From b42f1d9d07f7ac3d4bfb27cb8281724a70258a1f Mon Sep 17 00:00:00 2001 From: Lukas Geiger Date: Sun, 4 Oct 2026 00:02:32 +0200 Subject: [PATCH] docs: correct MailProcessor data flow claims --- README-DE.md | 14 ++++-- README.md | 14 ++++-- SECURITY.md | 26 ++++++---- SUPPORT.md | 43 ++++++++++++++++ docs/PRIVACY_POLICY_DRAFT.md | 97 ++++++++++++++++++++++++++++++++++++ llms.txt | 15 +++--- tests/test_metadata.py | 33 ++++++++++-- 7 files changed, 210 insertions(+), 32 deletions(-) create mode 100644 SUPPORT.md create mode 100644 docs/PRIVACY_POLICY_DRAFT.md diff --git a/README-DE.md b/README-DE.md index 43bf80b..dda93d7 100644 --- a/README-DE.md +++ b/README-DE.md @@ -16,7 +16,7 @@ System-Tray-Launcher für die drei Universal Mail Tools. [![Tests: 90 bestanden](https://img.shields.io/badge/tests-90%20bestanden-brightgreen.svg)](tests/) [![Sicherheit: Richtlinie](https://img.shields.io/badge/sicherheit-SECURITY.md-blue.svg)](SECURITY.md) [![Sicherheits-SLA: 48h Reaktion](https://img.shields.io/badge/sicherheits--SLA-48h%20Reaktion-blue.svg)](SECURITY.md) -[![Datenschutz: 100% Local--First](https://img.shields.io/badge/datenschutz-100%25%20Local--First-blueviolet.svg)](SECURITY.md) +[![Datenschutzhinweis: Entwurf](https://img.shields.io/badge/datenschutz-hinweis%20entwurf-blue.svg)](docs/PRIVACY_POLICY_DRAFT.md) [![Code-Stil: ruff](https://img.shields.io/badge/code--stil-ruff-000000.svg)](https://github.com/astral-sh/ruff) [![Dachverband: open-bricks](https://img.shields.io/badge/dachverband-open--bricks-blue.svg)](https://github.com/open-bricks) [![LLM Ready](https://img.shields.io/badge/LLM--Ready-llms.txt-brightgreen.svg)](llms.txt) @@ -66,6 +66,10 @@ MailProcessor sitzt im Windows-System-Tray und gibt per Rechtsklick Zugang zu: - Autostart mit Windows (Registry-Eintrag) - Zweisprachig: Deutsch / Englisch +### Daten- und Netzwerkumfang + +MailProcessor speichert seine Launcher-Konfiguration auf dem Gerät. Startet der Benutzer im Einrichtungsassistenten einen Werkzeug-Download, fragt der Launcher Release-Metadaten bei GitHub ab und lädt das Release-Archiv des Werkzeugs herunter. Im geprüften Launcher-Quellstand wurde keine Telemetrie-Implementierung gefunden. Die separat gestarteten Mailwerkzeuge haben eigene Datenflüsse; dieser Befund beschreibt oder begrenzt deren Netzwerkverhalten nicht. Siehe den [Prüfentwurf der Datenschutzhinweise](docs/PRIVACY_POLICY_DRAFT.md). + ## Systemarchitektur & Workflow ```mermaid @@ -188,16 +192,16 @@ werden in [RELEASES.md](RELEASES.md#current-platform-scope-2026-08-26) nachverfo ## Governance & Laufzeit-Invarianten -Die folgenden Invarianten definieren die Betriebs- und Sicherheitsgarantien von MailProcessor: +Die folgenden Kennungen fassen beobachtetes Produktverhalten und Sicherheitsgrenzen zusammen: -| Invarianten-ID | Bezeichnung | Richtlinie / Standard | Verifikation & Garantie | +| Invarianten-ID | Bezeichnung | Richtlinie / Standard | Beobachtetes Verhalten | |---|---|---|---| -| `INV-LOCAL-01` | **100% Local-First & Zero Egress** | Offline-Datenschutzstandard | Läuft vollständig auf dem lokalen System. Keine Telemetrie, keine Cloud-Weiterleitung, keine Speicherung von Mail-Inhalten, Passwörtern oder Zugangsdaten. | +| `INV-DATA-01` | **Daten- und Netzwerkumfang des Launchers** | Beobachtetes Quellverhalten | Launcher-Einstellungen werden lokal gespeichert. Vom Benutzer gestartete Werkzeug-Downloads kontaktieren GitHub Releases; separat gestartete Werkzeuge haben eigene Datenflüsse. Im geprüften Launcher-Quellstand wurde keine Telemetrie-Implementierung gefunden. | | `INV-NOELEV-02` | **Keine Rechteerweiterung (RunAsInvoker)** | Windows Least-Privilege-Prinzip | Läuft ausnahmslos als Standardbenutzer ohne UAC-Elevation (`runAsInvoker`). | | `INV-ZIPSLIP-03` | **Zip-Slip-Schutz gegen Pfadüberquerung** | CWE-22 Sicherheitsstandard | GitHub-Release-Downloads validieren alle Archivpfade vor dem Entpacken, um Verzeichnisüberquerungen auszuschließen. | | `INV-CFGISO-04` | **Lokale AppData-Isolation** | Windows AppData Konvention | Konfiguration liegt isoliert unter `%LOCALAPPDATA%\MailProcessor\config.json`. Keine Registry-Verschmutzung außer dem optionalen Benutzer-Autostart. | | `INV-PROCLIF-05` | **Sicherer Subprozess-Lebenszyklus** | Saubere Prozess-Entkopplung | Startet Universal Mail Tools als losgelöste unprivilegierte Subprozesse (`subprocess.Popen`), wodurch Blockaden des Trays verhindert werden. | -| `INV-REDACT-06` | **Deterministische Snapshot-Anonymisierung** | Datenminimierung | Der `mailprocessor-suite-v1.json`-Export bereinigt benutzerspezifische absolute Pfade für den sicheren Offline-Austausch. | +| `INV-REDACT-06` | **Pfadhinweise im Snapshot** | Datenverarbeitung | Der Export ersetzt Pfade unter lokalen Datenwurzeln; andere Pfade können die letzten ein oder zwei Ordnernamen enthalten. Prüfe die Datei vor dem Teilen. | | `INV-OSPAR-07` | **Plattform-Smoke-Vertrag** | Multi-OS Quelltext-Integrität | Primäre Ziellaufzeit ist Windows Desktop Tray; Multi-OS-Matrix prüft Quelltext-Kompatibilität unter Ubuntu und macOS. | | `INV-SLA-08` | **Sicherheitsreaktions- & Triage-SLA** | Responsible Disclosure | 48-Stunden-Reaktions-SLA und 5-Werktage-Triage über `security@ellmos.ai` und GitHub Security Advisories. | diff --git a/README.md b/README.md index bfaf3bc..b2002dc 100644 --- a/README.md +++ b/README.md @@ -16,7 +16,7 @@ System tray launcher for the three Universal Mail Tools. [![Tests: 90 passed](https://img.shields.io/badge/tests-90%20passed-brightgreen.svg)](tests/) [![Security: Policy](https://img.shields.io/badge/security-SECURITY.md-blue.svg)](SECURITY.md) [![Security SLA: 48h Response](https://img.shields.io/badge/security%20SLA-48h%20response-blue.svg)](SECURITY.md) -[![Privacy: 100% Local--First](https://img.shields.io/badge/privacy-100%25%20Local--First-blueviolet.svg)](SECURITY.md) +[![Privacy notice: draft](https://img.shields.io/badge/privacy-notice%20draft-blue.svg)](docs/PRIVACY_POLICY_DRAFT.md) [![Code Style: ruff](https://img.shields.io/badge/code%20style-ruff-000000.svg)](https://github.com/astral-sh/ruff) [![Umbrella: open-bricks](https://img.shields.io/badge/umbrella-open--bricks-blue.svg)](https://github.com/open-bricks) [![LLM Ready](https://img.shields.io/badge/LLM--Ready-llms.txt-brightgreen.svg)](llms.txt) @@ -66,6 +66,10 @@ MailProcessor sits in the Windows system tray and gives you one-click access to: - Windows autostart (registry entry) - Bilingual: German / English +### Data and network scope + +MailProcessor stores its launcher configuration on the device. When a user starts a tool download in the setup wizard, the launcher requests release metadata from GitHub and downloads that tool's release archive. No telemetry implementation was found in the reviewed launcher source. The separately launched mail tools have their own data flows; this finding does not describe or limit their network behavior. See the [launcher privacy notice draft](docs/PRIVACY_POLICY_DRAFT.md). + ## System Architecture & Workflow ```mermaid @@ -185,16 +189,16 @@ tracked in [RELEASES.md](RELEASES.md#current-platform-scope-2026-08-26). ## Governance & Runtime Invariants -The following invariants define the operational and security guarantees of MailProcessor: +The following identifiers summarize observed product behavior and security boundaries: -| Invariant ID | Name | Standard / Policy | Verification & Guarantee | +| Invariant ID | Name | Standard / Policy | Observed behavior | |---|---|---|---| -| `INV-LOCAL-01` | **100% Local-First & Zero Egress** | Offline Privacy Standard | Operates entirely on the local machine. No telemetry, no background analytics, no cloud relay, and zero storage of email content, passwords, or credentials. | +| `INV-DATA-01` | **Launcher data and network scope** | Observed source behavior | Launcher configuration is stored locally. User-started tool downloads contact GitHub Releases; separately launched tools have their own data flows. No telemetry implementation was found in the reviewed launcher source. | | `INV-NOELEV-02` | **Non-Elevation & RunAsInvoker** | Windows Least Privilege | Runs exclusively as standard unprivileged user. Never requests UAC elevation (`runAsInvoker`). | | `INV-ZIPSLIP-03` | **Zip-Slip Traversal Defense** | CWE-22 Security Standard | Tool downloads from GitHub releases validate archive member paths to prevent directory traversal attacks before extraction. | | `INV-CFGISO-04` | **Local AppData Isolation** | Windows AppData Convention | Configuration is isolated under `%LOCALAPPDATA%\MailProcessor\config.json`. No registry pollution except optional per-user autostart entry. | | `INV-PROCLIF-05` | **Safe Subprocess Lifecycle** | Clean Process Separation | Launches Universal Mail Tools via detached unprivileged subprocesses (`subprocess.Popen`) preventing parent tray lockups or cascaded crashes. | -| `INV-REDACT-06` | **Deterministic Snapshot Redaction** | Data Minimization | `mailprocessor-suite-v1.json` exports redact machine-specific absolute paths to protect user privacy in shared or offline bug reports. | +| `INV-REDACT-06` | **Snapshot path hints** | Data handling | The export replaces local data-root paths; other paths may retain the last one or two folder names. Review the file before sharing. | | `INV-OSPAR-07` | **Cross-Platform Source Smoke Contract** | Multi-OS Integrity | Primary product surface is Windows Desktop Tray; multi-platform smoke test matrix verifies source-level compatibility across Ubuntu and macOS. | | `INV-SLA-08` | **Security Response & Triage SLA** | Responsible Disclosure | 48-hour response SLA and 5-business-day triage commitment through `security@ellmos.ai` and GitHub Security Advisories. | diff --git a/SECURITY.md b/SECURITY.md index d5fdf7d..c4ea978 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -24,10 +24,13 @@ melden Sie diese bitte verantwortungsvoll: - `support@lukasgeiger.com` - `lukas@open-bricks.org` -### Verbindliche Sicherheitsgarantien (Invarianten) +### Laufzeitverhalten und Datenumfang -- **Local-First & Zero-Egress:** MailProcessor speichert keine E-Mail-Inhalte, Passwörter, - Tokens oder IMAP-Zugangsdaten. Alle Operationen laufen lokal auf dem Rechner des Nutzers. +- **Daten- und Netzwerkumfang des Launchers:** MailProcessor speichert seine Launcher-Konfiguration + lokal. Wenn Benutzer im Einrichtungsassistenten einen Werkzeug-Download starten, fragt der Launcher + GitHub-Release-Metadaten ab und lädt das Archiv herunter. Im geprüften Launcher-Quellstand wurde + keine Telemetrie-Implementierung gefunden. Separat gestartete Werkzeuge haben eigene Datenflüsse; + dieser Befund beschreibt oder begrenzt deren Netzwerkverhalten nicht. - **Unprivilegierter User-Mode (Non-Elevation):** MailProcessor benötigt und verlangt keine Administratorrechte. Autostart wird ausschließlich im aktuellen Benutzerkontext (`HKCU\Software\Microsoft\Windows\CurrentVersion\Run`) verwaltet. @@ -35,8 +38,8 @@ melden Sie diese bitte verantwortungsvoll: Entpacken strikt auf Pfadtraversierung (CWE-22) validiert, sodass keine Dateien außerhalb des vorgesehenen Tool-Ordners abgelegt werden können. - **Isolierte Konfiguration:** Konfigurationsdaten werden im lokalen Benutzerdatenverzeichnis - (`%LOCALAPPDATA%\MailProcessor\config.json`) gehalten. Snapshot-Exporte redigieren lokale - Pfade und enthalten keinerlei geheime Informationen. + (`%LOCALAPPDATA%\MailProcessor\config.json`) gehalten. Snapshot-Exporte ersetzen lokale + Pfadwurzeln; andere Pfade können die letzten Ordnernamen enthalten. Vor dem Teilen prüfen. ### Reaktionszeit @@ -68,10 +71,13 @@ If you discover a security vulnerability or concern in MailProcessor, please rep - `support@lukasgeiger.com` - `lukas@open-bricks.org` -### Core Security Invariants +### Runtime Behavior and Data Scope -- **Local-First & Zero-Egress:** MailProcessor does not store email contents, passwords, - tokens, or IMAP credentials. It operates 100% locally with zero cloud telemetry. +- **Launcher data and network scope:** MailProcessor stores its launcher configuration locally. + When a user starts a tool download in the setup wizard, the launcher requests GitHub release + metadata and downloads the archive. No telemetry implementation was found in the reviewed + launcher source. Separately launched tools have their own data flows; this finding does not + describe or limit their network behavior. - **Non-Elevation (User Mode):** MailProcessor runs unprivileged in standard user mode. Autostart entries are registered exclusively under the user scope (`HKCU\Software\Microsoft\Windows\CurrentVersion\Run`). @@ -79,8 +85,8 @@ If you discover a security vulnerability or concern in MailProcessor, please rep against path traversal (CWE-22) before extraction, preventing any file writes outside the designated tool target directory. - **Isolated Configuration:** Configuration data is stored in the local user directory - (`%LOCALAPPDATA%\MailProcessor\config.json`). Snapshot exports redact local paths and - contain zero secrets. + (`%LOCALAPPDATA%\MailProcessor\config.json`). Snapshot exports replace local data-root paths; + other paths may retain trailing folder names. Review an export before sharing it. ### Response Time diff --git a/SUPPORT.md b/SUPPORT.md new file mode 100644 index 0000000..e4236a7 --- /dev/null +++ b/SUPPORT.md @@ -0,0 +1,43 @@ +# MailProcessor Support + +**Source basis:** MailProcessor 0.1.0, reviewed at commit b5be8f20c5ec6fb519c40c4892b47f15e08c9be8 (2026-10-03). + +## English + +For ordinary usage questions and reproducible MailProcessor problems, use the public issue tracker: + +https://github.com/doc-bricks/MailProcessor/issues + +Please include, when known: + +- MailProcessor version and whether you use a source checkout or a downloaded build. The current source declares version 0.1.0 in pyproject.toml and RELEASES.md. The versions displayed beside tray menu entries belong to the separate mail tools, not to MailProcessor. +- Windows version and relevant language setting. +- Short steps to reproduce, expected result, actual result, and the exact visible error text. +- Whether the issue concerns MailProcessor itself or one of the separately launched tools. + +Do not post email addresses, mailbox names, message or attachment contents, passwords, tokens, private keys, or account exports. Do not attach config.json: it contains local tool paths. A MailProcessor snapshot redacts path roots but may retain trailing folder names; inspect it and remove identifying details before sharing. The launcher does not create an application log in the reviewed source. + +For a security vulnerability, do not use a public issue. Consult SECURITY.md for the project's documented reporting options: +https://github.com/doc-bricks/MailProcessor/blob/main/SECURITY.md + +The source repository does not promise a general support response time. + +## Deutsch + +Für allgemeine Nutzungsfragen und reproduzierbare Fehler in MailProcessor nutze bitte den öffentlichen Issue-Tracker: + +https://github.com/doc-bricks/MailProcessor/issues + +Gib, soweit bekannt, Folgendes an: + +- MailProcessor-Version und ob du einen Quellcode-Checkout oder einen heruntergeladenen Build verwendest. Der aktuelle Quellstand nennt Version 0.1.0 in pyproject.toml und RELEASES.md. Versionsangaben neben Einträgen im Tray-Menü gehören zu den separaten Mailwerkzeugen, nicht zu MailProcessor. +- Windows-Version und relevante Spracheinstellung. +- Kurze Schritte zur Reproduktion, erwartetes und tatsächliches Ergebnis sowie den genauen sichtbaren Fehlertext. +- Ob der Fehler MailProcessor selbst oder eines der separat gestarteten Werkzeuge betrifft. + +Veröffentliche keine E-Mail-Adressen, Postfachnamen, Nachrichten- oder Anhangsinhalte, Passwörter, Tokens, privaten Schlüssel oder Konto-Exporte. Hänge config.json nicht an: Sie enthält lokale Toolpfade. Ein MailProcessor-Snapshot kürzt Pfadwurzeln, kann aber die letzten Ordnernamen enthalten. Prüfe die Datei und entferne erkennbare persönliche Angaben, bevor du sie teilst. Im geprüften Quellstand legt der Launcher kein eigenes Anwendungsprotokoll an. + +Melde Sicherheitslücken nicht öffentlich als Issue. Prüfe dafür die in SECURITY.md dokumentierten Meldewege: +https://github.com/doc-bricks/MailProcessor/blob/main/SECURITY.md + +Der Quellstand verspricht keine allgemeine Support-Antwortzeit. \ No newline at end of file diff --git a/docs/PRIVACY_POLICY_DRAFT.md b/docs/PRIVACY_POLICY_DRAFT.md new file mode 100644 index 0000000..9936b89 --- /dev/null +++ b/docs/PRIVACY_POLICY_DRAFT.md @@ -0,0 +1,97 @@ +# MailProcessor Privacy Notice — review draft + +**Source basis:** MailProcessor 0.1.0, reviewed at commit b5be8f20c5ec6fb519c40c4892b47f15e08c9be8 (2026-10-03). + +**Review status:** This draft describes behavior found in the reviewed MailProcessor source. The repository does not identify a privacy-request contact or the legal publishing/operator entity. Those details need confirmation by the project owner before this text is published or submitted to the Microsoft Store. This is not a claim of legal compliance. + +## Scope + +MailProcessor is a Windows desktop tray launcher for Universal Mail Cleaner, Universal Docs Grabber, and Universal Invoice Mail. This notice covers the MailProcessor launcher only. The three separate tools are started as child processes and may access mail accounts, messages, attachments, or other services under their own behavior. Review the privacy information for each tool as well. + +## Information stored on this device + +MailProcessor reads and writes a JSON configuration file at %LOCALAPPDATA%\MailProcessor\config.json. If LOCALAPPDATA is missing or not an absolute path, the source falls back to a MailProcessor directory under the current user home directory. + +The configuration can contain the selected language, first-run state, the start-with-Windows setting, and for each configured tool its identifier, enabled state, folder path, entry-script filename, and installation source. Folder paths can reveal local directory names. + +The configuration is a UTF-8 JSON file. The reviewed source does not encrypt it; access to the file is subject to the operating system's file permissions. + +Downloaded tool release ZIP files and their extracted files are stored under %LOCALAPPDATA%\MailProcessor\tools (or the same home-directory fallback). The launcher has no scheduled cleanup for its configuration or downloaded ZIP files. Removing a tool registration in Settings does not delete that tool's files. A later download replaces the extracted folder for that tool. + +If start with Windows is enabled, MailProcessor maintains a per-user entry named MailProcessor under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Disabling the setting asks Windows to remove that entry. The preference is also stored in the configuration file. + +## Network connections + +When a user starts a tool download in the setup wizard, MailProcessor requests the latest-release metadata from the configured public GitHub repository and downloads the release archive URL returned by GitHub. The supported repositories are doc-bricks/UniversalMailCleaner, doc-bricks/UniversalDocsGrabber, and doc-bricks/UniversalInvoiceMail. The requests use the User-Agent MailProcessor/1.0 and do not add an application access token. GitHub and any server used for the archive URL may receive ordinary connection data such as the IP address and request time; GitHub describes its handling in the [GitHub General Privacy Statement](https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement). + +The reviewed MailProcessor source contains no telemetry, analytics, or account-sync implementation. This statement covers the launcher source only, not the separate child applications or third-party services they may use. + +## Separate tools + +When the user launches a configured tool, MailProcessor starts its selected script as a separate process and passes the current process environment to it. The launcher itself does not implement mailbox reading or attachment processing. The selected tool can have its own account settings, local files, and network connections; this notice does not describe or control those operations. + +## Optional snapshot export + +The user can choose Export Snapshot from the tray menu and select where to save a JSON file. The export contains the export time, MailProcessor name/version/platform, and each supported tool's identifier, display name, enabled state, installation source, detected version, availability status, and an optional path hint. + +The exporter replaces absolute path roots under LOCALAPPDATA or the home directory with labels. For other paths it can retain the last one or two directory names, so a path hint may still reveal identifying folder names. MailProcessor writes the file to the location selected by the user and does not upload it. Review the file before sharing it; a cloud-synced destination or later sharing is controlled by the user and that service. + +## Choices and removal + +Tool downloads are optional. Users can change or unregister tools in Settings and can turn off start with Windows there. Before removing the configuration, turn off start with Windows in Settings and save so the per-user startup entry is removed. The configuration file can also be read directly as UTF-8 JSON; the launcher has no account portal or server-side copy of this configuration. Then close MailProcessor and remove its MailProcessor configuration and tools directory from the applicable user data location to remove the launcher configuration and downloaded copies. This does not remove separately installed tools or their data. + +## Privacy contact + +The reviewed source and public project metadata do not specify a verified contact for privacy requests or identify the legal operator of MailProcessor. Do not post personal information in a public issue. The project owner must provide a private, verified privacy-contact route before this draft is published as a final policy. + +--- + +## Deutsch + +### Datenschutzhinweise für MailProcessor — Prüfentwurf + +**Quellgrundlage:** MailProcessor 0.1.0, geprüft auf Commit b5be8f20c5ec6fb519c40c4892b47f15e08c9be8 (2026-10-03). + +**Prüfstatus:** Dieser Entwurf beschreibt Verhalten, das im geprüften MailProcessor-Quellstand gefunden wurde. Das Repository benennt weder eine Ansprechstelle für Datenschutzanfragen noch eine rechtlich verantwortliche Veröffentlichungs- oder Betreiberstelle. Diese Angaben muss die Projektverantwortung vor einer Veröffentlichung oder Store-Einreichung bestätigen. Dies ist keine Zusicherung rechtlicher Konformität. + +### Geltungsbereich + +MailProcessor ist ein Windows-Desktopprogramm im Infobereich der Taskleiste und startet Universal Mail Cleaner, Universal Docs Grabber und Universal Invoice Mail. Diese Hinweise gelten nur für den MailProcessor-Launcher. Die drei separaten Werkzeuge werden als eigene Prozesse gestartet und können nach ihrem jeweiligen Verhalten auf E-Mail-Konten, Nachrichten, Anhänge oder weitere Dienste zugreifen. Bitte prüfe auch die Datenschutzhinweise der jeweiligen Werkzeuge. + +### Auf diesem Gerät gespeicherte Informationen + +MailProcessor liest und schreibt eine JSON-Konfigurationsdatei unter %LOCALAPPDATA%\MailProcessor\config.json. Wenn LOCALAPPDATA fehlt oder kein absoluter Pfad ist, verwendet der Quellstand stattdessen ein MailProcessor-Verzeichnis im Home-Verzeichnis des aktuellen Benutzers. + +Die Konfiguration kann die ausgewählte Sprache, den Ersteinrichtungsstatus, die Einstellung für den Windows-Start sowie für jedes eingerichtete Werkzeug dessen Kennung, Aktivierungsstatus, Verzeichnispfad, Dateinamen des Einstiegsskripts und Installationsherkunft enthalten. Verzeichnispfade können lokale Ordnernamen erkennen lassen. + +Die Konfiguration ist eine UTF-8-JSON-Datei. Der geprüfte Quellstand verschlüsselt sie nicht; der Zugriff richtet sich nach den Dateiberechtigungen des Betriebssystems. + +Heruntergeladene Release-ZIP-Dateien der Werkzeuge und deren entpackte Dateien liegen unter %LOCALAPPDATA%\MailProcessor\tools oder im entsprechenden Fallback-Verzeichnis im Home-Verzeichnis. Der Launcher hat keine zeitgesteuerte Bereinigung für Konfiguration oder heruntergeladene ZIP-Dateien. Wenn ein Werkzeug in den Einstellungen abgemeldet wird, löscht das seine Dateien nicht. Ein späterer Download ersetzt das entpackte Verzeichnis dieses Werkzeugs. + +Wenn Windows-Start aktiviert ist, verwaltet MailProcessor im aktuellen Benutzerkontext einen Eintrag namens MailProcessor unter HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Beim Deaktivieren der Einstellung versucht das Programm, diesen Eintrag zu entfernen. Die Einstellung steht außerdem in der Konfigurationsdatei. + +### Netzwerkverbindungen + +Wenn ein Benutzer im Einrichtungsassistenten einen Werkzeug-Download startet, fragt MailProcessor die Metadaten des neuesten Releases beim festgelegten öffentlichen GitHub-Repository ab und lädt anschließend die von GitHub gelieferte Release-Archivadresse herunter. Unterstützt werden die Repositories doc-bricks/UniversalMailCleaner, doc-bricks/UniversalDocsGrabber und doc-bricks/UniversalInvoiceMail. Die Anfragen verwenden den User-Agent MailProcessor/1.0 und fügen kein Anwendungszugangstoken hinzu. GitHub und ein Server, der für die Archivadresse verwendet wird, können übliche Verbindungsdaten wie IP-Adresse und Anfragezeit erhalten. GitHub beschreibt seine Verarbeitung in der [allgemeinen GitHub-Datenschutzerklärung](https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement). + +Im geprüften MailProcessor-Quellstand wurde keine Implementierung für Telemetrie, Analyse oder Kontosynchronisierung gefunden. Diese Aussage betrifft nur den Launcher und nicht die separat gestarteten Anwendungen oder von ihnen genutzten Drittanbieterdienste. + +### Separate Werkzeuge + +Wenn der Benutzer ein eingerichtetes Werkzeug startet, führt MailProcessor dessen ausgewähltes Skript als eigenen Prozess aus und übergibt ihm die aktuelle Prozessumgebung. Der Launcher selbst implementiert weder das Lesen von Postfächern noch die Verarbeitung von Anhängen. Das gestartete Werkzeug kann eigene Kontoeinstellungen, lokale Dateien und Netzwerkverbindungen haben. Diese Hinweise beschreiben oder steuern diese Vorgänge nicht. + +### Optionaler Snapshot-Export + +Über den Menüpunkt „Snapshot exportieren“ kann der Benutzer einen Speicherort wählen und eine JSON-Datei schreiben. Der Export enthält Exportzeitpunkt, MailProcessor-Name, Version und Plattform sowie für jedes unterstützte Werkzeug Kennung, Anzeigename, Aktivierungsstatus, Installationsherkunft, erkannte Version, Verfügbarkeitsstatus und gegebenenfalls einen Pfadhinweis. + +Der Export ersetzt absolute Pfadwurzeln unter LOCALAPPDATA oder im Home-Verzeichnis durch Bezeichnungen. Bei anderen Pfaden kann er die letzten ein oder zwei Ordnernamen behalten. Ein Pfadhinweis kann deshalb weiterhin identifizierende Ordnernamen offenbaren. MailProcessor schreibt die Datei an den ausgewählten Speicherort und lädt sie nicht selbst hoch. Bitte prüfe die Datei vor dem Teilen. Eine Cloud-Synchronisierung des ausgewählten Zielordners oder eine spätere Weitergabe wird durch den Benutzer oder den jeweiligen Dienst gesteuert. + +### Auswahl und Entfernen + +Werkzeug-Downloads sind optional. Benutzer können Werkzeuge in den Einstellungen ändern oder abmelden und dort auch den Windows-Start deaktivieren. Die Konfigurationsdatei lässt sich außerdem direkt als UTF-8-JSON lesen. Der Launcher hat kein Benutzerkonto-Portal und keine serverseitige Kopie dieser Konfiguration. + +Vor dem Entfernen der Konfiguration sollte der Benutzer in den Einstellungen den Windows-Start deaktivieren und speichern, damit der Autostarteintrag für den aktuellen Benutzer entfernt wird. Anschließend kann MailProcessor geschlossen und die MailProcessor-Konfiguration samt Werkzeugverzeichnis am zutreffenden Benutzerdatenort entfernt werden. Dadurch werden Launcher-Konfiguration und heruntergeladene Kopien entfernt, jedoch keine separat installierten Werkzeuge oder deren Daten. + +### Kontakt für Datenschutzanfragen + +Der geprüfte Quellstand und die öffentlichen Projektmetadaten nennen keinen bestätigten Kontakt für Datenschutzanfragen und keine rechtliche Betreiberstelle von MailProcessor. Bitte veröffentliche personenbezogene Informationen nicht in öffentlichen Issues. Die Projektverantwortung muss vor der Veröffentlichung dieses Entwurfs als endgültige Datenschutzerklärung einen privaten, bestätigten Kontaktweg angeben. \ No newline at end of file diff --git a/llms.txt b/llms.txt index 9b3cec9..5ffc3a7 100644 --- a/llms.txt +++ b/llms.txt @@ -10,7 +10,7 @@ Primary language: Python UI stack: PySide6 desktop tray application License: MIT -MailProcessor is the local-first Windows tray hub for the doc-bricks Universal Mail Tools: +MailProcessor is a Windows tray hub for the doc-bricks Universal Mail Tools. It stores launcher settings locally and can download selected tool releases from GitHub when the user starts a download: - Universal Mail Cleaner: https://github.com/doc-bricks/UniversalMailCleaner - Universal Docs Grabber: https://github.com/doc-bricks/UniversalDocsGrabber @@ -38,7 +38,7 @@ Visual architecture & diagrams: Governance & runtime invariants: -- INV-LOCAL-01: 100% Local-First & Zero Egress +- INV-DATA-01: Local launcher settings; user-started GitHub release downloads; separate child-tool data flows - INV-NOELEV-02: Non-Elevation & RunAsInvoker - INV-ZIPSLIP-03: CWE-22 Zip-Slip Traversal Defense - INV-CFGISO-04: Local AppData Isolation (%LOCALAPPDATA%\MailProcessor\config.json) @@ -47,11 +47,12 @@ Governance & runtime invariants: - INV-OSPAR-07: Cross-Platform Source Smoke Contract (Ubuntu, macOS smoke) - INV-SLA-08: Security Response & Triage SLA (48h acknowledgment, 5-day triage) -Privacy boundary: +Launcher data and network scope: -- MailProcessor does not store mail contents, passwords, tokens, or IMAP credentials. -- Snapshot exports redact local paths and contain only launcher metadata. -- MailProcessor operates 100% local-first on the user's desktop with no remote cloud dependencies. +- Launcher configuration is UTF-8 JSON under `%LOCALAPPDATA%\MailProcessor\config.json`, with a home-directory fallback; the reviewed source does not encrypt it. +- User-started tool downloads request GitHub release metadata and download archive files. +- Snapshot exports replace local data-root paths, but other paths may retain trailing folder names; review before sharing. +- No telemetry implementation was found in the reviewed launcher source. Separately launched tools have their own data flows. Local verification: @@ -71,7 +72,7 @@ python -m compileall . ```text MailProcessor Windows tray mail launcher doc-bricks MailProcessor PySide6 -local-first IMAP mail tools launcher +Windows mail tools launcher with optional GitHub downloads Universal Mail Cleaner Docs Grabber Invoice Mail hub Windows mail tool manager Python desktop ``` diff --git a/tests/test_metadata.py b/tests/test_metadata.py index 80ccb44..0874b3f 100644 --- a/tests/test_metadata.py +++ b/tests/test_metadata.py @@ -113,14 +113,37 @@ def test_security_policy_and_invariants(): assert "https://github.com/doc-bricks/MailProcessor/security/advisories/new" in security_content assert "48" in security_content - # Core invariants - assert "Local-First" in security_content - assert "Zero-Egress" in security_content + # The launcher performs user-started GitHub downloads; do not promise zero egress. + assert "Launcher data and network scope" in security_content + assert "user starts a tool download" in security_content + assert "separately launched tools" in security_content.casefold() + assert "Zero-Egress" not in security_content assert "Non-Elevation" in security_content assert "Zip-Slip" in security_content assert "%LOCALAPPDATA%\\MailProcessor\\config.json" in security_content +def test_public_docs_describe_launcher_network_scope_without_zero_egress_claim(): + docs = { + "README.md": _read_file("README.md"), + "README-DE.md": _read_file("README-DE.md"), + "SECURITY.md": _read_file("SECURITY.md"), + "llms.txt": _read_file("llms.txt"), + } + + for name, content in docs.items(): + normalized = content.casefold() + assert "zero-egress" not in normalized, name + assert "zero egress" not in normalized, name + assert "100% local-first" not in normalized, name + + assert "user-started tool downloads" in docs["README.md"].casefold() + assert "vom benutzer gestartete werkzeug-downloads" in docs["README-DE.md"].casefold() + assert "separately launched tools" in docs["SECURITY.md"].casefold() + assert "separat gestartete werkzeuge" in docs["README-DE.md"].casefold() + assert "no telemetry implementation was found" in docs["llms.txt"].casefold() + + def test_gitignore_integrity(): """Verify .gitignore contains cache, lock files, and conflict patterns.""" gitignore_content = _read_file(".gitignore") @@ -173,7 +196,7 @@ def test_readme_bilingual_parity(): # Governance invariants in both expected_invariants = [ - "INV-LOCAL-01", + "INV-DATA-01", "INV-NOELEV-02", "INV-ZIPSLIP-03", "INV-CFGISO-04", @@ -205,7 +228,7 @@ def test_llms_txt_integrity(): assert "UniversalInvoiceMail" in llms_content assert "source-platform smoke PASS" in llms_content assert "%LOCALAPPDATA%\\MailProcessor\\config.json" in llms_content - assert "INV-LOCAL-01" in llms_content + assert "INV-DATA-01" in llms_content assert "INV-SLA-08" in llms_content assert "flowchart TD" in llms_content assert "sequenceDiagram" in llms_content