summaryrefslogtreecommitdiffstats
path: root/src/cidschemehandler.h
blob: 1ca87f648c8290e83e63dcee44692bbfb4714f2e (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
/*
 * qtmaildir - a Qt6 mail client for notmuch-indexed Maildirs
 * Copyright (C) 2026 Danilo M. <danix@danix.xyz>
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License version 2 as
 * published by the Free Software Foundation.
 *
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License
 * along with this program; if not, write to the Free Software
 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
 */

#pragma once

#include <QHash>
#include <QWebEngineUrlSchemeHandler>

#include "mimeparser.h"

/// Serves cid: URLs from the currently displayed thread only.
///
/// Keys are the namespaced form "<prefix>!<content-id>" produced by
/// HtmlBuilder, so two messages in one thread that share a Content-ID do not
/// collide. The map is replaced wholesale on every thread change, so a thread
/// can never reference another thread's parts.
class CidSchemeHandler : public QWebEngineUrlSchemeHandler
{
    Q_OBJECT
public:
    explicit CidSchemeHandler(QObject *parent = nullptr);

    void setParts(const QHash<QString, InlinePart> &parts) { m_parts = parts; }

    /// Builds the namespaced key HtmlBuilder's rewritten URLs will request.
    ///
    /// The '!' separator disambiguates a hostile Content-ID from the prefix
    /// only because prefix is guaranteed '!'-free: the FIRST '!' in the
    /// result is always the separator, so an attacker-controlled contentId
    /// containing '!' (even several) cannot make one message's key collide
    /// with another's, it only extends the id half after that first '!'.
    /// This is asserted here rather than merely documented, since two call
    /// sites (this one and HtmlBuilder::namespaceCids) perform the same
    /// concatenation independently and neither should trust the other to
    /// have checked it. Q_ASSERT is compiled out in release builds; the
    /// property that matters there (distinct pairs never collide, and the
    /// key always splits at its first '!' back to the original prefix) is
    /// pinned by a test instead, since it holds unconditionally regardless
    /// of whether this assertion fires.
    static QString namespacedKey(const QString &prefix, const QString &contentId)
    {
        Q_ASSERT_X(!prefix.contains(QLatin1Char('!')), "CidSchemeHandler::namespacedKey",
                   "cidPrefix must never contain '!': it is the separator, and a "
                   "prefix containing one would make the split ambiguous");
        return prefix + QLatin1Char('!') + contentId;
    }

    void requestStarted(QWebEngineUrlRequestJob *job) override;

private:
    QHash<QString, InlinePart> m_parts;
};