From 56a6ed1186cb26d5a341708d9f02fa431f2a9014 Mon Sep 17 00:00:00 2001 From: randogoth Date: Sat, 26 Sep 2026 16:45:41 +0300 Subject: [PATCH] feat: emit a signed Reply-To by default, --anonymous to omit --- README.md | 2 ++ smolmail.py | 5 +++++ 2 files changed, 7 insertions(+) diff --git a/README.md b/README.md index bb85d43..4b9a7c7 100644 --- a/README.md +++ b/README.md @@ -70,6 +70,8 @@ uv run smolmail.py list uv run smolmail.py read ``` +Sent mail carries the sender's full `smol://` address in a signed `Reply-To` field (SPEC.md §5.7), so a first-time recipient can answer without an out-of-band channel; pass `--anonymous` to omit it. + `import` adds a contact from a `smol://` address without trusting any server, `contacts` lists known keys and how each was learned, and `rotate` replaces the identity with a signed certificate your contacts accept automatically. Mail is stored sealed and opened on demand, so the local database holds no plaintext. Superseded keys are retained after a rotation, because mail already addressed to them is readable with nothing else. diff --git a/smolmail.py b/smolmail.py index 83de2eb..a7dce6f 100755 --- a/smolmail.py +++ b/smolmail.py @@ -680,6 +680,9 @@ def cmd_send(args: argparse.Namespace, store: Store) -> int: if not sep or not FM_KEY.match(key.strip()): raise SmolError(f"{raw!r} is not a valid `Key: value` header") fields.append((key.strip(), value.strip())) + # §5.7: a signed reply address lets a first-time recipient answer us. + if (account := store.account()) is not None and not args.anonymous: + fields.append(("Reply-To", account.uri(me.pk))) body = build_frontmatter(fields, text).encode() envelope = seal(me, recipient, body, pad=not args.no_pad) @@ -828,6 +831,8 @@ COMMANDS = [ (("--body",), {"help": "message text; read from stdin when omitted"}), (("--header",), {"action": "append", "metavar": "KEY:VALUE", "help": "extra frontmatter field; repeatable"}), + (("--anonymous",), {"action": "store_true", + "help": "omit the Reply-To field carrying this address (SPEC.md §5.7)"}), (("--no-pad",), {"action": "store_true", "help": "do not pad to 1 KiB"})]), ("fetch", cmd_fetch, "retrieve, verify and acknowledge mail", [(("--keep",), {"action": "store_true", "help": "do not delete from the server"})]),