Fix 13 findings from adversarial milestone-1 review
Blockers in the ingest path (all funnel real mail in milestone 2): - H1: coerce body bytes to valid UTF-8 (ToValidUTF8) — non-UTF-8/mid-rune cuts no longer abort the ingest tx and drop the message. - H2: EnsurePart's recoverable parse error is non-fatal — proceed with the guaranteed-usable Part so messy real-world mail is stored, not rejected. - H3: extractBodies descends into message/rfc822 (Part.Message via SetMessageReaderAt) — forwarded/bounce bodies no longer lost. - H4: GetMessage/GetThread/GetThreadMessages scoped to inbox_id — no cross-inbox access; reply no longer a confused deputy. Hardening: - M1: /healthz no longer leaks DB error to unauthenticated callers. - M2: all DB errors funnel through handleErr; malformed UUID -> 404, dup -> 409, internal errors no longer echo the driver string. - M3: index messages(inbox_id, message_id_hdr) for thread resolution. - M4: pods UNIQUE(name) + ON CONFLICT (name) — no duplicate default pods. - L1: skip empty-User/Host addresses (no literal "@"). - L2: skip attachment-disposition parts when picking the body. - L3: case-insensitive, trimmed 'Re:' detection. Verified e2e vs Postgres 16: latin1 body stored valid UTF-8; rfc822-only body extracted; cross-inbox 404; malformed UUID 404; dup 409; threading regression OK. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -57,8 +57,9 @@ func (s *Server) handleHealth(w http.ResponseWriter, r *http.Request) {
|
||||
status := map[string]any{"status": "ok", "backend": backendName(s.backend)}
|
||||
if s.core != nil {
|
||||
if err := s.core.Ping(r.Context()); err != nil {
|
||||
// /healthz is unauthenticated — don't leak DSN/host/internal details.
|
||||
status["status"] = "degraded"
|
||||
status["db"] = err.Error()
|
||||
status["db"] = "error"
|
||||
writeJSON(w, http.StatusServiceUnavailable, status)
|
||||
return
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user