Skip to content

fix: Ignore protected headers in outer message part (#6357) #6370

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

iequidoo
Copy link
Collaborator

@iequidoo iequidoo commented Dec 28, 2024

No description provided.

@iequidoo iequidoo marked this pull request as ready for review December 28, 2024 02:00
@iequidoo iequidoo requested review from link2xt and Hocuri December 28, 2024 02:00
@iequidoo iequidoo force-pushed the iequidoo/outer-protected-hdrs branch from 3ff41b4 to 5445310 Compare December 28, 2024 20:23
@iequidoo iequidoo requested a review from link2xt December 28, 2024 20:32
@iequidoo iequidoo force-pushed the iequidoo/outer-protected-hdrs branch from 5445310 to 92a4af4 Compare December 29, 2024 17:30
@iequidoo iequidoo force-pushed the iequidoo/outer-protected-hdrs branch from 92a4af4 to 4638c12 Compare March 15, 2025 23:23
@iequidoo iequidoo force-pushed the iequidoo/outer-protected-hdrs branch from 4638c12 to 4d718ed Compare July 12, 2025 19:59
@iequidoo iequidoo marked this pull request as draft July 12, 2025 20:03
@iequidoo iequidoo force-pushed the iequidoo/outer-protected-hdrs branch from 4d718ed to bbf9f2b Compare July 12, 2025 21:18
@iequidoo iequidoo marked this pull request as ready for review July 12, 2025 21:18
@iequidoo iequidoo force-pushed the iequidoo/outer-protected-hdrs branch from bbf9f2b to ff411b6 Compare July 14, 2025 15:09
Delta Chat always adds protected headers to the inner encrypted or signed message, so if a protected
header is only present in the outer part, it should be ignored because it's probably added by the
server or somebody else. The exceptions are Subject and List-ID because there are known cases when
they are only present in the outer message part.

Also treat any Chat-* headers as protected. This fixes e.g. a case when the server injects a
"Chat-Version" IMF header tricking Delta Chat into thinking that it's a chat message.

Also handle "Auto-Submitted" and "Autocrypt-Setup-Message" as protected headers on the receiver
side, this was apparently forgotten.
@iequidoo iequidoo force-pushed the iequidoo/outer-protected-hdrs branch from ff411b6 to 9c6ec7b Compare July 15, 2025 13:10
@iequidoo iequidoo requested a review from link2xt July 15, 2025 13:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants