diff options
| author | Danilo M. <danix@danix.xyz> | 2026-09-09 09:19:27 +0200 |
|---|---|---|
| committer | Danilo M. <danix@danix.xyz> | 2026-09-09 09:19:27 +0200 |
| commit | 46e042a33bdd529da71115649d1736e703b676c8 (patch) | |
| tree | d0252dad8718c5091507360a20cca8a3b8518a6d /tests/fixtures | |
| parent | a3ff8f3b056c708872c5aedb4750d5cd32c5833d (diff) | |
| download | abusectl-46e042a33bdd529da71115649d1736e703b676c8.tar.gz abusectl-46e042a33bdd529da71115649d1736e703b676c8.zip | |
feat: read abuse addresses from a jCard, strictly
Only an entity whose roles contain abuse counts. No fallback to a
technical or registrant contact, who is a named human that never
volunteered for abuse mail, and no fallback to abuse@<domain> by
convention: for a phishing domain that mailbox belongs to the attacker,
so constructing it would confirm both the catch and that the reporter's
address is live.
Addresses are validated where they enter rather than where they are
used, because the value becomes a mail recipient later and a control
character in it is header injection into mail this tool sends.
Entity recursion is depth capped so remote JSON cannot hang the tool.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Wrfqr2xqQfhtXCscU7zrdz
Diffstat (limited to 'tests/fixtures')
0 files changed, 0 insertions, 0 deletions
