Reply by mail (#295) authenticates From only through trusted_authserv_id, which reads the mail host's Authentication-Results. On gitbay.org that does not work: mail from a sender hosted at the same provider (Migadu to Migadu, e.g. hello@cleberg.net to threads@gitbay.org) is delivered through the outbound path with no Authentication-Results header at all, so setting the id would refuse every such reply. gitbay.org therefore runs inbound without it (startup warns), and From is whatever the sender wrote; a leaked notification token plus a forged From posts as that user.
The messages do carry a DKIM-Signature (d=cleberg.net, aligned with From). Verify it in gitbayd:
- Verify DKIM signatures (RFC 6376; rsa-sha256 and ed25519-sha256, relaxed/simple canonicalization,
l=refused or ignored,x=honoured) against the selector key fetched from DNS, with a timeout and a small cache. - Require a passing signature whose
d=is in relaxed alignment with the From domain (the public-suffix rule #295 uses) and whoseh=covers From. - A config switch, e.g.
[mail.inbound] require_dkim = true, independent oftrusted_authserv_id; either passing is enough when both are set. - Evaluate github.com/emersion/go-msgauth (MIT) against a small in-tree verifier; justify the choice.
- Tests with fixed keys: pass, body altered, From not signed, misaligned d=, expired x=, DNS failure (temporary: retry, not refuse forever).
- Then enable it on gitbay.org and drop the startup warning there.
referenced in commit e58a7dbc60 by cmc: wiki: mail.inbound notes from configuring gitbay.org
2026-09-29 15:06 UTC