fix: seal the sent copy to the sender, not the recipient (sec 5.6)
This commit is contained in:
parent
7f3e30655f
commit
2d65d66012
1 changed files with 6 additions and 1 deletions
|
|
@ -523,6 +523,11 @@ pub fn send(
|
|||
|
||||
let envelope = seal(me, &recipient, &body, now(), !draft.no_pad)?;
|
||||
let mid = message_id(&envelope);
|
||||
// sec 5.6: the sent copy is sealed to ourselves, not to the recipient —
|
||||
// the recipient's envelope uses an ephemeral key that is gone, so the
|
||||
// only envelope its sender can ever open again is one sealed to their
|
||||
// own long-term key. The stored id stays the delivered message's.
|
||||
let self_copy = seal(me, &me.pk(), &body, now(), !draft.no_pad)?;
|
||||
|
||||
// sec 5.8: our token for their mailbox, if they have given us one.
|
||||
let mac = match store.token_of(&addr.short())? {
|
||||
|
|
@ -545,7 +550,7 @@ pub fn send(
|
|||
};
|
||||
|
||||
// sec 5.6: the ephemeral is gone, so keep a copy sealed to ourselves.
|
||||
store.store_sent(&mid, &addr.short(), &envelope, now())?;
|
||||
store.store_sent(&mid, &addr.short(), &self_copy, now())?;
|
||||
Ok(Sent {
|
||||
id: mid,
|
||||
bytes: envelope.len(),
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue