Fix inbound-email data loss, MIME truncation, and header injection
- server/data.js: preserve source/htmlBody/inboundTo/messageId across server restarts (sanitizeLoadedContactSubmissions was silently dropping them on reload from disk) - cloudflare/email-worker.js: rewrite MIME parsing to split on the actual boundary marker instead of any literal "--", unfold multi-line headers, and correctly recombine multi-byte UTF-8 in quoted-printable decoding - server/routes/inbound-email.js: validate Message-ID against RFC 5322 grammar before storing/using it, and compare the webhook secret with timingSafeEqual to match the rest of the codebase's auth checks - server/routes/contact.js: re-validate messageId at the point it's injected into outgoing In-Reply-To/References headers; move the allowed reply-from addresses into a shared config constant - src/AdminPage.tsx: 30s inbox poll now syncs field updates (e.g. archived) on already-loaded submissions instead of only appending new ones; consolidate the duplicated from-address list - .claude/launch.json: add a vite dev server preview config used to verify these changes Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -8,6 +8,7 @@ import {
|
||||
USE_RESEND_AUTOMATION_WELCOME,
|
||||
DEFAULT_SEO,
|
||||
ADMIN_REPLY_FROM,
|
||||
ADMIN_REPLY_FROM_OPTIONS,
|
||||
} from '../config.js'
|
||||
import { state } from '../state.js'
|
||||
import {
|
||||
@@ -39,6 +40,9 @@ import {
|
||||
syncContactToResend,
|
||||
} from '../email.js'
|
||||
|
||||
// RFC 5322 msg-id: "<" printable-ASCII-no-whitespace ">"
|
||||
const MESSAGE_ID_RE = /^<[\x21-\x7E]+>$/
|
||||
|
||||
function upsertContactEmailStatus(submissionId, stream, patch) {
|
||||
if (!submissionId || typeof submissionId !== 'string') return
|
||||
if (!stream || typeof stream !== 'string') return
|
||||
@@ -479,11 +483,7 @@ export function register(app) {
|
||||
const html = buildAdminReplyTemplate({ recipientName, message })
|
||||
const replyToAddress = getResendReplyToAddress()
|
||||
const defaultFrom = getResendFromAddress() || ADMIN_REPLY_FROM
|
||||
const ALLOWED_FROM = [
|
||||
'Verse by Verse with Nate <hello@versebyversewithnate.us>',
|
||||
'Verse by Verse with Nate <nate@versebyversewithnate.us>',
|
||||
]
|
||||
const fromAddress = ALLOWED_FROM.includes(requestedFrom) ? requestedFrom : defaultFrom
|
||||
const fromAddress = ADMIN_REPLY_FROM_OPTIONS.includes(requestedFrom) ? requestedFrom : defaultFrom
|
||||
const text = `Hi ${recipientName},\n\n${message}\n\nGrace and peace,\nVerse by Verse with Nate\n${replyToAddress}`
|
||||
const resend = new Resend(process.env.RESEND_API_KEY)
|
||||
|
||||
@@ -502,7 +502,7 @@ export function register(app) {
|
||||
],
|
||||
headers: {
|
||||
'X-Contact-Submission-Id': submission.id,
|
||||
...(submission.messageId ? {
|
||||
...(typeof submission.messageId === 'string' && MESSAGE_ID_RE.test(submission.messageId) ? {
|
||||
'In-Reply-To': submission.messageId,
|
||||
'References': submission.messageId,
|
||||
} : {}),
|
||||
|
||||
Reference in New Issue
Block a user