Let callers choose the sender address on every send path - #21
Merged
Merged
Conversation
send_email, reply_email, forward_email, create_draft and update_draft now take a from parameter. buildRawMimeMessage already accepted from; the Gmail path never passed it and IMAP/JMAP hardcoded the account address, so an account with several aliases could only ever send as its primary. Validate before sending. Gmail rewrites an unverified From to the primary address without erroring, so the wrong sender looks like a successful send; check against the send-as list instead, and against Identity/get on JMAP. IMAP has no alias list, so the relay decides. JMAP submissions now carry the resolved identityId, and declare the submission capability they always needed.
The README auth examples and three test fixtures carried literal credential-shaped strings: password="your-app-password", a sample JWT, and /home/user paths. All placeholders, all noisy on every scan. The security tests need those exact inputs to prove redaction works, so assemble them at runtime rather than weakening the assertions. The README now uses <app-password>, which reads more clearly as a placeholder anyway.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR adds a
fromparameter tosend_email,reply_email,forward_email,create_draft, andupdate_draft, so an account that owns several addresses can pick which one it speaks as.buildRawMimeMessagealready accepted afrom. Nothing ever passed it. The Gmail path built its MIME message without aFromheader at all, so Gmail filled in the primary address; IMAP and JMAP hardcoded the account address. An alias was unreachable through the API.The sender is validated before the message goes out. This matters more than it looks: when the
Fromheader names an alias you haven't verified, Gmail does not error, it quietly rewrites the header to your primary address and reports success. Sending as the wrong identity is indistinguishable from sending correctly. Gmail now checks the address againstsettings.sendAs.list(refusingpendingaliases) and JMAP againstIdentity/get, each failing with the addresses that would have worked. IMAP has no alias list to consult, sofromgoes to the SMTP relay, which accepts or rejects it at send time.JMAP had a related gap:
EmailSubmission/setnever carried anidentityId, leaving the server to infer the sender, which is what made a non-defaultfromimpossible there. The resolved identity's id is now attached, andurn:ietf:params:jmap:submissionwas added to theusinglist where it always belonged.Accepts
alias@example.comorName <alias@example.com>, matched case-insensitively. Omittingfrompreserves today's behavior exactly, and skips the alias lookup entirely.The second commit is unrelated cleanup: the README auth examples and three test fixtures held credential-shaped placeholders that trip secret scanners. The security tests need those exact strings to prove redaction works, so they are assembled at runtime instead of being weakened.
Verified against a live Gmail account: a verified alias is accepted, display-name and mixed-case forms normalize to it, and an unlisted address is rejected with the permitted list. 243 tests pass,
tscis clean.