GitHub sanitises SVG. If the style block were stripped, every rect would fall back to fill:black and the diagram would render as solid rectangles sitting on top of the text. Unreadable, and the kind of thing you only discover after it is already on the README. All fill, stroke and font attributes are now inline on the elements. No style element, no class attributes, nothing left to strip. Greys still chosen to stay legible on both light and dark backgrounds. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_013rTepGiDUe15iPn6XqmKjy --- docs/how-it-works.svg | 108 +++++++++++++++++++----------------------- 1 file changed, 48 insertions(+), 60 deletions(-) diff --git a/docs/how-it-works.svg b/docs/how-it-works.svg index d8cf874..9e3168a 100644 --- a/docs/how-it-works.svg +++ b/docs/how-it-works.svg @@ -1,81 +1,69 @@ - - - - + - - WHAT MAILSUITE PUTS IN YOUR EMAIL - - - Hi Bob, here's the doc. - your text - - - - <img src=".../trace/mail/a3f9.png"> - 1x1, invisible · does all the work - - - - <div id="mt-signature"> - visible · does nothing · an advert + + WHAT MAILSUITE PUTS IN YOUR EMAIL - ● kept - ● deleted by this extension + - - HOW THE READ RECEIPT HAPPENS + Hi Bob, here's the doc. + you wrote this - - 1 you hit send + + <img src=".../trace/mail/a3f9.png"> + 1×1, invisible · does all the work - + + <div id="mt-signature"> + visible · does nothing · an advert - - 2 Gmail mails the HTML, pixel included + + kept, tracking needs it + + deleted by this extension - + + WHERE THIS EXTENSION SITS + Mailsuite injects both. Nothing of theirs is patched or + replaced. This deletes one <div> from the compose box + before send, and leaves everything else running: + receipts, notifications, dashboard, campaigns - - 3 Bob opens it, his mail client - loads that pixel from mailsuite.com + + HOW THE READ RECEIPT HAPPENS - + + 1 you hit send + - - 4 their server logs "a3f9 = opened" + + 2 Gmail mails the HTML, pixel included + - + + 3 Bob opens it, his mail client + loads that pixel from mailsuite.com + - - 5 Mailsuite polls /trace/2/status - and paints the ticks ✓✓ + + 4 their server logs "a3f9 = opened" + - The watermark appears nowhere in this loop. - Deleting it changes nothing about steps 1 to 5. + + 5 Mailsuite polls /trace/2/status + and paints the ticks ✓✓ - - - WHERE THIS EXTENSION SITS - Mailsuite injects both. Nothing of theirs is patched - or replaced. This extension deletes one <div> from - the compose box before send, and leaves the rest. - read receipts, notifications, dashboard, - campaigns, link tracking → all still theirs + The watermark appears nowhere in this loop. + Deleting it changes nothing about steps 1 to 5.