Skip to content

fix: harden Gmail message parsing - #97

Open
nvtoan0201-swe wants to merge 1 commit into
CopilotKit:mainfrom
nvtoan0201-swe:fix/gmail-message-parsing
Open

nvtoan0201-swe wants to merge 1 commit into
CopilotKit:mainfrom
nvtoan0201-swe:fix/gmail-message-parsing

Conversation

@nvtoan0201-swe

Copy link
Copy Markdown

What changed

Five Gmail message-parsing gaps in packages/integrations/src/google.ts:

  1. An unknown or malformed charset label (unknown-8bit, default, …) threw from TextDecoder, failing the whole mailbox/thread read. Body decoding now falls back to UTF-8.
  2. RFC 2231 language-tagged encoded words (=?UTF-8*en?B?…?=) never decoded because the language tag was passed to TextDecoder. The tag is now stripped.
  3. addresses() matched an e-mail-looking string inside a quoted display name ("billing@other.example" <real@example.com>) before the real address. Quoted display names that precede an angle-addr are ignored.
  4. From: <bare@example.com> produced an empty sender (and therefore a blank sender in the UI). It now falls back to the address.
  5. A message/rfc822 attachment had its nested parts treated as message text, so a forwarded message body was merged into the parent body (and could trip the 1 MiB limit). Text collection no longer recurses into attachment parts.

Large message bodies that Gmail stores behind an attachment ID (no filename) are still hydrated by the existing hydrate() path and read as message text.

Verification

  • pnpm test — 278 pass, 0 fail (2 new tests: unknown charset + RFC 2231 + display-name address + bare sender; forwarded-message body stays out of the parent)
  • pnpm lint
  • pnpm typecheck

Integration limits

Fixtures only; no live Gmail account was exercised. Existing attachment references and imports are unchanged.

AI assistance was used to prepare this change; I reviewed the code, tests and checks above.

A single message could break or distort a mailbox read: an unknown charset label threw from TextDecoder, RFC 2231 language tags blocked header decoding, a quoted display name containing an address was preferred over the real sender, a bare angle-addr From produced an empty sender, and an attached message/rfc822 had its nested text merged into the parent body. Decode bodies with a UTF-8 fallback, strip language tags, ignore addresses inside quoted display names, fall back to the bare address, and stop recursing into attachment parts. Large remote bodies stored behind attachment IDs are still hydrated and read as message text.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant