diff options
| author | Danilo M. <danix@danix.xyz> | 2026-08-02 17:49:48 +0200 |
|---|---|---|
| committer | Danilo M. <danix@danix.xyz> | 2026-08-04 12:52:32 +0200 |
| commit | b09a44173e8671cbf25aff7db73b34f947ed49cf (patch) | |
| tree | 9b414cddaef9d9941061cb68abc4283d0f5768c0 /src/requestinterceptor.cpp | |
| parent | e8bf3a12cd24780dbe59c8798b1eb6536c9828d0 (diff) | |
| download | qtmaildir-b09a44173e8671cbf25aff7db73b34f947ed49cf.tar.gz qtmaildir-b09a44173e8671cbf25aff7db73b34f947ed49cf.zip | |
fix: enforce !-free cidPrefix invariant at both concatenation sites
The cid: namespacing scheme (cid:<prefix>!<id>) is only unambiguous
because the prefix half is guaranteed free of '!': the first '!' in the
result is always the separator, so an attacker-controlled Content-ID
containing '!' only extends the id half rather than colliding with a
different prefix. That invariant previously existed only as a comment.
Add Q_ASSERT_X at both independent call sites that perform this
concatenation (CidSchemeHandler::namespacedKey and
HtmlBuilder::namespaceCids) so a future prefix generator that violates it
traps in debug builds, per Task 5's precedent of not letting one unit's
correctness depend silently on another's future behaviour. Since
Q_ASSERT compiles out in release, pin the property that actually matters
release builds too test: distinct (prefix, id) pairs across a documented
"m<index>" prefix set and hostile Content-IDs (containing '!', percent-
encoded '!', empty, leading/trailing '!') never collide, and the key
always splits at its first '!' back to the exact original prefix.
Diffstat (limited to 'src/requestinterceptor.cpp')
0 files changed, 0 insertions, 0 deletions
