diff options
| author | Danilo M. <danix@danix.xyz> | 2026-09-09 19:00:26 +0200 |
|---|---|---|
| committer | Danilo M. <danix@danix.xyz> | 2026-09-09 19:00:26 +0200 |
| commit | b35d6e504719da97f8d2ef19b300d5d8ee45beb0 (patch) | |
| tree | 1350f13796d3bafd210a749ab207359699a00b00 /tests/test_config.py | |
| parent | 7cdeb7f2d8a92fce0355de70290cb7bbab6fb363 (diff) | |
| download | abusectl-b35d6e504719da97f8d2ef19b300d5d8ee45beb0.tar.gz abusectl-b35d6e504719da97f8d2ef19b300d5d8ee45beb0.zip | |
feat: store a whitelist of publishable headers in the manifest
report must never open source.eml, so parse decides once what may be
published and report formats only what it is given. To, Cc, Delivered-To and
X-Original-To are absent by construction rather than stripped.
Received is cut to the boundary hop alone, in both directions. Above it are
our own relays; below it is the attacker's own writing, and a forged chain
names an innocent third party there, so publishing a hop below the boundary
puts someone else's address into a report a desk will act on. That is the
third property applied to disclosure rather than to sending_ip().
Truncating the chain was not sufficient on its own: the surviving line is
written by our own relay and records the envelope recipient in its optional
"for <addr>" clause, so the whitelist alone would have published the
victim's address verbatim in the one header a report reproduces in full.
The clause is removed and the rest of the hop kept.
The manifest-wide "no example.org" assertion is narrowed to the headers
block only, where the whitelist deliberately publishes our receiving relay's
name in a by/authserv-id clause. The address itself is still barred there,
asserted separately.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Xj1ayFRSUQ2u7cwb3S4axE
Diffstat (limited to 'tests/test_config.py')
0 files changed, 0 insertions, 0 deletions
