fix: reject line breaks in frontmatter header values; note reference-impl limits

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
randogoth 2026-10-06 22:10:57 +03:00
parent 864daa0bad
commit 43e4be2b8a
3 changed files with 27 additions and 1 deletions

View file

@ -880,6 +880,11 @@ def cmd_send(args: argparse.Namespace, store: Store) -> int:
if not sep or not FM_KEY.match(key.strip()):
raise SmolError(f"{raw!r} is not a valid `Key: value` header")
fields.append((key.strip(), value.strip()))
# A frontmatter value is a single line (§5.5); a line break in a user-supplied
# value would smuggle extra fields into the sealed, signed payload.
for key, value in fields:
if "\n" in value or "\r" in value:
raise SmolError(f"{key} value must not contain a line break")
# §5.7: a signed reply address lets a first-time recipient answer us.
if (account_addr := store.account()) is not None and not args.anonymous:
fields.append(("Reply-To", account_addr.uri(me.pk)))