chore(security): validate Content-ID before MIME/Graph use #207

Merged
JMR-dev merged 2 commits from fix-204-contentid-validation into main 2026-07-03 13:57:54 +00:00
2 Commits
Author SHA1 Message Date
Jason Ross 364fe32aaa Merge main into fix-204-contentid-validation 2026-07-03 07:23:23 -05:00
JMR-devandClaude Opus 4.8 69cce168ef chore(security): validate Content-ID before MIME/Graph use
SmtpSender.inlinePart built the MIME header as `<${attachment.contentId}>`
and GraphSender put contentId straight into the Graph JSON — neither
stripped CR/LF or other ISO control characters. Not exploitable today
(contentId is always an app-generated `img-<uuid>@libremail`), but if an
external value ever reached contentId the SMTP path would be a MIME
header-injection vector.

New shared sanitizeContentId() strips ISO control chars (incl. CR/LF),
applied at both sinks: the SMTP Content-ID header and the Graph JSON
field. No behavior change for the app-generated ids in use today.

Tests: SmtpSenderTest sends an inline image whose contentId contains
`\r\nX-Injected: evil` and asserts (via GreenMail) no injected header
appears on any MIME part and the Content-ID stays a single line;
GraphSenderTest asserts the control chars are stripped from the payload.

Closes #204

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-03 07:11:00 -05:00