Concepts
Security model
How Squadmail isolates workspaces, renders untrusted mail and protects credentials.
Untrusted HTML
Email HTML is hostile by default. Squadmail:
- strips scripts, frames, forms, event handlers and
javascript:URLs on ingest, - renders mail in a sandboxed iframe without scripts or same-origin access,
- applies a strict CSP inside the frame and blocks remote images until you click Load images (no tracking pixels),
- inlines
cid:images as data URIs, so the frame never needs your session.
Attachments are served with content-disposition: attachment and a sandboxing CSP.
Credentials
- Passwords are hashed by Better Auth; sessions are HTTP-only cookies.
- API keys are random 30-byte secrets, stored only as SHA-256 hashes, shown once, revocable, optionally expiring.
- OAuth tokens for MCP clients are managed by
@cloudflare/workers-oauth-provider(hashed in KV). Consent requires a signed-in user who picks the workspace and scopes. Grants are re-checked against current membership on every call. - Webhook payloads are signed with HMAC-SHA256 (
t=…,v1=…) using a per-endpoint secret.
Isolation
Every query is scoped by workspace id derived from the credential — API keys cannot address another workspace’s inboxes, even by address.
Abuse controls
Sender allow/block lists, per-inbox and per-sender flood limits, daily quotas, Turnstile-ready sign-ups and invite-only mode by default.
Reporting
Please report vulnerabilities privately via GitHub Security Advisories on the repository.