Connect through the destination guard, keep server errors out of Test, and fix CI, pins and rules beyond en/fr/pt #1
Labels
No labels
bug
documentation
enhancement
security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo-imap#1
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Found in the 2026-09-15 audit of the plugin repositories.
1. The IMAP connection dials any host and port (SSRF, port scanning)
src/postulo_imap/mailbox.py:194-207callsIMAPClient(host, port=port, …)with the raw typed host and port. No destination check runs anywhere in the plugin.sync.py:133-137: Test returnsf"{type(error).__name__}: {error}"to the person.127.0.0.1:6379, a Compose service name or a cloud metadata address, and read reachability and banners through Test.POSTULO_CONNECTIONS_ALLOW_PRIVATEis ignored.Fix: resolve and approve the host under the instance's policy and connect to the approved address, keeping SNI and certificate checks on the typed name. The core already does this for SMTP (
core/destinations.py:approve,private_allowed) and should expose it on the plugin surface; that is tracked in the core's outbound-requests issue (postulo/postulo#215). Until then, refuse anything that is not a public address unless private destinations are allowed. Make Test errors generic ("could not connect", "sign-in refused").2. CI cannot pass
.forgejo/workflows/ci.yml:39,41runsuv run python scripts/compile_messages.py, and the repository has noscripts/directory.Fix: use the
postulo-messagescompile command the tests already name. Add a tag-triggered job that runsuv run pytest -m release.3. The version pin is a label
pyproject.tomlsays0.3.0, butsrc/postulo_imap/__init__.pyhas__version__ = "0.1.0", which is what Postulo displays.uv.lockpins amaincommit that is not on the0.3.0branch.importorskipsilently against that branch.Fix: derive
__version__fromimportlib.metadata, pin the core tov0.3.0(or the release branch), and make the skip a hard failure under-m release.4. Imports past
postulo.plugins.apisync.py:20-22andmatching.py:24-25importApplication,Suggestion,suggestandContactfrom core internals. Move to the surface once the core exposes them (core plugin-surface issue (postulo/postulo#229)), and add the surface AST check to this repo's CI.5. Detection rules only for en, fr and pt
src/postulo_imap/rules/has rule lists for English, French and Portuguese only, so rejection and interview detection fails silently for German, Spanish, Italian, Dutch, Polish and the rest of the EU scope.Fix: add
de,es,it,nlandplfirst, and a test that fails when a language with a translated catalogue has no rules file (or document the fallback).