Skip to content

fix(mailparse): decode base64 bodies and attachments without padding - #1073

Closed
RauPro wants to merge 1 commit into
tokencanopy:mainfrom
RauPro:codex/fix-1063-unpadded-base64
Closed

RauPro wants to merge 1 commit into
tokencanopy:mainfrom
RauPro:codex/fix-1063-unpadded-base64

Conversation

@RauPro

@RauPro RauPro commented Oct 8, 2026

Copy link
Copy Markdown

Summary

Fixes #1063. Base64 bodies and attachments with omitted padding currently fall back to their still-encoded wire content. Try RawStdEncoding after StdEncoding, matching the tolerance already used in piguard, so these messages return decoded text, HTML and attachment bytes.

Have decode() delegate to decodeBytes() so bodies and attachments share one transfer-decoding policy. If both base64 decoders fail, preserve the original bytes, including whitespace, rather than returning a partially decoded prefix. Quoted-printable and identity decoding retain their existing behavior.

Scope and operational risk

Internal MIME parsing only; no API schema, migration or SDK changes. The intended behavior change is accepting standard-alphabet base64 without padding. Malformed padding, impossible lengths, invalid characters and URL-safe alphabet inputs retain the existing raw fallback.

Test plan

Regression tests first reproduced six failing unpadded cases on main: plain text, HTML and binary attachments, each with one or two padding characters missing. The same tests pass with this change. Padded inputs, MIME whitespace, exact HTML and binary-byte preservation, and malformed-input fallback are covered as well.

Verified locally with Go 1.26.9:

  • go test ./...
  • go test -race ./internal/mailparse/ -count=1
  • make fmt-check
  • scripts/check-repository-text-integrity.sh
  • scripts/check-no-committed-credentials.sh
  • git diff --check

Postgres-backed integration tests and live SMTP delivery were not run locally; this change is confined to the parser.

Share transfer decoding between text bodies and attachments, and fall back
to RawStdEncoding after StdEncoding fails, matching piguard's tolerance.
Keep the original bytes when both decoders reject the input.

Cover missing one/two padding characters in plain text, HTML and binary
attachments, MIME whitespace, and malformed-input fallback.

Fixes tokencanopy#1063

Co-authored-by: Codex <noreply@openai.com>
Signed-off-by: Raul Ernesto Guillen Hernandez <37725305+RauPro@users.noreply.github.com>
@RauPro

RauPro commented Oct 8, 2026

Copy link
Copy Markdown
Author

Superseded by #1074 to use the source branch bug/1063-unpadded-base64. The replacement contains the same commit (26dd0be) and identical code changes and test results. Closing this duplicate; please continue review in #1074.

@RauPro RauPro closed this Oct 8, 2026
@RauPro
RauPro deleted the codex/fix-1063-unpadded-base64 branch October 8, 2026 22:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Unpadded base64 bodies/attachments fail to decode in mailparse (decode/decodeBytes only try StdEncoding)

1 participant