aboutsummaryrefslogtreecommitdiffstats
path: root/docs/specs/2026-09-09-report.md
diff options
context:
space:
mode:
authorDanilo M. <danix@danix.xyz>2026-09-09 19:00:26 +0200
committerDanilo M. <danix@danix.xyz>2026-09-09 19:00:26 +0200
commitb35d6e504719da97f8d2ef19b300d5d8ee45beb0 (patch)
tree1350f13796d3bafd210a749ab207359699a00b00 /docs/specs/2026-09-09-report.md
parent7cdeb7f2d8a92fce0355de70290cb7bbab6fb363 (diff)
downloadabusectl-b35d6e504719da97f8d2ef19b300d5d8ee45beb0.tar.gz
abusectl-b35d6e504719da97f8d2ef19b300d5d8ee45beb0.zip
feat: store a whitelist of publishable headers in the manifest
report must never open source.eml, so parse decides once what may be published and report formats only what it is given. To, Cc, Delivered-To and X-Original-To are absent by construction rather than stripped. Received is cut to the boundary hop alone, in both directions. Above it are our own relays; below it is the attacker's own writing, and a forged chain names an innocent third party there, so publishing a hop below the boundary puts someone else's address into a report a desk will act on. That is the third property applied to disclosure rather than to sending_ip(). Truncating the chain was not sufficient on its own: the surviving line is written by our own relay and records the envelope recipient in its optional "for <addr>" clause, so the whitelist alone would have published the victim's address verbatim in the one header a report reproduces in full. The clause is removed and the rest of the hop kept. The manifest-wide "no example.org" assertion is narrowed to the headers block only, where the whitelist deliberately publishes our receiving relay's name in a by/authserv-id clause. The address itself is still barred there, asserted separately. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Xj1ayFRSUQ2u7cwb3S4axE
Diffstat (limited to 'docs/specs/2026-09-09-report.md')
0 files changed, 0 insertions, 0 deletions