Fix inbound-email data loss, MIME truncation, and header injection
- server/data.js: preserve source/htmlBody/inboundTo/messageId across server restarts (sanitizeLoadedContactSubmissions was silently dropping them on reload from disk) - cloudflare/email-worker.js: rewrite MIME parsing to split on the actual boundary marker instead of any literal "--", unfold multi-line headers, and correctly recombine multi-byte UTF-8 in quoted-printable decoding - server/routes/inbound-email.js: validate Message-ID against RFC 5322 grammar before storing/using it, and compare the webhook secret with timingSafeEqual to match the rest of the codebase's auth checks - server/routes/contact.js: re-validate messageId at the point it's injected into outgoing In-Reply-To/References headers; move the allowed reply-from addresses into a shared config constant - src/AdminPage.tsx: 30s inbox poll now syncs field updates (e.g. archived) on already-loaded submissions instead of only appending new ones; consolidate the duplicated from-address list - .claude/launch.json: add a vite dev server preview config used to verify these changes Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -1,8 +1,11 @@
|
||||
import { randomUUID } from 'node:crypto'
|
||||
import { randomUUID, timingSafeEqual } from 'node:crypto'
|
||||
import { state } from '../state.js'
|
||||
import { queueContactSubmissionsWrite } from '../data.js'
|
||||
import { MAX_CONTACT_SUBMISSIONS } from '../config.js'
|
||||
|
||||
// RFC 5322 msg-id: "<" printable-ASCII-no-whitespace ">"
|
||||
const MESSAGE_ID_RE = /^<[\x21-\x7E]+>$/
|
||||
|
||||
export function register(app) {
|
||||
app.post('/api/inbound-email', (req, res) => {
|
||||
const secret = process.env.INBOUND_EMAIL_SECRET
|
||||
@@ -11,7 +14,9 @@ export function register(app) {
|
||||
}
|
||||
|
||||
const provided = req.get('x-webhook-secret') ?? ''
|
||||
if (!provided || provided !== secret) {
|
||||
const a = Buffer.from(provided, 'utf8')
|
||||
const b = Buffer.from(secret, 'utf8')
|
||||
if (!provided || a.length !== b.length || !timingSafeEqual(a, b)) {
|
||||
res.status(401).json({ message: 'Unauthorized.' }); return
|
||||
}
|
||||
|
||||
@@ -26,9 +31,11 @@ export function register(app) {
|
||||
const fromEmail = fromMatch ? fromMatch[2].trim() : from.trim()
|
||||
const fromName = fromMatch ? fromMatch[1].trim() : from.trim()
|
||||
|
||||
const normalizedMessageId = typeof messageId === 'string' && MESSAGE_ID_RE.test(messageId.trim()) ? messageId.trim() : ''
|
||||
|
||||
// Deduplicate by messageId if provided
|
||||
if (messageId && typeof messageId === 'string' && messageId.trim()) {
|
||||
const exists = state.contactSubmissions.some(s => s.messageId === messageId.trim())
|
||||
if (normalizedMessageId) {
|
||||
const exists = state.contactSubmissions.some(s => s.messageId === normalizedMessageId)
|
||||
if (exists) {
|
||||
res.json({ ok: true, duplicate: true }); return
|
||||
}
|
||||
@@ -46,7 +53,7 @@ export function register(app) {
|
||||
archived: false,
|
||||
source: 'inbound-email',
|
||||
inboundTo: typeof to === 'string' ? to : '',
|
||||
messageId: typeof messageId === 'string' ? messageId.trim() : '',
|
||||
messageId: normalizedMessageId,
|
||||
emailStatus: {
|
||||
welcome: { status: 'not-applicable', lastEventAt: null, lastEventType: null, resendEmailId: null, error: null },
|
||||
adminNotification: { status: 'not-applicable', lastEventAt: null, lastEventType: null, resendEmailId: null, error: null },
|
||||
|
||||
Reference in New Issue
Block a user