Files
AI-Studio/app/MindWork AI Studio/Tools/Mail/MailEncryptionDetection.cs
T
Thorsten Sommer c4400c0ff6
Build and Release / Determine run mode (push) Waiting to run
Build and Release / Read metadata (push) Blocked by required conditions
Build and Release / Sync Flatpak repo (push) Blocked by required conditions
Build and Release / Collect Flatpak artifacts (push) Blocked by required conditions
Build and Release / Verify (push) Waiting to run
Build and Release / Build app (${{ matrix.dotnet_runtime }}) (-aarch64-pc-windows-msvc.exe, win-arm64, windows-latest, aarch64-pc-windows-msvc, nsis,updater, nsis) (push) Blocked by required conditions
Build and Release / Build app (${{ matrix.dotnet_runtime }}) (-aarch64-unknown-linux-gnu, linux-arm64, ubuntu-22.04-arm, aarch64-unknown-linux-gnu, appimage,updater, appimage) (push) Blocked by required conditions
Build and Release / Build app (${{ matrix.dotnet_runtime }}) (-x86_64-apple-darwin, osx-x64, macos-latest, x86_64-apple-darwin, dmg,app,updater, dmg) (push) Blocked by required conditions
Build and Release / Build app (${{ matrix.dotnet_runtime }}) (-x86_64-pc-windows-msvc.exe, win-x64, windows-latest, x86_64-pc-windows-msvc, nsis,updater, nsis) (push) Blocked by required conditions
Build and Release / Prepare & create release (push) Blocked by required conditions
Build and Release / Publish release (push) Blocked by required conditions
Build and Release / Build app (${{ matrix.dotnet_runtime }}) (-aarch64-apple-darwin, osx-arm64, macos-latest, aarch64-apple-darwin, dmg,app,updater, dmg) (push) Blocked by required conditions
Build and Release / Build app (${{ matrix.dotnet_runtime }}) (-x86_64-unknown-linux-gnu, linux-x64, ubuntu-22.04, x86_64-unknown-linux-gnu, appimage,updater, appimage) (push) Blocked by required conditions
Added mailboxes as local data sources (#1022)
2026-10-04 12:26:26 +02:00

106 lines
5.1 KiB
C#

using MailKit;
using MimeKit;
namespace AIStudio.Tools.Mail;
/// <summary>
/// Finds out whether AI Studio can read the content of a mail.
/// </summary>
/// <remarks>
/// The structure of a mail tells most of it, so the sync asks before it fetches anything: from the
/// BODYSTRUCTURE the server describes, the encrypted blob never has to be downloaded. A parsed mail
/// gives the same answer through its MIME tree. Only a PGP block within the text needs the text
/// itself, see ContainsInlinePgpMessage.
///
/// An encrypted part counts wherever it sits, apart from mails attached to this one: some gateways
/// wrap an encrypted mail together with a disclaimer of their own, and that disclaimer is not what
/// the mail says. An attached mail keeps its protection to itself, though, because the mail around
/// it is readable.
///
/// A mail which is merely signed in the clear (multipart/signed) stays readable: its first part is
/// the content as it is, and the signature next to it is no encryption.
/// </remarks>
public static class MailEncryptionDetection
{
/// <summary>
/// The line which opens an encrypted PGP block, from RFC 4880. A signed block opens with
/// "-----BEGIN PGP SIGNED MESSAGE-----" instead and stays readable.
/// </summary>
private const string PGP_MESSAGE_ARMOR = "-----BEGIN PGP MESSAGE-----";
/// <summary>
/// The name Outlook gives the attachment which holds a mail protected by Information Rights Management.
/// </summary>
private const string IRM_FILE_NAME = "message.rpmsg";
/// <summary>
/// Reads the encryption from the structure the server describes.
/// </summary>
/// <param name="bodyStructure">The BODYSTRUCTURE of the mail, or null when the server sent none.</param>
/// <returns>How the content is encrypted, NONE when it is readable as far as the structure tells.</returns>
public static MailEncryptionKind Detect(BodyPart? bodyStructure) => bodyStructure switch
{
// An attached mail keeps its protection to itself:
BodyPartMessage => MailEncryptionKind.NONE,
BodyPartMultipart multipart => DetectMultipart(multipart.ContentType, multipart.BodyParts.Select(Detect)),
BodyPartBasic part => DetectPart(part.ContentType, part.FileName),
_ => MailEncryptionKind.NONE,
};
/// <summary>
/// Reads the encryption from the MIME tree of a parsed mail.
/// </summary>
/// <param name="body">The body of the mail, or null when only its header block was loaded.</param>
/// <returns>How the content is encrypted, NONE when it is readable as far as the structure tells.</returns>
public static MailEncryptionKind Detect(MimeEntity? body) => body switch
{
// An attached mail keeps its protection to itself:
MessagePart => MailEncryptionKind.NONE,
Multipart multipart => DetectMultipart(multipart.ContentType, multipart.Select(Detect)),
MimePart part => DetectPart(part.ContentType, part.FileName),
_ => MailEncryptionKind.NONE,
};
/// <summary>
/// Whether the text of a mail holds an encrypted PGP block, which the structure cannot show:
/// such a mail is plain text like any other.
/// </summary>
/// <param name="text">The text of the mail as it was sent, HTML or plain.</param>
/// <returns>True when the text holds such a block.</returns>
public static bool ContainsInlinePgpMessage(string? text) => text?.Contains(PGP_MESSAGE_ARMOR, StringComparison.Ordinal) is true;
private static MailEncryptionKind DetectMultipart(ContentType contentType, IEnumerable<MailEncryptionKind> partKinds)
{
// RFC 1847 knows no other use of multipart/encrypted than PGP/MIME in practice:
if (contentType.IsMimeType("multipart", "encrypted"))
return MailEncryptionKind.PGP_MIME;
return partKinds.FirstOrDefault(kind => kind is not MailEncryptionKind.NONE);
}
private static MailEncryptionKind DetectPart(ContentType contentType, string? fileName)
{
if (contentType.IsMimeType("application", "pkcs7-mime") || contentType.IsMimeType("application", "x-pkcs7-mime"))
{
//
// Signed data wraps the content into the signature, so it cannot be read without
// unpacking the envelope. Everything else is encrypted, and so is a part without any
// smime-type: Outlook sends enveloped data like that, too.
//
return contentType.Parameters.TryGetValue("smime-type", out string? smimeType) && "signed-data".Equals(smimeType, StringComparison.OrdinalIgnoreCase)
? MailEncryptionKind.SMIME_OPAQUE_SIGNED
: MailEncryptionKind.SMIME;
}
// Some programs send the S/MIME envelope as plain bytes, recognizable by its name only:
if (fileName?.EndsWith(".p7m", StringComparison.OrdinalIgnoreCase) is true)
return MailEncryptionKind.SMIME;
if (contentType.IsMimeType("application", "x-microsoft-rpmsg-message") || IRM_FILE_NAME.Equals(fileName, StringComparison.OrdinalIgnoreCase))
return MailEncryptionKind.MICROSOFT_IRM;
return MailEncryptionKind.NONE;
}
}