From 997134302332e7641101ce68d274eb3c03e7a124 Mon Sep 17 00:00:00 2001 From: "Danilo M." Date: Mon, 24 Aug 2026 19:46:14 +0200 Subject: feat(signatures): read a directory of markdown signatures One file per signature under a directory the caller names, the stem being the name shown to the user. A name containing a path separator is refused: it arrives from the config file, and it reaches a path that is read into a message about to be sent. Part of item 152. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01KEcn3u19xPqv6ggD15PG4c --- src/signatures.cpp | 67 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 67 insertions(+) create mode 100644 src/signatures.cpp (limited to 'src/signatures.cpp') diff --git a/src/signatures.cpp b/src/signatures.cpp new file mode 100644 index 0000000..67bf491 --- /dev/null +++ b/src/signatures.cpp @@ -0,0 +1,67 @@ +/* + * qtmaildir - a Qt6 mail client for notmuch-indexed Maildirs + * Copyright (C) 2026 Danilo M. + * + * This program is free software; you can redistribute it and/or modify + * it under the terms of the GNU General Public License version 2 as + * published by the Free Software Foundation. + * + * This program is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with this program; if not, write to the Free Software + * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. + */ + +#include "signatures.h" + +#include +#include +#include + +namespace Signatures { + +QStringList names(const QString &dir) +{ + QDir directory(dir); + if (!directory.exists()) + return {}; + + QStringList result; + const QStringList files = + directory.entryList({ QStringLiteral("*.md") }, QDir::Files, QDir::Name); + result.reserve(files.size()); + for (const QString &file : files) + result.append(QFileInfo(file).completeBaseName()); + return result; +} + +QString text(const QString &dir, const QString &name) +{ + // A name arriving from the config file is untrusted input reaching a path. + // Stems from names() never contain a separator, so rejecting one costs + // nothing and stops a name like `../../.ssh/id_rsa` from being read into a + // message the user is about to send. + if (name.isEmpty() || name.contains(QLatin1Char('/')) + || name.contains(QLatin1Char('\\'))) + return {}; + + QFile file(dir + QStringLiteral("/") + name + QStringLiteral(".md")); + if (!file.open(QIODevice::ReadOnly | QIODevice::Text)) + return {}; + return QString::fromUtf8(file.readAll()); +} + +QString replace(const QString &buffer, const QString &signature, + const QStringList &known, Position position) +{ + Q_UNUSED(signature); + Q_UNUSED(known); + Q_UNUSED(position); + return buffer; +} + +} // namespace Signatures -- cgit v1.2.3