4d02c78102
Follow-up to the #99641 salvage: - One module-level _normalize_security() (ssl/tls/implicit -> tls, starttls, plain/none -> plain; unknown -> WARNING + secure default) replaces the three copies of the alias set; _connect_imap/_connect_smtp/_standalone_send all compare against the canonical value. Unknown modes no longer raise. - _tls_context(verify, host) is module-level and shared by all sites; when verification is disabled for a non-loopback host it logs a WARNING. - _esecret_bool: an unset/empty env var now yields the caller's default (previously is_truthy_value('') returned False, silently disabling TLS verification whenever EMAIL_*_TLS_VERIFY was unset). - Documented surface is platforms.email.extra.{imap,smtp}_security and {imap,smtp}_tls_verify in config.yaml; env vars remain an internal bridge and are NOT added to plugin.yaml (optional_env feeds hermes setup prompts). - Docs: Proton Mail Bridge / local relays recipe in user-guide/messaging/email.md. - Tests: starttls builds IMAP4 then .starttls(); unknown mode falls back to tls/starttls with verification still on.