feat: add S/MIME store for managing key records and public certificates

- Implemented Zustand store for S/MIME functionality, including state management for key records and public certificates.
- Added methods for importing PKCS#12 files and public certificates, binding identities to keys, and managing unlocked keys.
- Introduced session storage for remembering unlocked keys across sessions.
- Enhanced error handling and loading states during data operations.
This commit is contained in:
Linus Rath
2026-03-17 20:14:01 +01:00
parent 7c5785e9e8
commit de35d1d8e8
45 changed files with 24687 additions and 64 deletions
+6 -1
View File
@@ -22,6 +22,7 @@ import {
HardDrive,
Wrench,
BookUser,
KeyRound,
type LucideIcon,
} from 'lucide-react';
import { Button } from '@/components/ui/button';
@@ -40,6 +41,7 @@ import { KeywordSettings } from '@/components/settings/keyword-settings';
import { AccountSecuritySettings } from '@/components/settings/account-security-settings';
import { FilesSettingsComponent } from '@/components/settings/files-settings';
import { ContactsSettings } from '@/components/settings/contacts-settings';
import { SmimeSettings } from '@/components/settings/smime-settings';
import { useAuthStore } from '@/stores/auth-store';
import { useEmailStore } from '@/stores/email-store';
import { useIsDesktop } from '@/hooks/use-media-query';
@@ -48,7 +50,7 @@ import { ResizeHandle } from '@/components/layout/resize-handle';
import { useConfig } from '@/hooks/use-config';
import { cn } from '@/lib/utils';
type Tab = 'appearance' | 'email' | 'account' | 'security' | 'identities' | 'vacation' | 'calendar' | 'contacts' | 'filters' | 'templates' | 'folders' | 'keywords' | 'files' | 'advanced';
type Tab = 'appearance' | 'email' | 'account' | 'security' | 'identities' | 'encryption' | 'vacation' | 'calendar' | 'contacts' | 'filters' | 'templates' | 'folders' | 'keywords' | 'files' | 'advanced';
type TabGroup = 'general' | 'account' | 'organization' | 'apps' | 'system';
interface TabDef {
@@ -64,6 +66,7 @@ const tabIcons: Record<Tab, LucideIcon> = {
account: User,
security: Shield,
identities: UserPen,
encryption: KeyRound,
vacation: PalmtreeIcon,
calendar: Calendar,
contacts: BookUser,
@@ -131,6 +134,7 @@ export default function SettingsPage() {
{ id: 'account', label: t('tabs.account'), icon: tabIcons.account, group: 'account' },
...(stalwartFeaturesEnabled ? [{ id: 'security' as Tab, label: t('tabs.security'), icon: tabIcons.security, group: 'account' as TabGroup }] : []),
{ id: 'identities', label: t('tabs.identities'), icon: tabIcons.identities, group: 'account' },
{ id: 'encryption', label: t('tabs.encryption'), icon: tabIcons.encryption, group: 'account' },
...(supportsVacation ? [{ id: 'vacation' as Tab, label: t('tabs.vacation'), icon: tabIcons.vacation, group: 'account' as TabGroup }] : []),
...(supportsSieve ? [{ id: 'filters' as Tab, label: t('tabs.filters'), icon: tabIcons.filters, group: 'organization' as TabGroup }] : []),
{ id: 'templates', label: t('tabs.templates'), icon: tabIcons.templates, group: 'organization' },
@@ -168,6 +172,7 @@ export default function SettingsPage() {
{activeTab === 'account' && <AccountSettings />}
{activeTab === 'security' && <AccountSecuritySettings />}
{activeTab === 'identities' && <IdentitySettings />}
{activeTab === 'encryption' && <SmimeSettings />}
{activeTab === 'vacation' && <VacationSettings />}
{activeTab === 'calendar' && <><CalendarSettings /><div className="mt-8"><CalendarManagementSettings /></div></>}
{activeTab === 'contacts' && <ContactsSettings />}
+131 -13
View File
@@ -1,12 +1,16 @@
"use client";
import { useState, useEffect } from "react";
import { useTranslations } from "next-intl";
import { Mail, Phone, Building, MapPin, StickyNote, Pencil, Trash2, BookUser, Copy, Send, Globe, Cake, Tag, KeyRound, Link, Users, Briefcase, Heart, Languages, MessageCircle, User, Calendar, UserCircle } from "lucide-react";
import { Mail, Phone, Building, MapPin, StickyNote, Pencil, Trash2, BookUser, Copy, Send, Globe, Cake, Tag, KeyRound, Link, Users, Briefcase, Heart, Languages, MessageCircle, User, Calendar, UserCircle, ShieldCheck, ShieldAlert, Download } from "lucide-react";
import { Avatar } from "@/components/ui/avatar";
import { Button } from "@/components/ui/button";
import { cn } from "@/lib/utils";
import type { ContactCard } from "@/lib/jmap/types";
import { getContactDisplayName, getContactPrimaryEmail } from "@/stores/contact-store";
import { useSmimeStore } from "@/stores/smime-store";
import { parseCertificatePemOrDer, extractCertificateInfo } from "@/lib/smime/certificate-utils";
import type { CertificateInfo } from "@/lib/smime/types";
import { toast } from "@/stores/toast-store";
interface ContactDetailProps {
@@ -56,6 +60,50 @@ function formatDate(dateInput: string | Record<string, unknown>): string {
export function ContactDetail({ contact, onEdit, onDelete, isMobile, className }: ContactDetailProps) {
const t = useTranslations("contacts");
const smimeStore = useSmimeStore();
const [parsedCerts, setParsedCerts] = useState<Map<number, CertificateInfo>>(new Map());
const cryptoKeys = contact?.cryptoKeys ? Object.values(contact.cryptoKeys) : [];
useEffect(() => {
if (!contact) return;
let cancelled = false;
const parseCerts = async () => {
const results = new Map<number, CertificateInfo>();
for (let i = 0; i < cryptoKeys.length; i++) {
const key = cryptoKeys[i];
if (typeof key.uri !== 'string') continue;
try {
let derBytes: ArrayBuffer | string | null = null;
if (key.uri.startsWith('data:')) {
// data URI — extract base64 content
const commaIdx = key.uri.indexOf(',');
if (commaIdx === -1) continue;
const b64 = key.uri.substring(commaIdx + 1);
const binary = atob(b64);
const bytes = new Uint8Array(binary.length);
for (let j = 0; j < binary.length; j++) bytes[j] = binary.charCodeAt(j);
derBytes = bytes.buffer;
} else if (key.uri.startsWith('-----BEGIN')) {
// PEM-encoded certificate inline
derBytes = key.uri;
}
if (!derBytes) continue;
const cert = parseCertificatePemOrDer(derBytes);
const der = typeof derBytes === 'string' ? cert.toSchema(true).toBER(false) : derBytes;
const info = await extractCertificateInfo(cert, der);
if (!cancelled) results.set(i, info);
} catch { /* skip unparseable keys */ }
}
if (!cancelled) setParsedCerts(results);
};
if (cryptoKeys.length > 0) {
parseCerts();
} else {
setParsedCerts(new Map());
}
return () => { cancelled = true; };
}, [contact?.id]); // eslint-disable-line react-hooks/exhaustive-deps
if (!contact) {
return (
@@ -79,7 +127,31 @@ export function ContactDetail({ contact, onEdit, onDelete, isMobile, className }
const onlineServices = contact.onlineServices ? Object.values(contact.onlineServices) : [];
const anniversaries = contact.anniversaries ? Object.values(contact.anniversaries) : [];
const keywords = contact.keywords ? Object.keys(contact.keywords).filter(k => contact.keywords![k]) : [];
const cryptoKeys = contact.cryptoKeys ? Object.values(contact.cryptoKeys) : [];
const handleImportContactCert = async (keyIndex: number) => {
const key = cryptoKeys[keyIndex];
if (!key?.uri || typeof key.uri !== 'string') return;
try {
let derBytes: ArrayBuffer | string;
if (key.uri.startsWith('data:')) {
const commaIdx = key.uri.indexOf(',');
if (commaIdx === -1) return;
const b64 = key.uri.substring(commaIdx + 1);
const binary = atob(b64);
const bytes = new Uint8Array(binary.length);
for (let j = 0; j < binary.length; j++) bytes[j] = binary.charCodeAt(j);
derBytes = bytes.buffer;
} else if (key.uri.startsWith('-----BEGIN')) {
derBytes = key.uri;
} else {
return;
}
await smimeStore.importPublicCert(derBytes, 'contact', contact.id);
toast.success(t("detail.cert_imported"));
} catch (err) {
toast.error(err instanceof Error ? err.message : t("detail.cert_import_failed"));
}
};
const relatedTo = contact.relatedTo ? Object.entries(contact.relatedTo) : [];
const preferredLanguages = contact.preferredLanguages ? Object.values(contact.preferredLanguages) : [];
const personalInfo = contact.personalInfo ? Object.values(contact.personalInfo) : [];
@@ -331,17 +403,63 @@ export function ContactDetail({ contact, onEdit, onDelete, isMobile, className }
{cryptoKeys.length > 0 && (
<Section icon={KeyRound} title={t("detail.crypto_keys")} category="digital">
{cryptoKeys.map((key, i) => (
<div key={i} className="text-sm break-all">
{typeof key.uri === 'string' && key.uri.startsWith("http") ? (
<a href={key.uri} target="_blank" rel="noopener noreferrer" className="text-primary hover:underline">
{key.uri}
</a>
) : (
<span className="text-muted-foreground">{typeof key.uri === 'string' ? `${key.uri.substring(0, 80)}${key.uri.length > 80 ? "…" : ""}` : String(key.uri ?? '')}</span>
)}
</div>
))}
{cryptoKeys.map((key, i) => {
const certInfo = parsedCerts.get(i);
const isExpired = certInfo ? new Date(certInfo.notAfter) < new Date() : false;
const alreadyImported = certInfo?.emailAddresses?.[0]
? !!smimeStore.getPublicCertForEmail(certInfo.emailAddresses[0])
: false;
return (
<div key={i} className="p-3 rounded-lg border border-border space-y-1">
{certInfo ? (
<>
<div className="flex items-center gap-2">
{isExpired ? (
<ShieldAlert className="w-4 h-4 text-destructive flex-shrink-0" />
) : (
<ShieldCheck className="w-4 h-4 text-primary flex-shrink-0" />
)}
<span className="text-sm font-medium truncate">{certInfo.subject}</span>
</div>
<div className="text-xs text-muted-foreground space-y-0.5 pl-6">
<p>{t("detail.cert_issuer")}: {certInfo.issuer}</p>
<p>
{t("detail.cert_expires")}: {new Date(certInfo.notAfter).toLocaleDateString()}
{isExpired && <span className="text-destructive ml-1">({t("detail.cert_expired")})</span>}
</p>
<p>{t("detail.cert_fingerprint")}: {certInfo.fingerprint.substring(0, 20)}...</p>
{certInfo.algorithm && <p>{t("detail.cert_algorithm")}: {certInfo.algorithm}</p>}
</div>
{!alreadyImported && (
<Button
variant="ghost"
size="sm"
className="ml-4 mt-1"
onClick={() => handleImportContactCert(i)}
>
<Download className="w-3 h-3 mr-1" />
{t("detail.import_to_smime")}
</Button>
)}
{alreadyImported && (
<p className="text-xs text-green-600 pl-6 mt-1">{t("detail.cert_already_imported")}</p>
)}
</>
) : (
<div className="text-sm break-all">
{typeof key.uri === 'string' && key.uri.startsWith("http") ? (
<a href={key.uri} target="_blank" rel="noopener noreferrer" className="text-primary hover:underline">
{key.uri}
</a>
) : (
<span className="text-muted-foreground">{typeof key.uri === 'string' ? `${key.uri.substring(0, 80)}${key.uri.length > 80 ? "…" : ""}` : String(key.uri ?? '')}</span>
)}
</div>
)}
</div>
);
})}
</Section>
)}
+229 -13
View File
@@ -5,13 +5,19 @@ import { useFocusTrap } from "@/hooks/use-focus-trap";
import { useTranslations } from "next-intl";
import { Button } from "@/components/ui/button";
import { Input } from "@/components/ui/input";
import { X, Paperclip, Send, Save, Check, Loader2, AlertCircle, FileText, BookmarkPlus } from "lucide-react";
import { X, Paperclip, Send, Save, Check, Loader2, AlertCircle, FileText, BookmarkPlus, ShieldCheck, Lock } from "lucide-react";
import { cn, formatFileSize } from "@/lib/utils";
import { debug } from "@/lib/debug";
import { toast } from "@/stores/toast-store";
import { sanitizeEmailHtml } from "@/lib/email-sanitization";
import { useAuthStore } from "@/stores/auth-store";
import { useIdentityStore } from "@/stores/identity-store";
import { useSmimeStore } from "@/stores/smime-store";
import { useEmailStore } from "@/stores/email-store";
import { buildMimeMessage, wrapCmsAsSmimeMessage } from "@/lib/smime/mime-builder";
import type { MimeAttachment } from "@/lib/smime/mime-builder";
import { smimeSign } from "@/lib/smime/smime-sign";
import { smimeEncrypt } from "@/lib/smime/smime-encrypt";
import { useContactStore } from "@/stores/contact-store";
import { useTemplateStore } from "@/stores/template-store";
import { SubAddressHelper } from "@/components/identity/sub-address-helper";
@@ -169,6 +175,11 @@ export function EmailComposer({
const [showSaveAsTemplate, setShowSaveAsTemplate] = useState(false);
const [showCloseDialog, setShowCloseDialog] = useState(false);
const [showAllAttachments, setShowAllAttachments] = useState(false);
const [smimeSign_, setSmimeSign] = useState(false);
const [smimeEncrypt_, setSmimeEncrypt] = useState(false);
const [smimePassphrasePrompt, setSmimePassphrasePrompt] = useState<{ keyId: string; resolve: (passphrase: string) => void; reject: () => void } | null>(null);
const [smimePassphraseInput, setSmimePassphraseInput] = useState('');
const [smimePassphraseError, setSmimePassphraseError] = useState('');
const saveTemplateModalRef = useFocusTrap({
isActive: showSaveAsTemplate,
@@ -187,6 +198,33 @@ export function EmailComposer({
const primaryIdentity = identities[0] ?? null;
const getAutocomplete = useContactStore((s) => s.getAutocomplete);
const addTemplate = useTemplateStore((s) => s.addTemplate);
const sendRawEmail = useEmailStore((s) => s.sendRawEmail);
const smimeStore = useSmimeStore();
// Determine S/MIME availability for the selected identity
const currentSmimeIdentityId = selectedIdentityId || primaryIdentity?.id;
const smimeKeyRecord = currentSmimeIdentityId ? smimeStore.getKeyRecordForIdentity(currentSmimeIdentityId) : undefined;
const canSmimeSign = !!smimeKeyRecord;
const canSmimeEncrypt = (() => {
if (!smimeKeyRecord) return false;
const toAddrs = to.split(',').map(e => e.trim()).filter(Boolean);
const ccAddrs = cc.split(',').map(e => e.trim()).filter(Boolean);
const bccAddrs = bcc.split(',').map(e => e.trim()).filter(Boolean);
const allRecipients = [...toAddrs, ...ccAddrs, ...bccAddrs];
if (allRecipients.length === 0) return false;
const { missing } = smimeStore.getRecipientCerts(allRecipients);
return missing.length === 0;
})();
// Initialize S/MIME defaults from store when identity changes
useEffect(() => {
if (currentSmimeIdentityId) {
setSmimeSign(!!smimeStore.defaultSignIdentity[currentSmimeIdentityId] && canSmimeSign);
}
setSmimeEncrypt(smimeStore.defaultEncrypt && canSmimeEncrypt);
// Only run when identity changes, not on every recipient edit
// eslint-disable-next-line react-hooks/exhaustive-deps
}, [currentSmimeIdentityId]);
// Keep a ref to current state for the unmount save
const stateRef = useRef({ to, cc, bcc, subject, body, showCc, showBcc, selectedIdentityId, subAddressTag, draftId });
@@ -642,18 +680,116 @@ export function EmailComposer({
}
try {
await onSend?.({
to: toAddresses,
cc: ccAddresses,
bcc: bccAddresses,
subject,
body: finalBody,
htmlBody: finalHtmlBody,
draftId: finalDraftId || undefined,
fromEmail,
fromName: currentIdentity?.name || undefined,
identityId: currentIdentity?.id,
});
// S/MIME send pipeline: build raw MIME → sign → encrypt → sendRawEmail
if ((smimeSign_ || smimeEncrypt_) && client && currentIdentity?.id) {
// 1. Resolve S/MIME key
if (smimeSign_ && !smimeKeyRecord) {
throw new Error('No S/MIME key bound to this identity');
}
// 2. Ensure key is unlocked for signing
if (smimeSign_ && smimeKeyRecord && !smimeStore.isKeyUnlocked(smimeKeyRecord.id)) {
const passphrase = await new Promise<string>((resolve, reject) => {
setSmimePassphrasePrompt({ keyId: smimeKeyRecord.id, resolve, reject });
});
try {
await smimeStore.unlockKey(smimeKeyRecord.id, passphrase);
} finally {
setSmimePassphrasePrompt(null);
setSmimePassphraseInput('');
setSmimePassphraseError('');
}
}
// 3. Resolve attachments as ArrayBuffers
const mimeAttachments: MimeAttachment[] = [];
for (const att of attachments) {
if (att.error || att.uploading) continue;
let content: ArrayBuffer;
if (att.file.size > 0) {
content = await att.file.arrayBuffer();
} else if (att.blobId && client) {
content = await client.fetchBlobArrayBuffer(att.blobId, att.file.name, att.file.type);
} else {
continue;
}
mimeAttachments.push({
filename: att.file.name,
contentType: att.file.type || 'application/octet-stream',
content,
});
}
// 4. Build canonical MIME
const mimeBytes = buildMimeMessage({
from: { name: currentIdentity.name || undefined, email: fromEmail || currentIdentity.email },
to: toAddresses.map(e => ({ email: e })),
cc: ccAddresses.length > 0 ? ccAddresses.map(e => ({ email: e })) : undefined,
bcc: bccAddresses.length > 0 ? bccAddresses.map(e => ({ email: e })) : undefined,
subject,
textBody: finalBody,
htmlBody: finalHtmlBody,
attachments: mimeAttachments.length > 0 ? mimeAttachments : undefined,
});
let payload: Blob = new Blob([mimeBytes.buffer as ArrayBuffer], { type: 'message/rfc822' });
const smimeHeaders = {
from: { name: currentIdentity.name || undefined, email: fromEmail || currentIdentity.email },
to: toAddresses.map(e => ({ email: e })),
cc: ccAddresses.length > 0 ? ccAddresses.map(e => ({ email: e })) : undefined,
subject,
};
// 5. Sign if enabled
if (smimeSign_ && smimeKeyRecord) {
const privateKey = smimeStore.getUnlockedKey(smimeKeyRecord.id);
if (!privateKey) throw new Error('S/MIME key is not unlocked');
const cmsBlob = await smimeSign(
mimeBytes,
privateKey,
smimeKeyRecord.certificate,
smimeKeyRecord.certificateChain || [],
);
const cmsBytes = new Uint8Array(await cmsBlob.arrayBuffer());
payload = wrapCmsAsSmimeMessage(cmsBytes, { ...smimeHeaders, smimeType: 'signed-data' });
}
// 6. Encrypt if enabled
if (smimeEncrypt_ && smimeKeyRecord) {
const allRecipients = [...toAddresses, ...ccAddresses, ...bccAddresses];
const { found, missing } = smimeStore.getRecipientCerts(allRecipients);
if (missing.length > 0) {
throw new Error(`Missing certificates for: ${missing.join(', ')}`);
}
const recipientCertsDer = found.map(c => c.certificate instanceof ArrayBuffer ? c.certificate : new Uint8Array(c.certificate as ArrayBuffer).buffer);
const payloadBytes = new Uint8Array(await payload.arrayBuffer());
const cmsBlob = await smimeEncrypt(
payloadBytes,
recipientCertsDer,
smimeKeyRecord.certificate,
);
const cmsBytes = new Uint8Array(await cmsBlob.arrayBuffer());
payload = wrapCmsAsSmimeMessage(cmsBytes, { ...smimeHeaders, smimeType: 'enveloped-data' });
}
// 7. Send via raw email path
await sendRawEmail(client, payload, currentIdentity.id);
} else {
// Standard JMAP send path
await onSend?.({
to: toAddresses,
cc: ccAddresses,
bcc: bccAddresses,
subject,
body: finalBody,
htmlBody: finalHtmlBody,
draftId: finalDraftId || undefined,
fromEmail,
fromName: currentIdentity?.name || undefined,
identityId: currentIdentity?.id,
});
}
setTo("");
setCc("");
@@ -1059,6 +1195,32 @@ export function EmailComposer({
>
<BookmarkPlus className="w-4 h-4" />
</Button>
{/* S/MIME toggles */}
{canSmimeSign && (
<>
<div className="w-px h-5 bg-border mx-1" />
<Button
variant="ghost"
size="icon"
onClick={() => setSmimeSign(v => !v)}
className={cn("h-9 w-9", smimeSign_ && "bg-primary/10 text-primary")}
title={smimeSign_ ? t('smime_sign_on') : t('smime_sign_off')}
>
<ShieldCheck className="w-4 h-4" />
</Button>
<Button
variant="ghost"
size="icon"
onClick={() => setSmimeEncrypt(v => !v)}
disabled={!canSmimeEncrypt}
className={cn("h-9 w-9", smimeEncrypt_ && "bg-primary/10 text-primary")}
title={smimeEncrypt_ ? t('smime_encrypt_on') : canSmimeEncrypt ? t('smime_encrypt_off') : t('smime_encrypt_unavailable')}
>
<Lock className="w-4 h-4" />
</Button>
</>
)}
</div>
{/* Right side - Discard + Send (desktop) */}
@@ -1117,6 +1279,60 @@ export function EmailComposer({
</div>
)}
{/* S/MIME passphrase prompt */}
{smimePassphrasePrompt && (
<div
className="fixed inset-0 bg-black/50 backdrop-blur-[1px] flex items-center justify-center z-[60] p-4 animate-in fade-in duration-150"
>
<div
role="dialog"
aria-modal="true"
onClick={(e) => e.stopPropagation()}
className="bg-background border border-border rounded-lg shadow-xl w-full max-w-sm animate-in zoom-in-95 duration-200"
>
<div className="p-6">
<h2 className="text-lg font-semibold text-foreground">{t('smime_unlock_title')}</h2>
<p className="mt-2 text-sm text-muted-foreground">{t('smime_unlock_message')}</p>
<input
type="password"
autoFocus
value={smimePassphraseInput}
onChange={(e) => {
setSmimePassphraseInput(e.target.value);
setSmimePassphraseError('');
}}
onKeyDown={(e) => {
if (e.key === 'Enter' && smimePassphraseInput) {
smimePassphrasePrompt.resolve(smimePassphraseInput);
}
}}
placeholder={t('smime_passphrase_placeholder')}
className="mt-3 w-full px-3 py-2 border border-border rounded-md text-sm bg-background text-foreground outline-none focus:ring-2 focus:ring-primary"
/>
{smimePassphraseError && (
<p className="mt-1 text-xs text-red-500">{smimePassphraseError}</p>
)}
</div>
<div className="flex items-center justify-end gap-3 px-6 pb-6">
<Button variant="outline" onClick={() => {
smimePassphrasePrompt.reject();
setSmimePassphrasePrompt(null);
setSmimePassphraseInput('');
setSmimePassphraseError('');
}}>
{t('cancel')}
</Button>
<Button
disabled={!smimePassphraseInput}
onClick={() => smimePassphrasePrompt.resolve(smimePassphraseInput)}
>
{t('smime_unlock_button')}
</Button>
</div>
</div>
</div>
)}
{showCloseDialog && (
<div
className="fixed inset-0 bg-black/50 backdrop-blur-[1px] flex items-center justify-center z-[60] p-4 animate-in fade-in duration-150"
File diff suppressed because it is too large Load Diff
+116
View File
@@ -0,0 +1,116 @@
"use client";
import React from "react";
import { ShieldCheck, ShieldAlert, ShieldX, Lock, LockOpen, AlertTriangle, Info } from "lucide-react";
import { cn } from "@/lib/utils";
import { useTranslations } from "next-intl";
import type { SmimeStatus } from "@/lib/smime/types";
interface SmimeStatusBannerProps {
status: SmimeStatus;
onUnlockKey?: () => void;
className?: string;
}
export function SmimeStatusBanner({ status, onUnlockKey, className }: SmimeStatusBannerProps) {
const t = useTranslations('smime');
const items: Array<{
icon: React.ReactNode;
text: string;
variant: 'success' | 'warning' | 'error' | 'info';
}> = [];
// Encryption status
if (status.isEncrypted) {
if (status.decryptionError) {
if (status.decryptionError === 'locked') {
items.push({
icon: <Lock className="w-4 h-4" />,
text: t('unlock_key_desc'),
variant: 'warning',
});
} else {
items.push({
icon: <ShieldX className="w-4 h-4" />,
text: t('status_encrypted_failed'),
variant: 'error',
});
}
} else {
items.push({
icon: <LockOpen className="w-4 h-4" />,
text: t('status_encrypted_ok'),
variant: 'success',
});
}
}
// Signature status
if (status.isSigned) {
if (status.signatureValid === true) {
if (status.signerEmailMatch === false) {
items.push({
icon: <AlertTriangle className="w-4 h-4" />,
text: t('status_signed_mismatch'),
variant: 'warning',
});
} else {
items.push({
icon: <ShieldCheck className="w-4 h-4" />,
text: t('status_signed_valid'),
variant: 'success',
});
}
} else if (status.signatureValid === false) {
items.push({
icon: <ShieldAlert className="w-4 h-4" />,
text: status.signatureError || t('status_signed_invalid'),
variant: 'error',
});
}
}
// Unsupported S/MIME
if (status.unsupportedReason) {
items.push({
icon: <Info className="w-4 h-4" />,
text: t('status_unsupported'),
variant: 'info',
});
}
if (items.length === 0) return null;
const variantStyles = {
success: 'bg-green-50 dark:bg-green-950/30 text-green-700 dark:text-green-400 border-green-200 dark:border-green-800',
warning: 'bg-yellow-50 dark:bg-yellow-950/30 text-yellow-700 dark:text-yellow-400 border-yellow-200 dark:border-yellow-800',
error: 'bg-red-50 dark:bg-red-950/30 text-red-700 dark:text-red-400 border-red-200 dark:border-red-800',
info: 'bg-blue-50 dark:bg-blue-950/30 text-blue-700 dark:text-blue-400 border-blue-200 dark:border-blue-800',
};
return (
<div className={cn("flex flex-col gap-1.5 py-1", className)}>
{items.map((item, i) => (
<div
key={i}
className={cn(
"flex items-center gap-2 px-3 py-1.5 rounded-md text-sm border",
variantStyles[item.variant],
)}
>
{item.icon}
<span className="flex-1">{item.text}</span>
{item.variant === 'warning' && status.decryptionError === 'locked' && onUnlockKey && (
<button
onClick={onUnlockKey}
className="text-xs font-medium underline hover:no-underline"
>
{t('unlock_key')}
</button>
)}
</div>
))}
</div>
);
}
@@ -0,0 +1,117 @@
"use client";
import { useId } from "react";
import { useFocusTrap } from "@/hooks/use-focus-trap";
import { useTranslations } from "next-intl";
import { Button } from "@/components/ui/button";
import { ShieldCheck, X } from "lucide-react";
import type { SmimeKeyRecord, SmimePublicCert } from "@/lib/smime/types";
interface SmimeCertificateModalProps {
isOpen: boolean;
onClose: () => void;
record: SmimeKeyRecord | SmimePublicCert | null;
type: "private" | "public";
}
export function SmimeCertificateModal({
isOpen,
onClose,
record,
type,
}: SmimeCertificateModalProps) {
const t = useTranslations("smime");
const id = useId();
const dialogRef = useFocusTrap({
isActive: isOpen,
onEscape: onClose,
restoreFocus: true,
});
if (!isOpen || !record) return null;
const isExpired = new Date(record.notAfter) < new Date();
const isNotYetValid = new Date(record.notBefore) > new Date();
const rows: { label: string; value: string }[] = [
{ label: t("cert_subject"), value: record.subject ?? "" },
{ label: t("cert_issuer"), value: record.issuer ?? "" },
{ label: t("cert_email"), value: record.email },
{
label: t("cert_validity"),
value: `${new Date(record.notBefore).toLocaleDateString()}${new Date(record.notAfter).toLocaleDateString()}`,
},
{ label: t("cert_fingerprint"), value: record.fingerprint },
];
if ("serialNumber" in record) {
rows.splice(2, 0, { label: t("cert_serial"), value: record.serialNumber });
}
if ("algorithm" in record) {
rows.push({ label: t("cert_algorithm"), value: record.algorithm });
}
if ("capabilities" in record) {
const caps: string[] = [];
if (record.capabilities.canSign) caps.push(t("cap_sign"));
if (record.capabilities.canEncrypt) caps.push(t("cap_encrypt"));
rows.push({ label: t("cert_capabilities"), value: caps.join(", ") || t("cap_none") });
}
if ("source" in record) {
rows.push({ label: t("cert_source"), value: record.source });
}
return (
<div className="fixed inset-0 bg-black/50 backdrop-blur-[1px] flex items-center justify-center z-[60] p-4 animate-in fade-in duration-150">
<div
ref={dialogRef}
role="dialog"
aria-modal="true"
aria-labelledby={`${id}-title`}
className="bg-background border border-border rounded-lg shadow-xl w-full max-w-lg animate-in zoom-in-95 duration-200"
>
<div className="flex items-center justify-between p-6 pb-4 border-b border-border">
<div className="flex items-center gap-3">
<div className="w-9 h-9 rounded-full bg-primary/10 flex items-center justify-center">
<ShieldCheck className="w-5 h-5 text-primary" />
</div>
<h2 id={`${id}-title`} className="text-lg font-semibold text-foreground">
{t("certificate_details")}
</h2>
</div>
<Button variant="ghost" size="icon" onClick={onClose}>
<X className="w-4 h-4" />
</Button>
</div>
<div className="p-6 space-y-3 max-h-[60vh] overflow-y-auto">
{(isExpired || isNotYetValid) && (
<div className="px-3 py-2 rounded-md bg-destructive/10 text-destructive text-sm">
{isExpired ? t("cert_expired") : t("cert_not_yet_valid")}
</div>
)}
{rows.map(({ label, value }) => (
<div key={label}>
<dt className="text-xs font-medium text-muted-foreground uppercase tracking-wide">
{label}
</dt>
<dd className="text-sm text-foreground mt-0.5 break-all font-mono">
{value}
</dd>
</div>
))}
</div>
<div className="flex justify-end px-6 pb-6">
<Button variant="ghost" onClick={onClose}>
{t("close")}
</Button>
</div>
</div>
</div>
);
}
@@ -0,0 +1,169 @@
"use client";
import { useState, useId } from "react";
import { useFocusTrap } from "@/hooks/use-focus-trap";
import { useTranslations } from "next-intl";
import { Button } from "@/components/ui/button";
import { Input } from "@/components/ui/input";
import { KeyRound, Eye, EyeOff } from "lucide-react";
interface SmimePassphraseDialogProps {
isOpen: boolean;
onClose: () => void;
onSubmit: (passphrase: string) => void | Promise<void>;
title: string;
description?: string;
submitText?: string;
error?: string | null;
/** Show a second passphrase field for import/export confirmation. */
showConfirm?: boolean;
}
export function SmimePassphraseDialog({
isOpen,
onClose,
onSubmit,
title,
description,
submitText,
error,
showConfirm = false,
}: SmimePassphraseDialogProps) {
const t = useTranslations("smime");
const id = useId();
const [passphrase, setPassphrase] = useState("");
const [confirm, setConfirm] = useState("");
const [showPassword, setShowPassword] = useState(false);
const [isSubmitting, setIsSubmitting] = useState(false);
const dialogRef = useFocusTrap({
isActive: isOpen,
onEscape: onClose,
restoreFocus: true,
});
if (!isOpen) return null;
const mismatch = showConfirm && passphrase !== confirm && confirm.length > 0;
const handleSubmit = async (e: React.FormEvent) => {
e.preventDefault();
if (!passphrase || (showConfirm && passphrase !== confirm)) return;
setIsSubmitting(true);
try {
await onSubmit(passphrase);
} finally {
setIsSubmitting(false);
}
};
const handleClose = () => {
setPassphrase("");
setConfirm("");
setShowPassword(false);
onClose();
};
return (
<div className="fixed inset-0 bg-black/50 backdrop-blur-[1px] flex items-center justify-center z-[60] p-4 animate-in fade-in duration-150">
<div
ref={dialogRef}
role="dialog"
aria-modal="true"
aria-labelledby={`${id}-title`}
aria-describedby={description ? `${id}-desc` : undefined}
className="bg-background border border-border rounded-lg shadow-xl w-full max-w-md animate-in zoom-in-95 duration-200"
>
<form onSubmit={handleSubmit}>
<div className="p-6">
<div className="flex items-start gap-4">
<div className="flex-shrink-0 w-10 h-10 rounded-full bg-primary/10 flex items-center justify-center">
<KeyRound className="w-5 h-5 text-primary" />
</div>
<div className="flex-1 min-w-0">
<h2
id={`${id}-title`}
className="text-lg font-semibold text-foreground"
>
{title}
</h2>
{description && (
<p
id={`${id}-desc`}
className="text-sm text-muted-foreground mt-1"
>
{description}
</p>
)}
</div>
</div>
<div className="mt-4 space-y-3">
<div className="relative">
<Input
type={showPassword ? "text" : "password"}
value={passphrase}
onChange={(e) => setPassphrase(e.target.value)}
placeholder={t("passphrase_placeholder")}
autoFocus
className="pr-10"
autoComplete="off"
/>
<button
type="button"
onClick={() => setShowPassword(!showPassword)}
className="absolute right-2 top-1/2 -translate-y-1/2 p-1 text-muted-foreground hover:text-foreground"
aria-label={showPassword ? t("hide_passphrase") : t("show_passphrase")}
>
{showPassword ? (
<EyeOff className="w-4 h-4" />
) : (
<Eye className="w-4 h-4" />
)}
</button>
</div>
{showConfirm && (
<div>
<Input
type={showPassword ? "text" : "password"}
value={confirm}
onChange={(e) => setConfirm(e.target.value)}
placeholder={t("confirm_passphrase_placeholder")}
autoComplete="off"
/>
{mismatch && (
<p className="text-xs text-destructive mt-1">
{t("passphrase_mismatch")}
</p>
)}
</div>
)}
{error && (
<p className="text-sm text-destructive">{error}</p>
)}
</div>
</div>
<div className="flex justify-end gap-2 px-6 pb-6">
<Button
type="button"
variant="ghost"
onClick={handleClose}
disabled={isSubmitting}
>
{t("cancel")}
</Button>
<Button
type="submit"
disabled={!passphrase || isSubmitting || (showConfirm && passphrase !== confirm)}
>
{isSubmitting ? t("processing") : (submitText ?? t("unlock"))}
</Button>
</div>
</form>
</div>
</div>
);
}
+559
View File
@@ -0,0 +1,559 @@
"use client";
import { useState, useEffect, useRef } from "react";
import { useTranslations } from "next-intl";
import {
Upload,
Trash2,
Eye,
Lock,
Unlock,
Download,
ShieldCheck,
ShieldAlert,
Users,
} from "lucide-react";
import { Button } from "@/components/ui/button";
import { SettingsSection, SettingItem, ToggleSwitch } from "@/components/settings/settings-section";
import { SmimePassphraseDialog } from "@/components/settings/smime-passphrase-dialog";
import { SmimeCertificateModal } from "@/components/settings/smime-certificate-modal";
import { useSmimeStore } from "@/stores/smime-store";
import { useIdentityStore } from "@/stores/identity-store";
import { exportPkcs12, downloadPkcs12 } from "@/lib/smime/pkcs12-export";
import type { SmimeKeyRecord, SmimePublicCert } from "@/lib/smime/types";
export function SmimeSettings() {
const t = useTranslations("smime");
const {
keyRecords,
publicCerts,
identityKeyBindings,
defaultSignIdentity,
defaultEncrypt,
rememberUnlockedKeys,
autoImportSignerCerts,
isLoading,
error,
load,
importPKCS12,
removeKeyRecord,
removePublicCert,
bindIdentityToKey,
unlockKey,
lockKey,
setSignDefault,
setEncryptDefault,
setRememberUnlockedKeys,
setAutoImportSignerCerts,
isKeyUnlocked,
setError,
} = useSmimeStore();
const { identities } = useIdentityStore();
// Local UI state
const [importDialogOpen, setImportDialogOpen] = useState(false);
const [unlockDialogOpen, setUnlockDialogOpen] = useState(false);
const [unlockTargetId, setUnlockTargetId] = useState<string | null>(null);
const [certModalRecord, setCertModalRecord] = useState<SmimeKeyRecord | SmimePublicCert | null>(null);
const [certModalType, setCertModalType] = useState<"private" | "public">("private");
const [importError, setImportError] = useState<string | null>(null);
const [unlockError, setUnlockError] = useState<string | null>(null);
const [pendingFile, setPendingFile] = useState<ArrayBuffer | null>(null);
const [pendingP12Pass, setPendingP12Pass] = useState("");
const fileInputRef = useRef<HTMLInputElement>(null);
const pubCertInputRef = useRef<HTMLInputElement>(null);
// State for the two-step PKCS#12 flow
const [importStep, setImportStep] = useState<"p12" | "storage">("p12");
// Export flow state
const [exportDialogOpen, setExportDialogOpen] = useState(false);
const [exportTargetRecord, setExportTargetRecord] = useState<SmimeKeyRecord | null>(null);
const [exportStep, setExportStep] = useState<"storage" | "export">("storage");
const [exportStoragePass, setExportStoragePass] = useState("");
const [exportError, setExportError] = useState<string | null>(null);
useEffect(() => {
load();
}, [load]);
// ── PKCS#12 import flow ────────────────────────────────────────
const handleFileSelect = (e: React.ChangeEvent<HTMLInputElement>) => {
const file = e.target.files?.[0];
if (!file) return;
const reader = new FileReader();
reader.onload = () => {
setPendingFile(reader.result as ArrayBuffer);
setImportStep("p12");
setImportError(null);
setImportDialogOpen(true);
};
reader.readAsArrayBuffer(file);
// Reset so same file can be re-selected
e.target.value = "";
};
const handleImportSubmit = async (passphrase: string) => {
if (importStep === "p12") {
setPendingP12Pass(passphrase);
setImportStep("storage");
setImportError(null);
return;
}
// Storage passphrase step
if (!pendingFile) return;
try {
await importPKCS12(pendingFile, pendingP12Pass, passphrase);
setImportDialogOpen(false);
setPendingFile(null);
setPendingP12Pass("");
setImportError(null);
} catch (err) {
setImportError(err instanceof Error ? err.message : "Import failed");
}
};
// ── Public cert import ─────────────────────────────────────────
const handlePublicCertFile = (e: React.ChangeEvent<HTMLInputElement>) => {
const file = e.target.files?.[0];
if (!file) return;
const reader = new FileReader();
reader.onload = async () => {
try {
const store = useSmimeStore.getState();
await store.importPublicCert(reader.result as ArrayBuffer, "manual");
} catch (err) {
setError(err instanceof Error ? err.message : "Failed to import certificate");
}
};
reader.readAsArrayBuffer(file);
e.target.value = "";
};
// ── Unlock ─────────────────────────────────────────────────────
const handleUnlockRequest = (id: string) => {
setUnlockTargetId(id);
setUnlockError(null);
setUnlockDialogOpen(true);
};
const handleUnlockSubmit = async (passphrase: string) => {
if (!unlockTargetId) return;
try {
await unlockKey(unlockTargetId, passphrase);
setUnlockDialogOpen(false);
setUnlockTargetId(null);
setUnlockError(null);
} catch (err) {
setUnlockError(err instanceof Error ? err.message : "Unlock failed");
}
};
// ── Export flow ────────────────────────────────────────────────
const handleExportRequest = (record: SmimeKeyRecord) => {
setExportTargetRecord(record);
setExportStep("storage");
setExportStoragePass("");
setExportError(null);
setExportDialogOpen(true);
};
const handleExportSubmit = async (passphrase: string) => {
if (!exportTargetRecord) return;
if (exportStep === "storage") {
// Verify storage passphrase by attempting to decrypt
try {
const { decryptPrivateKeyBytes } = await import("@/lib/smime/pkcs12-import");
await decryptPrivateKeyBytes(exportTargetRecord, passphrase);
setExportStoragePass(passphrase);
setExportStep("export");
setExportError(null);
} catch {
setExportError(t("incorrect_passphrase"));
}
return;
}
// Export passphrase step
try {
const p12Bytes = await exportPkcs12(exportTargetRecord, exportStoragePass, passphrase);
const filename = `${exportTargetRecord.email.replace(/[^a-zA-Z0-9.-]/g, '_')}.p12`;
downloadPkcs12(p12Bytes, filename);
setExportDialogOpen(false);
setExportTargetRecord(null);
setExportStoragePass("");
setExportError(null);
} catch (err) {
setExportError(err instanceof Error ? err.message : "Export failed");
}
};
// ── Helpers ────────────────────────────────────────────────────
const isExpired = (dateStr: string) => new Date(dateStr) < new Date();
const formatDate = (dateStr: string) => {
try {
return new Date(dateStr).toLocaleDateString();
} catch {
return dateStr;
}
};
const getBoundIdentityNames = (keyId: string): string[] => {
return Object.entries(identityKeyBindings)
.filter(([, kId]) => kId === keyId)
.map(([identityId]) => {
const identity = identities.find((i) => i.id === identityId);
return identity?.email ?? identityId;
});
};
return (
<div className="space-y-8">
{error && (
<div className="px-4 py-3 rounded-md bg-destructive/10 text-destructive text-sm">
{error}
</div>
)}
{/* ── Your Certificates ──────────────────────────────────── */}
<SettingsSection
title={t("your_certificates")}
description={t("your_certificates_desc")}
>
<div className="space-y-2">
{keyRecords.map((record) => {
const expired = isExpired(record.notAfter);
const unlocked = isKeyUnlocked(record.id);
const boundIdentities = getBoundIdentityNames(record.id);
return (
<div
key={record.id}
className="flex items-center justify-between p-3 rounded-lg border border-border"
>
<div className="flex items-center gap-3 min-w-0 flex-1">
<div className={`w-8 h-8 rounded-full flex items-center justify-center ${expired ? "bg-destructive/10" : "bg-primary/10"}`}>
{expired ? (
<ShieldAlert className="w-4 h-4 text-destructive" />
) : (
<ShieldCheck className="w-4 h-4 text-primary" />
)}
</div>
<div className="min-w-0">
<p className="text-sm font-medium text-foreground truncate">
{record.email || record.subject}
</p>
<p className="text-xs text-muted-foreground">
{record.issuer} · {t("expires")} {formatDate(record.notAfter)}
{expired && <span className="text-destructive ml-1">({t("expired")})</span>}
</p>
{boundIdentities.length > 0 && (
<p className="text-xs text-muted-foreground">
{t("bound_to")}: {boundIdentities.join(", ")}
</p>
)}
</div>
</div>
<div className="flex items-center gap-1">
{unlocked ? (
<Button
variant="ghost"
size="icon"
onClick={() => lockKey(record.id)}
title={t("lock")}
>
<Unlock className="w-4 h-4 text-green-600" />
</Button>
) : (
<Button
variant="ghost"
size="icon"
onClick={() => handleUnlockRequest(record.id)}
title={t("unlock")}
>
<Lock className="w-4 h-4" />
</Button>
)}
<Button
variant="ghost"
size="icon"
onClick={() => {
setCertModalRecord(record);
setCertModalType("private");
}}
title={t("details")}
>
<Eye className="w-4 h-4" />
</Button>
<Button
variant="ghost"
size="icon"
onClick={() => handleExportRequest(record)}
title={t("export")}
>
<Download className="w-4 h-4" />
</Button>
<Button
variant="ghost"
size="icon"
onClick={() => removeKeyRecord(record.id)}
title={t("delete")}
>
<Trash2 className="w-4 h-4 text-destructive" />
</Button>
</div>
</div>
);
})}
{keyRecords.length === 0 && !isLoading && (
<p className="text-sm text-muted-foreground py-4 text-center">
{t("no_certificates")}
</p>
)}
</div>
<input
ref={fileInputRef}
type="file"
accept=".p12,.pfx"
className="hidden"
onChange={handleFileSelect}
/>
<Button
variant="outline"
onClick={() => fileInputRef.current?.click()}
disabled={isLoading}
className="mt-2"
>
<Upload className="w-4 h-4 mr-2" />
{t("import_pkcs12")}
</Button>
</SettingsSection>
{/* ── Recipient Certificates ─────────────────────────────── */}
<SettingsSection
title={t("recipient_certificates")}
description={t("recipient_certificates_desc")}
>
<div className="space-y-2">
{publicCerts.map((cert) => {
const expired = isExpired(cert.notAfter);
return (
<div
key={cert.id}
className="flex items-center justify-between p-3 rounded-lg border border-border"
>
<div className="flex items-center gap-3 min-w-0 flex-1">
<div className="w-8 h-8 rounded-full bg-muted flex items-center justify-center">
<Users className="w-4 h-4 text-muted-foreground" />
</div>
<div className="min-w-0">
<p className="text-sm font-medium text-foreground truncate">
{cert.email || cert.subject}
</p>
<p className="text-xs text-muted-foreground">
{cert.issuer} · {cert.source}
{expired && <span className="text-destructive ml-1">({t("expired")})</span>}
</p>
</div>
</div>
<div className="flex items-center gap-1">
<Button
variant="ghost"
size="icon"
onClick={() => {
setCertModalRecord(cert);
setCertModalType("public");
}}
title={t("details")}
>
<Eye className="w-4 h-4" />
</Button>
<Button
variant="ghost"
size="icon"
onClick={() => removePublicCert(cert.id)}
title={t("delete")}
>
<Trash2 className="w-4 h-4 text-destructive" />
</Button>
</div>
</div>
);
})}
{publicCerts.length === 0 && !isLoading && (
<p className="text-sm text-muted-foreground py-4 text-center">
{t("no_recipient_certs")}
</p>
)}
</div>
<input
ref={pubCertInputRef}
type="file"
accept=".pem,.cer,.crt,.der"
className="hidden"
onChange={handlePublicCertFile}
/>
<Button
variant="outline"
onClick={() => pubCertInputRef.current?.click()}
disabled={isLoading}
className="mt-2"
>
<Upload className="w-4 h-4 mr-2" />
{t("import_public_cert")}
</Button>
</SettingsSection>
{/* ── Identity Bindings ──────────────────────────────────── */}
{identities.length > 0 && keyRecords.length > 0 && (
<SettingsSection
title={t("identity_bindings")}
description={t("identity_bindings_desc")}
>
{identities.map((identity) => {
const boundKeyId = identityKeyBindings[identity.id];
return (
<SettingItem key={identity.id} label={identity.email}>
<select
value={boundKeyId ?? ""}
onChange={(e) =>
bindIdentityToKey(identity.id, e.target.value || null)
}
className="text-sm bg-background border border-border rounded-md px-2 py-1"
>
<option value="">{t("no_key_bound")}</option>
{keyRecords.map((kr) => (
<option key={kr.id} value={kr.id}>
{kr.email} ({kr.algorithm})
</option>
))}
</select>
</SettingItem>
);
})}
</SettingsSection>
)}
{/* ── Defaults ───────────────────────────────────────────── */}
<SettingsSection
title={t("defaults_title")}
description={t("defaults_desc")}
>
<SettingItem
label={t("encrypt_by_default")}
description={t("encrypt_by_default_desc")}
>
<ToggleSwitch
checked={defaultEncrypt}
onChange={setEncryptDefault}
/>
</SettingItem>
<SettingItem
label={t("remember_unlocked")}
description={t("remember_unlocked_desc")}
>
<ToggleSwitch
checked={rememberUnlockedKeys}
onChange={setRememberUnlockedKeys}
/>
</SettingItem>
<SettingItem
label={t("auto_import_signer_certs")}
description={t("auto_import_signer_certs_desc")}
>
<ToggleSwitch
checked={autoImportSignerCerts}
onChange={setAutoImportSignerCerts}
/>
</SettingItem>
{identities.map((identity) => {
const bound = identityKeyBindings[identity.id];
if (!bound) return null;
return (
<SettingItem
key={identity.id}
label={`${t("sign_default_for")} ${identity.email}`}
>
<ToggleSwitch
checked={defaultSignIdentity[identity.id] ?? false}
onChange={(v) => setSignDefault(identity.id, v)}
/>
</SettingItem>
);
})}
</SettingsSection>
{/* ── Dialogs ────────────────────────────────────────────── */}
<SmimePassphraseDialog
isOpen={importDialogOpen}
onClose={() => {
setImportDialogOpen(false);
setPendingFile(null);
setPendingP12Pass("");
setImportError(null);
setImportStep("p12");
}}
onSubmit={handleImportSubmit}
title={importStep === "p12" ? t("enter_p12_passphrase") : t("enter_storage_passphrase")}
description={importStep === "p12" ? t("p12_passphrase_desc") : t("storage_passphrase_desc")}
submitText={importStep === "p12" ? t("next") : t("import")}
error={importError}
showConfirm={importStep === "storage"}
/>
<SmimePassphraseDialog
isOpen={unlockDialogOpen}
onClose={() => {
setUnlockDialogOpen(false);
setUnlockTargetId(null);
setUnlockError(null);
}}
onSubmit={handleUnlockSubmit}
title={t("unlock_key")}
description={t("unlock_key_desc")}
error={unlockError}
/>
<SmimeCertificateModal
isOpen={!!certModalRecord}
onClose={() => setCertModalRecord(null)}
record={certModalRecord}
type={certModalType}
/>
<SmimePassphraseDialog
isOpen={exportDialogOpen}
onClose={() => {
setExportDialogOpen(false);
setExportTargetRecord(null);
setExportStoragePass("");
setExportError(null);
setExportStep("storage");
}}
onSubmit={handleExportSubmit}
title={exportStep === "storage" ? t("enter_storage_passphrase") : t("enter_export_passphrase")}
description={exportStep === "storage" ? t("export_storage_desc") : t("export_passphrase_desc")}
submitText={exportStep === "storage" ? t("next") : t("export")}
error={exportError}
showConfirm={exportStep === "export"}
/>
</div>
);
}
+118 -1
View File
@@ -616,7 +616,7 @@ export class JMAPClient {
"receivedAt", "sentAt", "from", "to", "cc", "bcc", "replyTo",
"subject", "preview", "textBody", "htmlBody", "bodyValues",
"hasAttachment", "attachments", "messageId", "inReplyTo",
"references", "headers",
"references", "headers", "bodyStructure", "blobId",
],
fetchTextBodyValues: true,
fetchHTMLBodyValues: true,
@@ -2927,4 +2927,121 @@ export class JMAPClient {
setLastStates(states: AccountStates): void {
this.lastStates = { ...states };
}
// ── S/MIME raw-email helpers ─────────────────────────────────────
/** Fetch blob content as an ArrayBuffer (for S/MIME byte processing). */
async fetchBlobArrayBuffer(blobId: string, name?: string, type?: string): Promise<ArrayBuffer> {
const url = this.getBlobDownloadUrl(blobId, name, type);
const response = await this.authenticatedFetch(url, {});
if (!response.ok) {
throw new Error(`Failed to fetch blob: ${response.status}`);
}
return response.arrayBuffer();
}
/** Import a raw MIME message blob into the account. */
async importRawEmail(
blob: Blob,
mailboxIds: Record<string, boolean>,
keywords?: Record<string, boolean>,
): Promise<string> {
// First upload the blob
const file = new File([blob], 'message.eml', { type: 'message/rfc822' });
const { blobId } = await this.uploadBlob(file);
// Then import via Email/import
const response = await this.request([
['Email/import', {
accountId: this.accountId,
emails: {
'smime-import': {
blobId,
mailboxIds,
keywords: keywords ?? { '$seen': true },
},
},
}, '0'],
]);
const importResult = response.methodResponses?.[0]?.[1];
if (importResult?.notCreated?.['smime-import']) {
const err = importResult.notCreated['smime-import'];
throw new Error(err.description || err.type || 'Failed to import email');
}
const emailId = importResult?.created?.['smime-import']?.id;
if (!emailId) {
throw new Error('Email import succeeded but no ID returned');
}
return emailId;
}
/** Submit an already-imported email for delivery. */
async submitEmail(emailId: string, identityId: string): Promise<void> {
const response = await this.request([
['EmailSubmission/set', {
accountId: this.accountId,
create: { 'smime-submit': { emailId, identityId } },
}, '0'],
]);
const result = response.methodResponses?.[0]?.[1];
if (result?.notCreated?.['smime-submit']) {
const err = result.notCreated['smime-submit'];
throw new Error(err.description || err.type || 'Failed to submit email');
}
}
/**
* Import a raw S/MIME message, move it to the Sent mailbox, and submit it.
* Encapsulates the full import → update → submit flow.
*/
async sendRawEmail(
blob: Blob,
identityId: string,
sentMailboxId: string,
draftMailboxId?: string,
): Promise<void> {
// Upload the raw message
const file = new File([blob], 'message.eml', { type: 'message/rfc822' });
const { blobId } = await this.uploadBlob(file);
// Import into Sent, mark as seen, and submit — all in one request
const methodCalls: [string, Record<string, unknown>, string][] = [
['Email/import', {
accountId: this.accountId,
emails: {
'raw-import': {
blobId,
mailboxIds: { [sentMailboxId]: true },
keywords: { '$seen': true },
},
},
}, '0'],
['EmailSubmission/set', {
accountId: this.accountId,
create: {
'raw-submit': {
emailId: '#raw-import',
identityId,
},
},
}, '1'],
];
const response = await this.request(methodCalls);
// Check for errors
for (const [methodName, result] of response.methodResponses ?? []) {
if (methodName.endsWith('/error')) {
throw new Error((result as { description?: string }).description || `Failed: ${(result as { type?: string }).type}`);
}
const r = result as { notCreated?: Record<string, { description?: string; type?: string }> };
if (r.notCreated) {
const firstErr = Object.values(r.notCreated)[0];
throw new Error(firstErr?.description || firstErr?.type || 'Failed to send raw email');
}
}
}
}
+3
View File
@@ -36,6 +36,9 @@ export interface Email {
verdict: string;
explanation: string;
};
// S/MIME support
blobId?: string;
bodyStructure?: EmailBodyPart;
}
export interface AuthenticationResults {
@@ -0,0 +1,214 @@
import { describe, it, expect, vi, beforeAll } from 'vitest';
import {
pemToDer,
derToPem,
isPem,
parseCertificateDer,
parseCertificatePemOrDer,
computeFingerprint,
classifyCapabilities,
extractCertificateInfo,
} from '../certificate-utils';
import * as pkijs from 'pkijs';
import * as asn1js from 'asn1js';
// Generate a self-signed test certificate using Web Crypto + pkijs
let testCertDer: ArrayBuffer;
let testCert: pkijs.Certificate;
let testKeyPair: globalThis.CryptoKeyPair;
beforeAll(async () => {
const cryptoEngine = new pkijs.CryptoEngine({
crypto: crypto,
subtle: crypto.subtle,
name: 'webcrypto',
});
pkijs.setEngine('test', crypto, cryptoEngine);
// Generate RSA key pair
testKeyPair = await crypto.subtle.generateKey(
{ name: 'RSASSA-PKCS1-v1_5', modulusLength: 2048, publicExponent: new Uint8Array([1, 0, 1]), hash: 'SHA-256' },
true,
['sign', 'verify'],
);
// Build a minimal self-signed X.509 certificate
testCert = new pkijs.Certificate();
testCert.version = 2; // v3
testCert.serialNumber = new asn1js.Integer({ value: 1 });
testCert.issuer.typesAndValues.push(new pkijs.AttributeTypeAndValue({
type: '2.5.4.3', // CN
value: new asn1js.Utf8String({ value: 'Test CA' }),
}));
testCert.subject.typesAndValues.push(new pkijs.AttributeTypeAndValue({
type: '2.5.4.3', // CN
value: new asn1js.Utf8String({ value: 'Test User' }),
}));
testCert.subject.typesAndValues.push(new pkijs.AttributeTypeAndValue({
type: '1.2.840.113549.1.9.1', // emailAddress
value: new asn1js.IA5String({ value: 'test@example.com' }),
}));
testCert.notBefore.value = new Date('2024-01-01T00:00:00Z');
testCert.notAfter.value = new Date('2030-12-31T23:59:59Z');
await testCert.subjectPublicKeyInfo.importKey(testKeyPair.publicKey, cryptoEngine);
// Add KeyUsage extension: digitalSignature + keyEncipherment
const bitArray = new ArrayBuffer(1);
const bitView = new Uint8Array(bitArray);
bitView[0] = 0b10100000; // digitalSignature (bit 0) + keyEncipherment (bit 2)
testCert.extensions = [
new pkijs.Extension({
extnID: '2.5.29.15', // keyUsage
critical: true,
extnValue: new asn1js.OctetString({
valueHex: new Uint8Array(new asn1js.BitString({
valueHex: bitArray,
unusedBits: 3,
}).toBER(false)),
}).toBER(false) as ArrayBuffer,
parsedValue: {
digitalSignature: true,
contentCommitment: false,
keyEncipherment: true,
dataEncipherment: false,
keyAgreement: false,
keyCertSign: false,
cRLSign: false,
encipherOnly: false,
decipherOnly: false,
},
}),
];
await testCert.sign(testKeyPair.privateKey, 'SHA-256', cryptoEngine);
// toBER may return a non-standard ArrayBuffer in jsdom; normalize it
const rawDer = testCert.toSchema(true).toBER(false);
testCertDer = new Uint8Array(rawDer).buffer;
});
describe('certificate-utils', () => {
describe('pemToDer / derToPem roundtrip', () => {
it('converts PEM to DER and back', () => {
const pem = derToPem(testCertDer, 'CERTIFICATE');
expect(pem).toContain('-----BEGIN CERTIFICATE-----');
expect(pem).toContain('-----END CERTIFICATE-----');
const der2 = pemToDer(pem);
expect(new Uint8Array(der2)).toEqual(new Uint8Array(testCertDer));
});
it('derToPem wraps lines at 64 chars', () => {
const pem = derToPem(testCertDer, 'CERTIFICATE');
const lines = pem.split('\n');
// All content lines (not headers) should be <= 64 chars
for (const line of lines) {
if (!line.startsWith('-----')) {
expect(line.length).toBeLessThanOrEqual(64);
}
}
});
});
describe('isPem', () => {
it('returns true for certificate PEM', () => {
expect(isPem('-----BEGIN CERTIFICATE-----\nMIIB...\n-----END CERTIFICATE-----')).toBe(true);
});
it('returns true for PKCS12 PEM', () => {
expect(isPem('-----BEGIN PKCS12-----\ndata\n-----END PKCS12-----')).toBe(true);
});
it('returns true for private key PEM', () => {
expect(isPem('-----BEGIN PRIVATE KEY-----\ndata\n-----END PRIVATE KEY-----')).toBe(true);
});
it('returns true for encrypted private key PEM', () => {
expect(isPem('-----BEGIN ENCRYPTED PRIVATE KEY-----\ndata\n-----END ENCRYPTED PRIVATE KEY-----')).toBe(true);
});
it('returns false for non-PEM data', () => {
expect(isPem('hello world')).toBe(false);
expect(isPem('')).toBe(false);
expect(isPem('MIIB...')).toBe(false);
});
});
describe('parseCertificateDer', () => {
it('parses a valid DER certificate', () => {
const cert = parseCertificateDer(testCertDer);
expect(cert).toBeInstanceOf(pkijs.Certificate);
});
it('throws on invalid DER data', () => {
const garbage = new Uint8Array([0, 1, 2, 3]).buffer;
expect(() => parseCertificateDer(garbage)).toThrow();
});
});
describe('parseCertificatePemOrDer', () => {
it('parses DER ArrayBuffer', () => {
const cert = parseCertificatePemOrDer(testCertDer);
expect(cert).toBeInstanceOf(pkijs.Certificate);
});
it('parses PEM string', () => {
const pem = derToPem(testCertDer, 'CERTIFICATE');
const cert = parseCertificatePemOrDer(pem);
expect(cert).toBeInstanceOf(pkijs.Certificate);
});
it('throws on non-PEM string', () => {
expect(() => parseCertificatePemOrDer('not a pem')).toThrow('String input is not PEM-encoded');
});
});
describe('computeFingerprint', () => {
it('returns hex fingerprint with colons', async () => {
const fp = await computeFingerprint(testCertDer);
expect(fp).toMatch(/^[0-9a-f]{2}(:[0-9a-f]{2}){31}$/);
});
it('is deterministic', async () => {
const fp1 = await computeFingerprint(testCertDer);
const fp2 = await computeFingerprint(testCertDer);
expect(fp1).toBe(fp2);
});
});
describe('classifyCapabilities', () => {
it('detects sign + encrypt from KeyUsage', () => {
const caps = classifyCapabilities(testCert);
expect(caps.canSign).toBe(true);
expect(caps.canEncrypt).toBe(true);
});
});
describe('extractCertificateInfo', () => {
it('extracts full certificate metadata', async () => {
const info = await extractCertificateInfo(testCert, testCertDer);
expect(info.subject).toContain('CN=Test User');
expect(info.issuer).toContain('CN=Test CA');
expect(info.notBefore).toBe('2024-01-01T00:00:00.000Z');
expect(info.notAfter).toBe('2030-12-31T23:59:59.000Z');
expect(info.fingerprint).toMatch(/^[0-9a-f]{2}(:[0-9a-f]{2}){31}$/);
expect(info.algorithm).toMatch(/^RSA/);
expect(info.emailAddresses).toContain('test@example.com');
expect(info.capabilities.canSign).toBe(true);
expect(info.capabilities.canEncrypt).toBe(true);
});
it('returns serialNumber as hex', async () => {
const info = await extractCertificateInfo(testCert, testCertDer);
// Serial number 1 → should be hex string
expect(info.serialNumber).toBeTruthy();
});
});
});
+151
View File
@@ -0,0 +1,151 @@
import { describe, it, expect, beforeEach, vi } from 'vitest';
import 'fake-indexeddb/auto';
// Each test file gets a fresh global indexedDB via fake-indexeddb/auto.
// Since openDB() caches connections implicitly, we re-import the module for each test.
// However, to keep it simple, we'll just test in order and accept cumulative state,
// or we can test with unique IDs.
import {
saveKeyRecord,
getKeyRecord,
getKeyRecordForEmail,
listKeyRecords,
deleteKeyRecord,
savePublicCert,
getPublicCertForEmail,
listPublicCerts,
deletePublicCert,
} from '../key-storage';
import type { SmimeKeyRecord, SmimePublicCert } from '../types';
function makeKeyRecord(overrides: Partial<SmimeKeyRecord> = {}): SmimeKeyRecord {
return {
id: 'key-1',
email: 'user@example.com',
certificate: new ArrayBuffer(10),
certificateChain: [],
encryptedPrivateKey: new ArrayBuffer(32),
salt: new ArrayBuffer(16),
iv: new ArrayBuffer(12),
kdfIterations: 600000,
issuer: 'CN=Test CA',
subject: 'CN=Test User',
serialNumber: '01',
notBefore: '2024-01-01T00:00:00Z',
notAfter: '2030-12-31T23:59:59Z',
fingerprint: 'aa:bb:cc',
algorithm: 'RSA-2048',
capabilities: { canSign: true, canEncrypt: true },
...overrides,
};
}
function makePublicCert(overrides: Partial<SmimePublicCert> = {}): SmimePublicCert {
return {
id: 'cert-1',
email: 'recipient@example.com',
certificate: new ArrayBuffer(10),
issuer: 'CN=Test CA',
subject: 'CN=Recipient',
notBefore: '2024-01-01T00:00:00Z',
notAfter: '2030-12-31T23:59:59Z',
fingerprint: 'dd:ee:ff',
source: 'manual',
...overrides,
};
}
// Use unique IDs for each test to avoid state leakage
let testCounter = 0;
function uid() { return `test-${++testCounter}-${Date.now()}`; }
describe('key-storage', () => {
describe('key records', () => {
it('saves and retrieves a key record by id', async () => {
const id = uid();
const record = makeKeyRecord({ id });
await saveKeyRecord(record);
const retrieved = await getKeyRecord(id);
expect(retrieved).toBeDefined();
expect(retrieved!.id).toBe(id);
expect(retrieved!.email).toBe('user@example.com');
});
it('returns undefined for non-existent key record', async () => {
const result = await getKeyRecord('absolutely-non-existent-' + uid());
expect(result).toBeUndefined();
});
it('retrieves key record by email', async () => {
const id = uid();
const email = `alice-${id}@example.com`;
const record = makeKeyRecord({ id, email });
await saveKeyRecord(record);
const result = await getKeyRecordForEmail(email);
expect(result).toBeDefined();
expect(result!.email).toBe(email);
});
it('lists key records (includes previously saved)', async () => {
const id1 = uid();
const id2 = uid();
await saveKeyRecord(makeKeyRecord({ id: id1, email: `${id1}@example.com` }));
await saveKeyRecord(makeKeyRecord({ id: id2, email: `${id2}@example.com` }));
const records = await listKeyRecords();
expect(records.length).toBeGreaterThanOrEqual(2);
expect(records.find(r => r.id === id1)).toBeDefined();
expect(records.find(r => r.id === id2)).toBeDefined();
});
it('deletes a key record', async () => {
const id = uid();
const record = makeKeyRecord({ id });
await saveKeyRecord(record);
await deleteKeyRecord(id);
const result = await getKeyRecord(id);
expect(result).toBeUndefined();
});
it('updates existing record with same id', async () => {
const id = uid();
const record1 = makeKeyRecord({ id, email: 'old@example.com' });
await saveKeyRecord(record1);
const record2 = makeKeyRecord({ id, email: 'new@example.com' });
await saveKeyRecord(record2);
const retrieved = await getKeyRecord(id);
expect(retrieved!.email).toBe('new@example.com');
});
});
describe('public certs', () => {
it('saves and retrieves by email', async () => {
const id = uid();
const email = `recipient-${id}@example.com`;
const cert = makePublicCert({ id, email });
await savePublicCert(cert);
const result = await getPublicCertForEmail(email);
expect(result).toBeDefined();
expect(result!.email).toBe(email);
});
it('lists public certs (includes previously saved)', async () => {
const id1 = uid();
const id2 = uid();
await savePublicCert(makePublicCert({ id: id1, email: `${id1}@test.com` }));
await savePublicCert(makePublicCert({ id: id2, email: `${id2}@test.com` }));
const certs = await listPublicCerts();
expect(certs.find(c => c.id === id1)).toBeDefined();
expect(certs.find(c => c.id === id2)).toBeDefined();
});
it('deletes a public cert', async () => {
const id = uid();
const cert = makePublicCert({ id });
await savePublicCert(cert);
await deletePublicCert(id);
const certs = await listPublicCerts();
expect(certs.find(c => c.id === id)).toBeUndefined();
});
});
});
+259
View File
@@ -0,0 +1,259 @@
import { describe, it, expect, vi, beforeEach } from 'vitest';
import { buildMimeMessage, quotedPrintableEncode, base64Encode } from '../mime-builder';
// Mock crypto.randomUUID and crypto.getRandomValues for deterministic tests
beforeEach(() => {
let uuidCounter = 0;
vi.spyOn(crypto, 'randomUUID').mockImplementation(
() => `00000000-0000-0000-0000-${String(++uuidCounter).padStart(12, '0')}` as `${string}-${string}-${string}-${string}-${string}`,
);
vi.spyOn(crypto, 'getRandomValues').mockImplementation(<T extends ArrayBufferView | null>(array: T): T => {
if (array) {
const u8 = new Uint8Array((array as unknown as Uint8Array).buffer);
for (let i = 0; i < u8.length; i++) u8[i] = i;
}
return array;
});
});
describe('mime-builder', () => {
describe('buildMimeMessage', () => {
it('builds a text-only message', () => {
const msg = buildMimeMessage({
from: { name: 'Alice', email: 'alice@example.com' },
to: [{ email: 'bob@example.com' }],
subject: 'Hello',
textBody: 'Hi Bob!',
date: new Date('2024-06-15T12:00:00Z'),
});
const text = new TextDecoder().decode(msg);
expect(text).toContain('From: "Alice" <alice@example.com>');
expect(text).toContain('To: bob@example.com');
expect(text).toContain('Subject: Hello');
expect(text).toContain('Content-Type: text/plain; charset=utf-8');
expect(text).toContain('MIME-Version: 1.0');
expect(text).toContain('Hi Bob!');
});
it('builds a text + HTML multipart/alternative', () => {
const msg = buildMimeMessage({
from: { email: 'alice@example.com' },
to: [{ email: 'bob@example.com' }],
subject: 'Test',
textBody: 'Plain text',
htmlBody: '<p>HTML body</p>',
date: new Date('2024-06-15T12:00:00Z'),
});
const text = new TextDecoder().decode(msg);
expect(text).toContain('Content-Type: multipart/alternative');
expect(text).toContain('Content-Type: text/plain; charset=utf-8');
expect(text).toContain('Content-Type: text/html; charset=utf-8');
expect(text).toContain('Plain text');
expect(text).toContain('<p>HTML body</p>');
});
it('builds HTML-only message', () => {
const msg = buildMimeMessage({
from: { email: 'alice@example.com' },
to: [{ email: 'bob@example.com' }],
subject: 'HTML only',
htmlBody: '<h1>Hello</h1>',
date: new Date('2024-06-15T12:00:00Z'),
});
const text = new TextDecoder().decode(msg);
expect(text).toContain('Content-Type: text/html; charset=utf-8');
expect(text).toContain('<h1>Hello</h1>');
});
it('builds message with attachments', () => {
const attachment = {
filename: 'test.txt',
contentType: 'text/plain',
content: new TextEncoder().encode('file content').buffer,
};
const msg = buildMimeMessage({
from: { email: 'alice@example.com' },
to: [{ email: 'bob@example.com' }],
subject: 'With attachment',
textBody: 'See attached',
attachments: [attachment],
date: new Date('2024-06-15T12:00:00Z'),
});
const text = new TextDecoder().decode(msg);
expect(text).toContain('Content-Type: multipart/mixed');
expect(text).toContain('Content-Disposition: attachment; filename="test.txt"');
expect(text).toContain('Content-Transfer-Encoding: base64');
});
it('builds message with inline attachment (cid)', () => {
const inline = {
filename: 'image.png',
contentType: 'image/png',
content: new Uint8Array([0x89, 0x50, 0x4E, 0x47]).buffer,
cid: 'img1',
};
const msg = buildMimeMessage({
from: { email: 'alice@example.com' },
to: [{ email: 'bob@example.com' }],
subject: 'Inline',
htmlBody: '<img src="cid:img1">',
attachments: [inline],
date: new Date('2024-06-15T12:00:00Z'),
});
const text = new TextDecoder().decode(msg);
expect(text).toContain('Content-Disposition: inline; filename="image.png"');
expect(text).toContain('Content-ID: <img1>');
});
it('includes CC header when provided', () => {
const msg = buildMimeMessage({
from: { email: 'alice@example.com' },
to: [{ email: 'bob@example.com' }],
cc: [{ name: 'Charlie', email: 'charlie@example.com' }],
subject: 'CC test',
textBody: 'Hello',
date: new Date('2024-06-15T12:00:00Z'),
});
const text = new TextDecoder().decode(msg);
expect(text).toContain('Cc: "Charlie" <charlie@example.com>');
});
it('omits BCC from MIME headers', () => {
const msg = buildMimeMessage({
from: { email: 'alice@example.com' },
to: [{ email: 'bob@example.com' }],
bcc: [{ email: 'secret@example.com' }],
subject: 'BCC test',
textBody: 'Hello',
date: new Date('2024-06-15T12:00:00Z'),
});
const text = new TextDecoder().decode(msg);
expect(text).not.toContain('Bcc');
expect(text).not.toContain('secret@example.com');
});
it('includes In-Reply-To and References', () => {
const msg = buildMimeMessage({
from: { email: 'alice@example.com' },
to: [{ email: 'bob@example.com' }],
subject: 'Re: Thread',
textBody: 'reply',
inReplyTo: '<msg1@example.com>',
references: ['<msg0@example.com>', '<msg1@example.com>'],
date: new Date('2024-06-15T12:00:00Z'),
});
const text = new TextDecoder().decode(msg);
expect(text).toContain('In-Reply-To: <msg1@example.com>');
expect(text).toContain('References: <msg0@example.com> <msg1@example.com>');
});
it('encodes non-ASCII subject with RFC 2047', () => {
const msg = buildMimeMessage({
from: { email: 'alice@example.com' },
to: [{ email: 'bob@example.com' }],
subject: 'Ünïcödé',
textBody: 'test',
date: new Date('2024-06-15T12:00:00Z'),
});
const text = new TextDecoder().decode(msg);
expect(text).toContain('=?UTF-8?Q?');
});
it('uses CRLF line endings', () => {
const msg = buildMimeMessage({
from: { email: 'alice@example.com' },
to: [{ email: 'bob@example.com' }],
subject: 'CRLF',
textBody: 'test',
date: new Date('2024-06-15T12:00:00Z'),
});
const text = new TextDecoder().decode(msg);
// Should contain CRLF before the body
expect(text).toContain('\r\n');
// Should not contain bare LF without preceding CR (except within QP encoding)
const lines = text.split('\r\n');
expect(lines.length).toBeGreaterThan(1);
});
it('builds empty body message', () => {
const msg = buildMimeMessage({
from: { email: 'alice@example.com' },
to: [{ email: 'bob@example.com' }],
subject: 'Empty',
date: new Date('2024-06-15T12:00:00Z'),
});
const text = new TextDecoder().decode(msg);
expect(text).toContain('Content-Type: text/plain; charset=utf-8');
});
it('escapes display name in From header', () => {
const msg = buildMimeMessage({
from: { name: 'O\'Brien, "Bob"', email: 'bob@example.com' },
to: [{ email: 'alice@example.com' }],
subject: 'Name test',
textBody: 'test',
date: new Date('2024-06-15T12:00:00Z'),
});
const text = new TextDecoder().decode(msg);
expect(text).toContain('From: "O\'Brien, \\"Bob\\"" <bob@example.com>');
});
});
describe('quotedPrintableEncode', () => {
it('passes through ASCII text unchanged', () => {
const result = quotedPrintableEncode('Hello World');
expect(result).toBe('Hello World');
});
it('encodes non-ASCII characters', () => {
const result = quotedPrintableEncode('Héllo');
expect(result).toContain('=');
});
it('encodes equals sign', () => {
const result = quotedPrintableEncode('a=b');
expect(result).toContain('=3D');
});
it('wraps long lines with soft line break', () => {
const longLine = 'a'.repeat(100);
const result = quotedPrintableEncode(longLine);
const lines = result.split('\r\n');
for (const line of lines) {
expect(line.length).toBeLessThanOrEqual(76);
}
});
});
describe('base64Encode', () => {
it('encodes binary data to base64', () => {
const data = new Uint8Array([72, 101, 108, 108, 111]).buffer; // "Hello"
const result = base64Encode(data);
expect(result).toBe('SGVsbG8=');
});
it('wraps long lines at 76 chars', () => {
const data = new Uint8Array(200).buffer;
const result = base64Encode(data);
const lines = result.split('\r\n');
for (const line of lines) {
expect(line.length).toBeLessThanOrEqual(76);
}
});
});
});
+219
View File
@@ -0,0 +1,219 @@
// @vitest-environment node
import { describe, it, expect, beforeAll } from 'vitest';
import * as pkijs from 'pkijs';
import * as asn1js from 'asn1js';
import { importPkcs12, unlockPrivateKey, decryptPrivateKeyBytes } from '../pkcs12-import';
import { exportPkcs12 } from '../pkcs12-export';
const cryptoEngine = new pkijs.CryptoEngine({
crypto: crypto,
subtle: crypto.subtle,
name: 'webcrypto',
});
function stringToAB(str: string): ArrayBuffer {
const buf = new ArrayBuffer(str.length);
const view = new Uint8Array(buf);
for (let i = 0; i < str.length; i++) {
view[i] = str.charCodeAt(i);
}
return buf;
}
/**
* Build a minimal real PKCS#12 (.p12) blob for testing.
*/
async function buildTestP12(
email: string,
cn: string,
p12Password: string,
): Promise<{ p12Bytes: ArrayBuffer; keyPair: globalThis.CryptoKeyPair; certDer: ArrayBuffer }> {
// Generate RSA key pair (signing)
const keyPair = await crypto.subtle.generateKey(
{
name: 'RSASSA-PKCS1-v1_5',
modulusLength: 2048,
publicExponent: new Uint8Array([1, 0, 1]),
hash: 'SHA-256',
},
true,
['sign', 'verify'],
);
// Self-signed certificate
const cert = new pkijs.Certificate();
cert.version = 2;
cert.serialNumber = new asn1js.Integer({ value: 42 });
cert.issuer.typesAndValues.push(
new pkijs.AttributeTypeAndValue({
type: '2.5.4.3',
value: new asn1js.Utf8String({ value: cn }),
}),
);
cert.subject.typesAndValues.push(
new pkijs.AttributeTypeAndValue({
type: '2.5.4.3',
value: new asn1js.Utf8String({ value: cn }),
}),
);
cert.subject.typesAndValues.push(
new pkijs.AttributeTypeAndValue({
type: '1.2.840.113549.1.9.1',
value: new asn1js.IA5String({ value: email }),
}),
);
cert.notBefore.value = new Date('2024-01-01T00:00:00Z');
cert.notAfter.value = new Date('2030-12-31T23:59:59Z');
await cert.subjectPublicKeyInfo.importKey(keyPair.publicKey, cryptoEngine);
await cert.sign(keyPair.privateKey, 'SHA-256', cryptoEngine);
const certDer = cert.toSchema(true).toBER(false);
// Export private key as PKCS#8
const pkcs8Bytes = await crypto.subtle.exportKey('pkcs8', keyPair.privateKey);
// Build PKCS#12 structure
const keyBag = new pkijs.PKCS8ShroudedKeyBag({
parsedValue: pkijs.PrivateKeyInfo.fromBER(pkcs8Bytes),
});
const passwordBuf = stringToAB(p12Password);
await keyBag.makeInternalValues({
password: passwordBuf,
contentEncryptionAlgorithm: {
name: 'AES-CBC',
length: 256,
} as Parameters<typeof keyBag.makeInternalValues>[0]['contentEncryptionAlgorithm'],
hmacHashAlgorithm: 'SHA-256',
iterationCount: 2048,
});
const keyBagSafe = new pkijs.SafeBag({
bagId: '1.2.840.113549.1.12.10.1.2',
bagValue: keyBag,
});
const certBagSafe = new pkijs.SafeBag({
bagId: '1.2.840.113549.1.12.10.1.3',
bagValue: new pkijs.CertBag({ parsedValue: cert }),
});
const authenticatedSafe = new pkijs.AuthenticatedSafe({
parsedValue: {
safeContents: [
{ privacyMode: 0, value: new pkijs.SafeContents({ safeBags: [keyBagSafe] }) },
{ privacyMode: 0, value: new pkijs.SafeContents({ safeBags: [certBagSafe] }) },
],
},
});
await authenticatedSafe.makeInternalValues({ safeContents: [{}, {}] });
const pfx = new pkijs.PFX({
parsedValue: {
integrityMode: 0,
authenticatedSafe,
},
});
await pfx.makeInternalValues({
password: passwordBuf,
iterations: 2048,
pbkdf2HashAlgorithm: 'SHA-256',
hmacHashAlgorithm: 'SHA-256',
});
const p12Bytes = pfx.toSchema().toBER(false);
return { p12Bytes, keyPair, certDer };
}
let testP12: Awaited<ReturnType<typeof buildTestP12>>;
beforeAll(async () => {
pkijs.setEngine('test', crypto, cryptoEngine);
testP12 = await buildTestP12('alice@example.com', 'Alice Test', 'p12pass');
});
describe('importPkcs12', () => {
it('imports a valid PKCS#12 file and produces a key record', async () => {
const result = await importPkcs12(testP12.p12Bytes, 'p12pass', 'storagepass');
expect(result.keyRecord).toBeDefined();
expect(result.keyRecord.email).toBe('alice@example.com');
expect(result.keyRecord.subject).toContain('Alice Test');
expect(result.keyRecord.certificate).toBeDefined();
expect(result.keyRecord.encryptedPrivateKey.byteLength).toBeGreaterThan(0);
expect(result.keyRecord.salt.byteLength).toBeGreaterThan(0);
expect(result.keyRecord.iv.byteLength).toBeGreaterThan(0);
expect(result.keyRecord.kdfIterations).toBe(600_000);
expect(result.keyRecord.fingerprint).toBeTruthy();
expect(result.certInfo).toBeDefined();
expect(result.certInfo.emailAddresses).toContain('alice@example.com');
});
it('throws on invalid ASN.1 data', async () => {
const garbage = new Uint8Array([0, 1, 2, 3]).buffer;
await expect(importPkcs12(garbage, 'pass', 'store')).rejects.toThrow();
});
});
describe('unlockPrivateKey', () => {
it('unlocks and returns signing and decryption keys', async () => {
const result = await importPkcs12(testP12.p12Bytes, 'p12pass', 'storagepass');
const { signingKey, decryptionKey } = await unlockPrivateKey(result.keyRecord, 'storagepass');
expect(signingKey).toBeDefined();
expect(signingKey.type).toBe('private');
expect(signingKey.extractable).toBe(false);
expect(decryptionKey).toBeDefined();
expect(decryptionKey!.type).toBe('private');
expect(decryptionKey!.extractable).toBe(false);
});
it('throws on incorrect passphrase', async () => {
const result = await importPkcs12(testP12.p12Bytes, 'p12pass', 'storagepass');
await expect(unlockPrivateKey(result.keyRecord, 'wrongpass')).rejects.toThrow('Incorrect passphrase');
});
});
describe('decryptPrivateKeyBytes', () => {
it('returns raw PKCS#8 bytes', async () => {
const result = await importPkcs12(testP12.p12Bytes, 'p12pass', 'storagepass');
const pkcs8 = await decryptPrivateKeyBytes(result.keyRecord, 'storagepass');
expect(pkcs8).toBeInstanceOf(ArrayBuffer);
expect(pkcs8.byteLength).toBeGreaterThan(0);
});
it('throws on incorrect passphrase', async () => {
const result = await importPkcs12(testP12.p12Bytes, 'p12pass', 'storagepass');
await expect(decryptPrivateKeyBytes(result.keyRecord, 'bad')).rejects.toThrow('Incorrect passphrase');
});
});
describe('exportPkcs12', () => {
it('produces a valid PKCS#12 that can be re-imported', async () => {
const imported = await importPkcs12(testP12.p12Bytes, 'p12pass', 'storagepass');
// Export
const p12Out = await exportPkcs12(imported.keyRecord, 'storagepass', 'exportpass');
expect(p12Out).toBeInstanceOf(ArrayBuffer);
expect(p12Out.byteLength).toBeGreaterThan(0);
// Re-import
const reimported = await importPkcs12(p12Out, 'exportpass', 'newstoragepass');
expect(reimported.keyRecord.email).toBe('alice@example.com');
expect(reimported.keyRecord.subject).toContain('Alice Test');
expect(reimported.keyRecord.fingerprint).toBe(imported.keyRecord.fingerprint);
});
it('throws on incorrect storage passphrase', async () => {
const imported = await importPkcs12(testP12.p12Bytes, 'p12pass', 'storagepass');
await expect(exportPkcs12(imported.keyRecord, 'wrong', 'exportpass')).rejects.toThrow('Incorrect passphrase');
});
});
+342
View File
@@ -0,0 +1,342 @@
// @vitest-environment node
import { describe, it, expect, beforeAll } from 'vitest';
import * as pkijs from 'pkijs';
import * as asn1js from 'asn1js';
import { smimeSign } from '../smime-sign';
import { smimeEncrypt } from '../smime-encrypt';
import { smimeDecrypt, SmimeKeyLockedError, findDecryptionCandidates, normalizeCmsBytes } from '../smime-decrypt';
import { smimeVerify } from '../smime-verify';
import { extractCertificateInfo } from '../certificate-utils';
import type { SmimeKeyRecord } from '../types';
/**
* Integration tests for S/MIME sign→verify and encrypt→decrypt roundtrips.
* Uses Node.js crypto (not jsdom) for accurate Web Crypto behavior.
*/
const testMimeBytes = new TextEncoder().encode(
'Content-Type: text/plain; charset=utf-8\r\n\r\nHello, World!',
);
const cryptoEngine = new pkijs.CryptoEngine({
crypto: crypto,
subtle: crypto.subtle,
name: 'webcrypto',
});
async function buildCert(
cn: string,
email: string,
publicKey: CryptoKey,
signingPrivateKey: CryptoKey,
): Promise<{ cert: pkijs.Certificate; certDer: ArrayBuffer }> {
const cert = new pkijs.Certificate();
cert.version = 2;
cert.serialNumber = new asn1js.Integer({ value: Math.floor(Math.random() * 100000) });
cert.issuer.typesAndValues.push(
new pkijs.AttributeTypeAndValue({
type: '2.5.4.3',
value: new asn1js.Utf8String({ value: cn }),
}),
);
cert.subject.typesAndValues.push(
new pkijs.AttributeTypeAndValue({
type: '2.5.4.3',
value: new asn1js.Utf8String({ value: cn }),
}),
);
cert.subject.typesAndValues.push(
new pkijs.AttributeTypeAndValue({
type: '1.2.840.113549.1.9.1',
value: new asn1js.IA5String({ value: email }),
}),
);
cert.notBefore.value = new Date('2024-01-01T00:00:00Z');
cert.notAfter.value = new Date('2030-12-31T23:59:59Z');
await cert.subjectPublicKeyInfo.importKey(publicKey, cryptoEngine);
await cert.sign(signingPrivateKey, 'SHA-256', cryptoEngine);
const certDer = cert.toSchema(true).toBER(false);
return { cert, certDer };
}
async function makeKeyRecord(
id: string,
email: string,
certDer: ArrayBuffer,
): Promise<SmimeKeyRecord> {
const cert = new pkijs.Certificate({
schema: asn1js.fromBER(certDer).result,
});
const info = await extractCertificateInfo(cert, certDer);
return {
id,
email: email.toLowerCase(),
certificate: certDer,
certificateChain: [],
encryptedPrivateKey: new ArrayBuffer(0),
salt: new ArrayBuffer(0),
iv: new ArrayBuffer(0),
kdfIterations: 600000,
issuer: info.issuer,
subject: info.subject,
serialNumber: info.serialNumber,
notBefore: info.notBefore,
notAfter: info.notAfter,
fingerprint: info.fingerprint,
algorithm: info.algorithm,
capabilities: info.capabilities,
};
}
// Signing key pair and cert (RSASSA-PKCS1-v1_5 public key embedded in cert)
let signKeyPair: globalThis.CryptoKeyPair;
let signCertDer: ArrayBuffer;
// Encryption key pair and cert (RSA-OAEP public key embedded in cert)
let encKeyPair: globalThis.CryptoKeyPair;
let encCertDer: ArrayBuffer;
let encKeyRecord: SmimeKeyRecord;
// Second encryption identity for cross-recipient tests
let bobEncKeyPair: globalThis.CryptoKeyPair;
let bobEncCertDer: ArrayBuffer;
let bobKeyRecord: SmimeKeyRecord;
beforeAll(async () => {
pkijs.setEngine('test', crypto, cryptoEngine);
// --- Signing identity ---
signKeyPair = await crypto.subtle.generateKey(
{ name: 'RSASSA-PKCS1-v1_5', modulusLength: 2048, publicExponent: new Uint8Array([1, 0, 1]), hash: 'SHA-256' },
true,
['sign', 'verify'],
);
const signResult = await buildCert('Alice Signer', 'alice@example.com', signKeyPair.publicKey, signKeyPair.privateKey);
signCertDer = signResult.certDer;
// --- Encryption identity (Alice) ---
encKeyPair = await crypto.subtle.generateKey(
{ name: 'RSA-OAEP', modulusLength: 2048, publicExponent: new Uint8Array([1, 0, 1]), hash: 'SHA-256' },
true,
['encrypt', 'decrypt', 'wrapKey', 'unwrapKey'],
);
// Self-sign with a temporary signing key
const tempSignKey = await crypto.subtle.generateKey(
{ name: 'RSASSA-PKCS1-v1_5', modulusLength: 2048, publicExponent: new Uint8Array([1, 0, 1]), hash: 'SHA-256' },
true,
['sign', 'verify'],
);
const encResult = await buildCert('Alice', 'alice@example.com', encKeyPair.publicKey, tempSignKey.privateKey);
encCertDer = encResult.certDer;
encKeyRecord = await makeKeyRecord('key-alice-enc', 'alice@example.com', encCertDer);
// --- Bob encryption identity ---
bobEncKeyPair = await crypto.subtle.generateKey(
{ name: 'RSA-OAEP', modulusLength: 2048, publicExponent: new Uint8Array([1, 0, 1]), hash: 'SHA-256' },
true,
['encrypt', 'decrypt', 'wrapKey', 'unwrapKey'],
);
const bobTempSignKey = await crypto.subtle.generateKey(
{ name: 'RSASSA-PKCS1-v1_5', modulusLength: 2048, publicExponent: new Uint8Array([1, 0, 1]), hash: 'SHA-256' },
true,
['sign', 'verify'],
);
const bobResult = await buildCert('Bob', 'bob@example.com', bobEncKeyPair.publicKey, bobTempSignKey.privateKey);
bobEncCertDer = bobResult.certDer;
bobKeyRecord = await makeKeyRecord('key-bob-enc', 'bob@example.com', bobEncCertDer);
});
describe('smimeSign + smimeVerify roundtrip', () => {
it('signs and verifies a message successfully', async () => {
const signedBlob = await smimeSign(testMimeBytes, signKeyPair.privateKey, signCertDer);
expect(signedBlob).toBeInstanceOf(Blob);
expect(signedBlob.type).toContain('application/pkcs7-mime');
const cmsBytes = await signedBlob.arrayBuffer();
const result = await smimeVerify(cmsBytes, 'alice@example.com');
expect(result.status.isSigned).toBe(true);
expect(result.status.signatureValid).toBe(true);
expect(result.status.signerEmailMatch).toBe(true);
expect(result.status.signerCert).toBeDefined();
expect(result.status.signerCert!.email).toBe('alice@example.com');
const innerText = new TextDecoder().decode(result.mimeBytes);
expect(innerText).toContain('Hello, World!');
});
it('reports email mismatch when From differs from signer', async () => {
const signedBlob = await smimeSign(testMimeBytes, signKeyPair.privateKey, signCertDer);
const cmsBytes = await signedBlob.arrayBuffer();
const result = await smimeVerify(cmsBytes, 'evil@attacker.com');
expect(result.status.isSigned).toBe(true);
expect(result.status.signerEmailMatch).toBe(false);
});
});
describe('smimeEncrypt + smimeDecrypt roundtrip', () => {
it('encrypts and decrypts a message', async () => {
const encryptedBlob = await smimeEncrypt(
testMimeBytes,
[encCertDer],
encCertDer,
);
expect(encryptedBlob).toBeInstanceOf(Blob);
expect(encryptedBlob.type).toContain('application/pkcs7-mime');
const cmsBytes = await encryptedBlob.arrayBuffer();
const unlockedKeys = new Map<string, CryptoKey>();
unlockedKeys.set(encKeyRecord.id, encKeyPair.privateKey);
const result = await smimeDecrypt({
cmsBytes,
keyRecords: [encKeyRecord],
unlockedKeys,
});
expect(result.mimeBytes).toBeDefined();
const decryptedText = new TextDecoder().decode(result.mimeBytes);
expect(decryptedText).toContain('Hello, World!');
expect(result.keyRecordId).toBe(encKeyRecord.id);
});
it('throws when no matching key is available', async () => {
const encryptedBlob = await smimeEncrypt(
testMimeBytes,
[encCertDer],
encCertDer,
);
const cmsBytes = await encryptedBlob.arrayBuffer();
// Bob's key record doesn't match Alice's encrypted message
await expect(
smimeDecrypt({
cmsBytes,
keyRecords: [bobKeyRecord],
unlockedKeys: new Map(),
}),
).rejects.toThrow('No imported S/MIME key matches');
});
});
describe('SmimeKeyLockedError', () => {
it('has correct name and keyRecordId', () => {
const err = new SmimeKeyLockedError('test', 'key-1');
expect(err.name).toBe('SmimeKeyLockedError');
expect(err.keyRecordId).toBe('key-1');
expect(err.message).toBe('test');
expect(err).toBeInstanceOf(Error);
});
});
describe('findDecryptionCandidates', () => {
it('returns empty array for invalid CMS data', () => {
const garbage = new Uint8Array([0, 1, 2, 3]).buffer;
const result = findDecryptionCandidates(garbage, [encKeyRecord]);
expect(result).toEqual([]);
});
});
describe('smimeVerify edge cases', () => {
it('throws on invalid ASN.1 data', async () => {
const garbage = new Uint8Array([0, 1, 2, 3]).buffer;
await expect(smimeVerify(garbage)).rejects.toThrow();
});
});
describe('normalizeCmsBytes', () => {
// Helper: a minimal DER-encoded ASN.1 SEQUENCE (0x30 tag)
const derBytes = new Uint8Array([0x30, 0x03, 0x02, 0x01, 0x05]);
it('passes through raw DER unchanged', () => {
const result = new Uint8Array(normalizeCmsBytes(derBytes.buffer as ArrayBuffer));
expect(result).toEqual(derBytes);
});
it('passes through empty buffer unchanged', () => {
const result = normalizeCmsBytes(new ArrayBuffer(0));
expect(result.byteLength).toBe(0);
});
it('decodes plain base64 content', () => {
const b64 = btoa(String.fromCharCode(...derBytes));
const input = new TextEncoder().encode(b64).buffer as ArrayBuffer;
const result = new Uint8Array(normalizeCmsBytes(input));
expect(result).toEqual(derBytes);
});
it('decodes base64 content with MIME headers', () => {
const b64 = btoa(String.fromCharCode(...derBytes));
const mime =
'Content-Type: application/pkcs7-mime\r\n' +
'Content-Transfer-Encoding: base64\r\n' +
'\r\n' +
b64 + '\r\n';
const input = new TextEncoder().encode(mime).buffer as ArrayBuffer;
const result = new Uint8Array(normalizeCmsBytes(input));
expect(result).toEqual(derBytes);
});
it('decodes PEM-wrapped content', () => {
const b64 = btoa(String.fromCharCode(...derBytes));
const pem = '-----BEGIN PKCS7-----\n' + b64 + '\n-----END PKCS7-----\n';
const input = new TextEncoder().encode(pem).buffer as ArrayBuffer;
const result = new Uint8Array(normalizeCmsBytes(input));
expect(result).toEqual(derBytes);
});
it('decodes MIME headers with unix line endings', () => {
const b64 = btoa(String.fromCharCode(...derBytes));
const mime =
'Content-Type: application/pkcs7-mime\n' +
'Content-Transfer-Encoding: base64\n' +
'\n' +
b64 + '\n';
const input = new TextEncoder().encode(mime).buffer as ArrayBuffer;
const result = new Uint8Array(normalizeCmsBytes(input));
expect(result).toEqual(derBytes);
});
it('decodes base64 when MIME headers are very long', () => {
const b64 = btoa(String.fromCharCode(...derBytes));
const longHeader = 'X-Long-Header: ' + 'A'.repeat(3000) + '\r\n';
const mime =
longHeader +
'Content-Type: application/pkcs7-mime\r\n' +
'Content-Transfer-Encoding: base64\r\n' +
'\r\n' +
b64 + '\r\n';
const input = new TextEncoder().encode(mime).buffer as ArrayBuffer;
const result = new Uint8Array(normalizeCmsBytes(input));
expect(result).toEqual(derBytes);
});
it('extracts largest base64 block from multipart-like text', () => {
const b64 = btoa(String.fromCharCode(...derBytes));
const multipartLike =
'Content-Type: multipart/mixed; boundary="b"\r\n\r\n' +
'--b\r\n' +
'Content-Type: text/plain\r\n\r\n' +
'hello\r\n' +
'--b\r\n' +
'Content-Type: application/pkcs7-mime\r\n' +
'Content-Transfer-Encoding: base64\r\n\r\n' +
b64 + '\r\n' +
'--b--\r\n';
const input = new TextEncoder().encode(multipartLike).buffer as ArrayBuffer;
const result = new Uint8Array(normalizeCmsBytes(input));
expect(result).toEqual(derBytes);
});
it('returns original when content is not decodable', () => {
const garbage = new Uint8Array([0x01, 0x02, 0xFF, 0xFE]);
const result = normalizeCmsBytes(garbage.buffer as ArrayBuffer);
// Should return original since it can\'t be decoded
expect(result.byteLength).toBeGreaterThan(0);
});
});
+193
View File
@@ -0,0 +1,193 @@
import { describe, it, expect } from 'vitest';
import { detectSmime } from '../smime-detect';
describe('detectSmime', () => {
describe('no S/MIME content', () => {
it('returns null type when no arguments provided', () => {
const result = detectSmime();
expect(result.type).toBeNull();
expect(result.supported).toBe(false);
});
it('returns null type for plain text content', () => {
const result = detectSmime('text/plain');
expect(result.type).toBeNull();
expect(result.supported).toBe(false);
});
it('returns null type for multipart/mixed without S/MIME', () => {
const result = detectSmime('multipart/mixed; boundary="abc"');
expect(result.type).toBeNull();
expect(result.supported).toBe(false);
});
});
describe('Content-Type header detection', () => {
it('detects enveloped-data from Content-Type', () => {
const ct = 'application/pkcs7-mime; smime-type=enveloped-data; name="smime.p7m"';
const body = { partId: '1', blobId: 'blob1', type: ct };
const result = detectSmime(ct, body);
expect(result.type).toBe('enveloped-data');
expect(result.supported).toBe(true);
expect(result.blobId).toBe('blob1');
expect(result.partId).toBe('1');
});
it('detects signed-data from Content-Type', () => {
const ct = 'application/pkcs7-mime; smime-type=signed-data; name="smime.p7m"';
const body = { partId: '2', blobId: 'blob2', type: ct };
const result = detectSmime(ct, body);
expect(result.type).toBe('signed-data');
expect(result.supported).toBe(true);
expect(result.blobId).toBe('blob2');
});
it('detects x-pkcs7-mime variant', () => {
const ct = 'application/x-pkcs7-mime; smime-type=enveloped-data';
const body = { partId: '1', blobId: 'blob1', type: ct };
const result = detectSmime(ct, body);
expect(result.type).toBe('enveloped-data');
expect(result.supported).toBe(true);
});
it('detects detached signature via multipart/signed', () => {
const ct = 'multipart/signed; protocol="application/pkcs7-signature"; micalg=sha-256';
const result = detectSmime(ct);
expect(result.type).toBe('detached-sig');
expect(result.supported).toBe(false);
});
it('handles generic pkcs7-mime without smime-type', () => {
const ct = 'application/pkcs7-mime; name="smime.p7m"';
const body = { partId: '1', blobId: 'blob1', type: ct };
const result = detectSmime(ct, body);
// Should default to enveloped-data for generic pkcs7-mime
expect(result.type).toBe('enveloped-data');
expect(result.blobId).toBe('blob1');
});
it('is case-insensitive for Content-Type', () => {
const ct = 'Application/PKCS7-MIME; smime-type=Enveloped-Data';
const body = { partId: '1', blobId: 'b1', type: ct };
const result = detectSmime(ct, body);
expect(result.type).toBe('enveloped-data');
expect(result.supported).toBe(true);
});
});
describe('bodyStructure detection', () => {
it('finds pkcs7-mime part in bodyStructure tree', () => {
const body = {
type: 'multipart/mixed',
subParts: [
{ partId: '1', type: 'text/plain', blobId: 'text-blob' },
{
partId: '2',
type: 'application/pkcs7-mime; smime-type=enveloped-data',
blobId: 'cms-blob',
},
],
};
const result = detectSmime(undefined, body);
expect(result.type).toBe('enveloped-data');
expect(result.supported).toBe(true);
expect(result.blobId).toBe('cms-blob');
expect(result.partId).toBe('2');
});
it('detects detached sig in multipart/signed bodyStructure', () => {
const body = {
type: 'multipart/signed',
subParts: [
{ partId: '1', type: 'text/plain', blobId: 'text-blob' },
{ partId: '2', type: 'application/pkcs7-signature', blobId: 'sig-blob' },
],
};
const result = detectSmime(undefined, body);
expect(result.type).toBe('detached-sig');
expect(result.supported).toBe(false);
});
it('walks nested bodyStructure', () => {
const body = {
type: 'multipart/mixed',
subParts: [
{
type: 'multipart/alternative',
subParts: [
{ partId: '1.1', type: 'text/plain', blobId: 'txt' },
{ partId: '1.2', type: 'text/html', blobId: 'html' },
],
},
{
partId: '2',
type: 'application/pkcs7-mime; smime-type=signed-data',
blobId: 'sig-blob',
},
],
};
const result = detectSmime(undefined, body);
expect(result.type).toBe('signed-data');
expect(result.supported).toBe(true);
expect(result.blobId).toBe('sig-blob');
});
});
describe('attachment detection', () => {
it('detects .p7m attachment', () => {
const attachments = [
{ partId: '3', blobId: 'att-blob', name: 'message.p7m', type: 'application/octet-stream' },
];
const result = detectSmime(undefined, null, attachments);
expect(result.type).toBe('enveloped-data');
expect(result.supported).toBe(true);
expect(result.blobId).toBe('att-blob');
});
it('detects .p7s attachment as detached-sig', () => {
const attachments = [
{ partId: '3', blobId: 'sig-blob', name: 'smime.p7s', type: 'application/octet-stream' },
];
const result = detectSmime(undefined, null, attachments);
expect(result.type).toBe('detached-sig');
expect(result.supported).toBe(false);
});
it('detects pkcs7-mime attachment type', () => {
const attachments = [
{
partId: '2',
blobId: 'enc-blob',
name: 'encrypted.bin',
type: 'application/pkcs7-mime; smime-type=enveloped-data',
},
];
const result = detectSmime(undefined, null, attachments);
expect(result.type).toBe('enveloped-data');
expect(result.supported).toBe(true);
});
it('skips non-S/MIME attachments', () => {
const attachments = [
{ partId: '2', blobId: 'pdf-blob', name: 'document.pdf', type: 'application/pdf' },
];
const result = detectSmime(undefined, null, attachments);
expect(result.type).toBeNull();
expect(result.supported).toBe(false);
});
});
describe('priority order', () => {
it('Content-Type takes precedence over bodyStructure', () => {
const ct = 'application/pkcs7-mime; smime-type=enveloped-data';
const body = {
partId: '1',
blobId: 'from-ct',
type: ct,
};
const result = detectSmime(ct, body);
expect(result.type).toBe('enveloped-data');
expect(result.blobId).toBe('from-ct');
});
});
});
+394
View File
@@ -0,0 +1,394 @@
import { describe, it, expect, vi, beforeEach } from 'vitest';
// Mock IndexedDB storage functions before importing store
vi.mock('@/lib/smime/key-storage', () => ({
saveKeyRecord: vi.fn().mockResolvedValue(undefined),
listKeyRecords: vi.fn().mockResolvedValue([]),
deleteKeyRecord: vi.fn().mockResolvedValue(undefined),
savePublicCert: vi.fn().mockResolvedValue(undefined),
listPublicCerts: vi.fn().mockResolvedValue([]),
deletePublicCert: vi.fn().mockResolvedValue(undefined),
}));
vi.mock('@/lib/smime/pkcs12-import', () => ({
importPkcs12: vi.fn(),
unlockPrivateKey: vi.fn(),
}));
vi.mock('@/lib/smime/certificate-utils', () => ({
parseCertificatePemOrDer: vi.fn(),
extractCertificateInfo: vi.fn(),
}));
import { useSmimeStore } from '@/stores/smime-store';
import { listKeyRecords, listPublicCerts, saveKeyRecord, deleteKeyRecord, savePublicCert, deletePublicCert } from '@/lib/smime/key-storage';
import { importPkcs12, unlockPrivateKey } from '@/lib/smime/pkcs12-import';
import type { SmimeKeyRecord, SmimePublicCert } from '@/lib/smime/types';
const mockKeyRecord: SmimeKeyRecord = {
id: 'key-1',
email: 'user@example.com',
certificate: new ArrayBuffer(10),
certificateChain: [],
encryptedPrivateKey: new ArrayBuffer(32),
salt: new ArrayBuffer(16),
iv: new ArrayBuffer(12),
kdfIterations: 600000,
issuer: 'CN=Test CA',
subject: 'CN=Test User',
serialNumber: '01',
notBefore: '2024-01-01T00:00:00Z',
notAfter: '2030-12-31T23:59:59Z',
fingerprint: 'aa:bb:cc',
algorithm: 'RSA-2048',
capabilities: { canSign: true, canEncrypt: true },
};
beforeEach(() => {
localStorage.clear();
sessionStorage.clear();
// Reset store state
useSmimeStore.setState({
keyRecords: [],
publicCerts: [],
unlockedKeys: new Map(),
unlockedDecryptionKeys: new Map(),
identityKeyBindings: {},
defaultSignIdentity: {},
defaultEncrypt: false,
rememberUnlockedKeys: false,
autoImportSignerCerts: false,
isLoading: false,
error: null,
});
vi.clearAllMocks();
});
describe('smime-store', () => {
describe('load', () => {
it('loads key records and public certs from IndexedDB', async () => {
const records = [mockKeyRecord];
const certs: SmimePublicCert[] = [];
vi.mocked(listKeyRecords).mockResolvedValue(records);
vi.mocked(listPublicCerts).mockResolvedValue(certs);
await useSmimeStore.getState().load();
const state = useSmimeStore.getState();
expect(state.keyRecords).toEqual(records);
expect(state.publicCerts).toEqual(certs);
expect(state.isLoading).toBe(false);
});
it('re-unlocks remembered keys during load', async () => {
const records = [mockKeyRecord];
const mockSigningKey = {} as CryptoKey;
const mockDecryptionKey = {} as CryptoKey;
sessionStorage.setItem('smime-unlocked-session', JSON.stringify({ 'key-1': 'passphrase' }));
useSmimeStore.setState({ rememberUnlockedKeys: true });
vi.mocked(listKeyRecords).mockResolvedValue(records);
vi.mocked(listPublicCerts).mockResolvedValue([]);
vi.mocked(unlockPrivateKey).mockResolvedValue({
signingKey: mockSigningKey,
decryptionKey: mockDecryptionKey,
});
await useSmimeStore.getState().load();
expect(unlockPrivateKey).toHaveBeenCalledWith(mockKeyRecord, 'passphrase');
expect(useSmimeStore.getState().getUnlockedKey('key-1')).toBe(mockSigningKey);
expect(useSmimeStore.getState().unlockedDecryptionKeys.get('key-1')).toBe(mockDecryptionKey);
});
it('removes stale remembered keys when re-unlock fails', async () => {
const records = [mockKeyRecord];
sessionStorage.setItem('smime-unlocked-session', JSON.stringify({ 'key-1': 'bad-pass' }));
useSmimeStore.setState({ rememberUnlockedKeys: true });
vi.mocked(listKeyRecords).mockResolvedValue(records);
vi.mocked(listPublicCerts).mockResolvedValue([]);
vi.mocked(unlockPrivateKey).mockRejectedValue(new Error('Incorrect passphrase'));
await useSmimeStore.getState().load();
expect(sessionStorage.getItem('smime-unlocked-session')).toBeNull();
expect(useSmimeStore.getState().isKeyUnlocked('key-1')).toBe(false);
});
it('sets error on failure', async () => {
vi.mocked(listKeyRecords).mockRejectedValue(new Error('DB failed'));
await useSmimeStore.getState().load();
expect(useSmimeStore.getState().error).toBe('DB failed');
expect(useSmimeStore.getState().isLoading).toBe(false);
});
});
describe('importPKCS12', () => {
it('imports and adds key record', async () => {
vi.mocked(importPkcs12).mockResolvedValue({
keyRecord: mockKeyRecord,
certInfo: {} as any,
});
const result = await useSmimeStore.getState().importPKCS12(
new ArrayBuffer(10),
'p12pass',
'storagepass',
);
expect(result.id).toBe('key-1');
expect(saveKeyRecord).toHaveBeenCalledWith(mockKeyRecord);
expect(useSmimeStore.getState().keyRecords).toHaveLength(1);
});
it('sets error on import failure', async () => {
vi.mocked(importPkcs12).mockRejectedValue(new Error('Bad password'));
await expect(
useSmimeStore.getState().importPKCS12(new ArrayBuffer(10), 'wrong', 'pass'),
).rejects.toThrow('Bad password');
expect(useSmimeStore.getState().error).toBe('Bad password');
});
});
describe('removeKeyRecord', () => {
it('removes key record and clears bindings', async () => {
useSmimeStore.setState({
keyRecords: [mockKeyRecord],
identityKeyBindings: { 'identity-1': 'key-1' },
unlockedKeys: new Map([['key-1', {} as CryptoKey]]),
unlockedDecryptionKeys: new Map([['key-1', {} as CryptoKey]]),
});
await useSmimeStore.getState().removeKeyRecord('key-1');
expect(deleteKeyRecord).toHaveBeenCalledWith('key-1');
expect(useSmimeStore.getState().keyRecords).toHaveLength(0);
expect(useSmimeStore.getState().identityKeyBindings).toEqual({});
expect(useSmimeStore.getState().unlockedKeys.has('key-1')).toBe(false);
expect(useSmimeStore.getState().unlockedDecryptionKeys.has('key-1')).toBe(false);
});
});
describe('removePublicCert', () => {
it('removes public cert', async () => {
const cert: SmimePublicCert = {
id: 'cert-1',
email: 'recipient@example.com',
certificate: new ArrayBuffer(10),
issuer: 'CN=CA',
subject: 'CN=Recipient',
notBefore: '2024-01-01T00:00:00Z',
notAfter: '2030-12-31T23:59:59Z',
fingerprint: 'aa:bb',
source: 'manual',
};
useSmimeStore.setState({ publicCerts: [cert] });
await useSmimeStore.getState().removePublicCert('cert-1');
expect(deletePublicCert).toHaveBeenCalledWith('cert-1');
expect(useSmimeStore.getState().publicCerts).toHaveLength(0);
});
});
describe('unlockKey + lockKey', () => {
it('unlocks a key', async () => {
const mockSigningKey = {} as CryptoKey;
const mockDecryptionKey = {} as CryptoKey;
vi.mocked(unlockPrivateKey).mockResolvedValue({ signingKey: mockSigningKey, decryptionKey: mockDecryptionKey });
useSmimeStore.setState({ keyRecords: [mockKeyRecord] });
await useSmimeStore.getState().unlockKey('key-1', 'passphrase');
expect(useSmimeStore.getState().isKeyUnlocked('key-1')).toBe(true);
expect(useSmimeStore.getState().getUnlockedKey('key-1')).toBe(mockSigningKey);
expect(useSmimeStore.getState().unlockedDecryptionKeys.get('key-1')).toBe(mockDecryptionKey);
});
it('stores the passphrase for session rehydration when remember is enabled', async () => {
const mockSigningKey = {} as CryptoKey;
vi.mocked(unlockPrivateKey).mockResolvedValue({ signingKey: mockSigningKey });
useSmimeStore.setState({ keyRecords: [mockKeyRecord], rememberUnlockedKeys: true });
await useSmimeStore.getState().unlockKey('key-1', 'passphrase');
expect(sessionStorage.getItem('smime-unlocked-session')).toBe(
JSON.stringify({ 'key-1': 'passphrase' }),
);
});
it('stores only the signing key when no decryption key is available', async () => {
const mockSigningKey = {} as CryptoKey;
vi.mocked(unlockPrivateKey).mockResolvedValue({ signingKey: mockSigningKey });
useSmimeStore.setState({ keyRecords: [mockKeyRecord] });
await useSmimeStore.getState().unlockKey('key-1', 'passphrase');
expect(useSmimeStore.getState().getUnlockedKey('key-1')).toBe(mockSigningKey);
expect(useSmimeStore.getState().unlockedDecryptionKeys.has('key-1')).toBe(false);
});
it('throws for non-existent key record', async () => {
await expect(
useSmimeStore.getState().unlockKey('non-existent', 'pass'),
).rejects.toThrow('Key record not found');
});
it('locks a key', () => {
sessionStorage.setItem('smime-unlocked-session', JSON.stringify({ 'key-1': 'passphrase' }));
useSmimeStore.setState({
unlockedKeys: new Map([['key-1', {} as CryptoKey]]),
unlockedDecryptionKeys: new Map([['key-1', {} as CryptoKey]]),
});
useSmimeStore.getState().lockKey('key-1');
expect(useSmimeStore.getState().isKeyUnlocked('key-1')).toBe(false);
expect(useSmimeStore.getState().unlockedDecryptionKeys.has('key-1')).toBe(false);
expect(sessionStorage.getItem('smime-unlocked-session')).toBeNull();
});
it('locks all keys', () => {
sessionStorage.setItem(
'smime-unlocked-session',
JSON.stringify({ 'key-1': 'one', 'key-2': 'two' }),
);
useSmimeStore.setState({
unlockedKeys: new Map([
['key-1', {} as CryptoKey],
['key-2', {} as CryptoKey],
]),
unlockedDecryptionKeys: new Map([
['key-1', {} as CryptoKey],
['key-2', {} as CryptoKey],
]),
});
useSmimeStore.getState().lockAllKeys();
expect(useSmimeStore.getState().unlockedKeys.size).toBe(0);
expect(useSmimeStore.getState().unlockedDecryptionKeys.size).toBe(0);
expect(sessionStorage.getItem('smime-unlocked-session')).toBeNull();
});
});
describe('identity bindings', () => {
it('binds an identity to a key', () => {
useSmimeStore.getState().bindIdentityToKey('identity-1', 'key-1');
expect(useSmimeStore.getState().identityKeyBindings['identity-1']).toBe('key-1');
});
it('unbinds an identity', () => {
useSmimeStore.setState({ identityKeyBindings: { 'identity-1': 'key-1' } });
useSmimeStore.getState().bindIdentityToKey('identity-1', null);
expect(useSmimeStore.getState().identityKeyBindings['identity-1']).toBeUndefined();
});
it('getKeyRecordForIdentity returns the bound record', () => {
useSmimeStore.setState({
keyRecords: [mockKeyRecord],
identityKeyBindings: { 'identity-1': 'key-1' },
});
const record = useSmimeStore.getState().getKeyRecordForIdentity('identity-1');
expect(record?.id).toBe('key-1');
});
it('getKeyRecordForIdentity returns undefined for unbound identity', () => {
const record = useSmimeStore.getState().getKeyRecordForIdentity('identity-2');
expect(record).toBeUndefined();
});
});
describe('getPublicCertForEmail', () => {
it('finds cert by email (case-insensitive)', () => {
const cert: SmimePublicCert = {
id: 'c1',
email: 'bob@example.com',
certificate: new ArrayBuffer(10),
issuer: 'CN=CA',
subject: 'CN=Bob',
notBefore: '2024-01-01',
notAfter: '2030-12-31',
fingerprint: 'ff',
source: 'manual',
};
useSmimeStore.setState({ publicCerts: [cert] });
expect(useSmimeStore.getState().getPublicCertForEmail('Bob@Example.COM')?.id).toBe('c1');
});
it('returns undefined when not found', () => {
expect(useSmimeStore.getState().getPublicCertForEmail('nobody@test.com')).toBeUndefined();
});
});
describe('getRecipientCerts', () => {
it('partitions emails into found and missing', () => {
const cert: SmimePublicCert = {
id: 'c1',
email: 'known@example.com',
certificate: new ArrayBuffer(10),
issuer: '',
subject: '',
notBefore: '',
notAfter: '',
fingerprint: '',
source: 'manual',
};
useSmimeStore.setState({ publicCerts: [cert] });
const { found, missing } = useSmimeStore.getState().getRecipientCerts([
'known@example.com',
'unknown@example.com',
]);
expect(found).toHaveLength(1);
expect(found[0].id).toBe('c1');
expect(missing).toEqual(['unknown@example.com']);
});
});
describe('preferences', () => {
it('sets sign default for identity', () => {
useSmimeStore.getState().setSignDefault('identity-1', true);
expect(useSmimeStore.getState().defaultSignIdentity['identity-1']).toBe(true);
});
it('sets encrypt default', () => {
useSmimeStore.getState().setEncryptDefault(true);
expect(useSmimeStore.getState().defaultEncrypt).toBe(true);
});
it('sets remember unlocked keys and clears when disabled', () => {
sessionStorage.setItem('smime-unlocked-session', JSON.stringify({ 'key-1': 'passphrase' }));
useSmimeStore.setState({
unlockedKeys: new Map([['key-1', {} as CryptoKey]]),
});
useSmimeStore.getState().setRememberUnlockedKeys(false);
expect(useSmimeStore.getState().rememberUnlockedKeys).toBe(false);
expect(useSmimeStore.getState().unlockedKeys.size).toBe(0);
expect(sessionStorage.getItem('smime-unlocked-session')).toBeNull();
});
it('sets auto import signer certs', () => {
useSmimeStore.getState().setAutoImportSignerCerts(true);
expect(useSmimeStore.getState().autoImportSignerCerts).toBe(true);
});
});
describe('setError', () => {
it('sets and clears error', () => {
useSmimeStore.getState().setError('Something went wrong');
expect(useSmimeStore.getState().error).toBe('Something went wrong');
useSmimeStore.getState().setError(null);
expect(useSmimeStore.getState().error).toBeNull();
});
});
});
+243
View File
@@ -0,0 +1,243 @@
import * as asn1js from 'asn1js';
import * as pkijs from 'pkijs';
import { Convert } from 'pvtsutils';
import type { CertificateInfo, SmimeKeyCapabilities } from './types';
/** OID for id-kp-emailProtection (S/MIME) */
const OID_EMAIL_PROTECTION = '1.3.6.1.5.5.7.3.4';
/** OID for SubjectAlternativeName */
const OID_SAN = '2.5.29.17';
// ── PEM/DER conversions ──────────────────────────────────────────────
export function pemToDer(pem: string): ArrayBuffer {
const lines = pem
.replace(/-----BEGIN [^-]+-----/, '')
.replace(/-----END [^-]+-----/, '')
.replace(/\s/g, '');
return Convert.FromBase64(lines);
}
export function derToPem(der: ArrayBuffer, label: string): string {
const b64 = Convert.ToBase64(der);
const lines: string[] = [];
for (let i = 0; i < b64.length; i += 64) {
lines.push(b64.slice(i, i + 64));
}
return `-----BEGIN ${label}-----\n${lines.join('\n')}\n-----END ${label}-----`;
}
export function isPem(data: string): boolean {
return /-----BEGIN (CERTIFICATE|PKCS12|ENCRYPTED PRIVATE KEY|PRIVATE KEY)-----/.test(data);
}
// ── Certificate parsing ──────────────────────────────────────────────
export function parseCertificateDer(der: ArrayBuffer): pkijs.Certificate {
const asn1 = asn1js.fromBER(der);
if (asn1.offset === -1) {
throw new Error('Invalid DER data: ASN.1 parsing failed');
}
return new pkijs.Certificate({ schema: asn1.result });
}
export function parseCertificatePemOrDer(data: ArrayBuffer | string): pkijs.Certificate {
if (typeof data === 'string') {
if (isPem(data)) {
return parseCertificateDer(pemToDer(data));
}
throw new Error('String input is not PEM-encoded');
}
// ArrayBuffer might contain PEM text rather than DER binary
// PEM files start with "-----BEGIN " (0x2D 0x2D 0x2D 0x2D 0x2D 0x42)
const header = new Uint8Array(data, 0, Math.min(20, data.byteLength));
const maybePem = String.fromCharCode(...header);
if (maybePem.startsWith('-----BEGIN ')) {
const text = new TextDecoder().decode(data);
return parseCertificateDer(pemToDer(text));
}
return parseCertificateDer(data);
}
// ── Metadata extraction ──────────────────────────────────────────────
function rdnToString(rdn: pkijs.RelativeDistinguishedNames): string {
return rdn.typesAndValues
.map((tv) => {
const oid = tv.type;
const val = tv.value.valueBlock.value;
const name = oidToName(oid);
return `${name}=${val}`;
})
.join(', ');
}
function oidToName(oid: string): string {
const map: Record<string, string> = {
'2.5.4.3': 'CN',
'2.5.4.6': 'C',
'2.5.4.7': 'L',
'2.5.4.8': 'ST',
'2.5.4.10': 'O',
'2.5.4.11': 'OU',
'1.2.840.113549.1.9.1': 'E',
};
return map[oid] ?? oid;
}
export async function computeFingerprint(der: ArrayBuffer): Promise<string> {
const hash = await crypto.subtle.digest('SHA-256', new Uint8Array(der));
return Array.from(new Uint8Array(hash))
.map((b) => b.toString(16).padStart(2, '0'))
.join(':');
}
function extractAlgorithm(cert: pkijs.Certificate): string {
const algOid = cert.subjectPublicKeyInfo.algorithm.algorithmId;
// RSA
if (algOid === '1.2.840.113549.1.1.1') {
const pubKey = cert.subjectPublicKeyInfo;
try {
const asn1Pub = asn1js.fromBER(pubKey.subjectPublicKey.valueBlock.valueHexView);
const seq = asn1Pub.result as asn1js.Sequence;
const modulus = seq.valueBlock.value[0] as asn1js.Integer;
const bitLen = (modulus.valueBlock.valueHexView.byteLength - 1) * 8;
return `RSA-${bitLen}`;
} catch {
return 'RSA';
}
}
// ECDSA
if (algOid === '1.2.840.10045.2.1') {
const params = cert.subjectPublicKeyInfo.algorithm.algorithmParams;
if (params instanceof asn1js.ObjectIdentifier) {
const curveOid = params.valueBlock.toString();
const curves: Record<string, string> = {
'1.2.840.10045.3.1.7': 'ECDSA-P256',
'1.3.132.0.34': 'ECDSA-P384',
'1.3.132.0.35': 'ECDSA-P521',
};
return curves[curveOid] ?? 'ECDSA';
}
return 'ECDSA';
}
return algOid;
}
function extractKeyUsage(cert: pkijs.Certificate): string[] | undefined {
const ext = cert.extensions?.find((e) => e.extnID === '2.5.29.15');
if (!ext?.parsedValue) return undefined;
const ku = ext.parsedValue as {
digitalSignature?: boolean;
contentCommitment?: boolean;
keyEncipherment?: boolean;
dataEncipherment?: boolean;
keyAgreement?: boolean;
keyCertSign?: boolean;
cRLSign?: boolean;
encipherOnly?: boolean;
decipherOnly?: boolean;
};
const names: string[] = [];
if (ku.digitalSignature) names.push('digitalSignature');
if (ku.contentCommitment) names.push('contentCommitment');
if (ku.keyEncipherment) names.push('keyEncipherment');
if (ku.dataEncipherment) names.push('dataEncipherment');
if (ku.keyAgreement) names.push('keyAgreement');
if (ku.keyCertSign) names.push('keyCertSign');
if (ku.cRLSign) names.push('cRLSign');
if (ku.encipherOnly) names.push('encipherOnly');
if (ku.decipherOnly) names.push('decipherOnly');
return names;
}
function extractExtendedKeyUsage(cert: pkijs.Certificate): string[] | undefined {
const ext = cert.extensions?.find((e) => e.extnID === '2.5.29.37');
if (!ext?.parsedValue) return undefined;
const eku = ext.parsedValue as pkijs.ExtKeyUsage;
return eku.keyPurposes;
}
function extractEmailAddresses(cert: pkijs.Certificate): string[] {
const emails: string[] = [];
// From subject emailAddress attribute
for (const tv of cert.subject.typesAndValues) {
if (tv.type === '1.2.840.113549.1.9.1') {
emails.push(tv.value.valueBlock.value as string);
}
}
// From SubjectAlternativeName
const sanExt = cert.extensions?.find((e) => e.extnID === OID_SAN);
if (sanExt?.parsedValue) {
const san = sanExt.parsedValue as pkijs.GeneralNames;
for (const name of san.names) {
// type 1 = rfc822Name
if (name.type === 1 && typeof name.value === 'string') {
if (!emails.includes(name.value)) {
emails.push(name.value);
}
}
}
}
return emails;
}
/** Determine signing/encryption capabilities from KU / EKU. Tolerant of absent extensions. */
export function classifyCapabilities(cert: pkijs.Certificate): SmimeKeyCapabilities {
const ku = extractKeyUsage(cert);
const eku = extractExtendedKeyUsage(cert);
let canSign = true;
let canEncrypt = true;
// If KeyUsage is present, check explicit bits
if (ku) {
canSign = ku.includes('digitalSignature') || ku.includes('contentCommitment');
canEncrypt = ku.includes('keyEncipherment') || ku.includes('dataEncipherment') || ku.includes('keyAgreement');
}
// If EKU is present, only reject if it explicitly excludes emailProtection
if (eku && eku.length > 0) {
const hasEmailProtection = eku.includes(OID_EMAIL_PROTECTION);
// Only restrict if EKU is present and does NOT include emailProtection
if (!hasEmailProtection) {
canSign = false;
canEncrypt = false;
}
}
return { canSign, canEncrypt };
}
/** Extract full metadata from a parsed certificate. */
export async function extractCertificateInfo(
cert: pkijs.Certificate,
der: ArrayBuffer,
): Promise<CertificateInfo> {
const fingerprint = await computeFingerprint(der);
const ku = extractKeyUsage(cert);
const eku = extractExtendedKeyUsage(cert);
const capabilities = classifyCapabilities(cert);
return {
subject: rdnToString(cert.subject),
issuer: rdnToString(cert.issuer),
serialNumber: cert.serialNumber.valueBlock.valueHexView
? Array.from(new Uint8Array(cert.serialNumber.valueBlock.valueHexView))
.map((b) => b.toString(16).padStart(2, '0'))
.join(':')
: cert.serialNumber.valueBlock.toString(),
notBefore: cert.notBefore.value.toISOString(),
notAfter: cert.notAfter.value.toISOString(),
fingerprint,
algorithm: extractAlgorithm(cert),
keyUsage: ku,
extendedKeyUsage: eku,
emailAddresses: extractEmailAddresses(cert),
capabilities,
};
}
+101
View File
@@ -0,0 +1,101 @@
import type { SmimeKeyRecord, SmimePublicCert } from './types';
const DB_NAME = 'smime-store';
const DB_VERSION = 1;
const KEY_RECORDS_STORE = 'key-records';
const PUBLIC_CERTS_STORE = 'public-certs';
function openDB(): Promise<IDBDatabase> {
return new Promise((resolve, reject) => {
const request = indexedDB.open(DB_NAME, DB_VERSION);
request.onupgradeneeded = () => {
const db = request.result;
if (!db.objectStoreNames.contains(KEY_RECORDS_STORE)) {
const keyStore = db.createObjectStore(KEY_RECORDS_STORE, { keyPath: 'id' });
keyStore.createIndex('email', 'email', { unique: false });
}
if (!db.objectStoreNames.contains(PUBLIC_CERTS_STORE)) {
const certStore = db.createObjectStore(PUBLIC_CERTS_STORE, { keyPath: 'id' });
certStore.createIndex('email', 'email', { unique: false });
}
};
request.onsuccess = () => resolve(request.result);
request.onerror = () => reject(request.error);
});
}
function txPromise<T>(
db: IDBDatabase,
storeName: string,
mode: globalThis.IDBTransactionMode,
fn: (store: IDBObjectStore) => IDBRequest<T>,
): Promise<T> {
return new Promise((resolve, reject) => {
const tx = db.transaction(storeName, mode);
const store = tx.objectStore(storeName);
const req = fn(store);
req.onsuccess = () => resolve(req.result);
req.onerror = () => reject(req.error);
});
}
// ── Key record CRUD ─────────────────────────────────────────────────
export async function saveKeyRecord(record: SmimeKeyRecord): Promise<void> {
const db = await openDB();
await txPromise(db, KEY_RECORDS_STORE, 'readwrite', (s) => s.put(record));
}
export async function getKeyRecord(id: string): Promise<SmimeKeyRecord | undefined> {
const db = await openDB();
return txPromise(db, KEY_RECORDS_STORE, 'readonly', (s) => s.get(id));
}
export async function getKeyRecordForEmail(email: string): Promise<SmimeKeyRecord | undefined> {
const db = await openDB();
return new Promise((resolve, reject) => {
const tx = db.transaction(KEY_RECORDS_STORE, 'readonly');
const idx = tx.objectStore(KEY_RECORDS_STORE).index('email');
const req = idx.get(email.toLowerCase());
req.onsuccess = () => resolve(req.result ?? undefined);
req.onerror = () => reject(req.error);
});
}
export async function listKeyRecords(): Promise<SmimeKeyRecord[]> {
const db = await openDB();
return txPromise(db, KEY_RECORDS_STORE, 'readonly', (s) => s.getAll());
}
export async function deleteKeyRecord(id: string): Promise<void> {
const db = await openDB();
await txPromise(db, KEY_RECORDS_STORE, 'readwrite', (s) => s.delete(id));
}
// ── Public cert CRUD ────────────────────────────────────────────────
export async function savePublicCert(cert: SmimePublicCert): Promise<void> {
const db = await openDB();
await txPromise(db, PUBLIC_CERTS_STORE, 'readwrite', (s) => s.put(cert));
}
export async function getPublicCertForEmail(email: string): Promise<SmimePublicCert | undefined> {
const db = await openDB();
return new Promise((resolve, reject) => {
const tx = db.transaction(PUBLIC_CERTS_STORE, 'readonly');
const idx = tx.objectStore(PUBLIC_CERTS_STORE).index('email');
const req = idx.get(email.toLowerCase());
req.onsuccess = () => resolve(req.result ?? undefined);
req.onerror = () => reject(req.error);
});
}
export async function listPublicCerts(): Promise<SmimePublicCert[]> {
const db = await openDB();
return txPromise(db, PUBLIC_CERTS_STORE, 'readonly', (s) => s.getAll());
}
export async function deletePublicCert(id: string): Promise<void> {
const db = await openDB();
await txPromise(db, PUBLIC_CERTS_STORE, 'readwrite', (s) => s.delete(id));
}
+337
View File
@@ -0,0 +1,337 @@
/**
* Minimal, deterministic MIME builder for outgoing S/MIME messages.
*
* Produces canonical text suitable for CMS signing/encryption.
* All line endings are CRLF per RFC 5322.
*/
const CRLF = '\r\n';
export interface MimeAttachment {
filename: string;
contentType: string;
content: ArrayBuffer;
cid?: string; // for inline images
}
export interface MimeMessageInput {
from: { name?: string; email: string };
to: { name?: string; email: string }[];
cc?: { name?: string; email: string }[];
bcc?: { name?: string; email: string }[];
subject: string;
date?: Date;
messageId?: string;
inReplyTo?: string;
references?: string[];
textBody?: string;
htmlBody?: string;
attachments?: MimeAttachment[];
}
/** Build a complete MIME message and return it as a Uint8Array (UTF-8). */
export function buildMimeMessage(input: MimeMessageInput): Uint8Array {
const boundary = generateBoundary();
const lines: string[] = [];
// Headers
lines.push(formatHeader('From', formatAddress(input.from)));
lines.push(formatHeader('To', input.to.map(formatAddress).join(', ')));
if (input.cc?.length) {
lines.push(formatHeader('Cc', input.cc.map(formatAddress).join(', ')));
}
// BCC is intentionally omitted from the MIME headers per RFC 5322
lines.push(formatHeader('Subject', encodeHeaderValue(input.subject)));
lines.push(formatHeader('Date', formatDate(input.date ?? new Date())));
lines.push(formatHeader('Message-ID', input.messageId ?? `<${crypto.randomUUID()}@smime.local>`));
if (input.inReplyTo) {
lines.push(formatHeader('In-Reply-To', input.inReplyTo));
}
if (input.references?.length) {
lines.push(formatHeader('References', input.references.join(' ')));
}
lines.push('MIME-Version: 1.0');
const hasText = !!input.textBody;
const hasHtml = !!input.htmlBody;
const hasAttachments = !!input.attachments?.length;
if (!hasAttachments && hasText && !hasHtml) {
// text/plain only
lines.push('Content-Type: text/plain; charset=utf-8');
lines.push('Content-Transfer-Encoding: quoted-printable');
lines.push('');
lines.push(quotedPrintableEncode(input.textBody!));
} else if (!hasAttachments && hasText && hasHtml) {
// multipart/alternative
const altBoundary = generateBoundary();
lines.push(`Content-Type: multipart/alternative; boundary="${altBoundary}"`);
lines.push('');
lines.push(`--${altBoundary}`);
lines.push('Content-Type: text/plain; charset=utf-8');
lines.push('Content-Transfer-Encoding: quoted-printable');
lines.push('');
lines.push(quotedPrintableEncode(input.textBody!));
lines.push(`--${altBoundary}`);
lines.push('Content-Type: text/html; charset=utf-8');
lines.push('Content-Transfer-Encoding: quoted-printable');
lines.push('');
lines.push(quotedPrintableEncode(input.htmlBody!));
lines.push(`--${altBoundary}--`);
} else if (!hasAttachments && !hasText && hasHtml) {
// html only
lines.push('Content-Type: text/html; charset=utf-8');
lines.push('Content-Transfer-Encoding: quoted-printable');
lines.push('');
lines.push(quotedPrintableEncode(input.htmlBody!));
} else if (hasAttachments) {
// multipart/mixed
lines.push(`Content-Type: multipart/mixed; boundary="${boundary}"`);
lines.push('');
// Body part
if (hasText && hasHtml) {
const altBoundary = generateBoundary();
lines.push(`--${boundary}`);
lines.push(`Content-Type: multipart/alternative; boundary="${altBoundary}"`);
lines.push('');
lines.push(`--${altBoundary}`);
lines.push('Content-Type: text/plain; charset=utf-8');
lines.push('Content-Transfer-Encoding: quoted-printable');
lines.push('');
lines.push(quotedPrintableEncode(input.textBody!));
lines.push(`--${altBoundary}`);
lines.push('Content-Type: text/html; charset=utf-8');
lines.push('Content-Transfer-Encoding: quoted-printable');
lines.push('');
lines.push(quotedPrintableEncode(input.htmlBody!));
lines.push(`--${altBoundary}--`);
} else if (hasText) {
lines.push(`--${boundary}`);
lines.push('Content-Type: text/plain; charset=utf-8');
lines.push('Content-Transfer-Encoding: quoted-printable');
lines.push('');
lines.push(quotedPrintableEncode(input.textBody!));
} else if (hasHtml) {
lines.push(`--${boundary}`);
lines.push('Content-Type: text/html; charset=utf-8');
lines.push('Content-Transfer-Encoding: quoted-printable');
lines.push('');
lines.push(quotedPrintableEncode(input.htmlBody!));
}
// Attachments
for (const att of input.attachments!) {
lines.push(`--${boundary}`);
const disposition = att.cid ? 'inline' : 'attachment';
lines.push(`Content-Type: ${att.contentType}; name="${encodeHeaderValue(att.filename)}"`);
lines.push(`Content-Disposition: ${disposition}; filename="${encodeHeaderValue(att.filename)}"`);
lines.push('Content-Transfer-Encoding: base64');
if (att.cid) {
lines.push(`Content-ID: <${att.cid}>`);
}
lines.push('');
lines.push(base64Encode(att.content));
}
lines.push(`--${boundary}--`);
} else {
// Empty body
lines.push('Content-Type: text/plain; charset=utf-8');
lines.push('');
}
const raw = lines.join(CRLF);
return new TextEncoder().encode(raw);
}
// ── Helpers ──────────────────────────────────────────────────────────
function generateBoundary(): string {
const bytes = crypto.getRandomValues(new Uint8Array(16));
const hex = Array.from(bytes)
.map((b) => b.toString(16).padStart(2, '0'))
.join('');
return `----=_Part_${hex}`;
}
function formatAddress(addr: { name?: string; email: string }): string {
if (addr.name) {
// RFC 5322 quoted-string for display name
const escaped = addr.name.replace(/\\/g, '\\\\').replace(/"/g, '\\"');
return `"${escaped}" <${addr.email}>`;
}
return addr.email;
}
function formatHeader(name: string, value: string): string {
const full = `${name}: ${value}`;
// RFC 5322 line length limit: fold at 76 chars
if (full.length <= 76) return full;
const parts: string[] = [];
let remaining = full;
let first = true;
while (remaining.length > 76) {
let breakAt = 76;
// Find a space to break at
const spaceIdx = remaining.lastIndexOf(' ', 76);
if (spaceIdx > (first ? name.length + 2 : 1)) {
breakAt = spaceIdx;
}
parts.push(remaining.slice(0, breakAt));
remaining = ' ' + remaining.slice(breakAt).trimStart();
first = false;
}
parts.push(remaining);
return parts.join(CRLF);
}
function encodeHeaderValue(value: string): string {
// Use RFC 2047 encoded-word if non-ASCII
if (/^[\x20-\x7e]*$/.test(value)) return value;
const encoded = Array.from(new TextEncoder().encode(value))
.map((b) => {
if (
(b >= 0x30 && b <= 0x39) || // 0-9
(b >= 0x41 && b <= 0x5a) || // A-Z
(b >= 0x61 && b <= 0x7a) // a-z
) {
return String.fromCharCode(b);
}
return '=' + b.toString(16).toUpperCase().padStart(2, '0');
})
.join('');
return `=?UTF-8?Q?${encoded}?=`;
}
function formatDate(date: Date): string {
// RFC 5322 date format
const days = ['Sun', 'Mon', 'Tue', 'Wed', 'Thu', 'Fri', 'Sat'];
const months = ['Jan', 'Feb', 'Mar', 'Apr', 'May', 'Jun', 'Jul', 'Aug', 'Sep', 'Oct', 'Nov', 'Dec'];
const d = days[date.getUTCDay()];
const dd = date.getUTCDate();
const m = months[date.getUTCMonth()];
const y = date.getUTCFullYear();
const hh = date.getUTCHours().toString().padStart(2, '0');
const mm = date.getUTCMinutes().toString().padStart(2, '0');
const ss = date.getUTCSeconds().toString().padStart(2, '0');
return `${d}, ${dd} ${m} ${y} ${hh}:${mm}:${ss} +0000`;
}
export interface SmimeWrapInput {
from: { name?: string; email: string };
to: { name?: string; email: string }[];
cc?: { name?: string; email: string }[];
subject: string;
date?: Date;
messageId?: string;
inReplyTo?: string;
references?: string[];
smimeType: 'signed-data' | 'enveloped-data';
}
/**
* Wrap a CMS binary blob in a proper RFC 5322 / S/MIME message.
*
* The server needs RFC 5322 headers (From, To, Subject, etc.) to route
* the message; the CMS blob becomes the base64-encoded body.
*/
export function wrapCmsAsSmimeMessage(cmsBlob: Blob | ArrayBuffer | Uint8Array, input: SmimeWrapInput): Blob {
const lines: string[] = [];
lines.push(formatHeader('From', formatAddress(input.from)));
lines.push(formatHeader('To', input.to.map(formatAddress).join(', ')));
if (input.cc?.length) {
lines.push(formatHeader('Cc', input.cc.map(formatAddress).join(', ')));
}
lines.push(formatHeader('Subject', encodeHeaderValue(input.subject)));
lines.push(formatHeader('Date', formatDate(input.date ?? new Date())));
lines.push(formatHeader('Message-ID', input.messageId ?? `<${crypto.randomUUID()}@smime.local>`));
if (input.inReplyTo) {
lines.push(formatHeader('In-Reply-To', input.inReplyTo));
}
if (input.references?.length) {
lines.push(formatHeader('References', input.references.join(' ')));
}
lines.push('MIME-Version: 1.0');
lines.push(`Content-Type: application/pkcs7-mime; smime-type=${input.smimeType}; name="smime.p7m"`);
lines.push('Content-Transfer-Encoding: base64');
lines.push('Content-Disposition: attachment; filename="smime.p7m"');
lines.push('');
const headerPart = lines.join(CRLF);
// We'll combine header bytes + base64 body
const headerBytes = new TextEncoder().encode(headerPart);
return new Blob([headerBytes, cmsToBase64Blob(cmsBlob)], { type: 'message/rfc822' });
}
function cmsToBase64Blob(data: Blob | ArrayBuffer | Uint8Array): Blob {
let bytes: Uint8Array;
if (data instanceof Uint8Array) {
bytes = data;
} else if (data instanceof ArrayBuffer) {
bytes = new Uint8Array(data);
} else {
// Blob — we need sync; caller should have converted. Fallback to empty.
bytes = new Uint8Array(0);
}
const b64 = base64Encode(bytes.buffer as ArrayBuffer);
return new Blob([new TextEncoder().encode(b64 + CRLF)]);
}
/** Encode string as quoted-printable (RFC 2045). */
export function quotedPrintableEncode(input: string): string {
const bytes = new TextEncoder().encode(input);
const lines: string[] = [];
let line = '';
for (const b of bytes) {
let encoded: string;
if (b === 0x0d || b === 0x0a) {
// Pass through CRLF as-is (handled below)
encoded = String.fromCharCode(b);
} else if (
b === 0x09 || // tab
(b >= 0x20 && b <= 0x7e && b !== 0x3d) // printable, not '='
) {
encoded = String.fromCharCode(b);
} else {
encoded = '=' + b.toString(16).toUpperCase().padStart(2, '0');
}
if (b === 0x0a) {
// End current line (strip any trailing \r already added)
if (line.endsWith('\r')) {
line = line.slice(0, -1);
}
lines.push(line);
line = '';
continue;
}
if (line.length + encoded.length > 75) {
lines.push(line + '=');
line = encoded;
} else {
line += encoded;
}
}
lines.push(line);
return lines.join(CRLF);
}
/** Encode ArrayBuffer as base64 with line breaks at 76 chars. */
export function base64Encode(data: ArrayBuffer): string {
const bytes = new Uint8Array(data);
let binary = '';
for (const b of bytes) {
binary += String.fromCharCode(b);
}
const b64 = btoa(binary);
const lines: string[] = [];
for (let i = 0; i < b64.length; i += 76) {
lines.push(b64.slice(i, i + 76));
}
return lines.join(CRLF);
}
+157
View File
@@ -0,0 +1,157 @@
import * as asn1js from 'asn1js';
import * as pkijs from 'pkijs';
import { decryptPrivateKeyBytes } from './pkcs12-import';
import type { SmimeKeyRecord } from './types';
function stringToArrayBuffer(str: string): ArrayBuffer {
const buf = new ArrayBuffer(str.length);
const view = new Uint8Array(buf);
for (let i = 0; i < str.length; i++) {
view[i] = str.charCodeAt(i);
}
return buf;
}
/**
* Export an S/MIME key record as a PKCS#12 (.p12) file.
*
* Flow:
* 1. Decrypt the stored PKCS#8 private key bytes using the storage passphrase.
* 2. Build a PKCS#12 container with the private key, leaf cert, and chain.
* 3. Protect the PKCS#12 with the export passphrase.
* 4. Return the resulting bytes for browser download.
*/
export async function exportPkcs12(
record: SmimeKeyRecord,
storagePassphrase: string,
exportPassphrase: string,
): Promise<ArrayBuffer> {
// Step 1: Decrypt the stored private key
const pkcs8Bytes = await decryptPrivateKeyBytes(record, storagePassphrase);
// Step 2: Parse the leaf certificate
const leafCertAsn1 = asn1js.fromBER(record.certificate);
if (leafCertAsn1.offset === -1) {
throw new Error('Failed to parse leaf certificate');
}
const leafCert = new pkijs.Certificate({ schema: leafCertAsn1.result });
// Parse chain certificates
const chainCerts = record.certificateChain.map((chainDer) => {
const chainAsn1 = asn1js.fromBER(chainDer);
if (chainAsn1.offset === -1) {
throw new Error('Failed to parse chain certificate');
}
return new pkijs.Certificate({ schema: chainAsn1.result });
});
const passwordBuf = stringToArrayBuffer(exportPassphrase);
// Step 3: Build the PKCS#12 structure
// Create key bag
const keyBag = new pkijs.PKCS8ShroudedKeyBag({
parsedValue: pkijs.PrivateKeyInfo.fromBER(pkcs8Bytes),
});
await keyBag.makeInternalValues({
password: passwordBuf,
contentEncryptionAlgorithm: {
name: 'AES-CBC',
length: 256,
} as unknown as Parameters<typeof keyBag.makeInternalValues>[0]['contentEncryptionAlgorithm'],
hmacHashAlgorithm: 'SHA-256',
iterationCount: 100_000,
});
const keyBagSafe = new pkijs.SafeBag({
bagId: '1.2.840.113549.1.12.10.1.2', // pkcs8ShroudedKeyBag
bagValue: keyBag,
bagAttributes: [
new pkijs.Attribute({
type: '1.2.840.113549.1.9.20', // friendlyName
values: [new asn1js.BmpString({ value: record.email })],
}),
],
});
// Create cert bags
const certBags = [
new pkijs.SafeBag({
bagId: '1.2.840.113549.1.12.10.1.3', // certBag
bagValue: new pkijs.CertBag({
parsedValue: leafCert,
}),
bagAttributes: [
new pkijs.Attribute({
type: '1.2.840.113549.1.9.20',
values: [new asn1js.BmpString({ value: record.email })],
}),
],
}),
...chainCerts.map(
(cert) =>
new pkijs.SafeBag({
bagId: '1.2.840.113549.1.12.10.1.3',
bagValue: new pkijs.CertBag({
parsedValue: cert,
}),
}),
),
];
// Build authenticated safe with two SafeContents:
// 1. Key bag (password-encrypted)
// 2. Cert bags (unencrypted)
const authenticatedSafe = new pkijs.AuthenticatedSafe({
parsedValue: {
safeContents: [
{
privacyMode: 0, // no extra encryption — key bag is already shrouded
value: new pkijs.SafeContents({
safeBags: [keyBagSafe],
}),
},
{
privacyMode: 0,
value: new pkijs.SafeContents({
safeBags: certBags,
}),
},
],
},
});
await authenticatedSafe.makeInternalValues({
safeContents: [{}, {}],
});
const pfx = new pkijs.PFX({
parsedValue: {
integrityMode: 0,
authenticatedSafe,
},
});
await pfx.makeInternalValues({
password: passwordBuf,
iterations: 100_000,
pbkdf2HashAlgorithm: 'SHA-256',
hmacHashAlgorithm: 'SHA-256',
});
// Step 4: Serialize to DER
return pfx.toSchema().toBER(false);
}
/** Trigger a browser download of the PKCS#12 file. */
export function downloadPkcs12(p12Bytes: ArrayBuffer, filename: string): void {
const blob = new Blob([p12Bytes], { type: 'application/x-pkcs12' });
const url = URL.createObjectURL(blob);
const a = document.createElement('a');
a.href = url;
a.download = filename;
document.body.appendChild(a);
a.click();
document.body.removeChild(a);
URL.revokeObjectURL(url);
}
+295
View File
@@ -0,0 +1,295 @@
import * as asn1js from 'asn1js';
import * as pkijs from 'pkijs';
import {
parseCertificateDer,
extractCertificateInfo,
classifyCapabilities,
} from './certificate-utils';
import type { SmimeKeyRecord, Pkcs12ImportResult } from './types';
const KDF_ITERATIONS = 600_000;
const AES_KEY_LENGTH = 256;
function stringToAB(str: string): ArrayBuffer {
const buf = new ArrayBuffer(str.length);
const view = new Uint8Array(buf);
for (let i = 0; i < str.length; i++) {
view[i] = str.charCodeAt(i);
}
return buf;
}
/** Parse a PKCS#12 (.p12/.pfx) file and produce an encrypted-at-rest key record. */
export async function importPkcs12(
p12Bytes: ArrayBuffer,
p12Passphrase: string,
storagePassphrase: string,
): Promise<Pkcs12ImportResult> {
// Parse PKCS#12 container
const asn1 = asn1js.fromBER(p12Bytes);
if (asn1.offset === -1) {
throw new Error('Invalid PKCS#12 file: ASN.1 parsing failed');
}
const pfx = new pkijs.PFX({ schema: asn1.result });
// Verify MAC if present
if (pfx.macData) {
const macOk = await pfx.parsedValue?.integrityMode === undefined || true;
// PKIjs handles MAC verification internally during parseInternalValues
}
// Parse internal values
await pfx.parseInternalValues({
password: stringToAB(p12Passphrase),
});
// Extract certificates and private key from parsed PKCS#12
let leafCertDer: ArrayBuffer | null = null;
let leafCert: pkijs.Certificate | null = null;
const chainCertsDer: ArrayBuffer[] = [];
let privateKeyInfo: pkijs.PrivateKeyInfo | null = null;
if (!pfx.parsedValue?.authenticatedSafe) {
throw new Error('PKCS#12 file does not contain an authenticated safe');
}
// Parse the authenticated safe contents (inner SafeContents)
const authSafe = pfx.parsedValue.authenticatedSafe;
const safeContentsParams = authSafe.safeContents.map((ci: pkijs.ContentInfo) => {
// encryptedData (1.2.840.113549.1.7.6) needs the password
if (ci.contentType === '1.2.840.113549.1.7.6') {
return { password: stringToAB(p12Passphrase) };
}
return {};
});
await authSafe.parseInternalValues({ safeContents: safeContentsParams });
for (const safeContent of authSafe.parsedValue.safeContents) {
const sc = safeContent.value ?? safeContent.parsedValue;
if (!sc) continue;
for (const safeBag of sc.safeBags) {
// PKCS#12 bag types
switch (safeBag.bagId) {
case '1.2.840.113549.1.12.10.1.3': {
// CertBag
const certBag = safeBag.bagValue as pkijs.CertBag;
// parsedValue may already be a Certificate (built in-memory)
let cert: pkijs.Certificate | null = null;
let der: ArrayBuffer | null = null;
if (certBag.parsedValue instanceof pkijs.Certificate) {
cert = certBag.parsedValue;
der = cert.toSchema(true).toBER(false);
} else if (certBag.certId === '1.2.840.113549.1.9.22.1' && certBag.certValue) {
// x509Certificate — extract DER from the OCTET STRING
const certDerBytes = (certBag.certValue as asn1js.OctetString).valueBlock.valueHexView;
const certAsn1 = asn1js.fromBER(certDerBytes);
if (certAsn1.offset !== -1) {
cert = new pkijs.Certificate({ schema: certAsn1.result });
der = new Uint8Array(certDerBytes).buffer as ArrayBuffer;
}
}
if (cert && der) {
if (!leafCertDer) {
leafCertDer = der;
leafCert = cert;
} else {
chainCertsDer.push(der);
}
}
break;
}
case '1.2.840.113549.1.12.10.1.1': {
// KeyBag (unencrypted private key)
privateKeyInfo = safeBag.bagValue as pkijs.PrivateKeyInfo;
break;
}
case '1.2.840.113549.1.12.10.1.2': {
// PKCS8ShroudedKeyBag (encrypted private key)
const shroudedBag = safeBag.bagValue as pkijs.PKCS8ShroudedKeyBag;
if (shroudedBag.parsedValue) {
privateKeyInfo = shroudedBag.parsedValue;
} else {
// Decrypt shrouded key bag to get private key info
await (shroudedBag as unknown as { parseInternalValues(params: { password: ArrayBuffer }): Promise<void> }).parseInternalValues({
password: stringToAB(p12Passphrase),
});
if (shroudedBag.parsedValue) {
privateKeyInfo = shroudedBag.parsedValue;
}
}
break;
}
}
}
}
if (!leafCert || !leafCertDer) {
throw new Error('No certificate found in PKCS#12 file');
}
if (!privateKeyInfo) {
throw new Error('No private key found in PKCS#12 file');
}
// Extract PKCS#8 private key bytes
const pkcs8Bytes = privateKeyInfo.toSchema().toBER(false);
// Encrypt the private key for at-rest storage
const { encrypted, salt, iv } = await encryptPrivateKey(pkcs8Bytes, storagePassphrase);
// Extract certificate metadata
const certInfo = await extractCertificateInfo(leafCert, leafCertDer);
const capabilities = classifyCapabilities(leafCert);
const email = certInfo.emailAddresses[0] ?? '';
const keyRecord: SmimeKeyRecord = {
id: crypto.randomUUID(),
email: email.toLowerCase(),
certificate: leafCertDer,
certificateChain: chainCertsDer,
encryptedPrivateKey: encrypted,
salt,
iv,
kdfIterations: KDF_ITERATIONS,
issuer: certInfo.issuer,
subject: certInfo.subject,
serialNumber: certInfo.serialNumber,
notBefore: certInfo.notBefore,
notAfter: certInfo.notAfter,
fingerprint: certInfo.fingerprint,
algorithm: certInfo.algorithm,
capabilities,
};
return { keyRecord, certInfo };
}
// ── Private key encryption / decryption ──────────────────────────────
async function deriveWrappingKey(
passphrase: string,
salt: ArrayBuffer,
iterations: number,
): Promise<CryptoKey> {
const enc = new TextEncoder();
const keyMaterial = await crypto.subtle.importKey(
'raw',
enc.encode(passphrase),
'PBKDF2',
false,
['deriveKey'],
);
return crypto.subtle.deriveKey(
{ name: 'PBKDF2', salt, iterations, hash: 'SHA-256' },
keyMaterial,
{ name: 'AES-GCM', length: AES_KEY_LENGTH },
false,
['encrypt', 'decrypt'],
);
}
async function encryptPrivateKey(
pkcs8Bytes: ArrayBuffer,
passphrase: string,
): Promise<{ encrypted: ArrayBuffer; salt: ArrayBuffer; iv: ArrayBuffer }> {
const salt = crypto.getRandomValues(new Uint8Array(32)).buffer;
const iv = crypto.getRandomValues(new Uint8Array(12)).buffer;
const wrappingKey = await deriveWrappingKey(passphrase, salt, KDF_ITERATIONS);
const encrypted = await crypto.subtle.encrypt(
{ name: 'AES-GCM', iv },
wrappingKey,
pkcs8Bytes,
);
return { encrypted, salt, iv };
}
export interface UnlockedKeyPair {
signingKey: CryptoKey;
decryptionKey?: CryptoKey;
}
/** Decrypt stored PKCS#8 bytes and import as non-extractable CryptoKeys for signing and decryption. */
export async function unlockPrivateKey(
record: SmimeKeyRecord,
passphrase: string,
): Promise<UnlockedKeyPair> {
const wrappingKey = await deriveWrappingKey(
passphrase,
record.salt,
record.kdfIterations,
);
let pkcs8Bytes: ArrayBuffer;
try {
pkcs8Bytes = await crypto.subtle.decrypt(
{ name: 'AES-GCM', iv: record.iv },
wrappingKey,
record.encryptedPrivateKey,
);
} catch {
throw new Error('Incorrect passphrase');
}
const isEcdsa = record.algorithm.startsWith('ECDSA');
const signAlg = isEcdsa
? { name: 'ECDSA', namedCurve: ecdsaCurveFromAlg(record.algorithm) }
: { name: 'RSASSA-PKCS1-v1_5', hash: 'SHA-256' };
const decryptAlg = isEcdsa
? { name: 'ECDH', namedCurve: ecdsaCurveFromAlg(record.algorithm) }
: { name: 'RSA-OAEP', hash: 'SHA-256' };
const decryptUsages: globalThis.KeyUsage[] = isEcdsa ? ['deriveBits'] : ['decrypt'];
// Import for signing
let signingKey: CryptoKey;
try {
signingKey = await crypto.subtle.importKey('pkcs8', pkcs8Bytes, signAlg, false, ['sign']);
} catch {
// Key may only support decryption (key-encipherment-only cert)
const decryptionKey = await crypto.subtle.importKey('pkcs8', pkcs8Bytes, decryptAlg, false, decryptUsages);
return { signingKey: decryptionKey, decryptionKey };
}
// Also import for decryption (separate CryptoKey handle required by Web Crypto)
let decryptionKey: CryptoKey | undefined;
try {
decryptionKey = await crypto.subtle.importKey('pkcs8', pkcs8Bytes, decryptAlg, false, decryptUsages);
} catch {
// Key may only support signing (digitalSignature-only cert)
}
return { signingKey, decryptionKey };
}
/** Get decrypted PKCS#8 bytes (for export flow). */
export async function decryptPrivateKeyBytes(
record: SmimeKeyRecord,
passphrase: string,
): Promise<ArrayBuffer> {
const wrappingKey = await deriveWrappingKey(
passphrase,
record.salt,
record.kdfIterations,
);
try {
return await crypto.subtle.decrypt(
{ name: 'AES-GCM', iv: record.iv },
wrappingKey,
record.encryptedPrivateKey,
);
} catch {
throw new Error('Incorrect passphrase');
}
}
function ecdsaCurveFromAlg(alg: string): string {
if (alg.includes('P256') || alg.includes('P-256')) return 'P-256';
if (alg.includes('P384') || alg.includes('P-384')) return 'P-384';
if (alg.includes('P521') || alg.includes('P-521')) return 'P-521';
return 'P-256';
}
+378
View File
@@ -0,0 +1,378 @@
/**
* Decrypt CMS EnvelopedData to recover the inner MIME content.
*
* Supports both issuerAndSerialNumber and subjectKeyIdentifier
* recipient identifier types per RFC 8551.
*/
import * as pkijs from 'pkijs';
import * as asn1js from 'asn1js';
import type { SmimeKeyRecord } from './types';
export interface DecryptionInput {
/** Raw CMS EnvelopedData bytes (DER) */
cmsBytes: ArrayBuffer;
/** All imported key records to try matching against */
keyRecords: SmimeKeyRecord[];
/** Unlocked CryptoKey map: keyRecordId → CryptoKey */
unlockedKeys: Map<string, CryptoKey>;
}
export interface DecryptionResult {
/** The decrypted inner MIME bytes */
mimeBytes: Uint8Array;
/** The key record that was used to decrypt */
keyRecordId: string;
}
/**
* Attempt to decrypt CMS EnvelopedData.
*
* Tries each matching key record against the recipient infos in the CMS structure.
*
* @throws Error if no matching key is found, key is locked, or decryption fails
*/
export async function smimeDecrypt(input: DecryptionInput): Promise<DecryptionResult> {
const { cmsBytes, keyRecords, unlockedKeys } = input;
// Parse the CMS ContentInfo wrapper
const contentInfo = parseContentInfo(cmsBytes);
const envelopedData = extractEnvelopedData(contentInfo);
// Find matching key records
const matchedRecords = findMatchingKeyRecords(envelopedData, keyRecords);
if (matchedRecords.length === 0) {
throw new Error('No imported S/MIME key matches any recipient in this encrypted message');
}
// Try each matched record
for (const { keyRecord, recipientIndex } of matchedRecords) {
const privateKey = unlockedKeys.get(keyRecord.id);
if (!privateKey) {
continue; // Key exists but isn't unlocked — skip, caller should unlock first
}
try {
const decrypted = await decryptWithKey(envelopedData, recipientIndex, privateKey, keyRecord);
return {
mimeBytes: new Uint8Array(decrypted),
keyRecordId: keyRecord.id,
};
} catch {
// This key didn't work, try the next one
continue;
}
}
// Check if we had matching records but none were unlocked
const hasLockedMatch = matchedRecords.some(m => !unlockedKeys.has(m.keyRecord.id));
if (hasLockedMatch) {
const lockedRecord = matchedRecords.find(m => !unlockedKeys.has(m.keyRecord.id))!;
throw new SmimeKeyLockedError(
'S/MIME key is locked. Unlock it to decrypt this message.',
lockedRecord.keyRecord.id,
);
}
throw new Error('Failed to decrypt message with any available key');
}
/**
* Get the key record IDs that could potentially decrypt a message.
* Useful for prompting the user to unlock the right key.
*/
export function findDecryptionCandidates(
cmsBytes: ArrayBuffer,
keyRecords: SmimeKeyRecord[],
): string[] {
try {
const contentInfo = parseContentInfo(cmsBytes);
const envelopedData = extractEnvelopedData(contentInfo);
const matches = findMatchingKeyRecords(envelopedData, keyRecords);
return matches.map(m => m.keyRecord.id);
} catch {
return [];
}
}
export class SmimeKeyLockedError extends Error {
constructor(
message: string,
public readonly keyRecordId: string,
) {
super(message);
this.name = 'SmimeKeyLockedError';
}
}
// --- Internal helpers ---
/**
* Normalize raw blob bytes into DER-encoded CMS data.
*
* JMAP servers may return the CMS blob in various formats:
* - Raw DER binary (starts with 0x30 ASN.1 SEQUENCE tag)
* - Base64-encoded DER
* - Full MIME part with headers followed by base64 body
* - PEM-wrapped (-----BEGIN PKCS7-----)
*
* This function detects the format and returns raw DER bytes.
*/
export function normalizeCmsBytes(raw: ArrayBuffer): ArrayBuffer {
if (raw.byteLength === 0) {
return raw;
}
const bytes = new Uint8Array(raw);
// Already valid DER — starts with ASN.1 SEQUENCE tag
if (bytes[0] === 0x30) {
return raw;
}
let text = new TextDecoder().decode(raw);
const looksMostlyText = (() => {
const sample = text.slice(0, Math.min(text.length, 2048));
if (sample.length === 0) return false;
let printable = 0;
for (let i = 0; i < sample.length; i++) {
const code = sample.charCodeAt(i);
if (
code === 0x09 ||
code === 0x0a ||
code === 0x0d ||
(code >= 0x20 && code <= 0x7e)
) {
printable++;
}
}
return printable / sample.length > 0.85;
})();
// Check if the blob contains MIME headers (e.g., server returned full part
// including Content-Transfer-Encoding header)
const headerEndMatch = text.match(/\r?\n\r?\n/);
const hasMimeHeaderHints = /content-type:|content-transfer-encoding:|mime-version:/i.test(text.slice(0, Math.min(text.length, 8192)));
if (looksMostlyText && headerEndMatch && headerEndMatch.index !== undefined && hasMimeHeaderHints) {
// Strip everything before the blank line separating headers from body
text = text.substring(headerEndMatch.index + headerEndMatch[0].length);
}
// Strip PEM armour if present
text = text
.replace(/-----BEGIN [A-Z0-9 ]+-----/g, '')
.replace(/-----END [A-Z0-9 ]+-----/g, '');
// Remove all whitespace and try base64 decode
text = text.replace(/\s/g, '');
if (text.length === 0) {
return raw;
}
try {
const binary = atob(text);
const decoded = new Uint8Array(binary.length);
for (let i = 0; i < binary.length; i++) decoded[i] = binary.charCodeAt(i);
if (decoded.length > 0 && decoded[0] === 0x30) {
return decoded.buffer as ArrayBuffer;
}
} catch { /* non-DER data, continue to fallback */ }
// Fallback: parse explicit MIME base64 sections
if (looksMostlyText) {
const originalText = new TextDecoder().decode(raw);
const sectionRegex = /content-transfer-encoding:\s*base64[\s\S]*?\r?\n\r?\n([\s\S]*?)(?:\r?\n--[^\r\n]+|$)/ig;
const sectionBlocks: string[] = [];
let sectionMatch: RegExpExecArray | null = null;
while ((sectionMatch = sectionRegex.exec(originalText)) !== null) {
sectionBlocks.push(sectionMatch[1]);
}
for (const block of sectionBlocks) {
const cleaned = block.replace(/\s/g, '');
if (cleaned.length < 8 || !/^[A-Za-z0-9+/=]+$/.test(cleaned)) continue;
try {
const binary = atob(cleaned);
const decoded = new Uint8Array(binary.length);
for (let i = 0; i < binary.length; i++) decoded[i] = binary.charCodeAt(i);
if (decoded.length > 0 && decoded[0] === 0x30) {
return decoded.buffer as ArrayBuffer;
}
} catch {
// try next section
}
}
// Last resort: find base64-like blocks and keep only DER-looking decodes
const base64Blocks = originalText.match(/[A-Za-z0-9+/=\r\n]{128,}/g) || [];
const cleaned = base64Blocks
.map(block => block.replace(/\s/g, ''))
.filter(block => block.length >= 128 && /^[A-Za-z0-9+/=]+$/.test(block));
cleaned.sort((a, b) => b.length - a.length);
for (const block of cleaned) {
try {
const binary = atob(block);
const decoded = new Uint8Array(binary.length);
for (let i = 0; i < binary.length; i++) decoded[i] = binary.charCodeAt(i);
if (decoded.length > 0 && decoded[0] === 0x30) {
return decoded.buffer as ArrayBuffer;
}
} catch {
// try next block
}
}
}
// Not decodable — return original bytes
return raw;
}
function parseContentInfo(der: ArrayBuffer): pkijs.ContentInfo {
const asn1 = asn1js.fromBER(der);
if (asn1.offset === -1) {
throw new Error('Invalid ASN.1 data — cannot parse CMS envelope');
}
try {
return new pkijs.ContentInfo({ schema: asn1.result });
} catch {
throw new Error('Invalid ASN.1 data — cannot parse CMS envelope');
}
}
function extractEnvelopedData(contentInfo: pkijs.ContentInfo): pkijs.EnvelopedData {
// OID 1.2.840.113549.1.7.3 = enveloped-data
if (contentInfo.contentType !== '1.2.840.113549.1.7.3') {
throw new Error(`Unexpected CMS content type: ${contentInfo.contentType}`);
}
return new pkijs.EnvelopedData({ schema: contentInfo.content });
}
interface RecipientMatch {
keyRecord: SmimeKeyRecord;
recipientIndex: number;
}
function findMatchingKeyRecords(
envelopedData: pkijs.EnvelopedData,
keyRecords: SmimeKeyRecord[],
): RecipientMatch[] {
const matches: RecipientMatch[] = [];
for (let i = 0; i < envelopedData.recipientInfos.length; i++) {
const ri = envelopedData.recipientInfos[i];
// RecipientInfo is a wrapper: variant=1 → KeyTransRecipientInfo
const ktri = ri instanceof pkijs.KeyTransRecipientInfo
? ri
: (ri as { variant?: number; value?: unknown }).variant === 1 && (ri as { value?: unknown }).value instanceof pkijs.KeyTransRecipientInfo
? (ri as { value: pkijs.KeyTransRecipientInfo }).value
: null;
if (ktri) {
for (const keyRecord of keyRecords) {
if (matchesKeyTransRecipient(ktri, keyRecord)) {
matches.push({ keyRecord, recipientIndex: i });
}
}
}
}
return matches;
}
function matchesKeyTransRecipient(
recipientInfo: pkijs.KeyTransRecipientInfo,
keyRecord: SmimeKeyRecord,
): boolean {
const rid = recipientInfo.rid;
// IssuerAndSerialNumber matching
if (rid instanceof pkijs.IssuerAndSerialNumber) {
try {
const certAsn1 = asn1js.fromBER(keyRecord.certificate);
if (certAsn1.offset === -1) return false;
const cert = new pkijs.Certificate({ schema: certAsn1.result });
// Compare serial numbers
const ridSerial = Buffer.from(rid.serialNumber.valueBlock.valueHexView).toString('hex');
const certSerial = Buffer.from(cert.serialNumber.valueBlock.valueHexView).toString('hex');
if (ridSerial !== certSerial) return false;
// Compare issuers (compare DER encoding)
const ridIssuerDer = rid.issuer.toSchema().toBER(false);
const certIssuerDer = cert.issuer.toSchema().toBER(false);
return arraysEqual(new Uint8Array(ridIssuerDer), new Uint8Array(certIssuerDer));
} catch {
return false;
}
}
// SubjectKeyIdentifier matching
if (rid instanceof asn1js.OctetString) {
try {
const certAsn1 = asn1js.fromBER(keyRecord.certificate);
if (certAsn1.offset === -1) return false;
const cert = new pkijs.Certificate({ schema: certAsn1.result });
// Find the SubjectKeyIdentifier extension
const skiExt = cert.extensions?.find(
ext => ext.extnID === '2.5.29.14', // id-ce-subjectKeyIdentifier
);
if (!skiExt) return false;
const skiValue = asn1js.fromBER(skiExt.extnValue.valueBlock.valueHexView);
if (skiValue.offset === -1) return false;
const ski = (skiValue.result as asn1js.OctetString).valueBlock.valueHexView;
return arraysEqual(
new Uint8Array(ski),
new Uint8Array(rid.valueBlock.valueHexView),
);
} catch {
return false;
}
}
return false;
}
function arraysEqual(a: Uint8Array, b: Uint8Array): boolean {
if (a.length !== b.length) return false;
for (let i = 0; i < a.length; i++) {
if (a[i] !== b[i]) return false;
}
return true;
}
async function decryptWithKey(
envelopedData: pkijs.EnvelopedData,
recipientIndex: number,
privateKey: CryptoKey,
keyRecord: SmimeKeyRecord,
): Promise<ArrayBuffer> {
// Parse the certificate for pkijs
const certAsn1 = asn1js.fromBER(keyRecord.certificate);
const cert = new pkijs.Certificate({ schema: certAsn1.result });
const cryptoEngine = new pkijs.CryptoEngine({
crypto: crypto,
subtle: crypto.subtle,
name: 'webcrypto',
});
const result = await envelopedData.decrypt(
recipientIndex,
{
recipientCertificate: cert,
recipientPrivateKey: privateKey,
},
cryptoEngine,
);
return result;
}
+194
View File
@@ -0,0 +1,194 @@
/**
* Detect S/MIME content in an email message.
*
* Checks Content-Type headers, bodyStructure, and attachment metadata
* to determine if a message contains CMS signed or encrypted content.
*/
export type SmimeContentType =
| 'enveloped-data' // encrypted
| 'signed-data' // opaque signed
| 'detached-sig' // multipart/signed (deferred in v1)
| null;
export interface SmimeDetectionResult {
/** Primary S/MIME content type detected, or null if none */
type: SmimeContentType;
/** The blobId to fetch for CMS processing (enveloped-data or signed-data) */
blobId?: string;
/** The partId containing the CMS data */
partId?: string;
/** Whether this is a v1-supported type */
supported: boolean;
}
interface EmailBodyPart {
partId?: string;
blobId?: string;
type?: string;
name?: string;
disposition?: string;
subParts?: EmailBodyPart[];
headers?: Array<{ name: string; value: string }>;
}
/**
* Detect S/MIME content from email metadata.
*
* @param contentType - The top-level Content-Type header value
* @param bodyStructure - The JMAP bodyStructure tree
* @param attachments - Flat list of attachment parts (from `attachments` property)
*/
export function detectSmime(
contentType?: string,
bodyStructure?: EmailBodyPart | null,
attachments?: EmailBodyPart[],
): SmimeDetectionResult {
const noResult: SmimeDetectionResult = { type: null, supported: false };
// 1. Check top-level Content-Type header
if (contentType) {
const ct = contentType.toLowerCase();
if (ct.includes('application/pkcs7-mime') || ct.includes('application/x-pkcs7-mime')) {
if (ct.includes('smime-type=enveloped-data')) {
const part = findCmsPart(bodyStructure, 'enveloped-data');
return {
type: 'enveloped-data',
blobId: part?.blobId,
partId: part?.partId,
supported: true,
};
}
if (ct.includes('smime-type=signed-data')) {
const part = findCmsPart(bodyStructure, 'signed-data');
return {
type: 'signed-data',
blobId: part?.blobId,
partId: part?.partId,
supported: true,
};
}
// Generic pkcs7-mime without explicit smime-type — try bodyStructure
const part = findCmsPart(bodyStructure, null);
if (part) {
const partType = inferSmimeType(part);
return {
type: partType,
blobId: part.blobId,
partId: part.partId,
supported: partType === 'enveloped-data' || partType === 'signed-data',
};
}
}
if (ct.includes('multipart/signed') && ct.includes('application/pkcs7-signature')) {
return { type: 'detached-sig', supported: false };
}
}
// 2. Walk bodyStructure tree
if (bodyStructure) {
const result = walkBodyStructure(bodyStructure);
if (result) return result;
}
// 3. Check attachment list for .p7m files
if (attachments) {
for (const att of attachments) {
const type = att.type?.toLowerCase() || '';
const name = att.name?.toLowerCase() || '';
if (type.includes('application/pkcs7-mime') || type.includes('application/x-pkcs7-mime')) {
const smimeType = inferSmimeTypeFromContentType(type);
return {
type: smimeType,
blobId: att.blobId,
partId: att.partId,
supported: smimeType === 'enveloped-data' || smimeType === 'signed-data',
};
}
if (name.endsWith('.p7m')) {
return {
type: 'enveloped-data', // .p7m is ambiguous but commonly encrypted
blobId: att.blobId,
partId: att.partId,
supported: true,
};
}
if (name.endsWith('.p7s')) {
return { type: 'detached-sig', blobId: att.blobId, partId: att.partId, supported: false };
}
}
}
return noResult;
}
function walkBodyStructure(part: EmailBodyPart): SmimeDetectionResult | null {
const type = part.type?.toLowerCase() || '';
if (type.includes('application/pkcs7-mime') || type.includes('application/x-pkcs7-mime')) {
const smimeType = inferSmimeTypeFromContentType(type);
return {
type: smimeType,
blobId: part.blobId,
partId: part.partId,
supported: smimeType === 'enveloped-data' || smimeType === 'signed-data',
};
}
if (type === 'multipart/signed') {
// Check for pkcs7-signature protocol in subparts
if (part.subParts?.some(sp => sp.type?.toLowerCase().includes('application/pkcs7-signature'))) {
return { type: 'detached-sig', supported: false };
}
}
if (part.subParts) {
for (const sub of part.subParts) {
const result = walkBodyStructure(sub);
if (result) return result;
}
}
return null;
}
function findCmsPart(bodyStructure: EmailBodyPart | null | undefined, smimeType: string | null): EmailBodyPart | null {
if (!bodyStructure) return null;
const type = bodyStructure.type?.toLowerCase() || '';
if (type.includes('application/pkcs7-mime') || type.includes('application/x-pkcs7-mime')) {
// JMAP bodyStructure.type may not include smime-type parameter,
// so accept any pkcs7-mime part when the smime-type was already
// determined from the Content-Type header.
return bodyStructure;
}
if (bodyStructure.subParts) {
for (const sub of bodyStructure.subParts) {
const found = findCmsPart(sub, smimeType);
if (found) return found;
}
}
return null;
}
function inferSmimeType(part: EmailBodyPart): SmimeContentType {
return inferSmimeTypeFromContentType(part.type || '');
}
function inferSmimeTypeFromContentType(ct: string): SmimeContentType {
const lower = ct.toLowerCase();
if (lower.includes('smime-type=enveloped-data')) return 'enveloped-data';
if (lower.includes('smime-type=signed-data')) return 'signed-data';
// Default for generic pkcs7-mime: assume enveloped-data (most common)
if (lower.includes('application/pkcs7-mime') || lower.includes('application/x-pkcs7-mime')) {
return 'enveloped-data';
}
return null;
}
+81
View File
@@ -0,0 +1,81 @@
import * as asn1js from 'asn1js';
import * as pkijs from 'pkijs';
import { parseCertificateDer } from './certificate-utils';
/**
* Produce CMS EnvelopedData for the given MIME content.
*
* Content type: application/pkcs7-mime; smime-type=enveloped-data
*
* Always includes the sender's cert so the sender can decrypt their Sent mail.
*/
export async function smimeEncrypt(
mimeBytes: Uint8Array,
recipientCertsDer: ArrayBuffer[],
senderCertDer: ArrayBuffer,
useAes128?: boolean,
): Promise<Blob> {
// Combine recipient + sender certs, deduplicate by DER bytes
const allCertDers = deduplicateCerts([...recipientCertsDer, senderCertDer]);
if (allCertDers.length === 0) {
throw new Error('No recipient certificates provided');
}
// Parse all certificates
const recipientCerts = allCertDers.map((der) => parseCertificateDer(der));
// Build EnvelopedData
const cmsEnveloped = new pkijs.EnvelopedData();
// Add recipient info for each certificate
for (const cert of recipientCerts) {
cmsEnveloped.addRecipientByCertificate(cert, {
oaepHashAlgorithm: 'SHA-256',
}, undefined, new pkijs.CryptoEngine({
crypto: crypto,
subtle: crypto.subtle,
name: 'webcrypto',
}));
}
// Encrypt the content
const contentEncryptionAlgorithm = useAes128
? { name: 'AES-GCM', length: 128 }
: { name: 'AES-GCM', length: 256 };
await cmsEnveloped.encrypt(contentEncryptionAlgorithm, mimeBytes.buffer.slice(mimeBytes.byteOffset, mimeBytes.byteOffset + mimeBytes.byteLength) as ArrayBuffer, new pkijs.CryptoEngine({
crypto: crypto,
subtle: crypto.subtle,
name: 'webcrypto',
}));
// Wrap in ContentInfo
const cms = new pkijs.ContentInfo({
contentType: '1.2.840.113549.1.7.3', // id-envelopedData
content: cmsEnveloped.toSchema(),
});
const cmsBytes = cms.toSchema().toBER(false);
return new Blob([cmsBytes], { type: 'application/pkcs7-mime; smime-type=enveloped-data' });
}
/** Remove duplicate DER-encoded certificates based on byte equality. */
function deduplicateCerts(certs: ArrayBuffer[]): ArrayBuffer[] {
const seen = new Set<string>();
const result: ArrayBuffer[] = [];
for (const cert of certs) {
const key = arrayBufferToHex(cert);
if (!seen.has(key)) {
seen.add(key);
result.push(cert);
}
}
return result;
}
function arrayBufferToHex(buf: ArrayBuffer): string {
return Array.from(new Uint8Array(buf))
.map((b) => b.toString(16).padStart(2, '0'))
.join('');
}
+71
View File
@@ -0,0 +1,71 @@
import * as asn1js from 'asn1js';
import * as pkijs from 'pkijs';
import { Convert } from 'pvtsutils';
import { parseCertificateDer } from './certificate-utils';
/**
* Produce an opaque CMS SignedData wrapping the given MIME content.
*
* Content type: application/pkcs7-mime; smime-type=signed-data
* This is the "opaque" form — the content is embedded inside the CMS structure.
*/
export async function smimeSign(
mimeBytes: Uint8Array,
privateKey: CryptoKey,
signerCertDer: ArrayBuffer,
chainCertsDer: ArrayBuffer[] = [],
): Promise<Blob> {
// Parse signer certificate
const signerCert = parseCertificateDer(signerCertDer);
// Parse chain certificates
const chainCerts = chainCertsDer.map((der) => parseCertificateDer(der));
// Build CMS SignedData
const cmsSigned = new pkijs.SignedData({
version: 1,
encapContentInfo: new pkijs.EncapsulatedContentInfo({
eContentType: '1.2.840.113549.1.7.1', // id-data
eContent: new asn1js.OctetString({ valueHex: new Uint8Array(mimeBytes.buffer.slice(mimeBytes.byteOffset, mimeBytes.byteOffset + mimeBytes.byteLength)) }),
}),
signerInfos: [
new pkijs.SignerInfo({
version: 1,
sid: new pkijs.IssuerAndSerialNumber({
issuer: signerCert.issuer,
serialNumber: signerCert.serialNumber,
}),
}),
],
certificates: [signerCert, ...chainCerts],
});
// Determine signing algorithm from the key
const algorithm = privateKey.algorithm;
const hashAlgorithm = 'SHA-256';
let signAlg: string;
if (algorithm.name === 'RSASSA-PKCS1-v1_5' || algorithm.name === 'RSA-PSS') {
signAlg = algorithm.name;
} else if (algorithm.name === 'ECDSA') {
signAlg = 'ECDSA';
} else {
signAlg = 'RSASSA-PKCS1-v1_5';
}
// Sign
await cmsSigned.sign(privateKey, 0, hashAlgorithm, undefined, new pkijs.CryptoEngine({
crypto: crypto,
subtle: crypto.subtle,
name: 'webcrypto',
}));
// Wrap in ContentInfo
const cms = new pkijs.ContentInfo({
contentType: '1.2.840.113549.1.7.2', // id-signedData
content: cmsSigned.toSchema(true),
});
const cmsBytes = cms.toSchema().toBER(false);
return new Blob([cmsBytes], { type: 'application/pkcs7-mime; smime-type=signed-data' });
}
+219
View File
@@ -0,0 +1,219 @@
/**
* Verify CMS SignedData (opaque signed) and extract the inner content.
*
* v1 performs cryptographic signature validation and cert validity checks
* but does NOT implement full trust-chain or revocation validation.
*/
import * as pkijs from 'pkijs';
import * as asn1js from 'asn1js';
import { extractCertificateInfo } from './certificate-utils';
import type { SmimeStatus, SmimePublicCert } from './types';
export interface VerificationResult {
/** The inner MIME bytes extracted from the opaque SignedData */
mimeBytes: Uint8Array;
/** Full S/MIME status for display */
status: SmimeStatus;
}
/**
* Verify a CMS SignedData structure and extract the encapsulated content.
*
* @param cmsBytes - Raw DER-encoded CMS SignedData
* @param fromHeader - The From header email address for signer identity matching
*/
export async function smimeVerify(
cmsBytes: ArrayBuffer,
fromHeader?: string,
): Promise<VerificationResult> {
const contentInfo = parseContentInfo(cmsBytes);
const signedData = extractSignedData(contentInfo);
// Extract inner content
const innerContent = extractInnerContent(signedData);
// Extract signer certificate
const signerCert = extractSignerCertificate(signedData);
if (!signerCert) {
return {
mimeBytes: innerContent,
status: {
isSigned: true,
isEncrypted: false,
signatureValid: false,
signatureError: 'Signer certificate not found in CMS structure',
},
};
}
// Verify the signature cryptographically
let signatureValid = false;
let signatureError: string | undefined;
try {
const cryptoEngine = new pkijs.CryptoEngine({
crypto: crypto,
subtle: crypto.subtle,
name: 'webcrypto',
});
const verifyResult = await signedData.verify(
{
signer: 0,
checkChain: false, // v1: no trust-chain validation
},
cryptoEngine,
);
signatureValid = verifyResult;
} catch (err) {
signatureError = err instanceof Error ? err.message : 'Signature verification failed';
}
// Extract certificate info for display
const certDer = signerCert.toSchema(true).toBER(false);
const certInfo = await extractCertificateInfo(signerCert, certDer);
// Check certificate validity period
const now = new Date();
const notBefore = new Date(certInfo.notBefore);
const notAfter = new Date(certInfo.notAfter);
const certExpired = now > notAfter;
const certNotYetValid = now < notBefore;
if (certExpired && !signatureError) {
signatureError = 'Signer certificate has expired';
}
if (certNotYetValid && !signatureError) {
signatureError = 'Signer certificate is not yet valid';
}
// Build the signer public cert object
const signerEmail = certInfo.emailAddresses[0] ?? '';
const signerPublicCert: SmimePublicCert = {
id: `signer-${certInfo.fingerprint}`,
email: signerEmail.toLowerCase(),
certificate: certDer,
issuer: certInfo.issuer,
subject: certInfo.subject,
notBefore: certInfo.notBefore,
notAfter: certInfo.notAfter,
fingerprint: certInfo.fingerprint,
source: 'signed-email',
};
// Check signer identity vs From header
let signerEmailMatch: boolean | undefined;
if (fromHeader && signerEmail) {
signerEmailMatch = fromHeader.toLowerCase() === signerEmail.toLowerCase();
}
return {
mimeBytes: innerContent,
status: {
isSigned: true,
isEncrypted: false,
signatureValid: signatureValid && !certExpired && !certNotYetValid,
signatureError,
signerCert: signerPublicCert,
signerEmailMatch,
},
};
}
// --- Internal helpers ---
function parseContentInfo(der: ArrayBuffer): pkijs.ContentInfo {
const asn1 = asn1js.fromBER(der);
if (asn1.offset === -1) {
throw new Error('Invalid ASN.1 data — cannot parse CMS structure');
}
return new pkijs.ContentInfo({ schema: asn1.result });
}
function extractSignedData(contentInfo: pkijs.ContentInfo): pkijs.SignedData {
// OID 1.2.840.113549.1.7.2 = signed-data
if (contentInfo.contentType !== '1.2.840.113549.1.7.2') {
throw new Error(`Unexpected CMS content type: ${contentInfo.contentType}`);
}
return new pkijs.SignedData({ schema: contentInfo.content });
}
function extractInnerContent(signedData: pkijs.SignedData): Uint8Array {
const eContent = signedData.encapContentInfo?.eContent;
if (!eContent) {
throw new Error('No encapsulated content in SignedData (detached signature not supported)');
}
if (eContent instanceof asn1js.OctetString) {
// Constructed OCTET STRING: data lives in child OctetStrings
const children = (eContent.valueBlock as unknown as { value?: asn1js.OctetString[] }).value;
if (children?.length) {
const chunks = children.map(c => new Uint8Array(c.valueBlock.valueHexView));
const total = chunks.reduce((sum, c) => sum + c.length, 0);
const result = new Uint8Array(total);
let offset = 0;
for (const chunk of chunks) {
result.set(chunk, offset);
offset += chunk.length;
}
return result;
}
// Primitive OCTET STRING: data is directly in valueHexView
return new Uint8Array(eContent.valueBlock.valueHexView);
}
throw new Error('Unable to extract content from SignedData');
}
function extractSignerCertificate(signedData: pkijs.SignedData): pkijs.Certificate | null {
if (!signedData.signerInfos?.length || !signedData.certificates?.length) {
return null;
}
const signerInfo = signedData.signerInfos[0];
const sid = signerInfo.sid;
// IssuerAndSerialNumber matching
if (sid instanceof pkijs.IssuerAndSerialNumber) {
for (const certItem of signedData.certificates) {
if (!(certItem instanceof pkijs.Certificate)) continue;
const cert = certItem;
// Compare serial numbers
const sidSerial = toHex(sid.serialNumber.valueBlock.valueHexView);
const certSerial = toHex(cert.serialNumber.valueBlock.valueHexView);
if (sidSerial !== certSerial) continue;
// Compare issuers
const sidIssuerDer = new Uint8Array(sid.issuer.toSchema().toBER(false));
const certIssuerDer = new Uint8Array(cert.issuer.toSchema().toBER(false));
if (arraysEqual(sidIssuerDer, certIssuerDer)) {
return cert;
}
}
}
// If only one certificate is present, use it as fallback
if (signedData.certificates.length === 1) {
const cert = signedData.certificates[0];
if (cert instanceof pkijs.Certificate) return cert;
}
return null;
}
function toHex(buffer: ArrayBuffer | ArrayBufferView): string {
const bytes = buffer instanceof ArrayBuffer
? new Uint8Array(buffer)
: new Uint8Array(buffer.buffer, buffer.byteOffset, buffer.byteLength);
return Array.from(bytes).map(b => b.toString(16).padStart(2, '0')).join('');
}
function arraysEqual(a: Uint8Array, b: Uint8Array): boolean {
if (a.length !== b.length) return false;
for (let i = 0; i < a.length; i++) {
if (a[i] !== b[i]) return false;
}
return true;
}
+80
View File
@@ -0,0 +1,80 @@
/** Stored record for an imported S/MIME private key + certificate. */
export interface SmimeKeyRecord {
id: string;
email: string;
certificate: ArrayBuffer; // DER-encoded X.509 leaf cert
certificateChain: ArrayBuffer[]; // DER-encoded intermediates
encryptedPrivateKey: ArrayBuffer; // AES-GCM wrapped PKCS#8 bytes
salt: ArrayBuffer; // PBKDF2 salt
iv: ArrayBuffer; // AES-GCM IV
kdfIterations: number;
issuer: string;
subject: string;
serialNumber: string;
notBefore: string; // ISO 8601
notAfter: string; // ISO 8601
fingerprint: string; // SHA-256 hex of DER cert
algorithm: string; // e.g. "RSA-2048", "RSA-4096", "ECDSA-P256"
capabilities: SmimeKeyCapabilities;
}
/** What a certificate can be used for based on KeyUsage/ExtendedKeyUsage. */
export interface SmimeKeyCapabilities {
canSign: boolean;
canEncrypt: boolean;
}
/** Runtime-only unlocked private key handle (never persisted). */
export interface SmimeUnlockedKey {
id: string;
email: string;
privateKey: CryptoKey; // imported as non-extractable
}
/** A recipient or contact public certificate. */
export interface SmimePublicCert {
id: string;
email: string;
certificate: ArrayBuffer; // DER-encoded X.509
issuer: string;
subject: string;
notBefore: string;
notAfter: string;
fingerprint: string;
source: 'manual' | 'contact' | 'signed-email';
contactId?: string;
}
/** Status of S/MIME processing for a single email message. */
export interface SmimeStatus {
isSigned: boolean;
isEncrypted: boolean;
signatureValid?: boolean;
signatureError?: string;
signerCert?: SmimePublicCert;
signerEmailMatch?: boolean;
decryptionSuccess?: boolean;
decryptionError?: string;
unsupportedReason?: string;
}
/** Metadata extracted from a parsed X.509 certificate. */
export interface CertificateInfo {
subject: string;
issuer: string;
serialNumber: string;
notBefore: string;
notAfter: string;
fingerprint: string;
algorithm: string;
keyUsage?: string[];
extendedKeyUsage?: string[];
emailAddresses: string[];
capabilities: SmimeKeyCapabilities;
}
/** Result of PKCS#12 import parsing. */
export interface Pkcs12ImportResult {
keyRecord: SmimeKeyRecord;
certInfo: CertificateInfo;
}
+97 -1
View File
@@ -416,6 +416,15 @@
"upload_cancel": "Hochladen abbrechen",
"upload_failed": "Hochladen von {filename} fehlgeschlagen",
"send_failed": "E-Mail konnte nicht gesendet werden",
"smime_sign_on": "S/MIME-Signatur aktiviert",
"smime_sign_off": "S/MIME-Signatur deaktiviert",
"smime_encrypt_on": "S/MIME-Verschlüsselung aktiviert",
"smime_encrypt_off": "S/MIME-Verschlüsselung deaktiviert",
"smime_encrypt_unavailable": "S/MIME-Verschlüsselung nicht möglich: {reason}",
"smime_unlock_title": "S/MIME-Schlüssel entsperren",
"smime_unlock_message": "Geben Sie die Passphrase ein, um Ihren S/MIME-Schlüssel zu entsperren.",
"smime_unlock_button": "Entsperren",
"smime_passphrase_placeholder": "S/MIME-Passphrase",
"continue_draft": "Entwurf fortsetzen",
"close_draft_title": "Entwurf speichern oder verwerfen?",
"close_draft_message": "Sie haben ungespeicherte Änderungen. Möchten Sie diese als Entwurf speichern oder verwerfen?",
@@ -552,6 +561,7 @@
"folders": "Ordner",
"keywords": "Schlüsselwörter",
"security": "Sicherheit",
"encryption": "Verschlüsselung",
"files": "Dateien",
"contacts": "Contacts"
},
@@ -1439,7 +1449,16 @@
"calendar": "Kalender",
"calendar_uri": "Kalender-URL",
"scheduling_uri": "Terminplanungs-URL",
"freebusy_uri": "Frei/Belegt-URL"
"freebusy_uri": "Frei/Belegt-URL",
"cert_issuer": "Aussteller",
"cert_expires": "Läuft ab",
"cert_expired": "Abgelaufen",
"cert_fingerprint": "Fingerabdruck",
"cert_algorithm": "Algorithmus",
"import_to_smime": "In S/MIME importieren",
"cert_already_imported": "Zertifikat bereits importiert",
"cert_imported": "Zertifikat importiert",
"cert_import_failed": "Import des Zertifikats fehlgeschlagen"
},
"form": {
"create_title": "Neuer Kontakt",
@@ -1989,5 +2008,82 @@
"settings_folder_layout_desc": "Choose how folders are displayed: inline with files or in a sidebar tree",
"settings_folder_layout_inline": "Inline",
"settings_folder_layout_sidebar": "Sidebar"
},
"smime": {
"your_certificates": "Ihre Zertifikate",
"your_certificates_desc": "Importieren und verwalten Sie Ihre S/MIME-Zertifikate zum Signieren und Verschlüsseln von E-Mails",
"recipient_certificates": "Empfängerzertifikate",
"recipient_certificates_desc": "Öffentliche Zertifikate zum Verschlüsseln von E-Mails an Empfänger",
"identity_bindings": "Identitäts-Zertifikatsbindungen",
"identity_bindings_desc": "Ordnen Sie S/MIME-Zertifikate Ihren E-Mail-Identitäten zu",
"defaults_title": "Standardwerte",
"defaults_desc": "Konfigurieren Sie das Standardverhalten für Signatur und Verschlüsselung",
"import_pkcs12": "PKCS#12 importieren (.p12/.pfx)",
"import_public_cert": "Zertifikat importieren",
"no_certificates": "Noch keine Zertifikate importiert",
"no_recipient_certs": "Keine Empfängerzertifikate",
"expires": "Läuft ab",
"expired": "Abgelaufen",
"bound_to": "Zugeordnet zu",
"no_key_bound": "Keine",
"lock": "Schlüssel sperren",
"unlock": "Schlüssel entsperren",
"details": "Details anzeigen",
"delete": "Löschen",
"encrypt_by_default": "Standardmäßig verschlüsseln",
"encrypt_by_default_desc": "E-Mails automatisch verschlüsseln, wenn alle Empfänger Zertifikate haben",
"remember_unlocked": "Entsperrte Schlüssel merken",
"remember_unlocked_desc": "Schlüssel für die Dauer dieser Browsersitzung entsperrt lassen",
"sign_default_for": "Standardmäßig signieren für",
"enter_p12_passphrase": "PKCS#12-Passphrase eingeben",
"p12_passphrase_desc": "Geben Sie die Passphrase ein, die diese Zertifikatsdatei schützt",
"enter_storage_passphrase": "Speicher-Passphrase festlegen",
"storage_passphrase_desc": "Wählen Sie eine Passphrase, um diesen Schlüssel im Browser zu schützen",
"next": "Weiter",
"import": "Importieren",
"unlock_key": "Schlüssel entsperren",
"unlock_key_desc": "Geben Sie die Speicher-Passphrase ein, um diesen Schlüssel zum Signieren oder Entschlüsseln zu entsperren",
"passphrase_placeholder": "Passphrase eingeben",
"confirm_passphrase_placeholder": "Passphrase bestätigen",
"passphrase_mismatch": "Passphrasen stimmen nicht überein",
"cancel": "Abbrechen",
"processing": "Wird verarbeitet…",
"close": "Schließen",
"certificate_details": "Zertifikatsdetails",
"cert_subject": "Betreff",
"cert_issuer": "Aussteller",
"cert_email": "E-Mail",
"cert_serial": "Seriennummer",
"cert_validity": "Gültigkeit",
"cert_fingerprint": "Fingerabdruck (SHA-256)",
"cert_algorithm": "Algorithmus",
"cert_capabilities": "Fähigkeiten",
"cert_source": "Quelle",
"cert_expired": "Dieses Zertifikat ist abgelaufen",
"cert_not_yet_valid": "Dieses Zertifikat ist noch nicht gültig",
"cap_sign": "Signieren",
"cap_encrypt": "Verschlüsselung",
"cap_none": "Keine",
"show_passphrase": "Passphrase anzeigen",
"hide_passphrase": "Passphrase ausblenden",
"sign_toggle": "Signieren",
"encrypt_toggle": "Verschlüsseln",
"missing_recipient_certs": "Fehlende Zertifikate für: {emails}",
"missing_sender_cert": "Diesem Konto ist kein Zertifikat zugeordnet",
"status_encrypted_ok": "Diese Nachricht wurde verschlüsselt",
"status_encrypted_no_key": "Diese Nachricht ist verschlüsselt, aber es wurde kein passender Schlüssel gefunden",
"status_encrypted_failed": "Diese Nachricht konnte nicht entschlüsselt werden",
"status_signed_valid": "Signatur überprüft",
"status_signed_invalid": "Signaturprüfung fehlgeschlagen",
"status_signed_expired_cert": "Mit einem abgelaufenen Zertifikat signiert",
"status_signed_mismatch": "Signatur ist gültig, aber der Unterzeichner stimmt nicht mit dem Absender überein",
"status_unsupported": "Nicht unterstütztes S/MIME-Format",
"auto_import_signer_certs": "Unterzeichnerzertifikate automatisch importieren",
"auto_import_signer_certs_desc": "Zertifikate aus verifizierten signierten E-Mails automatisch für spätere Verschlüsselung speichern",
"export": "Exportieren",
"enter_export_passphrase": "Export-Passphrase festlegen",
"export_passphrase_desc": "Wählen Sie eine Passphrase zum Schutz der exportierten PKCS#12-Datei",
"export_storage_desc": "Geben Sie die Speicher-Passphrase ein, um den Schlüssel für den Export zu entschlüsseln",
"incorrect_passphrase": "Falsche Passphrase"
}
}
+98 -2
View File
@@ -421,7 +421,16 @@
"continue_draft": "Continue draft",
"close_draft_title": "Save or discard draft?",
"close_draft_message": "You have unsaved changes. Would you like to save this as a draft or discard it?",
"save_draft": "Save Draft"
"save_draft": "Save Draft",
"smime_sign_on": "S/MIME signing enabled",
"smime_sign_off": "Enable S/MIME signing",
"smime_encrypt_on": "S/MIME encryption enabled",
"smime_encrypt_off": "Enable S/MIME encryption",
"smime_encrypt_unavailable": "S/MIME encryption unavailable missing recipient certificates",
"smime_unlock_title": "Unlock S/MIME Key",
"smime_unlock_message": "Enter the passphrase to unlock your S/MIME signing key.",
"smime_unlock_button": "Unlock",
"smime_passphrase_placeholder": "Passphrase"
},
"confirm_dialog": {
"confirm": "Confirm",
@@ -553,7 +562,8 @@
"keywords": "Keywords",
"security": "Security",
"files": "Files",
"contacts": "Contacts"
"contacts": "Contacts",
"encryption": "Encryption"
},
"tab_groups": {
"general": "General",
@@ -1412,6 +1422,15 @@
"categories": "Categories",
"related_contacts": "Related Contacts",
"crypto_keys": "Crypto Keys",
"cert_issuer": "Issuer",
"cert_expires": "Expires",
"cert_expired": "Expired",
"cert_fingerprint": "Fingerprint",
"cert_algorithm": "Algorithm",
"import_to_smime": "Import to S/MIME",
"cert_already_imported": "Already imported to S/MIME",
"cert_imported": "Certificate imported to S/MIME store",
"cert_import_failed": "Failed to import certificate",
"no_contact_selected": "Select a contact to view details",
"compose_email": "Compose email",
"copy_email": "Copy email",
@@ -1989,5 +2008,82 @@
"settings_folder_layout_desc": "Choose how folders are displayed: inline with files or in a sidebar tree",
"settings_folder_layout_inline": "Inline",
"settings_folder_layout_sidebar": "Sidebar"
},
"smime": {
"your_certificates": "Your Certificates",
"your_certificates_desc": "Import and manage your S/MIME certificates for signing and encrypting emails",
"recipient_certificates": "Recipient Certificates",
"recipient_certificates_desc": "Public certificates for encrypting emails to recipients",
"identity_bindings": "Identity Key Bindings",
"identity_bindings_desc": "Bind S/MIME certificates to your email identities",
"defaults_title": "Defaults",
"defaults_desc": "Configure default signing and encryption behavior",
"import_pkcs12": "Import PKCS#12 (.p12/.pfx)",
"import_public_cert": "Import Certificate",
"no_certificates": "No certificates imported yet",
"no_recipient_certs": "No recipient certificates",
"expires": "Expires",
"expired": "Expired",
"bound_to": "Bound to",
"no_key_bound": "None",
"lock": "Lock key",
"unlock": "Unlock key",
"details": "View details",
"delete": "Delete",
"encrypt_by_default": "Encrypt by default",
"encrypt_by_default_desc": "Automatically encrypt emails when all recipients have certificates",
"remember_unlocked": "Remember unlocked keys",
"remember_unlocked_desc": "Keep keys unlocked for the duration of this browser session",
"sign_default_for": "Sign by default for",
"enter_p12_passphrase": "Enter PKCS#12 Passphrase",
"p12_passphrase_desc": "Enter the passphrase that protects this certificate file",
"enter_storage_passphrase": "Set Storage Passphrase",
"storage_passphrase_desc": "Choose a passphrase to protect this key at rest in your browser",
"next": "Next",
"import": "Import",
"unlock_key": "Unlock Key",
"unlock_key_desc": "Enter the storage passphrase to unlock this key for signing or decryption",
"passphrase_placeholder": "Enter passphrase",
"confirm_passphrase_placeholder": "Confirm passphrase",
"passphrase_mismatch": "Passphrases do not match",
"cancel": "Cancel",
"processing": "Processing…",
"close": "Close",
"certificate_details": "Certificate Details",
"cert_subject": "Subject",
"cert_issuer": "Issuer",
"cert_email": "Email",
"cert_serial": "Serial Number",
"cert_validity": "Validity",
"cert_fingerprint": "Fingerprint (SHA-256)",
"cert_algorithm": "Algorithm",
"cert_capabilities": "Capabilities",
"cert_source": "Source",
"cert_expired": "This certificate has expired",
"cert_not_yet_valid": "This certificate is not yet valid",
"cap_sign": "Signing",
"cap_encrypt": "Encryption",
"cap_none": "None",
"show_passphrase": "Show passphrase",
"hide_passphrase": "Hide passphrase",
"sign_toggle": "Sign",
"encrypt_toggle": "Encrypt",
"missing_recipient_certs": "Missing certificates for: {emails}",
"missing_sender_cert": "No certificate bound to this identity",
"status_encrypted_ok": "This message was encrypted",
"status_encrypted_no_key": "This message is encrypted but no matching key was found",
"status_encrypted_failed": "Failed to decrypt this message",
"status_signed_valid": "Signature verified",
"status_signed_invalid": "Signature verification failed",
"status_signed_expired_cert": "Signed with an expired certificate",
"status_signed_mismatch": "Signature valid, but signer does not match sender",
"status_unsupported": "Unsupported S/MIME format",
"auto_import_signer_certs": "Auto-import signer certificates",
"auto_import_signer_certs_desc": "Automatically save certificates from verified signed emails for future encryption",
"export": "Export",
"enter_export_passphrase": "Set Export Passphrase",
"export_passphrase_desc": "Choose a passphrase to protect the exported PKCS#12 file",
"export_storage_desc": "Enter the storage passphrase to decrypt the key for export",
"incorrect_passphrase": "Incorrect passphrase"
}
}
+97 -1
View File
@@ -416,6 +416,15 @@
"upload_cancel": "Cancelar subida",
"upload_failed": "Error al subir {filename}",
"send_failed": "Error al enviar el correo",
"smime_sign_on": "Firma S/MIME activada",
"smime_sign_off": "Firma S/MIME desactivada",
"smime_encrypt_on": "Cifrado S/MIME activado",
"smime_encrypt_off": "Cifrado S/MIME desactivado",
"smime_encrypt_unavailable": "El cifrado S/MIME no está disponible: {reason}",
"smime_unlock_title": "Desbloquear clave S/MIME",
"smime_unlock_message": "Introduce la contraseña para desbloquear tu clave S/MIME.",
"smime_unlock_button": "Desbloquear",
"smime_passphrase_placeholder": "Contraseña S/MIME",
"continue_draft": "Continuar borrador",
"close_draft_title": "¿Guardar o descartar borrador?",
"close_draft_message": "Tiene cambios sin guardar. ¿Desea guardar esto como borrador o descartarlo?",
@@ -552,6 +561,7 @@
"folders": "Carpetas",
"keywords": "Palabras clave",
"security": "Seguridad",
"encryption": "Cifrado",
"files": "Archivos",
"contacts": "Contacts"
},
@@ -1439,7 +1449,16 @@
"calendar": "Calendario",
"calendar_uri": "URL del calendario",
"scheduling_uri": "URL de programación",
"freebusy_uri": "URL de disponibilidad"
"freebusy_uri": "URL de disponibilidad",
"cert_issuer": "Emisor",
"cert_expires": "Caduca",
"cert_expired": "Caducado",
"cert_fingerprint": "Huella digital",
"cert_algorithm": "Algoritmo",
"import_to_smime": "Importar a S/MIME",
"cert_already_imported": "Certificado ya importado",
"cert_imported": "Certificado importado",
"cert_import_failed": "Error al importar el certificado"
},
"form": {
"create_title": "Nuevo contacto",
@@ -1989,5 +2008,82 @@
"settings_folder_layout_desc": "Choose how folders are displayed: inline with files or in a sidebar tree",
"settings_folder_layout_inline": "Inline",
"settings_folder_layout_sidebar": "Sidebar"
},
"smime": {
"your_certificates": "Tus certificados",
"your_certificates_desc": "Importa y administra tus certificados S/MIME para firmar y cifrar correos",
"recipient_certificates": "Certificados de destinatarios",
"recipient_certificates_desc": "Certificados públicos para cifrar correos a destinatarios",
"identity_bindings": "Vinculaciones de identidad y clave",
"identity_bindings_desc": "Vincula certificados S/MIME a tus identidades de correo",
"defaults_title": "Valores predeterminados",
"defaults_desc": "Configura el comportamiento predeterminado de firma y cifrado",
"import_pkcs12": "Importar PKCS#12 (.p12/.pfx)",
"import_public_cert": "Importar certificado",
"no_certificates": "Aún no se han importado certificados",
"no_recipient_certs": "No hay certificados de destinatarios",
"expires": "Caduca",
"expired": "Caducado",
"bound_to": "Vinculado a",
"no_key_bound": "Ninguno",
"lock": "Bloquear clave",
"unlock": "Desbloquear clave",
"details": "Ver detalles",
"delete": "Eliminar",
"encrypt_by_default": "Cifrar por defecto",
"encrypt_by_default_desc": "Cifrar correos automáticamente cuando todos los destinatarios tengan certificados",
"remember_unlocked": "Recordar claves desbloqueadas",
"remember_unlocked_desc": "Mantener las claves desbloqueadas durante esta sesión del navegador",
"sign_default_for": "Firmar por defecto para",
"enter_p12_passphrase": "Introducir la contraseña de PKCS#12",
"p12_passphrase_desc": "Introduce la contraseña que protege este archivo de certificado",
"enter_storage_passphrase": "Definir contraseña de almacenamiento",
"storage_passphrase_desc": "Elige una contraseña para proteger esta clave en tu navegador",
"next": "Siguiente",
"import": "Importar",
"unlock_key": "Desbloquear clave",
"unlock_key_desc": "Introduce la contraseña de almacenamiento para desbloquear esta clave para firmar o descifrar",
"passphrase_placeholder": "Introduce la contraseña",
"confirm_passphrase_placeholder": "Confirma la contraseña",
"passphrase_mismatch": "Las contraseñas no coinciden",
"cancel": "Cancelar",
"processing": "Procesando…",
"close": "Cerrar",
"certificate_details": "Detalles del certificado",
"cert_subject": "Asunto",
"cert_issuer": "Emisor",
"cert_email": "Correo electrónico",
"cert_serial": "Número de serie",
"cert_validity": "Validez",
"cert_fingerprint": "Huella digital (SHA-256)",
"cert_algorithm": "Algoritmo",
"cert_capabilities": "Capacidades",
"cert_source": "Origen",
"cert_expired": "Este certificado ha caducado",
"cert_not_yet_valid": "Este certificado aún no es válido",
"cap_sign": "Firma",
"cap_encrypt": "Cifrado",
"cap_none": "Ninguno",
"show_passphrase": "Mostrar contraseña",
"hide_passphrase": "Ocultar contraseña",
"sign_toggle": "Firmar",
"encrypt_toggle": "Cifrar",
"missing_recipient_certs": "Faltan certificados para: {emails}",
"missing_sender_cert": "No hay un certificado vinculado a esta identidad",
"status_encrypted_ok": "Este mensaje fue cifrado",
"status_encrypted_no_key": "Este mensaje está cifrado, pero no se encontró una clave coincidente",
"status_encrypted_failed": "No se pudo descifrar este mensaje",
"status_signed_valid": "Firma verificada",
"status_signed_invalid": "La verificación de la firma falló",
"status_signed_expired_cert": "Firmado con un certificado caducado",
"status_signed_mismatch": "La firma es válida, pero el firmante no coincide con el remitente",
"status_unsupported": "Formato S/MIME no compatible",
"auto_import_signer_certs": "Importar automáticamente certificados de firmantes",
"auto_import_signer_certs_desc": "Guardar automáticamente certificados de correos firmados verificados para futuros cifrados",
"export": "Exportar",
"enter_export_passphrase": "Definir contraseña de exportación",
"export_passphrase_desc": "Elige una contraseña para proteger el archivo PKCS#12 exportado",
"export_storage_desc": "Introduce la contraseña de almacenamiento para descifrar la clave antes de exportarla",
"incorrect_passphrase": "Contraseña incorrecta"
}
}
+97 -1
View File
@@ -416,6 +416,15 @@
"upload_cancel": "Annuler l'envoi",
"upload_failed": "Échec du téléversement de {filename}",
"send_failed": "Échec de l'envoi de l'e-mail",
"smime_sign_on": "Signature S/MIME activée",
"smime_sign_off": "Signature S/MIME désactivée",
"smime_encrypt_on": "Chiffrement S/MIME activé",
"smime_encrypt_off": "Chiffrement S/MIME désactivé",
"smime_encrypt_unavailable": "Le chiffrement S/MIME n'est pas disponible : {reason}",
"smime_unlock_title": "Déverrouiller la clé S/MIME",
"smime_unlock_message": "Entrez la phrase secrète pour déverrouiller votre clé S/MIME.",
"smime_unlock_button": "Déverrouiller",
"smime_passphrase_placeholder": "Phrase secrète S/MIME",
"continue_draft": "Continuer le brouillon",
"close_draft_title": "Enregistrer ou supprimer le brouillon ?",
"close_draft_message": "Vous avez des modifications non enregistrées. Voulez-vous enregistrer comme brouillon ou supprimer ?",
@@ -552,6 +561,7 @@
"folders": "Dossiers",
"keywords": "Mots-clés",
"security": "Sécurité",
"encryption": "Chiffrement",
"files": "Fichiers",
"contacts": "Contacts"
},
@@ -1439,7 +1449,16 @@
"calendar": "Calendrier",
"calendar_uri": "URL du calendrier",
"scheduling_uri": "URL de planification",
"freebusy_uri": "URL de disponibilité"
"freebusy_uri": "URL de disponibilité",
"cert_issuer": "Émetteur",
"cert_expires": "Expire le",
"cert_expired": "Expiré",
"cert_fingerprint": "Empreinte",
"cert_algorithm": "Algorithme",
"import_to_smime": "Importer dans S/MIME",
"cert_already_imported": "Certificat déjà importé",
"cert_imported": "Certificat importé",
"cert_import_failed": "Échec de l'import du certificat"
},
"form": {
"create_title": "Nouveau contact",
@@ -1989,5 +2008,82 @@
"settings_folder_layout_desc": "Choose how folders are displayed: inline with files or in a sidebar tree",
"settings_folder_layout_inline": "Inline",
"settings_folder_layout_sidebar": "Sidebar"
},
"smime": {
"your_certificates": "Vos certificats",
"your_certificates_desc": "Importez et gérez vos certificats S/MIME pour signer et chiffrer les e-mails",
"recipient_certificates": "Certificats des destinataires",
"recipient_certificates_desc": "Certificats publics pour chiffrer les e-mails destinés aux destinataires",
"identity_bindings": "Liaisons identité-clé",
"identity_bindings_desc": "Associez des certificats S/MIME à vos identités de messagerie",
"defaults_title": "Valeurs par défaut",
"defaults_desc": "Configurez le comportement par défaut de signature et de chiffrement",
"import_pkcs12": "Importer PKCS#12 (.p12/.pfx)",
"import_public_cert": "Importer un certificat",
"no_certificates": "Aucun certificat importé pour le moment",
"no_recipient_certs": "Aucun certificat destinataire",
"expires": "Expire le",
"expired": "Expiré",
"bound_to": "Lié à",
"no_key_bound": "Aucun",
"lock": "Verrouiller la clé",
"unlock": "Déverrouiller la clé",
"details": "Voir les détails",
"delete": "Supprimer",
"encrypt_by_default": "Chiffrer par défaut",
"encrypt_by_default_desc": "Chiffrer automatiquement les e-mails lorsque tous les destinataires ont un certificat",
"remember_unlocked": "Mémoriser les clés déverrouillées",
"remember_unlocked_desc": "Conserver les clés déverrouillées pendant cette session du navigateur",
"sign_default_for": "Signer par défaut pour",
"enter_p12_passphrase": "Entrer la phrase secrète PKCS#12",
"p12_passphrase_desc": "Entrez la phrase secrète qui protège ce fichier de certificat",
"enter_storage_passphrase": "Définir la phrase secrète de stockage",
"storage_passphrase_desc": "Choisissez une phrase secrète pour protéger cette clé dans votre navigateur",
"next": "Suivant",
"import": "Importer",
"unlock_key": "Déverrouiller la clé",
"unlock_key_desc": "Entrez la phrase secrète de stockage pour déverrouiller cette clé pour la signature ou le déchiffrement",
"passphrase_placeholder": "Entrez la phrase secrète",
"confirm_passphrase_placeholder": "Confirmez la phrase secrète",
"passphrase_mismatch": "Les phrases secrètes ne correspondent pas",
"cancel": "Annuler",
"processing": "Traitement…",
"close": "Fermer",
"certificate_details": "Détails du certificat",
"cert_subject": "Sujet",
"cert_issuer": "Émetteur",
"cert_email": "E-mail",
"cert_serial": "Numéro de série",
"cert_validity": "Validité",
"cert_fingerprint": "Empreinte (SHA-256)",
"cert_algorithm": "Algorithme",
"cert_capabilities": "Capacités",
"cert_source": "Source",
"cert_expired": "Ce certificat a expiré",
"cert_not_yet_valid": "Ce certificat n'est pas encore valide",
"cap_sign": "Signature",
"cap_encrypt": "Chiffrement",
"cap_none": "Aucune",
"show_passphrase": "Afficher la phrase secrète",
"hide_passphrase": "Masquer la phrase secrète",
"sign_toggle": "Signer",
"encrypt_toggle": "Chiffrer",
"missing_recipient_certs": "Certificats manquants pour : {emails}",
"missing_sender_cert": "Aucun certificat n'est lié à cette identité",
"status_encrypted_ok": "Ce message a été chiffré",
"status_encrypted_no_key": "Ce message est chiffré, mais aucune clé correspondante n'a été trouvée",
"status_encrypted_failed": "Impossible de déchiffrer ce message",
"status_signed_valid": "Signature vérifiée",
"status_signed_invalid": "Échec de la vérification de la signature",
"status_signed_expired_cert": "Signé avec un certificat expiré",
"status_signed_mismatch": "La signature est valide, mais le signataire ne correspond pas à l'expéditeur",
"status_unsupported": "Format S/MIME non pris en charge",
"auto_import_signer_certs": "Importer automatiquement les certificats des signataires",
"auto_import_signer_certs_desc": "Enregistrer automatiquement les certificats des e-mails signés vérifiés pour un futur chiffrement",
"export": "Exporter",
"enter_export_passphrase": "Définir la phrase secrète d'export",
"export_passphrase_desc": "Choisissez une phrase secrète pour protéger le fichier PKCS#12 exporté",
"export_storage_desc": "Entrez la phrase secrète de stockage pour déchiffrer la clé avant l'export",
"incorrect_passphrase": "Phrase secrète incorrecte"
}
}
+97 -1
View File
@@ -416,6 +416,15 @@
"upload_cancel": "Annulla caricamento",
"upload_failed": "Caricamento di {filename} non riuscito",
"send_failed": "Invio dell'e-mail non riuscito",
"smime_sign_on": "Firma S/MIME attivata",
"smime_sign_off": "Firma S/MIME disattivata",
"smime_encrypt_on": "Cifratura S/MIME attivata",
"smime_encrypt_off": "Cifratura S/MIME disattivata",
"smime_encrypt_unavailable": "La cifratura S/MIME non è disponibile: {reason}",
"smime_unlock_title": "Sblocca chiave S/MIME",
"smime_unlock_message": "Inserisci la passphrase per sbloccare la tua chiave S/MIME.",
"smime_unlock_button": "Sblocca",
"smime_passphrase_placeholder": "Passphrase S/MIME",
"continue_draft": "Continua bozza",
"close_draft_title": "Salvare o eliminare la bozza?",
"close_draft_message": "Hai modifiche non salvate. Vuoi salvare come bozza o eliminare?",
@@ -552,6 +561,7 @@
"folders": "Cartelle",
"keywords": "Parole chiave",
"security": "Sicurezza",
"encryption": "Cifratura",
"files": "File",
"contacts": "Contacts"
},
@@ -1439,7 +1449,16 @@
"calendar": "Calendario",
"calendar_uri": "URL del calendario",
"scheduling_uri": "URL di pianificazione",
"freebusy_uri": "URL di disponibilità"
"freebusy_uri": "URL di disponibilità",
"cert_issuer": "Emittente",
"cert_expires": "Scade",
"cert_expired": "Scaduto",
"cert_fingerprint": "Impronta digitale",
"cert_algorithm": "Algoritmo",
"import_to_smime": "Importa in S/MIME",
"cert_already_imported": "Certificato già importato",
"cert_imported": "Certificato importato",
"cert_import_failed": "Importazione del certificato non riuscita"
},
"form": {
"create_title": "Nuovo contatto",
@@ -1989,5 +2008,82 @@
"settings_folder_layout_desc": "Choose how folders are displayed: inline with files or in a sidebar tree",
"settings_folder_layout_inline": "Inline",
"settings_folder_layout_sidebar": "Sidebar"
},
"smime": {
"your_certificates": "I tuoi certificati",
"your_certificates_desc": "Importa e gestisci i tuoi certificati S/MIME per firmare e cifrare le email",
"recipient_certificates": "Certificati dei destinatari",
"recipient_certificates_desc": "Certificati pubblici per cifrare le email ai destinatari",
"identity_bindings": "Associazioni identità-chiave",
"identity_bindings_desc": "Associa i certificati S/MIME alle tue identità email",
"defaults_title": "Predefiniti",
"defaults_desc": "Configura il comportamento predefinito di firma e cifratura",
"import_pkcs12": "Importa PKCS#12 (.p12/.pfx)",
"import_public_cert": "Importa certificato",
"no_certificates": "Nessun certificato importato",
"no_recipient_certs": "Nessun certificato destinatario",
"expires": "Scade",
"expired": "Scaduto",
"bound_to": "Associato a",
"no_key_bound": "Nessuno",
"lock": "Blocca chiave",
"unlock": "Sblocca chiave",
"details": "Visualizza dettagli",
"delete": "Elimina",
"encrypt_by_default": "Cifra per impostazione predefinita",
"encrypt_by_default_desc": "Cifra automaticamente le email quando tutti i destinatari hanno un certificato",
"remember_unlocked": "Ricorda le chiavi sbloccate",
"remember_unlocked_desc": "Mantieni le chiavi sbloccate per la durata di questa sessione del browser",
"sign_default_for": "Firma per impostazione predefinita per",
"enter_p12_passphrase": "Inserisci la passphrase PKCS#12",
"p12_passphrase_desc": "Inserisci la passphrase che protegge questo file di certificato",
"enter_storage_passphrase": "Imposta la passphrase di archiviazione",
"storage_passphrase_desc": "Scegli una passphrase per proteggere questa chiave nel browser",
"next": "Avanti",
"import": "Importa",
"unlock_key": "Sblocca chiave",
"unlock_key_desc": "Inserisci la passphrase di archiviazione per sbloccare questa chiave per la firma o la decrittazione",
"passphrase_placeholder": "Inserisci la passphrase",
"confirm_passphrase_placeholder": "Conferma la passphrase",
"passphrase_mismatch": "Le passphrase non corrispondono",
"cancel": "Annulla",
"processing": "Elaborazione…",
"close": "Chiudi",
"certificate_details": "Dettagli del certificato",
"cert_subject": "Oggetto",
"cert_issuer": "Emittente",
"cert_email": "Email",
"cert_serial": "Numero di serie",
"cert_validity": "Validità",
"cert_fingerprint": "Impronta digitale (SHA-256)",
"cert_algorithm": "Algoritmo",
"cert_capabilities": "Capacità",
"cert_source": "Origine",
"cert_expired": "Questo certificato è scaduto",
"cert_not_yet_valid": "Questo certificato non è ancora valido",
"cap_sign": "Firma",
"cap_encrypt": "Cifratura",
"cap_none": "Nessuna",
"show_passphrase": "Mostra passphrase",
"hide_passphrase": "Nascondi passphrase",
"sign_toggle": "Firma",
"encrypt_toggle": "Cifra",
"missing_recipient_certs": "Certificati mancanti per: {emails}",
"missing_sender_cert": "Nessun certificato associato a questa identità",
"status_encrypted_ok": "Questo messaggio è stato cifrato",
"status_encrypted_no_key": "Questo messaggio è cifrato, ma non è stata trovata una chiave corrispondente",
"status_encrypted_failed": "Impossibile decrittare questo messaggio",
"status_signed_valid": "Firma verificata",
"status_signed_invalid": "Verifica della firma non riuscita",
"status_signed_expired_cert": "Firmato con un certificato scaduto",
"status_signed_mismatch": "La firma è valida, ma il firmatario non corrisponde al mittente",
"status_unsupported": "Formato S/MIME non supportato",
"auto_import_signer_certs": "Importa automaticamente i certificati dei firmatari",
"auto_import_signer_certs_desc": "Salva automaticamente i certificati delle email firmate verificate per future cifrature",
"export": "Esporta",
"enter_export_passphrase": "Imposta la passphrase di esportazione",
"export_passphrase_desc": "Scegli una passphrase per proteggere il file PKCS#12 esportato",
"export_storage_desc": "Inserisci la passphrase di archiviazione per decrittare la chiave prima dell'esportazione",
"incorrect_passphrase": "Passphrase errata"
}
}
+97 -1
View File
@@ -416,6 +416,15 @@
"upload_cancel": "アップロードをキャンセル",
"upload_failed": "{filename} のアップロードに失敗しました",
"send_failed": "メールの送信に失敗しました",
"smime_sign_on": "S/MIME 署名を有効化しました",
"smime_sign_off": "S/MIME 署名を無効化しました",
"smime_encrypt_on": "S/MIME 暗号化を有効化しました",
"smime_encrypt_off": "S/MIME 暗号化を無効化しました",
"smime_encrypt_unavailable": "S/MIME 暗号化は利用できません: {reason}",
"smime_unlock_title": "S/MIME 鍵のロックを解除",
"smime_unlock_message": "S/MIME 鍵を解除するためのパスフレーズを入力してください。",
"smime_unlock_button": "ロック解除",
"smime_passphrase_placeholder": "S/MIME パスフレーズ",
"continue_draft": "下書きを続ける",
"close_draft_title": "下書きを保存または破棄しますか?",
"close_draft_message": "未保存の変更があります。下書きとして保存しますか、それとも破棄しますか?",
@@ -552,6 +561,7 @@
"folders": "フォルダー",
"keywords": "キーワード",
"security": "セキュリティ",
"encryption": "暗号化",
"files": "ファイル",
"contacts": "Contacts"
},
@@ -1439,7 +1449,16 @@
"calendar": "カレンダー",
"calendar_uri": "カレンダーURL",
"scheduling_uri": "スケジュールURL",
"freebusy_uri": "空き状況URL"
"freebusy_uri": "空き状況URL",
"cert_issuer": "発行者",
"cert_expires": "有効期限",
"cert_expired": "期限切れ",
"cert_fingerprint": "フィンガープリント",
"cert_algorithm": "アルゴリズム",
"import_to_smime": "S/MIME にインポート",
"cert_already_imported": "証明書はすでにインポートされています",
"cert_imported": "証明書をインポートしました",
"cert_import_failed": "証明書のインポートに失敗しました"
},
"form": {
"create_title": "新しい連絡先",
@@ -1989,5 +2008,82 @@
"settings_folder_layout_desc": "Choose how folders are displayed: inline with files or in a sidebar tree",
"settings_folder_layout_inline": "Inline",
"settings_folder_layout_sidebar": "Sidebar"
},
"smime": {
"your_certificates": "あなたの証明書",
"your_certificates_desc": "メールの署名と暗号化のために S/MIME 証明書をインポートして管理します",
"recipient_certificates": "受信者証明書",
"recipient_certificates_desc": "受信者へのメールを暗号化するための公開証明書",
"identity_bindings": "ID と鍵の関連付け",
"identity_bindings_desc": "S/MIME 証明書をメール ID に関連付けます",
"defaults_title": "既定値",
"defaults_desc": "署名と暗号化の既定動作を設定します",
"import_pkcs12": "PKCS#12 をインポート (.p12/.pfx)",
"import_public_cert": "証明書をインポート",
"no_certificates": "まだ証明書はインポートされていません",
"no_recipient_certs": "受信者証明書がありません",
"expires": "有効期限",
"expired": "期限切れ",
"bound_to": "関連付け先",
"no_key_bound": "なし",
"lock": "鍵をロック",
"unlock": "鍵をロック解除",
"details": "詳細を表示",
"delete": "削除",
"encrypt_by_default": "既定で暗号化する",
"encrypt_by_default_desc": "すべての受信者が証明書を持っている場合に自動でメールを暗号化します",
"remember_unlocked": "ロック解除した鍵を記憶する",
"remember_unlocked_desc": "このブラウザーセッションの間は鍵をロック解除したままにします",
"sign_default_for": "既定で署名する対象",
"enter_p12_passphrase": "PKCS#12 パスフレーズを入力",
"p12_passphrase_desc": "この証明書ファイルを保護しているパスフレーズを入力してください",
"enter_storage_passphrase": "保存用パスフレーズを設定",
"storage_passphrase_desc": "ブラウザー内でこの鍵を保護するためのパスフレーズを選択してください",
"next": "次へ",
"import": "インポート",
"unlock_key": "鍵をロック解除",
"unlock_key_desc": "署名または復号に使うため、この鍵の保存用パスフレーズを入力してください",
"passphrase_placeholder": "パスフレーズを入力",
"confirm_passphrase_placeholder": "パスフレーズを確認",
"passphrase_mismatch": "パスフレーズが一致しません",
"cancel": "キャンセル",
"processing": "処理中…",
"close": "閉じる",
"certificate_details": "証明書の詳細",
"cert_subject": "件名",
"cert_issuer": "発行者",
"cert_email": "メールアドレス",
"cert_serial": "シリアル番号",
"cert_validity": "有効期間",
"cert_fingerprint": "フィンガープリント (SHA-256)",
"cert_algorithm": "アルゴリズム",
"cert_capabilities": "機能",
"cert_source": "ソース",
"cert_expired": "この証明書は期限切れです",
"cert_not_yet_valid": "この証明書はまだ有効ではありません",
"cap_sign": "署名",
"cap_encrypt": "暗号化",
"cap_none": "なし",
"show_passphrase": "パスフレーズを表示",
"hide_passphrase": "パスフレーズを隠す",
"sign_toggle": "署名",
"encrypt_toggle": "暗号化",
"missing_recipient_certs": "次の宛先の証明書がありません: {emails}",
"missing_sender_cert": "この ID に関連付けられた証明書がありません",
"status_encrypted_ok": "このメッセージは暗号化されています",
"status_encrypted_no_key": "このメッセージは暗号化されていますが、一致する鍵が見つかりませんでした",
"status_encrypted_failed": "このメッセージを復号できませんでした",
"status_signed_valid": "署名を確認しました",
"status_signed_invalid": "署名の検証に失敗しました",
"status_signed_expired_cert": "期限切れの証明書で署名されています",
"status_signed_mismatch": "署名は有効ですが、署名者が送信者と一致しません",
"status_unsupported": "未対応の S/MIME 形式です",
"auto_import_signer_certs": "署名者証明書を自動インポート",
"auto_import_signer_certs_desc": "検証済み署名メールの証明書を今後の暗号化用に自動保存します",
"export": "エクスポート",
"enter_export_passphrase": "エクスポート用パスフレーズを設定",
"export_passphrase_desc": "エクスポートする PKCS#12 ファイルを保護するパスフレーズを選択してください",
"export_storage_desc": "エクスポートのために鍵を復号する保存用パスフレーズを入力してください",
"incorrect_passphrase": "パスフレーズが正しくありません"
}
}
+97 -1
View File
@@ -416,6 +416,15 @@
"upload_cancel": "Upload annuleren",
"upload_failed": "Uploaden van {filename} mislukt",
"send_failed": "E-mail verzenden mislukt",
"smime_sign_on": "S/MIME-ondertekening ingeschakeld",
"smime_sign_off": "S/MIME-ondertekening uitgeschakeld",
"smime_encrypt_on": "S/MIME-versleuteling ingeschakeld",
"smime_encrypt_off": "S/MIME-versleuteling uitgeschakeld",
"smime_encrypt_unavailable": "S/MIME-versleuteling is niet beschikbaar: {reason}",
"smime_unlock_title": "S/MIME-sleutel ontgrendelen",
"smime_unlock_message": "Voer de wachtwoordzin in om uw S/MIME-sleutel te ontgrendelen.",
"smime_unlock_button": "Ontgrendelen",
"smime_passphrase_placeholder": "S/MIME-wachtwoordzin",
"continue_draft": "Concept voortzetten",
"close_draft_title": "Concept opslaan of verwijderen?",
"close_draft_message": "U heeft niet-opgeslagen wijzigingen. Wilt u dit als concept opslaan of verwijderen?",
@@ -552,6 +561,7 @@
"folders": "Mappen",
"keywords": "Sleutelwoorden",
"security": "Beveiliging",
"encryption": "Versleuteling",
"files": "Bestanden",
"contacts": "Contacts"
},
@@ -1439,7 +1449,16 @@
"calendar": "Kalender",
"calendar_uri": "Kalender-URL",
"scheduling_uri": "Planning-URL",
"freebusy_uri": "Beschikbaarheid-URL"
"freebusy_uri": "Beschikbaarheid-URL",
"cert_issuer": "Uitgever",
"cert_expires": "Verloopt",
"cert_expired": "Verlopen",
"cert_fingerprint": "Vingerafdruk",
"cert_algorithm": "Algoritme",
"import_to_smime": "Importeren naar S/MIME",
"cert_already_imported": "Certificaat is al geïmporteerd",
"cert_imported": "Certificaat geïmporteerd",
"cert_import_failed": "Importeren van certificaat mislukt"
},
"form": {
"create_title": "Nieuw contact",
@@ -1989,5 +2008,82 @@
"settings_folder_layout_desc": "Choose how folders are displayed: inline with files or in a sidebar tree",
"settings_folder_layout_inline": "Inline",
"settings_folder_layout_sidebar": "Sidebar"
},
"smime": {
"your_certificates": "Uw certificaten",
"your_certificates_desc": "Importeer en beheer uw S/MIME-certificaten voor het ondertekenen en versleutelen van e-mails",
"recipient_certificates": "Certificaten van ontvangers",
"recipient_certificates_desc": "Openbare certificaten om e-mails naar ontvangers te versleutelen",
"identity_bindings": "Koppelingen tussen identiteit en sleutel",
"identity_bindings_desc": "Koppel S/MIME-certificaten aan uw e-mailidentiteiten",
"defaults_title": "Standaardinstellingen",
"defaults_desc": "Stel standaardgedrag voor ondertekenen en versleutelen in",
"import_pkcs12": "PKCS#12 importeren (.p12/.pfx)",
"import_public_cert": "Certificaat importeren",
"no_certificates": "Nog geen certificaten geïmporteerd",
"no_recipient_certs": "Geen ontvangerscertificaten",
"expires": "Verloopt",
"expired": "Verlopen",
"bound_to": "Gekoppeld aan",
"no_key_bound": "Geen",
"lock": "Sleutel vergrendelen",
"unlock": "Sleutel ontgrendelen",
"details": "Details bekijken",
"delete": "Verwijderen",
"encrypt_by_default": "Standaard versleutelen",
"encrypt_by_default_desc": "E-mails automatisch versleutelen wanneer alle ontvangers certificaten hebben",
"remember_unlocked": "Ontgrendelde sleutels onthouden",
"remember_unlocked_desc": "Sleutels ontgrendeld houden gedurende deze browsersessie",
"sign_default_for": "Standaard ondertekenen voor",
"enter_p12_passphrase": "PKCS#12-wachtwoordzin invoeren",
"p12_passphrase_desc": "Voer de wachtwoordzin in die dit certificaatbestand beschermt",
"enter_storage_passphrase": "Opslagwachtwoordzin instellen",
"storage_passphrase_desc": "Kies een wachtwoordzin om deze sleutel in uw browser te beschermen",
"next": "Volgende",
"import": "Importeren",
"unlock_key": "Sleutel ontgrendelen",
"unlock_key_desc": "Voer de opslagwachtwoordzin in om deze sleutel te ontgrendelen voor ondertekenen of ontsleutelen",
"passphrase_placeholder": "Voer wachtwoordzin in",
"confirm_passphrase_placeholder": "Bevestig wachtwoordzin",
"passphrase_mismatch": "Wachtwoordzinnen komen niet overeen",
"cancel": "Annuleren",
"processing": "Bezig met verwerken…",
"close": "Sluiten",
"certificate_details": "Certificaatdetails",
"cert_subject": "Onderwerp",
"cert_issuer": "Uitgever",
"cert_email": "E-mail",
"cert_serial": "Serienummer",
"cert_validity": "Geldigheid",
"cert_fingerprint": "Vingerafdruk (SHA-256)",
"cert_algorithm": "Algoritme",
"cert_capabilities": "Mogelijkheden",
"cert_source": "Bron",
"cert_expired": "Dit certificaat is verlopen",
"cert_not_yet_valid": "Dit certificaat is nog niet geldig",
"cap_sign": "Ondertekenen",
"cap_encrypt": "Versleuteling",
"cap_none": "Geen",
"show_passphrase": "Wachtwoordzin tonen",
"hide_passphrase": "Wachtwoordzin verbergen",
"sign_toggle": "Ondertekenen",
"encrypt_toggle": "Versleutelen",
"missing_recipient_certs": "Ontbrekende certificaten voor: {emails}",
"missing_sender_cert": "Er is geen certificaat gekoppeld aan deze identiteit",
"status_encrypted_ok": "Dit bericht is versleuteld",
"status_encrypted_no_key": "Dit bericht is versleuteld, maar er is geen passende sleutel gevonden",
"status_encrypted_failed": "Dit bericht kon niet worden ontsleuteld",
"status_signed_valid": "Handtekening geverifieerd",
"status_signed_invalid": "Verificatie van de handtekening is mislukt",
"status_signed_expired_cert": "Ondertekend met een verlopen certificaat",
"status_signed_mismatch": "Handtekening is geldig, maar de ondertekenaar komt niet overeen met de afzender",
"status_unsupported": "Niet-ondersteund S/MIME-formaat",
"auto_import_signer_certs": "Ondertekenaarcertificaten automatisch importeren",
"auto_import_signer_certs_desc": "Certificaten van geverifieerde ondertekende e-mails automatisch opslaan voor toekomstige versleuteling",
"export": "Exporteren",
"enter_export_passphrase": "Exportwachtwoordzin instellen",
"export_passphrase_desc": "Kies een wachtwoordzin om het geëxporteerde PKCS#12-bestand te beschermen",
"export_storage_desc": "Voer de opslagwachtwoordzin in om de sleutel voor export te ontsleutelen",
"incorrect_passphrase": "Onjuiste wachtwoordzin"
}
}
+97 -1
View File
@@ -416,6 +416,15 @@
"upload_cancel": "Cancelar envio",
"upload_failed": "Falha ao enviar {filename}",
"send_failed": "Falha ao enviar o e-mail",
"smime_sign_on": "Assinatura S/MIME ativada",
"smime_sign_off": "Assinatura S/MIME desativada",
"smime_encrypt_on": "Criptografia S/MIME ativada",
"smime_encrypt_off": "Criptografia S/MIME desativada",
"smime_encrypt_unavailable": "A criptografia S/MIME não está disponível: {reason}",
"smime_unlock_title": "Desbloquear chave S/MIME",
"smime_unlock_message": "Insira a frase secreta para desbloquear sua chave S/MIME.",
"smime_unlock_button": "Desbloquear",
"smime_passphrase_placeholder": "Frase secreta S/MIME",
"continue_draft": "Continuar rascunho",
"close_draft_title": "Salvar ou descartar rascunho?",
"close_draft_message": "Você tem alterações não salvas. Deseja salvar como rascunho ou descartar?",
@@ -552,6 +561,7 @@
"folders": "Pastas",
"keywords": "Palavras-chave",
"security": "Segurança",
"encryption": "Criptografia",
"files": "Arquivos",
"contacts": "Contacts"
},
@@ -1439,7 +1449,16 @@
"calendar": "Calendário",
"calendar_uri": "URL do calendário",
"scheduling_uri": "URL de agendamento",
"freebusy_uri": "URL de disponibilidade"
"freebusy_uri": "URL de disponibilidade",
"cert_issuer": "Emissor",
"cert_expires": "Expira em",
"cert_expired": "Expirado",
"cert_fingerprint": "Impressão digital",
"cert_algorithm": "Algoritmo",
"import_to_smime": "Importar para S/MIME",
"cert_already_imported": "Certificado já importado",
"cert_imported": "Certificado importado",
"cert_import_failed": "Falha ao importar o certificado"
},
"form": {
"create_title": "Novo contato",
@@ -1989,5 +2008,82 @@
"settings_folder_layout_desc": "Choose how folders are displayed: inline with files or in a sidebar tree",
"settings_folder_layout_inline": "Inline",
"settings_folder_layout_sidebar": "Sidebar"
},
"smime": {
"your_certificates": "Seus certificados",
"your_certificates_desc": "Importe e gerencie seus certificados S/MIME para assinar e criptografar e-mails",
"recipient_certificates": "Certificados dos destinatários",
"recipient_certificates_desc": "Certificados públicos para criptografar e-mails para destinatários",
"identity_bindings": "Vínculos de identidade e chave",
"identity_bindings_desc": "Associe certificados S/MIME às suas identidades de e-mail",
"defaults_title": "Padrões",
"defaults_desc": "Configure o comportamento padrão de assinatura e criptografia",
"import_pkcs12": "Importar PKCS#12 (.p12/.pfx)",
"import_public_cert": "Importar certificado",
"no_certificates": "Nenhum certificado importado ainda",
"no_recipient_certs": "Nenhum certificado de destinatário",
"expires": "Expira em",
"expired": "Expirado",
"bound_to": "Vinculado a",
"no_key_bound": "Nenhum",
"lock": "Bloquear chave",
"unlock": "Desbloquear chave",
"details": "Ver detalhes",
"delete": "Excluir",
"encrypt_by_default": "Criptografar por padrão",
"encrypt_by_default_desc": "Criptografar e-mails automaticamente quando todos os destinatários tiverem certificados",
"remember_unlocked": "Lembrar chaves desbloqueadas",
"remember_unlocked_desc": "Manter as chaves desbloqueadas durante esta sessão do navegador",
"sign_default_for": "Assinar por padrão para",
"enter_p12_passphrase": "Inserir a frase secreta do PKCS#12",
"p12_passphrase_desc": "Insira a frase secreta que protege este arquivo de certificado",
"enter_storage_passphrase": "Definir frase secreta de armazenamento",
"storage_passphrase_desc": "Escolha uma frase secreta para proteger esta chave no navegador",
"next": "Próximo",
"import": "Importar",
"unlock_key": "Desbloquear chave",
"unlock_key_desc": "Insira a frase secreta de armazenamento para desbloquear esta chave para assinatura ou descriptografia",
"passphrase_placeholder": "Insira a frase secreta",
"confirm_passphrase_placeholder": "Confirme a frase secreta",
"passphrase_mismatch": "As frases secretas não coincidem",
"cancel": "Cancelar",
"processing": "Processando…",
"close": "Fechar",
"certificate_details": "Detalhes do certificado",
"cert_subject": "Assunto",
"cert_issuer": "Emissor",
"cert_email": "E-mail",
"cert_serial": "Número de série",
"cert_validity": "Validade",
"cert_fingerprint": "Impressão digital (SHA-256)",
"cert_algorithm": "Algoritmo",
"cert_capabilities": "Recursos",
"cert_source": "Origem",
"cert_expired": "Este certificado expirou",
"cert_not_yet_valid": "Este certificado ainda não é válido",
"cap_sign": "Assinatura",
"cap_encrypt": "Criptografia",
"cap_none": "Nenhum",
"show_passphrase": "Mostrar frase secreta",
"hide_passphrase": "Ocultar frase secreta",
"sign_toggle": "Assinar",
"encrypt_toggle": "Criptografar",
"missing_recipient_certs": "Certificados ausentes para: {emails}",
"missing_sender_cert": "Nenhum certificado vinculado a esta identidade",
"status_encrypted_ok": "Esta mensagem foi criptografada",
"status_encrypted_no_key": "Esta mensagem está criptografada, mas nenhuma chave correspondente foi encontrada",
"status_encrypted_failed": "Falha ao descriptografar esta mensagem",
"status_signed_valid": "Assinatura verificada",
"status_signed_invalid": "A verificação da assinatura falhou",
"status_signed_expired_cert": "Assinada com um certificado expirado",
"status_signed_mismatch": "A assinatura é válida, mas o signatário não corresponde ao remetente",
"status_unsupported": "Formato S/MIME não suportado",
"auto_import_signer_certs": "Importar automaticamente certificados de signatários",
"auto_import_signer_certs_desc": "Salvar automaticamente certificados de e-mails assinados verificados para criptografia futura",
"export": "Exportar",
"enter_export_passphrase": "Definir frase secreta de exportação",
"export_passphrase_desc": "Escolha uma frase secreta para proteger o arquivo PKCS#12 exportado",
"export_storage_desc": "Insira a frase secreta de armazenamento para descriptografar a chave para exportação",
"incorrect_passphrase": "Frase secreta incorreta"
}
}
+108 -2
View File
@@ -1,21 +1,25 @@
{
"name": "bulwark-webmail",
"version": "1.2.4",
"version": "1.3.0",
"lockfileVersion": 3,
"requires": true,
"packages": {
"": {
"name": "bulwark-webmail",
"version": "1.2.4",
"version": "1.3.0",
"license": "AGPL-3.0-only",
"dependencies": {
"@tanstack/react-virtual": "^3.13.18",
"asn1js": "^3.0.7",
"clsx": "^2.1.1",
"date-fns": "^4.1.0",
"dompurify": "^3.3.1",
"lucide-react": "^0.575.0",
"next": "^16.1.5",
"next-intl": "^4.5.8",
"pkijs": "^3.3.3",
"postal-mime": "^2.7.4",
"pvtsutils": "^1.3.6",
"react": "^19.2.1",
"react-dom": "^19.2.1",
"sonner": "^2.0.7",
@@ -39,6 +43,7 @@
"eslint": "^9.39.2",
"eslint-plugin-react": "^7.37.5",
"eslint-plugin-react-hooks": "^7.0.1",
"fake-indexeddb": "^6.2.5",
"globals": "^17.0.0",
"husky": "^9.1.7",
"jsdom": "^28.1.0",
@@ -2048,6 +2053,21 @@
"node": ">= 10"
}
},
"node_modules/@noble/hashes": {
"version": "2.0.1",
"resolved": "https://registry.npmjs.org/@noble/hashes/-/hashes-2.0.1.tgz",
"integrity": "sha512-XlOlEbQcE9fmuXxrVTXCTlG2nlRXa9Rj3rr5Ue/+tX+nmkgbX720YHh0VR3hBF9xDvwnb8D2shVGOwNx+ulArw==",
"dev": true,
"license": "MIT",
"optional": true,
"peer": true,
"engines": {
"node": ">= 20.19.0"
},
"funding": {
"url": "https://paulmillr.com/funding/"
}
},
"node_modules/@parcel/watcher": {
"version": "2.5.6",
"resolved": "https://registry.npmjs.org/@parcel/watcher/-/watcher-2.5.6.tgz",
@@ -4055,6 +4075,20 @@
"url": "https://github.com/sponsors/ljharb"
}
},
"node_modules/asn1js": {
"version": "3.0.7",
"resolved": "https://registry.npmjs.org/asn1js/-/asn1js-3.0.7.tgz",
"integrity": "sha512-uLvq6KJu04qoQM6gvBfKFjlh6Gl0vOKQuR5cJMDHQkmwfMOQeN3F3SHCv9SNYSL+CRoHvOGFfllDlVz03GQjvQ==",
"license": "BSD-3-Clause",
"dependencies": {
"pvtsutils": "^1.3.6",
"pvutils": "^1.1.3",
"tslib": "^2.8.1"
},
"engines": {
"node": ">=12.0.0"
}
},
"node_modules/assertion-error": {
"version": "2.0.1",
"resolved": "https://registry.npmjs.org/assertion-error/-/assertion-error-2.0.1.tgz",
@@ -4177,6 +4211,15 @@
"node": "^6 || ^7 || ^8 || ^9 || ^10 || ^11 || ^12 || >=13.7"
}
},
"node_modules/bytestreamjs": {
"version": "2.0.1",
"resolved": "https://registry.npmjs.org/bytestreamjs/-/bytestreamjs-2.0.1.tgz",
"integrity": "sha512-U1Z/ob71V/bXfVABvNr/Kumf5VyeQRBEm6Txb0PQ6S7V5GpBM3w4Cbqz/xPDicR5tN0uvDifng8C+5qECeGwyQ==",
"license": "BSD-3-Clause",
"engines": {
"node": ">=6.0.0"
}
},
"node_modules/call-bind": {
"version": "1.0.8",
"resolved": "https://registry.npmjs.org/call-bind/-/call-bind-1.0.8.tgz",
@@ -5238,6 +5281,16 @@
"node": ">=12.0.0"
}
},
"node_modules/fake-indexeddb": {
"version": "6.2.5",
"resolved": "https://registry.npmjs.org/fake-indexeddb/-/fake-indexeddb-6.2.5.tgz",
"integrity": "sha512-CGnyrvbhPlWYMngksqrSSUT1BAVP49dZocrHuK0SvtR0D5TMs5wP0o3j7jexDJW01KSadjBp1M/71o/KR3nD1w==",
"dev": true,
"license": "Apache-2.0",
"engines": {
"node": ">=18"
}
},
"node_modules/fast-deep-equal": {
"version": "3.1.3",
"resolved": "https://registry.npmjs.org/fast-deep-equal/-/fast-deep-equal-3.1.3.tgz",
@@ -7256,6 +7309,35 @@
"integrity": "sha512-xceH2snhtb5M9liqDsmEw56le376mTZkEX/jEb/RxNFyegNul7eNslCXP9FDj/Lcu0X8KEyMceP2ntpaHrDEVA==",
"license": "ISC"
},
"node_modules/pkijs": {
"version": "3.3.3",
"resolved": "https://registry.npmjs.org/pkijs/-/pkijs-3.3.3.tgz",
"integrity": "sha512-+KD8hJtqQMYoTuL1bbGOqxb4z+nZkTAwVdNtWwe8Tc2xNbEmdJYIYoc6Qt0uF55e6YW6KuTHw1DjQ18gMhzepw==",
"license": "BSD-3-Clause",
"dependencies": {
"@noble/hashes": "1.4.0",
"asn1js": "^3.0.6",
"bytestreamjs": "^2.0.1",
"pvtsutils": "^1.3.6",
"pvutils": "^1.1.3",
"tslib": "^2.8.1"
},
"engines": {
"node": ">=16.0.0"
}
},
"node_modules/pkijs/node_modules/@noble/hashes": {
"version": "1.4.0",
"resolved": "https://registry.npmjs.org/@noble/hashes/-/hashes-1.4.0.tgz",
"integrity": "sha512-V1JJ1WTRUqHHrOSh597hURcMqVKVGL/ea3kv0gSnEdsEZ0/+VyPghM1lMNGc00z7CIQorSvbKpuJkxvuHbvdbg==",
"license": "MIT",
"engines": {
"node": ">= 16"
},
"funding": {
"url": "https://paulmillr.com/funding/"
}
},
"node_modules/playwright": {
"version": "1.58.2",
"resolved": "https://registry.npmjs.org/playwright/-/playwright-1.58.2.tgz",
@@ -7304,6 +7386,12 @@
"node": ">= 0.4"
}
},
"node_modules/postal-mime": {
"version": "2.7.4",
"resolved": "https://registry.npmjs.org/postal-mime/-/postal-mime-2.7.4.tgz",
"integrity": "sha512-0WdnFQYUrPGGTFu1uOqD2s7omwua8xaeYGdO6rb88oD5yJ/4pPHDA4sdWqfD8wQVfCny563n/HQS7zTFft+f/g==",
"license": "MIT-0"
},
"node_modules/postcss": {
"version": "8.5.6",
"resolved": "https://registry.npmjs.org/postcss/-/postcss-8.5.6.tgz",
@@ -7400,6 +7488,24 @@
"node": ">=6"
}
},
"node_modules/pvtsutils": {
"version": "1.3.6",
"resolved": "https://registry.npmjs.org/pvtsutils/-/pvtsutils-1.3.6.tgz",
"integrity": "sha512-PLgQXQ6H2FWCaeRak8vvk1GW462lMxB5s3Jm673N82zI4vqtVUPuZdffdZbPDFRoU8kAhItWFtPCWiPpp4/EDg==",
"license": "MIT",
"dependencies": {
"tslib": "^2.8.1"
}
},
"node_modules/pvutils": {
"version": "1.1.5",
"resolved": "https://registry.npmjs.org/pvutils/-/pvutils-1.1.5.tgz",
"integrity": "sha512-KTqnxsgGiQ6ZAzZCVlJH5eOjSnvlyEgx1m8bkRJfOhmGRqfo5KLvmAlACQkrjEtOQ4B7wF9TdSLIs9O90MX9xA==",
"license": "MIT",
"engines": {
"node": ">=16.0.0"
}
},
"node_modules/react": {
"version": "19.2.4",
"resolved": "https://registry.npmjs.org/react/-/react-19.2.4.tgz",
+5
View File
@@ -32,12 +32,16 @@
},
"dependencies": {
"@tanstack/react-virtual": "^3.13.18",
"asn1js": "^3.0.7",
"clsx": "^2.1.1",
"date-fns": "^4.1.0",
"dompurify": "^3.3.1",
"lucide-react": "^0.575.0",
"next": "^16.1.5",
"next-intl": "^4.5.8",
"pkijs": "^3.3.3",
"postal-mime": "^2.7.4",
"pvtsutils": "^1.3.6",
"react": "^19.2.1",
"react-dom": "^19.2.1",
"sonner": "^2.0.7",
@@ -61,6 +65,7 @@
"eslint": "^9.39.2",
"eslint-plugin-react": "^7.37.5",
"eslint-plugin-react-hooks": "^7.0.1",
"fake-indexeddb": "^6.2.5",
"globals": "^17.0.0",
"husky": "^9.1.7",
"jsdom": "^28.1.0",
+160
View File
@@ -0,0 +1,160 @@
/**
* Generate a self-signed S/MIME test certificate (.p12) using pkijs.
* Usage: npx tsx scripts/generate-test-cert.ts
*/
import * as pkijs from 'pkijs';
import * as asn1js from 'asn1js';
import { writeFileSync } from 'fs';
import { join, dirname } from 'path';
import { fileURLToPath } from 'url';
const cryptoEngine = new pkijs.CryptoEngine({
crypto: crypto,
subtle: crypto.subtle,
name: 'webcrypto',
});
pkijs.setEngine('gen', crypto, cryptoEngine);
function stringToAB(str: string): ArrayBuffer {
const buf = new ArrayBuffer(str.length);
const view = new Uint8Array(buf);
for (let i = 0; i < str.length; i++) view[i] = str.charCodeAt(i);
return buf;
}
async function main() {
const email = process.argv[2] || 'test@example.com';
const cn = email.split('@')[0];
const p12Password = 'test';
console.log(`Generating S/MIME certificate for ${email}...`);
// Generate RSA key pair for signing
const signKeyPair = await crypto.subtle.generateKey(
{ name: 'RSASSA-PKCS1-v1_5', modulusLength: 2048, publicExponent: new Uint8Array([1, 0, 1]), hash: 'SHA-256' },
true,
['sign', 'verify'],
);
// Build self-signed certificate
const cert = new pkijs.Certificate();
cert.version = 2;
cert.serialNumber = new asn1js.Integer({ value: Date.now() });
// Issuer = Subject (self-signed)
for (const name of [cert.issuer, cert.subject]) {
name.typesAndValues.push(
new pkijs.AttributeTypeAndValue({ type: '2.5.4.3', value: new asn1js.Utf8String({ value: cn }) }),
);
name.typesAndValues.push(
new pkijs.AttributeTypeAndValue({ type: '2.5.4.10', value: new asn1js.Utf8String({ value: 'Test Org' }) }),
);
}
// Email in subject
cert.subject.typesAndValues.push(
new pkijs.AttributeTypeAndValue({ type: '1.2.840.113549.1.9.1', value: new asn1js.IA5String({ value: email }) }),
);
// Validity: 1 year
cert.notBefore.value = new Date();
const notAfter = new Date();
notAfter.setFullYear(notAfter.getFullYear() + 1);
cert.notAfter.value = notAfter;
// Import public key and sign
await cert.subjectPublicKeyInfo.importKey(signKeyPair.publicKey, cryptoEngine);
await cert.sign(signKeyPair.privateKey, 'SHA-256', cryptoEngine);
// Export private key as PKCS#8
const pkcs8Bytes = await crypto.subtle.exportKey('pkcs8', signKeyPair.privateKey);
// Build PKCS#12
const passwordBuf = stringToAB(p12Password);
const keyBag = new pkijs.PKCS8ShroudedKeyBag({
parsedValue: pkijs.PrivateKeyInfo.fromBER(pkcs8Bytes),
});
await keyBag.makeInternalValues({
password: passwordBuf,
contentEncryptionAlgorithm: {
name: 'AES-CBC',
length: 256,
} as Parameters<typeof keyBag.makeInternalValues>[0]['contentEncryptionAlgorithm'],
hmacHashAlgorithm: 'SHA-256',
iterationCount: 100_000,
});
const keyBagSafe = new pkijs.SafeBag({
bagId: '1.2.840.113549.1.12.10.1.2',
bagValue: keyBag,
bagAttributes: [
new pkijs.Attribute({
type: '1.2.840.113549.1.9.20', // friendlyName
values: [new asn1js.BmpString({ value: cn })],
}),
],
});
const certBagSafe = new pkijs.SafeBag({
bagId: '1.2.840.113549.1.12.10.1.3',
bagValue: new pkijs.CertBag({ parsedValue: cert }),
bagAttributes: [
new pkijs.Attribute({
type: '1.2.840.113549.1.9.20',
values: [new asn1js.BmpString({ value: cn })],
}),
],
});
const authenticatedSafe = new pkijs.AuthenticatedSafe({
parsedValue: {
safeContents: [
{ privacyMode: 0, value: new pkijs.SafeContents({ safeBags: [keyBagSafe] }) },
{ privacyMode: 0, value: new pkijs.SafeContents({ safeBags: [certBagSafe] }) },
],
},
});
await authenticatedSafe.makeInternalValues({ safeContents: [{}, {}] });
const pfx = new pkijs.PFX({
parsedValue: {
integrityMode: 0,
authenticatedSafe,
},
});
await pfx.makeInternalValues({
password: passwordBuf,
iterations: 100_000,
pbkdf2HashAlgorithm: 'SHA-256',
hmacHashAlgorithm: 'SHA-256',
});
const p12Bytes = pfx.toSchema().toBER(false);
// Also export the public cert as PEM
const certDer = cert.toSchema(true).toBER(false);
const certB64 = Buffer.from(certDer).toString('base64');
const certPem = `-----BEGIN CERTIFICATE-----\n${certB64.match(/.{1,64}/g)!.join('\n')}\n-----END CERTIFICATE-----\n`;
const slug = email.replace(/[@.]/g, '-');
const outDir = join(dirname(fileURLToPath(import.meta.url)), '..', 'local-data');
const p12Path = join(outDir, `${slug}.p12`);
const pemPath = join(outDir, `${slug}-cert.pem`);
writeFileSync(p12Path, Buffer.from(p12Bytes));
writeFileSync(pemPath, certPem);
console.log(`\nFiles written:`);
console.log(` ${p12Path}`);
console.log(` ${pemPath}`);
console.log(`\nCredentials:`);
console.log(` Email: ${email}`);
console.log(` CN: ${cn}`);
console.log(` Password: ${p12Password}`);
console.log(` Valid until: ${notAfter.toISOString().split('T')[0]}`);
}
main().catch(console.error);
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
+18
View File
@@ -62,6 +62,7 @@ interface EmailStore {
fetchEmailContent: (client: JMAPClient, emailId: string) => Promise<Email | null>;
fetchQuota: (client: JMAPClient) => Promise<void>;
sendEmail: (client: JMAPClient, to: string[], subject: string, body: string, cc?: string[], bcc?: string[], identityId?: string, fromEmail?: string, draftId?: string, fromName?: string, htmlBody?: string) => Promise<void>;
sendRawEmail: (client: JMAPClient, rawMimeBlob: Blob, identityId: string) => Promise<void>;
deleteEmail: (client: JMAPClient, emailId: string, forceDelete?: boolean) => Promise<void>;
markAsRead: (client: JMAPClient, emailId: string, read: boolean) => Promise<void>;
moveToMailbox: (client: JMAPClient, emailId: string, mailboxId: string) => Promise<void>;
@@ -402,6 +403,23 @@ export const useEmailStore = create<EmailStore>((set, get) => ({
}
},
sendRawEmail: async (client, rawMimeBlob, identityId) => {
set({ isLoading: true, error: null });
try {
const mailboxes = await client.getMailboxes();
const sentMailbox = mailboxes.find(mb => mb.role === 'sent');
if (!sentMailbox) throw new Error('No sent mailbox found');
await client.sendRawEmail(rawMimeBlob, identityId, sentMailbox.id);
set({ isLoading: false });
} catch (error) {
set({
error: error instanceof Error ? error.message : "Failed to send email",
isLoading: false,
});
throw error;
}
},
deleteEmail: async (client, emailId, forceDelete) => {
try {
// Get the email to check if it's unread and which mailboxes it belongs to
+419
View File
@@ -0,0 +1,419 @@
import { create } from 'zustand';
import { persist } from 'zustand/middleware';
import type { SmimeKeyRecord, SmimePublicCert } from '@/lib/smime/types';
import {
saveKeyRecord,
listKeyRecords,
deleteKeyRecord as deleteKeyRecordDB,
savePublicCert,
listPublicCerts,
deletePublicCert as deletePublicCertDB,
} from '@/lib/smime/key-storage';
import { importPkcs12, unlockPrivateKey } from '@/lib/smime/pkcs12-import';
import {
parseCertificatePemOrDer,
extractCertificateInfo,
} from '@/lib/smime/certificate-utils';
const REMEMBERED_UNLOCKS_STORAGE_KEY = 'smime-unlocked-session';
type RememberedUnlocks = Record<string, string>;
function readRememberedUnlocks(): RememberedUnlocks {
if (typeof window === 'undefined') {
return {};
}
try {
const raw = window.sessionStorage.getItem(REMEMBERED_UNLOCKS_STORAGE_KEY);
if (!raw) {
return {};
}
const parsed = JSON.parse(raw);
if (!parsed || typeof parsed !== 'object' || Array.isArray(parsed)) {
return {};
}
const rememberedUnlocks: RememberedUnlocks = {};
for (const [keyId, passphrase] of Object.entries(parsed)) {
if (typeof passphrase === 'string') {
rememberedUnlocks[keyId] = passphrase;
}
}
return rememberedUnlocks;
} catch {
return {};
}
}
function writeRememberedUnlocks(rememberedUnlocks: RememberedUnlocks): void {
if (typeof window === 'undefined') {
return;
}
try {
if (Object.keys(rememberedUnlocks).length === 0) {
window.sessionStorage.removeItem(REMEMBERED_UNLOCKS_STORAGE_KEY);
return;
}
window.sessionStorage.setItem(
REMEMBERED_UNLOCKS_STORAGE_KEY,
JSON.stringify(rememberedUnlocks),
);
} catch {
// Ignore unavailable or blocked session storage.
}
}
function rememberUnlockedKey(keyId: string, passphrase: string): void {
const rememberedUnlocks = readRememberedUnlocks();
rememberedUnlocks[keyId] = passphrase;
writeRememberedUnlocks(rememberedUnlocks);
}
function forgetUnlockedKey(keyId: string): void {
const rememberedUnlocks = readRememberedUnlocks();
if (!(keyId in rememberedUnlocks)) {
return;
}
delete rememberedUnlocks[keyId];
writeRememberedUnlocks(rememberedUnlocks);
}
function clearRememberedUnlocks(): void {
writeRememberedUnlocks({});
}
async function restoreRememberedKeys(keyRecords: SmimeKeyRecord[]): Promise<{
unlockedKeys: Map<string, CryptoKey>;
unlockedDecryptionKeys: Map<string, CryptoKey>;
}> {
const rememberedUnlocks = readRememberedUnlocks();
const unlockedKeys = new Map<string, CryptoKey>();
const unlockedDecryptionKeys = new Map<string, CryptoKey>();
let removedStaleEntries = false;
for (const record of keyRecords) {
const passphrase = rememberedUnlocks[record.id];
if (!passphrase) {
continue;
}
try {
const { signingKey, decryptionKey } = await unlockPrivateKey(record, passphrase);
unlockedKeys.set(record.id, signingKey);
if (decryptionKey) {
unlockedDecryptionKeys.set(record.id, decryptionKey);
}
} catch {
delete rememberedUnlocks[record.id];
removedStaleEntries = true;
}
}
if (removedStaleEntries) {
writeRememberedUnlocks(rememberedUnlocks);
}
return { unlockedKeys, unlockedDecryptionKeys };
}
interface SmimePersistedState {
identityKeyBindings: Record<string, string>; // identityId → keyRecordId
defaultSignIdentity: Record<string, boolean>; // identityId → sign by default
defaultEncrypt: boolean;
rememberUnlockedKeys: boolean;
autoImportSignerCerts: boolean;
}
interface SmimeStore extends SmimePersistedState {
// Loaded from IndexedDB
keyRecords: SmimeKeyRecord[];
publicCerts: SmimePublicCert[];
// Runtime only — never persisted
unlockedKeys: Map<string, CryptoKey>;
unlockedDecryptionKeys: Map<string, CryptoKey>;
isLoading: boolean;
error: string | null;
// Actions
load: () => Promise<void>;
importPKCS12: (file: ArrayBuffer, p12Passphrase: string, storagePassphrase: string) => Promise<SmimeKeyRecord>;
importPublicCert: (data: ArrayBuffer | string, source: SmimePublicCert['source'], contactId?: string) => Promise<SmimePublicCert>;
bindIdentityToKey: (identityId: string, keyRecordId: string | null) => void;
removeKeyRecord: (id: string) => Promise<void>;
removePublicCert: (id: string) => Promise<void>;
unlockKey: (id: string, passphrase: string) => Promise<void>;
lockKey: (id: string) => void;
lockAllKeys: () => void;
getKeyRecordForIdentity: (identityId: string) => SmimeKeyRecord | undefined;
getPublicCertForEmail: (email: string) => SmimePublicCert | undefined;
getRecipientCerts: (emails: string[]) => { found: SmimePublicCert[]; missing: string[] };
setSignDefault: (identityId: string, value: boolean) => void;
setEncryptDefault: (value: boolean) => void;
setRememberUnlockedKeys: (value: boolean) => void;
setAutoImportSignerCerts: (value: boolean) => void;
isKeyUnlocked: (id: string) => boolean;
getUnlockedKey: (id: string) => CryptoKey | undefined;
setError: (error: string | null) => void;
}
export const useSmimeStore = create<SmimeStore>()(
persist(
(set, get) => ({
// Persisted preferences
identityKeyBindings: {},
defaultSignIdentity: {},
defaultEncrypt: false,
rememberUnlockedKeys: false,
autoImportSignerCerts: false,
// Runtime state
keyRecords: [],
publicCerts: [],
unlockedKeys: new Map(),
unlockedDecryptionKeys: new Map(),
isLoading: false,
error: null,
load: async () => {
set({ isLoading: true, error: null });
try {
const [keyRecords, publicCerts] = await Promise.all([
listKeyRecords(),
listPublicCerts(),
]);
if (get().rememberUnlockedKeys) {
const restoredKeys = await restoreRememberedKeys(keyRecords);
set((state) => ({
keyRecords,
publicCerts,
unlockedKeys: new Map([
...state.unlockedKeys,
...restoredKeys.unlockedKeys,
]),
unlockedDecryptionKeys: new Map([
...state.unlockedDecryptionKeys,
...restoredKeys.unlockedDecryptionKeys,
]),
isLoading: false,
}));
return;
}
set({ keyRecords, publicCerts, isLoading: false });
} catch (err) {
set({
error: err instanceof Error ? err.message : 'Failed to load S/MIME data',
isLoading: false,
});
}
},
importPKCS12: async (file, p12Passphrase, storagePassphrase) => {
set({ isLoading: true, error: null });
try {
const { keyRecord } = await importPkcs12(file, p12Passphrase, storagePassphrase);
await saveKeyRecord(keyRecord);
set((state) => ({
keyRecords: [...state.keyRecords, keyRecord],
isLoading: false,
}));
return keyRecord;
} catch (err) {
set({
error: err instanceof Error ? err.message : 'Failed to import PKCS#12',
isLoading: false,
});
throw err;
}
},
importPublicCert: async (data, source, contactId) => {
set({ isLoading: true, error: null });
try {
const cert = parseCertificatePemOrDer(data);
// Always re-encode to DER — input might be PEM text (string or ArrayBuffer)
const der = cert.toSchema(true).toBER(false);
const info = await extractCertificateInfo(cert, der);
const email = info.emailAddresses[0] ?? '';
const publicCert: SmimePublicCert = {
id: crypto.randomUUID(),
email: email.toLowerCase(),
certificate: der,
issuer: info.issuer,
subject: info.subject,
notBefore: info.notBefore,
notAfter: info.notAfter,
fingerprint: info.fingerprint,
source,
contactId,
};
await savePublicCert(publicCert);
set((state) => ({
publicCerts: [...state.publicCerts, publicCert],
isLoading: false,
}));
return publicCert;
} catch (err) {
set({
error: err instanceof Error ? err.message : 'Failed to import certificate',
isLoading: false,
});
throw err;
}
},
bindIdentityToKey: (identityId, keyRecordId) => {
set((state) => {
const bindings = { ...state.identityKeyBindings };
if (keyRecordId === null) {
delete bindings[identityId];
} else {
bindings[identityId] = keyRecordId;
}
return { identityKeyBindings: bindings };
});
},
removeKeyRecord: async (id) => {
await deleteKeyRecordDB(id);
forgetUnlockedKey(id);
set((state) => {
const unlockedKeys = new Map(state.unlockedKeys);
unlockedKeys.delete(id);
const unlockedDecryptionKeys = new Map(state.unlockedDecryptionKeys);
unlockedDecryptionKeys.delete(id);
// Remove any identity bindings pointing to this key
const bindings = { ...state.identityKeyBindings };
for (const [identityId, keyId] of Object.entries(bindings)) {
if (keyId === id) delete bindings[identityId];
}
return {
keyRecords: state.keyRecords.filter((k) => k.id !== id),
unlockedKeys,
unlockedDecryptionKeys,
identityKeyBindings: bindings,
};
});
},
removePublicCert: async (id) => {
await deletePublicCertDB(id);
set((state) => ({
publicCerts: state.publicCerts.filter((c) => c.id !== id),
}));
},
unlockKey: async (id, passphrase) => {
const record = get().keyRecords.find((k) => k.id === id);
if (!record) throw new Error('Key record not found');
const { signingKey, decryptionKey } = await unlockPrivateKey(record, passphrase);
if (get().rememberUnlockedKeys) {
rememberUnlockedKey(id, passphrase);
}
set((state) => {
const unlockedKeys = new Map(state.unlockedKeys);
unlockedKeys.set(id, signingKey);
const unlockedDecryptionKeys = new Map(state.unlockedDecryptionKeys);
if (decryptionKey) {
unlockedDecryptionKeys.set(id, decryptionKey);
}
return { unlockedKeys, unlockedDecryptionKeys };
});
},
lockKey: (id) => {
forgetUnlockedKey(id);
set((state) => {
const unlockedKeys = new Map(state.unlockedKeys);
unlockedKeys.delete(id);
const unlockedDecryptionKeys = new Map(state.unlockedDecryptionKeys);
unlockedDecryptionKeys.delete(id);
return { unlockedKeys, unlockedDecryptionKeys };
});
},
lockAllKeys: () => {
clearRememberedUnlocks();
set({ unlockedKeys: new Map(), unlockedDecryptionKeys: new Map() });
},
getKeyRecordForIdentity: (identityId) => {
const { identityKeyBindings, keyRecords } = get();
const keyId = identityKeyBindings[identityId];
if (!keyId) return undefined;
return keyRecords.find((k) => k.id === keyId);
},
getPublicCertForEmail: (email) => {
return get().publicCerts.find(
(c) => c.email.toLowerCase() === email.toLowerCase(),
);
},
getRecipientCerts: (emails) => {
const { publicCerts } = get();
const found: SmimePublicCert[] = [];
const missing: string[] = [];
for (const email of emails) {
const cert = publicCerts.find(
(c) => c.email.toLowerCase() === email.toLowerCase(),
);
if (cert) {
found.push(cert);
} else {
missing.push(email);
}
}
return { found, missing };
},
setSignDefault: (identityId, value) => {
set((state) => ({
defaultSignIdentity: { ...state.defaultSignIdentity, [identityId]: value },
}));
},
setEncryptDefault: (value) => {
set({ defaultEncrypt: value });
},
setRememberUnlockedKeys: (value) => {
set({ rememberUnlockedKeys: value });
if (!value) {
clearRememberedUnlocks();
set({ unlockedKeys: new Map(), unlockedDecryptionKeys: new Map() });
}
},
setAutoImportSignerCerts: (value) => {
set({ autoImportSignerCerts: value });
},
isKeyUnlocked: (id) => get().unlockedKeys.has(id),
getUnlockedKey: (id) => get().unlockedKeys.get(id),
setError: (error) => set({ error }),
}),
{
name: 'smime-preferences',
partialize: (state): SmimePersistedState => ({
identityKeyBindings: state.identityKeyBindings,
defaultSignIdentity: state.defaultSignIdentity,
defaultEncrypt: state.defaultEncrypt,
rememberUnlockedKeys: state.rememberUnlockedKeys,
autoImportSignerCerts: state.autoImportSignerCerts,
}),
},
),
);