You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit a9343b4
Browse filesBrowse the repository at this point in the historyBrowse files
fix(mime): normalize an address so header and envelope agree
A local part is emitted bare, so anything that is not a valid dot-atom now
goes out as a quoted-string. The previous check only looked at the first and
last character, so a value that merely started and ended with a quote, such as
'"a"@evil.com"@good.com', passed through untouched. Sender and receiver then
split the domain off at a different '@' and the message goes somewhere other
than the header shows.
Along the same lines:
* an address that carries a special is emitted inside angle brackets. A domain
has no quoting construct, so without them a ',' or a ';' in a domain reads as
a recipient separator and the header lists a recipient the envelope never had.
* addressparser keeps the quotes on a local part it read out of a quoted
string, so consumers of the standalone package stop receiving the ambiguous
bare form.
* a custom envelope is normalized on the sendmail, ses, json and stream
transports as well, which read it raw before. The smtp transports already
went through getEnvelope.
* an explicit envelope keeps a bare local username such as 'root'. An envelope
value is an addr-spec, not the display name a header would read it as.
* the sendmail argv guard looks past an opening quote, so a quoted local part
can no longer hide a leading dash from it.
* _parseAddresses no longer rewrites the address object the caller passed in.
Observable change: info.accepted, info.rejected and info.envelope now carry the
quoted form for addresses that were previously emitted malformed.
Co-Authored-By: Claude Opus 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_019EN8xhmtzZvxjFfBUuygVi
0 commit comments