Manage public keys, over Stalwart's x:PublicKey registry
A new Settings section, next to Identities & signatures: list, add, rename and remove the OpenPGP public keys and S/MIME certificates published on this account. Only public material -- no private key is stored, requested or sent by any of this. This is PR #67 revived. That branch was built against 0.16.19, closed unmerged on 2026-08-26, and shares no ancestry with main after the email scrub, so it is ported rather than rebased: the four files it added are carried over, the three it edited are applied by hand, and everything it claimed was re-probed against the live 0.16.20 on 2026-09-05. The i18n work is new -- nine catalogues landed on 2026-08-31, after that branch was written. What the re-probe confirmed, unchanged from 0.16.19: - An ordinary user may read *and* write their own keys, though the permissions table lists every sysPublicKey* permission as administrative. get and query both answered for a normal account, and a malformed create came back invalidProperties naming `key` rather than forbidden -- a rejection of the key, not of the person. - The server parses the key and says precisely what is wrong. So ihasmail does not validate key material; the server's message is shown verbatim, as password-policy rejections already are. - urn:stalwart:jmap is still absent from the session's top-level capabilities and present per-account, so the check that reads all three places is still the one that works. What it added, none of which was known before: - A key can parse perfectly and still be refused, with different words: a sign-and-certify key with no encryption subkey -- what `gpg --quick-generate-key` produces -- gets "Could not find any suitable keys in OpenPGP public key". That is the rejection somebody exporting from GnuPG will actually meet, and it is not a paste error, so collapsing both to "invalid key" would send them back to the clipboard for a problem that is in the key. - emailAddresses comes back as {} when empty -- an object where a JMAP list property should be an array. It type-checks, then throws in join() while the list renders. normalize() checked the shape already; there is now a test saying why, and the mock answers {} the same way, because one that helpfully returned [] would let that crash ship. - A create answers with the id alone, no createdAt, so adding a key reloads rather than believing the response. - destroy works and leaves the registry empty. PR #67 shipped that path untested -- its live probe was refused before anything was created, so there was nothing to destroy. - Patching `key` is allowed by the server. The mock still refuses it, now deliberately rather than for want of evidence: ihasmail replaces a key by adding one and removing the old, which keeps createdAt meaning what it says. x:EncryptionAtRest still does not exist on 0.16.20 -- asking for it is an unknownMethod. encryptionAtRest is a field on x:AccountSettings, and its value is a typed object ({"@type":"Disabled"}) rather than the bare string ROADMAP described. Nothing here writes it. An empty description is now sent as empty rather than filled in with "Key". The description is stored on the server, so a default invented in the client would be whichever language the adder happened to be using; the list labels a blank one at render time instead. Verified in a browser against the mock, not only in tests: both rejections reach the toast in the server's own words with the form still filled in, a good key renders its card, the kind is labelled from the armour header, renaming persists, removing asks first and empties the list, and the whole section reads correctly in German.
This commit is contained in:
1 parent
1f9c17ad18
commit
e93d42d27e
19 files changed
+1087
-3
No files matched your search
@@ -1309,6 +1309,36 @@ export const catalog: Catalog = {
|
||||
"Empty “{name}”?": "Vider « {name} » ?",
|
||||
"Delete them": "Les supprimer",
|
||||
"Nothing was deleted": "Rien n’a été supprimé",
|
||||
// ── Encryption keys, over Stalwart's x:PublicKey registry (#67) ──
|
||||
"Encryption keys": "Clés de chiffrement",
|
||||
"Not available on this server": "Non disponible sur ce serveur",
|
||||
"Public keys are kept in Stalwart's registry, which this server does not offer. ihasmail needs Stalwart 0.16 or newer for it.": "Les clés publiques sont conservées dans le registre de Stalwart, que ce serveur ne propose pas. ihasmail nécessite Stalwart 0.16 ou plus récent pour cela.",
|
||||
"Public keys for this account — what other people encrypt to, and what a signature is checked against. These are public by nature: no private key is stored, requested, or sent by ihasmail.": "Clés publiques de ce compte — ce avec quoi les autres chiffrent, et ce sur quoi une signature est vérifiée. Elles sont publiques par nature : ihasmail ne stocke, ne demande ni n'envoie aucune clé privée.",
|
||||
"No keys yet": "Aucune clé pour l'instant",
|
||||
"Add an OpenPGP public key or an S/MIME certificate to publish it on this account.": "Ajoutez une clé publique OpenPGP ou un certificat S/MIME pour le publier sur ce compte.",
|
||||
"Key added": "Clé ajoutée",
|
||||
"Key removed": "Clé retirée",
|
||||
"Remove “{name}”?": "Retirer « {name} » ?",
|
||||
"this key": "cette clé",
|
||||
"Anyone holding it can still use it — removing it here only stops this account offering it.": "Quiconque la détient peut toujours l'utiliser — la retirer ici empêche seulement ce compte de la proposer.",
|
||||
"Remove key": "Retirer la clé",
|
||||
"Key description": "Description de la clé",
|
||||
"Untitled key": "Clé sans titre",
|
||||
"Click to rename": "Cliquez pour renommer",
|
||||
"Expired": "Expirée",
|
||||
"Added": "Ajoutée",
|
||||
"Addresses": "Adresses",
|
||||
"No expiry set": "Aucune expiration définie",
|
||||
"Any address on this account": "Toute adresse de ce compte",
|
||||
"cryptography\u0004Key": "Clé",
|
||||
"Public key": "Clé publique",
|
||||
"Work key": "Clé professionnelle",
|
||||
"Paste the whole armoured block, headers included. The server checks it and says what is wrong if it cannot read it.": "Collez le bloc ASCII complet, en-têtes compris. Le serveur le vérifie et indique ce qui ne va pas s'il ne peut pas le lire.",
|
||||
"Add key": "Ajouter la clé",
|
||||
"Add a key": "Ajouter une clé",
|
||||
"Stalwart stores these keys, and this release does no more than manage them: ihasmail does not yet sign, encrypt, decrypt or verify anything with them. Adding one does not by itself start encrypting your mail.": "Stalwart conserve ces clés, et cette version ne fait que les gérer : ihasmail ne signe, ne chiffre, ne déchiffre et ne vérifie encore rien avec elles. En ajouter une ne commence pas à chiffrer votre courrier.",
|
||||
"Unrecognised": "Non reconnue",
|
||||
"No account to add a key to.": "Aucun compte auquel ajouter une clé.",
|
||||
},
|
||||
plurals: {
|
||||
// ── Third pass ─────────────────────────────────────────────────────
|
||||
|
||||
Reference in new issue
Block a user