From 2d65d66012fa40121e4dc3d8d15db9ffc486569a Mon Sep 17 00:00:00 2001 From: randogoth Date: Tue, 29 Sep 2026 13:04:08 +0300 Subject: [PATCH] fix: seal the sent copy to the sender, not the recipient (sec 5.6) --- core/src/client.rs | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/core/src/client.rs b/core/src/client.rs index 81e8054..9d58c85 100644 --- a/core/src/client.rs +++ b/core/src/client.rs @@ -523,6 +523,11 @@ pub fn send( let envelope = seal(me, &recipient, &body, now(), !draft.no_pad)?; let mid = message_id(&envelope); + // sec 5.6: the sent copy is sealed to ourselves, not to the recipient — + // the recipient's envelope uses an ephemeral key that is gone, so the + // only envelope its sender can ever open again is one sealed to their + // own long-term key. The stored id stays the delivered message's. + let self_copy = seal(me, &me.pk(), &body, now(), !draft.no_pad)?; // sec 5.8: our token for their mailbox, if they have given us one. let mac = match store.token_of(&addr.short())? { @@ -545,7 +550,7 @@ pub fn send( }; // sec 5.6: the ephemeral is gone, so keep a copy sealed to ourselves. - store.store_sent(&mid, &addr.short(), &envelope, now())?; + store.store_sent(&mid, &addr.short(), &self_copy, now())?; Ok(Sent { id: mid, bytes: envelope.len(),