1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
|
/*
* qtmaildir - a Qt6 mail client for notmuch-indexed Maildirs
* Copyright (C) 2026 Danilo M. <danix@danix.xyz>
*
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License version 2 as
* published by the Free Software Foundation.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program; if not, write to the Free Software
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
*/
#pragma once
#include <QByteArray>
#include <QHash>
#include <QList>
#include <QString>
/// An inline part referenced by a cid: URL from the HTML body.
struct InlinePart
{
QString mimeType;
QByteArray data;
};
struct Attachment
{
QString filename; ///< As it appeared in the message. Untrusted.
QString mimeType;
QByteArray data;
/// filename reduced to a basename safe to join onto a directory.
/// Attacker-controlled input: a filename may contain path separators or
/// "..", so anything that could escape the target directory is stripped.
/// Returns a generated name when nothing usable remains.
QString safeFilename() const;
/// Writes the attachment into directory. Returns the full path written, or
/// an empty string on failure with *error set.
///
/// **Overwrites an existing file of the same name.** That is right for a
/// single save the user just confirmed a location for, and wrong for
/// saving a batch: several messages in one thread commonly attach the
/// same filename. Use saveWithoutOverwriting() there.
QString saveTo(const QString &directory, QString *error) const;
/// Writes the attachment into directory under a name that is not already
/// taken, appending " (2)", " (3)" and so on before the extension.
/// Returns the full path written, or an empty string on failure.
///
/// Saving a thread's attachments with saveTo() silently destroyed files:
/// six of sixteen were lost to same-name collisions and every write still
/// reported success.
QString saveWithoutOverwriting(const QString &directory, QString *error) const;
/// True if candidatePath (need not exist) is directory itself or strictly
/// beneath it, by path-boundary comparison after QDir::cleanPath on both
/// sides (so ".." segments are resolved rather than compared textually).
/// A bare QString::startsWith() is NOT sufficient here: it would let
/// "/tmp/safe-evil" pass against "/tmp/safe" since one string is a
/// textual prefix of the other despite being sibling directories.
///
/// This is defence-in-depth, not currently load-bearing: saveTo() always
/// sanitises the name with safeFilename() first, which reduces it to a
/// plain basename, so no path reaching this check via saveTo()'s public
/// interface can actually fail it today. It exists for a future change
/// that stops sanitising, or that accepts a caller-supplied subpath.
/// Exposed as its own function so that guarantee can be tested directly,
/// independent of safeFilename() — a test driven purely through saveTo()
/// cannot exercise this comparison at all, since safeFilename() always
/// runs first and never produces a path that could fail it.
static bool isPathInsideDirectory(const QString &directory, const QString &candidatePath);
};
/// A directory name for a thread's saved attachments, "<date> <subject>".
///
/// `rfc822Date` is a raw Date: header as ParsedMessage stores it; it is
/// reduced to "yyyy-MM-dd" when it parses and dropped when it does not.
///
/// Both inputs are untrusted: a subject is attacker-controlled and may carry
/// path separators, "..", control characters, or nothing usable at all. The
/// result is always a single plain component, never a path, and never "." or
/// "..". Falls back to the date alone, then to a generated name, so it is
/// never empty.
///
/// Length is capped: many filesystems limit one component to 255 bytes, and a
/// subject can be far longer than that.
QString attachmentFolderName(const QString &rfc822Date, const QString &subject);
struct ParsedMessage
{
bool ok = false;
QString error;
QString subject;
QString from;
QString to;
QString cc;
QString date;
QString messageId;
QString plainBody;
QString htmlBody;
QHash<QString, InlinePart> inlineParts; ///< Keyed by Content-ID, no <>.
QList<Attachment> attachments;
bool hasHtml() const { return !htmlBody.isEmpty(); }
};
/// Parses a single message file using GMime.
///
/// Hand-rolling this would mean reimplementing RFC 2047 encoded words, RFC 2231
/// parameter continuations, transfer encodings, and charset conversion, plus
/// tolerance for malformed real-world mail.
class MimeParser
{
public:
MimeParser();
ParsedMessage parse(const QString &filePath) const;
};
|