Skip to content

Harden Gmail connector: header injection, body encoding, lost mail, dup sends - #156

Merged
KrisBraun merged 2 commits into
mainfrom
fix/gmail-connector-hardening
May 29, 2026
Merged

Harden Gmail connector: header injection, body encoding, lost mail, dup sends#156
KrisBraun merged 2 commits into
mainfrom
fix/gmail-connector-hardening

Conversation

@KrisBraun

Copy link
Copy Markdown
Contributor

Four correctness/security fixes in the Gmail connector (connectors/gmail/src/).

Fixes

  1. Email header injection. Subjects and recipients were interpolated into RFC 2822 headers with no CRLF sanitization (only attachment filenames were sanitized). Added sanitizeHeaderValue() (strips CR/LF/NUL) and applied it to From/To/Cc/Bcc/Subject/In-Reply-To/References in both buildNewEmailMessage and buildReplyMessage.

  2. quoted-printable declared but body inserted raw. The multipart text part declared Content-Transfer-Encoding: quoted-printable while inserting the raw 8-bit body, corrupting non-ASCII content. Now base64-encodes the UTF-8 body and declares base64 so the encoding matches the bytes.

  3. historyId cursor advanced over failed getThread → lost mail.syncGmailMailboxIncremental now returns failedThreadIds and accepts retryThreadIds. Both callers (incrementalSyncBatch, selfHealCheck) persist failures in incremental_state.pendingThreadIds and feed them back on the next sync — the cursor still advances (no full re-walk) but failed fetches are retried, bounded by MAX_THREAD_FETCH_ATTEMPTS so a permanently-deleted thread is eventually abandoned with a log line.

  4. Duplicate sends on callback retry.onNoteCreated now guards on the stable note.id; onCreateLink (no stable id) dedupes on an FNV-1a content hash within a 10-minute window. A retried dispatch whose send already succeeded returns the original result instead of sending a second email.

Tests

New workers/api/src/twist/tools/__tests__/gmail-build-message.test.ts (lives in the main repo, imports these helpers via relative path) covers header sanitization, the base64 body encoding, and the failed-fetch/retry behavior. Written test-first.

Note for reviewers

This branch is stacked on the prior unpushed commit 3143e09 "Fix BCC/CC collapse in Gmail compose", which therefore also appears in this PR's diff — the hardening changes build directly on that commit's to/cc/bcc recipient handling. The corresponding main-repo PR (test, docs, submodule pointer bump) is intentionally not opened yet.

🤖 Generated with Claude Code

KrisBraunand others added 2 commits May 29, 2026 04:39
`Gmail.onCreateLink` flattened every recipient into the To: header,
ignoring the email link type's to/cc/bcc roles. A BCC recipient would
have been exposed to everyone else in the visible To: header (privacy
leak). The role was unavailable to the connector because
`ResolvedRecipient` had no role field.
- twister: add `ResolvedRecipient.role` (null = link type's default role)
- gmail-api: `buildNewEmailMessage` now accepts `bcc` and emits a Bcc:
header (Gmail's send API delivers to BCC and strips the header from
the copy other recipients receive); recipient headers emitted only
when non-empty
- gmail: `onCreateLink` splits recipients into To/Cc/Bcc by role;
free-form `inviteEmails` default to To
The runtime side (resolving each recipient's role from the thread's
contact_meta) is committed separately in the main repo.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…up sends
- Sanitize every value interpolated into an email header (From/To/Cc/Bcc/
Subject/In-Reply-To/References) to prevent CRLF header injection.
- Base64-encode the multipart text body so the declared
Content-Transfer-Encoding matches the bytes emitted (was declaring
quoted-printable while inserting a raw 8-bit body, corrupting non-ASCII).
- syncGmailMailboxIncremental now returns failedThreadIds and accepts
retryThreadIds; callers persist failures in incremental_state and retry
them, so advancing the historyId cursor past a failed getThread no longer
silently loses mail (bounded by MAX_THREAD_FETCH_ATTEMPTS).
- Add send idempotency: onNoteCreated guards on the stable note.id, and
onCreateLink dedupes on a content hash within a 10-minute window, so a
retried callback dispatch no longer sends a duplicate email.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@KrisBraun
KrisBraun merged commit 1e904fa into mainMay 29, 2026
1 check passed
@KrisBraun
KrisBraun deleted the fix/gmail-connector-hardening branch May 29, 2026 08:55
@github-actionsgithub-actionsBot mentioned this pull request May 29, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@KrisBraun
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Harden Gmail connector: header injection, body encoding, lost mail, dup sends by KrisBraun · Pull Request #156 · plotday/plot · GitHub
Skip to content

Harden Gmail connector: header injection, body encoding, lost mail, dup sends - #156

Merged
KrisBraun merged 2 commits into
mainfrom
fix/gmail-connector-hardening
May 29, 2026
Merged

Harden Gmail connector: header injection, body encoding, lost mail, dup sends#156
KrisBraun merged 2 commits into
mainfrom
fix/gmail-connector-hardening

Conversation

@KrisBraun

Copy link
Copy Markdown
Contributor

Four correctness/security fixes in the Gmail connector (connectors/gmail/src/).

Fixes

  1. Email header injection. Subjects and recipients were interpolated into RFC 2822 headers with no CRLF sanitization (only attachment filenames were sanitized). Added sanitizeHeaderValue() (strips CR/LF/NUL) and applied it to From/To/Cc/Bcc/Subject/In-Reply-To/References in both buildNewEmailMessage and buildReplyMessage.

  2. quoted-printable declared but body inserted raw. The multipart text part declared Content-Transfer-Encoding: quoted-printable while inserting the raw 8-bit body, corrupting non-ASCII content. Now base64-encodes the UTF-8 body and declares base64 so the encoding matches the bytes.

  3. historyId cursor advanced over failed getThread → lost mail.syncGmailMailboxIncremental now returns failedThreadIds and accepts retryThreadIds. Both callers (incrementalSyncBatch, selfHealCheck) persist failures in incremental_state.pendingThreadIds and feed them back on the next sync — the cursor still advances (no full re-walk) but failed fetches are retried, bounded by MAX_THREAD_FETCH_ATTEMPTS so a permanently-deleted thread is eventually abandoned with a log line.

  4. Duplicate sends on callback retry.onNoteCreated now guards on the stable note.id; onCreateLink (no stable id) dedupes on an FNV-1a content hash within a 10-minute window. A retried dispatch whose send already succeeded returns the original result instead of sending a second email.

Tests

New workers/api/src/twist/tools/__tests__/gmail-build-message.test.ts (lives in the main repo, imports these helpers via relative path) covers header sanitization, the base64 body encoding, and the failed-fetch/retry behavior. Written test-first.

Note for reviewers

This branch is stacked on the prior unpushed commit 3143e09 "Fix BCC/CC collapse in Gmail compose", which therefore also appears in this PR's diff — the hardening changes build directly on that commit's to/cc/bcc recipient handling. The corresponding main-repo PR (test, docs, submodule pointer bump) is intentionally not opened yet.

🤖 Generated with Claude Code

KrisBraunand others added 2 commits May 29, 2026 04:39
`Gmail.onCreateLink` flattened every recipient into the To: header,
ignoring the email link type's to/cc/bcc roles. A BCC recipient would
have been exposed to everyone else in the visible To: header (privacy
leak). The role was unavailable to the connector because
`ResolvedRecipient` had no role field.
- twister: add `ResolvedRecipient.role` (null = link type's default role)
- gmail-api: `buildNewEmailMessage` now accepts `bcc` and emits a Bcc:
header (Gmail's send API delivers to BCC and strips the header from
the copy other recipients receive); recipient headers emitted only
when non-empty
- gmail: `onCreateLink` splits recipients into To/Cc/Bcc by role;
free-form `inviteEmails` default to To
The runtime side (resolving each recipient's role from the thread's
contact_meta) is committed separately in the main repo.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…up sends
- Sanitize every value interpolated into an email header (From/To/Cc/Bcc/
Subject/In-Reply-To/References) to prevent CRLF header injection.
- Base64-encode the multipart text body so the declared
Content-Transfer-Encoding matches the bytes emitted (was declaring
quoted-printable while inserting a raw 8-bit body, corrupting non-ASCII).
- syncGmailMailboxIncremental now returns failedThreadIds and accepts
retryThreadIds; callers persist failures in incremental_state and retry
them, so advancing the historyId cursor past a failed getThread no longer
silently loses mail (bounded by MAX_THREAD_FETCH_ATTEMPTS).
- Add send idempotency: onNoteCreated guards on the stable note.id, and
onCreateLink dedupes on a content hash within a 10-minute window, so a
retried callback dispatch no longer sends a duplicate email.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@KrisBraun
KrisBraun merged commit 1e904fa into mainMay 29, 2026
1 check passed
@KrisBraun
KrisBraun deleted the fix/gmail-connector-hardening branch May 29, 2026 08:55
@github-actionsgithub-actionsBot mentioned this pull request May 29, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@KrisBraun
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Harden Gmail connector: header injection, body encoding, lost mail, dup sends by KrisBraun · Pull Request #156 · plotday/plot · GitHub
Skip to content

Harden Gmail connector: header injection, body encoding, lost mail, dup sends - #156

Merged
KrisBraun merged 2 commits into
mainfrom
fix/gmail-connector-hardening
May 29, 2026
Merged

Harden Gmail connector: header injection, body encoding, lost mail, dup sends#156
KrisBraun merged 2 commits into
mainfrom
fix/gmail-connector-hardening

Conversation

@KrisBraun

Copy link
Copy Markdown
Contributor

Four correctness/security fixes in the Gmail connector (connectors/gmail/src/).

Fixes

  1. Email header injection. Subjects and recipients were interpolated into RFC 2822 headers with no CRLF sanitization (only attachment filenames were sanitized). Added sanitizeHeaderValue() (strips CR/LF/NUL) and applied it to From/To/Cc/Bcc/Subject/In-Reply-To/References in both buildNewEmailMessage and buildReplyMessage.

  2. quoted-printable declared but body inserted raw. The multipart text part declared Content-Transfer-Encoding: quoted-printable while inserting the raw 8-bit body, corrupting non-ASCII content. Now base64-encodes the UTF-8 body and declares base64 so the encoding matches the bytes.

  3. historyId cursor advanced over failed getThread → lost mail.syncGmailMailboxIncremental now returns failedThreadIds and accepts retryThreadIds. Both callers (incrementalSyncBatch, selfHealCheck) persist failures in incremental_state.pendingThreadIds and feed them back on the next sync — the cursor still advances (no full re-walk) but failed fetches are retried, bounded by MAX_THREAD_FETCH_ATTEMPTS so a permanently-deleted thread is eventually abandoned with a log line.

  4. Duplicate sends on callback retry.onNoteCreated now guards on the stable note.id; onCreateLink (no stable id) dedupes on an FNV-1a content hash within a 10-minute window. A retried dispatch whose send already succeeded returns the original result instead of sending a second email.

Tests

New workers/api/src/twist/tools/__tests__/gmail-build-message.test.ts (lives in the main repo, imports these helpers via relative path) covers header sanitization, the base64 body encoding, and the failed-fetch/retry behavior. Written test-first.

Note for reviewers

This branch is stacked on the prior unpushed commit 3143e09 "Fix BCC/CC collapse in Gmail compose", which therefore also appears in this PR's diff — the hardening changes build directly on that commit's to/cc/bcc recipient handling. The corresponding main-repo PR (test, docs, submodule pointer bump) is intentionally not opened yet.

🤖 Generated with Claude Code

KrisBraunand others added 2 commits May 29, 2026 04:39
`Gmail.onCreateLink` flattened every recipient into the To: header,
ignoring the email link type's to/cc/bcc roles. A BCC recipient would
have been exposed to everyone else in the visible To: header (privacy
leak). The role was unavailable to the connector because
`ResolvedRecipient` had no role field.
- twister: add `ResolvedRecipient.role` (null = link type's default role)
- gmail-api: `buildNewEmailMessage` now accepts `bcc` and emits a Bcc:
header (Gmail's send API delivers to BCC and strips the header from
the copy other recipients receive); recipient headers emitted only
when non-empty
- gmail: `onCreateLink` splits recipients into To/Cc/Bcc by role;
free-form `inviteEmails` default to To
The runtime side (resolving each recipient's role from the thread's
contact_meta) is committed separately in the main repo.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…up sends
- Sanitize every value interpolated into an email header (From/To/Cc/Bcc/
Subject/In-Reply-To/References) to prevent CRLF header injection.
- Base64-encode the multipart text body so the declared
Content-Transfer-Encoding matches the bytes emitted (was declaring
quoted-printable while inserting a raw 8-bit body, corrupting non-ASCII).
- syncGmailMailboxIncremental now returns failedThreadIds and accepts
retryThreadIds; callers persist failures in incremental_state and retry
them, so advancing the historyId cursor past a failed getThread no longer
silently loses mail (bounded by MAX_THREAD_FETCH_ATTEMPTS).
- Add send idempotency: onNoteCreated guards on the stable note.id, and
onCreateLink dedupes on a content hash within a 10-minute window, so a
retried callback dispatch no longer sends a duplicate email.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@KrisBraun
KrisBraun merged commit 1e904fa into mainMay 29, 2026
1 check passed
@KrisBraun
KrisBraun deleted the fix/gmail-connector-hardening branch May 29, 2026 08:55
@github-actionsgithub-actionsBot mentioned this pull request May 29, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@KrisBraun
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Harden Gmail connector: header injection, body encoding, lost mail, dup sends by KrisBraun · Pull Request #156 · plotday/plot · GitHub
Skip to content

Harden Gmail connector: header injection, body encoding, lost mail, dup sends - #156

Merged
KrisBraun merged 2 commits into
mainfrom
fix/gmail-connector-hardening
May 29, 2026
Merged

Harden Gmail connector: header injection, body encoding, lost mail, dup sends#156
KrisBraun merged 2 commits into
mainfrom
fix/gmail-connector-hardening

Conversation

@KrisBraun

Copy link
Copy Markdown
Contributor

Four correctness/security fixes in the Gmail connector (connectors/gmail/src/).

Fixes

  1. Email header injection. Subjects and recipients were interpolated into RFC 2822 headers with no CRLF sanitization (only attachment filenames were sanitized). Added sanitizeHeaderValue() (strips CR/LF/NUL) and applied it to From/To/Cc/Bcc/Subject/In-Reply-To/References in both buildNewEmailMessage and buildReplyMessage.

  2. quoted-printable declared but body inserted raw. The multipart text part declared Content-Transfer-Encoding: quoted-printable while inserting the raw 8-bit body, corrupting non-ASCII content. Now base64-encodes the UTF-8 body and declares base64 so the encoding matches the bytes.

  3. historyId cursor advanced over failed getThread → lost mail.syncGmailMailboxIncremental now returns failedThreadIds and accepts retryThreadIds. Both callers (incrementalSyncBatch, selfHealCheck) persist failures in incremental_state.pendingThreadIds and feed them back on the next sync — the cursor still advances (no full re-walk) but failed fetches are retried, bounded by MAX_THREAD_FETCH_ATTEMPTS so a permanently-deleted thread is eventually abandoned with a log line.

  4. Duplicate sends on callback retry.onNoteCreated now guards on the stable note.id; onCreateLink (no stable id) dedupes on an FNV-1a content hash within a 10-minute window. A retried dispatch whose send already succeeded returns the original result instead of sending a second email.

Tests

New workers/api/src/twist/tools/__tests__/gmail-build-message.test.ts (lives in the main repo, imports these helpers via relative path) covers header sanitization, the base64 body encoding, and the failed-fetch/retry behavior. Written test-first.

Note for reviewers

This branch is stacked on the prior unpushed commit 3143e09 "Fix BCC/CC collapse in Gmail compose", which therefore also appears in this PR's diff — the hardening changes build directly on that commit's to/cc/bcc recipient handling. The corresponding main-repo PR (test, docs, submodule pointer bump) is intentionally not opened yet.

🤖 Generated with Claude Code

KrisBraunand others added 2 commits May 29, 2026 04:39
`Gmail.onCreateLink` flattened every recipient into the To: header,
ignoring the email link type's to/cc/bcc roles. A BCC recipient would
have been exposed to everyone else in the visible To: header (privacy
leak). The role was unavailable to the connector because
`ResolvedRecipient` had no role field.
- twister: add `ResolvedRecipient.role` (null = link type's default role)
- gmail-api: `buildNewEmailMessage` now accepts `bcc` and emits a Bcc:
header (Gmail's send API delivers to BCC and strips the header from
the copy other recipients receive); recipient headers emitted only
when non-empty
- gmail: `onCreateLink` splits recipients into To/Cc/Bcc by role;
free-form `inviteEmails` default to To
The runtime side (resolving each recipient's role from the thread's
contact_meta) is committed separately in the main repo.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…up sends
- Sanitize every value interpolated into an email header (From/To/Cc/Bcc/
Subject/In-Reply-To/References) to prevent CRLF header injection.
- Base64-encode the multipart text body so the declared
Content-Transfer-Encoding matches the bytes emitted (was declaring
quoted-printable while inserting a raw 8-bit body, corrupting non-ASCII).
- syncGmailMailboxIncremental now returns failedThreadIds and accepts
retryThreadIds; callers persist failures in incremental_state and retry
them, so advancing the historyId cursor past a failed getThread no longer
silently loses mail (bounded by MAX_THREAD_FETCH_ATTEMPTS).
- Add send idempotency: onNoteCreated guards on the stable note.id, and
onCreateLink dedupes on a content hash within a 10-minute window, so a
retried callback dispatch no longer sends a duplicate email.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@KrisBraun
KrisBraun merged commit 1e904fa into mainMay 29, 2026
1 check passed
@KrisBraun
KrisBraun deleted the fix/gmail-connector-hardening branch May 29, 2026 08:55
@github-actionsgithub-actionsBot mentioned this pull request May 29, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@KrisBraun
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Harden Gmail connector: header injection, body encoding, lost mail, dup sends by KrisBraun · Pull Request #156 · plotday/plot · GitHub
Skip to content

Harden Gmail connector: header injection, body encoding, lost mail, dup sends - #156

Merged
KrisBraun merged 2 commits into
mainfrom
fix/gmail-connector-hardening
May 29, 2026
Merged

Harden Gmail connector: header injection, body encoding, lost mail, dup sends#156
KrisBraun merged 2 commits into
mainfrom
fix/gmail-connector-hardening

Conversation

@KrisBraun

Copy link
Copy Markdown
Contributor

Four correctness/security fixes in the Gmail connector (connectors/gmail/src/).

Fixes

  1. Email header injection. Subjects and recipients were interpolated into RFC 2822 headers with no CRLF sanitization (only attachment filenames were sanitized). Added sanitizeHeaderValue() (strips CR/LF/NUL) and applied it to From/To/Cc/Bcc/Subject/In-Reply-To/References in both buildNewEmailMessage and buildReplyMessage.

  2. quoted-printable declared but body inserted raw. The multipart text part declared Content-Transfer-Encoding: quoted-printable while inserting the raw 8-bit body, corrupting non-ASCII content. Now base64-encodes the UTF-8 body and declares base64 so the encoding matches the bytes.

  3. historyId cursor advanced over failed getThread → lost mail.syncGmailMailboxIncremental now returns failedThreadIds and accepts retryThreadIds. Both callers (incrementalSyncBatch, selfHealCheck) persist failures in incremental_state.pendingThreadIds and feed them back on the next sync — the cursor still advances (no full re-walk) but failed fetches are retried, bounded by MAX_THREAD_FETCH_ATTEMPTS so a permanently-deleted thread is eventually abandoned with a log line.

  4. Duplicate sends on callback retry.onNoteCreated now guards on the stable note.id; onCreateLink (no stable id) dedupes on an FNV-1a content hash within a 10-minute window. A retried dispatch whose send already succeeded returns the original result instead of sending a second email.

Tests

New workers/api/src/twist/tools/__tests__/gmail-build-message.test.ts (lives in the main repo, imports these helpers via relative path) covers header sanitization, the base64 body encoding, and the failed-fetch/retry behavior. Written test-first.

Note for reviewers

This branch is stacked on the prior unpushed commit 3143e09 "Fix BCC/CC collapse in Gmail compose", which therefore also appears in this PR's diff — the hardening changes build directly on that commit's to/cc/bcc recipient handling. The corresponding main-repo PR (test, docs, submodule pointer bump) is intentionally not opened yet.

🤖 Generated with Claude Code

KrisBraunand others added 2 commits May 29, 2026 04:39
`Gmail.onCreateLink` flattened every recipient into the To: header,
ignoring the email link type's to/cc/bcc roles. A BCC recipient would
have been exposed to everyone else in the visible To: header (privacy
leak). The role was unavailable to the connector because
`ResolvedRecipient` had no role field.
- twister: add `ResolvedRecipient.role` (null = link type's default role)
- gmail-api: `buildNewEmailMessage` now accepts `bcc` and emits a Bcc:
header (Gmail's send API delivers to BCC and strips the header from
the copy other recipients receive); recipient headers emitted only
when non-empty
- gmail: `onCreateLink` splits recipients into To/Cc/Bcc by role;
free-form `inviteEmails` default to To
The runtime side (resolving each recipient's role from the thread's
contact_meta) is committed separately in the main repo.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…up sends
- Sanitize every value interpolated into an email header (From/To/Cc/Bcc/
Subject/In-Reply-To/References) to prevent CRLF header injection.
- Base64-encode the multipart text body so the declared
Content-Transfer-Encoding matches the bytes emitted (was declaring
quoted-printable while inserting a raw 8-bit body, corrupting non-ASCII).
- syncGmailMailboxIncremental now returns failedThreadIds and accepts
retryThreadIds; callers persist failures in incremental_state and retry
them, so advancing the historyId cursor past a failed getThread no longer
silently loses mail (bounded by MAX_THREAD_FETCH_ATTEMPTS).
- Add send idempotency: onNoteCreated guards on the stable note.id, and
onCreateLink dedupes on a content hash within a 10-minute window, so a
retried callback dispatch no longer sends a duplicate email.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@KrisBraun
KrisBraun merged commit 1e904fa into mainMay 29, 2026
1 check passed
@KrisBraun
KrisBraun deleted the fix/gmail-connector-hardening branch May 29, 2026 08:55
@github-actionsgithub-actionsBot mentioned this pull request May 29, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@KrisBraun
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Harden Gmail connector: header injection, body encoding, lost mail, dup sends by KrisBraun · Pull Request #156 · plotday/plot · GitHub
Skip to content

Harden Gmail connector: header injection, body encoding, lost mail, dup sends - #156

Merged
KrisBraun merged 2 commits into
mainfrom
fix/gmail-connector-hardening
May 29, 2026
Merged

Harden Gmail connector: header injection, body encoding, lost mail, dup sends#156
KrisBraun merged 2 commits into
mainfrom
fix/gmail-connector-hardening

Conversation

@KrisBraun

Copy link
Copy Markdown
Contributor

Four correctness/security fixes in the Gmail connector (connectors/gmail/src/).

Fixes

  1. Email header injection. Subjects and recipients were interpolated into RFC 2822 headers with no CRLF sanitization (only attachment filenames were sanitized). Added sanitizeHeaderValue() (strips CR/LF/NUL) and applied it to From/To/Cc/Bcc/Subject/In-Reply-To/References in both buildNewEmailMessage and buildReplyMessage.

  2. quoted-printable declared but body inserted raw. The multipart text part declared Content-Transfer-Encoding: quoted-printable while inserting the raw 8-bit body, corrupting non-ASCII content. Now base64-encodes the UTF-8 body and declares base64 so the encoding matches the bytes.

  3. historyId cursor advanced over failed getThread → lost mail.syncGmailMailboxIncremental now returns failedThreadIds and accepts retryThreadIds. Both callers (incrementalSyncBatch, selfHealCheck) persist failures in incremental_state.pendingThreadIds and feed them back on the next sync — the cursor still advances (no full re-walk) but failed fetches are retried, bounded by MAX_THREAD_FETCH_ATTEMPTS so a permanently-deleted thread is eventually abandoned with a log line.

  4. Duplicate sends on callback retry.onNoteCreated now guards on the stable note.id; onCreateLink (no stable id) dedupes on an FNV-1a content hash within a 10-minute window. A retried dispatch whose send already succeeded returns the original result instead of sending a second email.

Tests

New workers/api/src/twist/tools/__tests__/gmail-build-message.test.ts (lives in the main repo, imports these helpers via relative path) covers header sanitization, the base64 body encoding, and the failed-fetch/retry behavior. Written test-first.

Note for reviewers

This branch is stacked on the prior unpushed commit 3143e09 "Fix BCC/CC collapse in Gmail compose", which therefore also appears in this PR's diff — the hardening changes build directly on that commit's to/cc/bcc recipient handling. The corresponding main-repo PR (test, docs, submodule pointer bump) is intentionally not opened yet.

🤖 Generated with Claude Code

KrisBraunand others added 2 commits May 29, 2026 04:39
`Gmail.onCreateLink` flattened every recipient into the To: header,
ignoring the email link type's to/cc/bcc roles. A BCC recipient would
have been exposed to everyone else in the visible To: header (privacy
leak). The role was unavailable to the connector because
`ResolvedRecipient` had no role field.
- twister: add `ResolvedRecipient.role` (null = link type's default role)
- gmail-api: `buildNewEmailMessage` now accepts `bcc` and emits a Bcc:
header (Gmail's send API delivers to BCC and strips the header from
the copy other recipients receive); recipient headers emitted only
when non-empty
- gmail: `onCreateLink` splits recipients into To/Cc/Bcc by role;
free-form `inviteEmails` default to To
The runtime side (resolving each recipient's role from the thread's
contact_meta) is committed separately in the main repo.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…up sends
- Sanitize every value interpolated into an email header (From/To/Cc/Bcc/
Subject/In-Reply-To/References) to prevent CRLF header injection.
- Base64-encode the multipart text body so the declared
Content-Transfer-Encoding matches the bytes emitted (was declaring
quoted-printable while inserting a raw 8-bit body, corrupting non-ASCII).
- syncGmailMailboxIncremental now returns failedThreadIds and accepts
retryThreadIds; callers persist failures in incremental_state and retry
them, so advancing the historyId cursor past a failed getThread no longer
silently loses mail (bounded by MAX_THREAD_FETCH_ATTEMPTS).
- Add send idempotency: onNoteCreated guards on the stable note.id, and
onCreateLink dedupes on a content hash within a 10-minute window, so a
retried callback dispatch no longer sends a duplicate email.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@KrisBraun
KrisBraun merged commit 1e904fa into mainMay 29, 2026
1 check passed
@KrisBraun
KrisBraun deleted the fix/gmail-connector-hardening branch May 29, 2026 08:55
@github-actionsgithub-actionsBot mentioned this pull request May 29, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@KrisBraun
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Harden Gmail connector: header injection, body encoding, lost mail, dup sends by KrisBraun · Pull Request #156 · plotday/plot · GitHub
Skip to content

Harden Gmail connector: header injection, body encoding, lost mail, dup sends - #156

Merged
KrisBraun merged 2 commits into
mainfrom
fix/gmail-connector-hardening
May 29, 2026
Merged

Harden Gmail connector: header injection, body encoding, lost mail, dup sends#156
KrisBraun merged 2 commits into
mainfrom
fix/gmail-connector-hardening

Conversation

@KrisBraun

Copy link
Copy Markdown
Contributor

Four correctness/security fixes in the Gmail connector (connectors/gmail/src/).

Fixes

  1. Email header injection. Subjects and recipients were interpolated into RFC 2822 headers with no CRLF sanitization (only attachment filenames were sanitized). Added sanitizeHeaderValue() (strips CR/LF/NUL) and applied it to From/To/Cc/Bcc/Subject/In-Reply-To/References in both buildNewEmailMessage and buildReplyMessage.

  2. quoted-printable declared but body inserted raw. The multipart text part declared Content-Transfer-Encoding: quoted-printable while inserting the raw 8-bit body, corrupting non-ASCII content. Now base64-encodes the UTF-8 body and declares base64 so the encoding matches the bytes.

  3. historyId cursor advanced over failed getThread → lost mail.syncGmailMailboxIncremental now returns failedThreadIds and accepts retryThreadIds. Both callers (incrementalSyncBatch, selfHealCheck) persist failures in incremental_state.pendingThreadIds and feed them back on the next sync — the cursor still advances (no full re-walk) but failed fetches are retried, bounded by MAX_THREAD_FETCH_ATTEMPTS so a permanently-deleted thread is eventually abandoned with a log line.

  4. Duplicate sends on callback retry.onNoteCreated now guards on the stable note.id; onCreateLink (no stable id) dedupes on an FNV-1a content hash within a 10-minute window. A retried dispatch whose send already succeeded returns the original result instead of sending a second email.

Tests

New workers/api/src/twist/tools/__tests__/gmail-build-message.test.ts (lives in the main repo, imports these helpers via relative path) covers header sanitization, the base64 body encoding, and the failed-fetch/retry behavior. Written test-first.

Note for reviewers

This branch is stacked on the prior unpushed commit 3143e09 "Fix BCC/CC collapse in Gmail compose", which therefore also appears in this PR's diff — the hardening changes build directly on that commit's to/cc/bcc recipient handling. The corresponding main-repo PR (test, docs, submodule pointer bump) is intentionally not opened yet.

🤖 Generated with Claude Code

KrisBraunand others added 2 commits May 29, 2026 04:39
`Gmail.onCreateLink` flattened every recipient into the To: header,
ignoring the email link type's to/cc/bcc roles. A BCC recipient would
have been exposed to everyone else in the visible To: header (privacy
leak). The role was unavailable to the connector because
`ResolvedRecipient` had no role field.
- twister: add `ResolvedRecipient.role` (null = link type's default role)
- gmail-api: `buildNewEmailMessage` now accepts `bcc` and emits a Bcc:
header (Gmail's send API delivers to BCC and strips the header from
the copy other recipients receive); recipient headers emitted only
when non-empty
- gmail: `onCreateLink` splits recipients into To/Cc/Bcc by role;
free-form `inviteEmails` default to To
The runtime side (resolving each recipient's role from the thread's
contact_meta) is committed separately in the main repo.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…up sends
- Sanitize every value interpolated into an email header (From/To/Cc/Bcc/
Subject/In-Reply-To/References) to prevent CRLF header injection.
- Base64-encode the multipart text body so the declared
Content-Transfer-Encoding matches the bytes emitted (was declaring
quoted-printable while inserting a raw 8-bit body, corrupting non-ASCII).
- syncGmailMailboxIncremental now returns failedThreadIds and accepts
retryThreadIds; callers persist failures in incremental_state and retry
them, so advancing the historyId cursor past a failed getThread no longer
silently loses mail (bounded by MAX_THREAD_FETCH_ATTEMPTS).
- Add send idempotency: onNoteCreated guards on the stable note.id, and
onCreateLink dedupes on a content hash within a 10-minute window, so a
retried callback dispatch no longer sends a duplicate email.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@KrisBraun
KrisBraun merged commit 1e904fa into mainMay 29, 2026
1 check passed
@KrisBraun
KrisBraun deleted the fix/gmail-connector-hardening branch May 29, 2026 08:55
@github-actionsgithub-actionsBot mentioned this pull request May 29, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@KrisBraun
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Harden Gmail connector: header injection, body encoding, lost mail, dup sends by KrisBraun · Pull Request #156 · plotday/plot · GitHub
Skip to content

Harden Gmail connector: header injection, body encoding, lost mail, dup sends - #156

Merged
KrisBraun merged 2 commits into
mainfrom
fix/gmail-connector-hardening
May 29, 2026
Merged

Harden Gmail connector: header injection, body encoding, lost mail, dup sends#156
KrisBraun merged 2 commits into
mainfrom
fix/gmail-connector-hardening

Conversation

@KrisBraun

Copy link
Copy Markdown
Contributor

Four correctness/security fixes in the Gmail connector (connectors/gmail/src/).

Fixes

  1. Email header injection. Subjects and recipients were interpolated into RFC 2822 headers with no CRLF sanitization (only attachment filenames were sanitized). Added sanitizeHeaderValue() (strips CR/LF/NUL) and applied it to From/To/Cc/Bcc/Subject/In-Reply-To/References in both buildNewEmailMessage and buildReplyMessage.

  2. quoted-printable declared but body inserted raw. The multipart text part declared Content-Transfer-Encoding: quoted-printable while inserting the raw 8-bit body, corrupting non-ASCII content. Now base64-encodes the UTF-8 body and declares base64 so the encoding matches the bytes.

  3. historyId cursor advanced over failed getThread → lost mail.syncGmailMailboxIncremental now returns failedThreadIds and accepts retryThreadIds. Both callers (incrementalSyncBatch, selfHealCheck) persist failures in incremental_state.pendingThreadIds and feed them back on the next sync — the cursor still advances (no full re-walk) but failed fetches are retried, bounded by MAX_THREAD_FETCH_ATTEMPTS so a permanently-deleted thread is eventually abandoned with a log line.

  4. Duplicate sends on callback retry.onNoteCreated now guards on the stable note.id; onCreateLink (no stable id) dedupes on an FNV-1a content hash within a 10-minute window. A retried dispatch whose send already succeeded returns the original result instead of sending a second email.

Tests

New workers/api/src/twist/tools/__tests__/gmail-build-message.test.ts (lives in the main repo, imports these helpers via relative path) covers header sanitization, the base64 body encoding, and the failed-fetch/retry behavior. Written test-first.

Note for reviewers

This branch is stacked on the prior unpushed commit 3143e09 "Fix BCC/CC collapse in Gmail compose", which therefore also appears in this PR's diff — the hardening changes build directly on that commit's to/cc/bcc recipient handling. The corresponding main-repo PR (test, docs, submodule pointer bump) is intentionally not opened yet.

🤖 Generated with Claude Code

KrisBraunand others added 2 commits May 29, 2026 04:39
`Gmail.onCreateLink` flattened every recipient into the To: header,
ignoring the email link type's to/cc/bcc roles. A BCC recipient would
have been exposed to everyone else in the visible To: header (privacy
leak). The role was unavailable to the connector because
`ResolvedRecipient` had no role field.
- twister: add `ResolvedRecipient.role` (null = link type's default role)
- gmail-api: `buildNewEmailMessage` now accepts `bcc` and emits a Bcc:
header (Gmail's send API delivers to BCC and strips the header from
the copy other recipients receive); recipient headers emitted only
when non-empty
- gmail: `onCreateLink` splits recipients into To/Cc/Bcc by role;
free-form `inviteEmails` default to To
The runtime side (resolving each recipient's role from the thread's
contact_meta) is committed separately in the main repo.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…up sends
- Sanitize every value interpolated into an email header (From/To/Cc/Bcc/
Subject/In-Reply-To/References) to prevent CRLF header injection.
- Base64-encode the multipart text body so the declared
Content-Transfer-Encoding matches the bytes emitted (was declaring
quoted-printable while inserting a raw 8-bit body, corrupting non-ASCII).
- syncGmailMailboxIncremental now returns failedThreadIds and accepts
retryThreadIds; callers persist failures in incremental_state and retry
them, so advancing the historyId cursor past a failed getThread no longer
silently loses mail (bounded by MAX_THREAD_FETCH_ATTEMPTS).
- Add send idempotency: onNoteCreated guards on the stable note.id, and
onCreateLink dedupes on a content hash within a 10-minute window, so a
retried callback dispatch no longer sends a duplicate email.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@KrisBraun
KrisBraun merged commit 1e904fa into mainMay 29, 2026
1 check passed
@KrisBraun
KrisBraun deleted the fix/gmail-connector-hardening branch May 29, 2026 08:55
@github-actionsgithub-actionsBot mentioned this pull request May 29, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@KrisBraun