Skip to main content

rmut_core/
config.rs

1//! TOML configuration from $RMUT_CONFIG or ~/.config/rmut/config.toml.
2//!
3//! ```toml
4//! [identity]
5//! name = "Jane Doe"
6//! email = "jane@example.com"
7//! reverse_name = false  # reply From = the address the mail came to
8//!
9//! [[identities]]        # conditional identity (folder-/send-hook)
10//! folder = "*work*"     # glob on the open mailbox, and/or:
11//! recipient = "*@work.example.com"   # glob on a draft recipient
12//! name = "Jane Work"
13//! email = "jane@work.example.com"
14//!
15//! [mail]
16//! alternates = ["jane@old\\.example\\.com"]  # my other addresses
17//! my_hdr = ["Organization: Acme"]        # on every draft
18//! mailboxes = ["~/Maildir", "~/Maildir/.Sent"]
19//! sent = "~/Maildir/.Sent"
20//! postponed = "~/Maildir/.Drafts"
21//! sendmail = "/usr/sbin/sendmail"
22//! editor = "vim"
23//! poll_seconds = 5
24//! print = "lpr"
25//!
26//! [index]
27//! format = "%4C %Z %-6d %-15.15L (%?l?%4l&%4c?) %s"
28//!
29//! [ui]
30//! theme = "default"   # or "mono"
31//!
32//! [colors]            # overrides: status_fg status_bg deleted flagged header
33//! deleted = "red"
34//!
35//! [keys.index]        # action = key, e.g. sync = "w", delete = "ctrl+d"
36//! [keys.pager]
37//!
38//! [[accounts]]        # remote account, opened as imap:name/FOLDER
39//! name = "work"
40//! user = "jane@example.com"
41//! password_command = "pass show mail/work"   # or: password = "..."
42//! imap_host = "imap.example.com"   # imap_port = 993, imap_tls = true
43//! smtp_host = "smtp.example.com"   # smtp_port = 587, smtp_tls = true
44//! sent_folder = "Sent"             # Fcc target via IMAP APPEND
45//!
46//! [[folder_hooks]]      # mutt's folder-hook, any `:` command line
47//! folder = "*work*"
48//! command = "set index_format=\"%4C %Z %-6d %-20.20F %s\""
49//!
50//! [[message_hooks]]     # applied while the message is selected
51//! pattern = "~f boss@example.com"
52//! command = "set pager_context=5"
53//!
54//! [[reply_hooks]]       # applied while a reply to it is built
55//! pattern = "~t @work.example.com"
56//! command = "set from=jane@work.example.com"
57//!
58//! [[fcc_hooks]]         # where the sent copy goes
59//! pattern = "~t @work.example.com"
60//! mailbox = "~/Maildir/.WorkSent"
61//!
62//! [[crypt_hooks]]       # encrypt to this key for this recipient
63//! address = "boss@example.com"
64//! key = "0xDEADBEEF"
65//!
66//! [pgp]
67//! command = "gpg"              # runs via $PATH; passphrases come from
68//! sign_key = "jane@example.com"  # the gpg agent, never from rmut
69//! sign_by_default = false
70//! encrypt_by_default = false
71//! ```
72
73use std::collections::HashMap;
74use std::path::PathBuf;
75
76use anyhow::{Context, Result, ensure};
77use serde::Deserialize;
78
79#[derive(Debug, Clone, Default, Deserialize)]
80#[serde(default)]
81pub struct Config {
82    pub identity: Identity,
83    pub mail: Mail,
84    pub index: Index,
85    pub pager: Pager,
86    pub ui: Ui,
87    pub gui: Gui,
88    pub net: Net,
89    pub sidebar: Sidebar,
90    pub colors: HashMap<String, String>,
91    /// Pattern → color rules for index lines, evaluated in order.
92    pub color_index: Vec<ColorRule>,
93    /// Regex → color rules for pager body spans (mutt's `color body`),
94    /// applied in order; `pattern` here is a plain regex, not a
95    /// message pattern.
96    pub color_body: Vec<ColorRule>,
97    /// MIME type → shell command that renders the part (stdin → stdout),
98    /// e.g. "text/html" = "w3m -dump -T text/html", mutt's auto_view.
99    /// Applied to matching parts wherever they sit in the message,
100    /// preferred in multipart/alternative, and used in the attachment
101    /// viewer. An empty command means mutt's arrangement: the command
102    /// comes from mailcap, from the first `copiousoutput` entry for
103    /// the type; a type with no such entry simply does not autoview.
104    pub filters: HashMap<String, String>,
105    pub keys: Keys,
106    /// Macros: a key that replays a sequence of keys, per menu:
107    /// [macros.index] / [macros.pager], `key = "sequence"`. The
108    /// sequence is literal characters plus `<enter>`/`<esc>`/
109    /// `<ctrl+x>`/... names in angle brackets; it feeds the input
110    /// queue, so it can drive prompts.
111    pub macros: Keys,
112    pub accounts: Vec<Account>,
113    /// Conditional identities, applied in order over `identity` when
114    /// their globs match: the minimal folder-hook / send-hook.
115    pub identities: Vec<IdentityRule>,
116    /// mutt's folder-hook with an arbitrary command: enter-command
117    /// lines run when a matching mailbox is opened.
118    pub folder_hooks: Vec<FolderHook>,
119    /// mutt's message-hook: lines applied while a matching message is
120    /// the selected one, and taken back off when it stops matching.
121    pub message_hooks: Vec<MessageHook>,
122    /// mutt's reply-hook: lines applied while a reply to a matching
123    /// message is built.
124    pub reply_hooks: Vec<MessageHook>,
125    /// mutt's fcc-hook: where a matching outgoing message's copy goes.
126    pub fcc_hooks: Vec<FccHook>,
127    /// mutt's crypt-hook: the PGP key to encrypt to for a recipient.
128    pub crypt_hooks: Vec<CryptHook>,
129    pub pgp: Pgp,
130}
131
132/// One `[[folder_hooks]]` entry: mutt's folder-hook. Like mutt, a
133/// folder-hook is not undone when you leave the mailbox, so a
134/// catch-all entry (`folder = "*"`) is the way to put a setting back.
135#[derive(Debug, Clone, Default, Deserialize)]
136#[serde(default)]
137pub struct FolderHook {
138    /// Glob (`*`) on the opened mailbox: a path or an `imap:` spec.
139    pub folder: String,
140    /// One enter-command line, e.g. `set index_format="%s"`.
141    pub command: String,
142}
143
144/// One `[[message_hooks]]` or `[[reply_hooks]]` entry: a message
145/// pattern and the enter-command line it runs.
146#[derive(Debug, Clone, Default, Deserialize)]
147#[serde(default)]
148pub struct MessageHook {
149    pub pattern: String,
150    pub command: String,
151}
152
153/// One `[[fcc_hooks]]` entry: the mailbox a matching outgoing
154/// message's copy goes to (a local maildir path).
155#[derive(Debug, Clone, Default, Deserialize)]
156#[serde(default)]
157pub struct FccHook {
158    /// Message pattern matched against the draft being sent.
159    pub pattern: String,
160    pub mailbox: String,
161}
162
163/// One `[[crypt_hooks]]` entry: encrypt to `key` for any recipient
164/// address matching `address` (a case-insensitive regex).
165#[derive(Debug, Clone, Default, Deserialize)]
166#[serde(default)]
167pub struct CryptHook {
168    pub address: String,
169    pub key: String,
170}
171
172#[derive(Debug, Clone, Default, Deserialize)]
173#[serde(default)]
174pub struct Identity {
175    pub name: Option<String>,
176    pub email: Option<String>,
177    /// mutt's reverse_name: a reply's From becomes whichever of your
178    /// addresses the original was sent to.
179    pub reverse_name: bool,
180    /// mutt's $reverse_realname: the display name comes over with the
181    /// address reverse_name found. True unless set otherwise, as in
182    /// mutt; false keeps the configured name and takes the address
183    /// alone.
184    pub reverse_realname: Option<bool>,
185}
186
187/// One `[[identities]]` entry. With both globs set, both must match;
188/// with neither, it always applies. Unset name/email keep the value
189/// from the layer below.
190#[derive(Debug, Clone, Default, Deserialize)]
191#[serde(default)]
192pub struct IdentityRule {
193    /// Glob (`*`) on the open mailbox: a path or an `imap:` spec.
194    pub folder: Option<String>,
195    /// Glob (`*`) on any recipient address of the draft.
196    pub recipient: Option<String>,
197    pub name: Option<String>,
198    pub email: Option<String>,
199}
200
201#[derive(Debug, Clone, Default, Deserialize)]
202#[serde(default)]
203pub struct Mail {
204    /// mutt's $folder: where mailboxes live, so `=x` and `+x` name a
205    /// mailbox under it, at a prompt or in a macro. An IMAP account
206    /// spec works too ("imap:work"), making `=Archive` mean
207    /// imap:work/Archive.
208    pub folder: Option<String>,
209    pub mailboxes: Vec<String>,
210    pub sent: Option<String>,
211    pub postponed: Option<String>,
212    pub sendmail: Option<String>,
213    pub editor: Option<String>,
214    /// mutt's $ispell: the spell checker the compose menu's `i` runs
215    /// over the draft, as `ispell -x FILE`. "ispell" when unset.
216    pub ispell: Option<String>,
217    pub poll_seconds: Option<u64>,
218    /// Shell command the printed message is piped to (default lpr).
219    pub print: Option<String>,
220    /// mutt's $pipe_decode: pipe the decoded message (brief headers,
221    /// decoded body) rather than the raw one. Off by default.
222    pub pipe_decode: Option<bool>,
223    /// mutt's $print_decode: print the decoded message. On by
224    /// default, as in mutt.
225    pub print_decode: Option<bool>,
226    /// mutt's $pipe_split / $print_split: run the command once per
227    /// tagged message instead of once over them all. Off by default.
228    pub pipe_split: Option<bool>,
229    pub print_split: Option<bool>,
230    /// mutt's $pipe_sep: what separates concatenated messages in one
231    /// pipe run. Newline by default.
232    pub pipe_sep: Option<String>,
233    /// Default target offered by `s` (save message to a mailbox).
234    pub save: Option<String>,
235    /// "inline" (quoted text, the default) or "attach" (the original
236    /// goes along as a message/rfc822 part, mutt's mime_forward).
237    pub forward: Option<String>,
238    /// mutt's query_command: external address lookup for Tab
239    /// completion at the To prompt (`%s` = the word, or appended),
240    /// e.g. "khard email --parsable %s".
241    pub query_command: Option<String>,
242    /// mutt's $trash: purged messages move here (a maildir path, or
243    /// `imap:account/folder` of the open account) instead of being
244    /// erased; purging inside the trash itself deletes for real.
245    pub trash: Option<String>,
246    /// mutt's edit_headers (default false, like mutt): true puts the
247    /// draft's header block (From/To/Cc/Subject, Attach: lines) into
248    /// the editor buffer. Off, the prompts set To/Subject and
249    /// attachments go through the compose menu's a.
250    pub edit_headers: Option<bool>,
251    /// notmuch(1) search (`X`): false disables the key; unset/true
252    /// leaves it on (notmuch itself must be installed; keep the
253    /// database fresh with `notmuch new` in a hook or cron).
254    pub notmuch: Option<bool>,
255    /// mutt's $fast_reply: replies skip the To and Subject prompts,
256    /// forwards skip Subject (the ask-yes questions still run).
257    pub fast_reply: bool,
258    /// mutt's $quit: "yes" (the default) leaves at once, "no"
259    /// refuses, "ask-yes" and "ask-no" ask first.
260    pub quit: Option<String>,
261    /// mutt's $postpone: leaving a draft. "ask-yes" (the default) and
262    /// "ask-no" ask whether to postpone (else discard); "yes"
263    /// postpones without asking, "no" discards without asking.
264    pub postpone: Option<String>,
265    /// mutt's $recall: composing when postponed drafts exist. "no"
266    /// never offers to recall (always a new message); "yes" recalls
267    /// the newest without asking; "ask-yes" / "ask-no" (the default
268    /// is to ask) offer the new/recall choice.
269    pub recall: Option<String>,
270    /// mutt's $confirmappend: ask before adding messages to a mailbox
271    /// that already exists. Off by default, where mutt asks: rmut has
272    /// never asked, and a save is one keystroke either way.
273    pub confirmappend: bool,
274    /// mutt's $save_name: the default save target is the sender's
275    /// local part under $folder, when such a mailbox exists.
276    pub save_name: bool,
277    /// mutt's $force_name: the same, whether or not it exists.
278    pub force_name: bool,
279    /// mutt's $mark_old: unread mail left behind in the mailbox ages
280    /// to old (O in the index, out of the new count) when you leave.
281    /// True unless set otherwise, as in mutt.
282    pub mark_old: Option<bool>,
283    /// mutt's $delete_untag: marking a tagged message for deletion
284    /// (d, or a save) takes its tag off. True unless set otherwise,
285    /// as in mutt.
286    pub delete_untag: Option<bool>,
287    /// mutt's $flag_safe: a flagged message cannot be marked for
288    /// deletion, by any of the ways of doing so. Off by default.
289    pub flag_safe: bool,
290    /// mutt's $maildir_trash: a purge gives deleted messages the
291    /// maildir T flag instead of unlinking them; they stay in the
292    /// index marked D. Maildir only. Off by default.
293    pub maildir_trash: bool,
294    /// mutt's $mail_check_recent: "new mail in X" only when X has
295    /// grown since the last look. False announces any mailbox holding
296    /// new mail, once, until it empties. True unless set otherwise.
297    pub mail_check_recent: Option<bool>,
298    /// mutt's $sort_alias: the order address completion offers alias
299    /// expansions in: "address" (by the expansion, the default here),
300    /// "alias" (by nick). "unsorted" reads as "alias": the alias file
301    /// is a map. A "reverse-" prefix flips it.
302    pub sort_alias: Option<String>,
303    /// mutt's $shell: what a bare `!` (an empty shell command) runs
304    /// interactively. $SHELL, then sh, when unset.
305    pub shell: Option<String>,
306    /// mutt's $tmpdir: where temporary files go (drafts on their way
307    /// to the editor, parts on their way to a viewer). $TMPDIR, then
308    /// /tmp, when unset.
309    pub tmpdir: Option<String>,
310    /// mutt's $check_new: look for mail delivered to the open maildir
311    /// while it is open. False stops the rescan (IMAP is unaffected,
312    /// as in mutt). True unless set otherwise.
313    pub check_new: Option<bool>,
314    /// mutt's $print: what `p` does. "ask-no" (the default) asks with
315    /// Enter declining, "ask-yes" asks with Enter printing, "yes"
316    /// prints without asking and "no" refuses to print at all.
317    pub print_confirm: Option<String>,
318    /// mutt's $alias_file: where aliases are read from and where
319    /// create-alias appends. $RMUT_ALIASES, then
320    /// ~/.config/rmut/aliases, when unset.
321    pub alias_file: Option<String>,
322    /// mutt's $attribution: the line a quoted reply opens with, over
323    /// the message being replied to (%a address, %n name, %f the From
324    /// header, %s subject, %i message-id, %d date, %{...} strftime).
325    pub attribution: Option<String>,
326    /// mutt's $indent_string: what each quoted line is prefixed with,
327    /// `"> "` by default.
328    pub indent_string: Option<String>,
329    /// mutt's $forward_format: the subject a forward carries, the
330    /// same format string over the message being forwarded.
331    pub forward_format: Option<String>,
332    /// mutt's $wrap_search: `n` wraps around the ends of the index.
333    /// True by default, as in mutt; false stops at the last / first
334    /// match instead.
335    pub wrap_search: Option<bool>,
336    /// mutt's $simple_search: the template a bare-word search expands
337    /// to, `%s` the word. Default `~f %s | ~s %s` (from or subject),
338    /// which is what a bare word already did; set it to add `~b %s`
339    /// for the body, say. Only a single word with no `~` expands.
340    pub simple_search: Option<String>,
341    /// mutt's $reply_regexp: what a reply's subject may already start
342    /// with ("Re:" with an optional [n], by default). Replying takes
343    /// it off and puts "Re: " on, so prefixes never pile up; a
344    /// locale's own prefixes go in as `^(re|aw|sv):[ \t]*`.
345    /// Case-insensitive unless the regex has an uppercase letter, as
346    /// mutt compiles it.
347    pub reply_regexp: Option<String>,
348    /// mutt's $include: quote the original in a reply? "ask-yes" (the
349    /// default) and "ask-no" ask, "yes" and "no" decide it.
350    pub include: Option<String>,
351    /// mutt's $forward_quote: the forwarded text inside the
352    /// "----- Forwarded message" markers is quoted with
353    /// $indent_string, the way a reply is.
354    pub forward_quote: bool,
355    /// mutt's $signature: a file whose contents end every new draft,
356    /// or, when the name ends in `|`, a command whose output does.
357    /// `~` is expanded. Unset (the default) appends nothing.
358    pub signature: Option<String>,
359    /// mutt's $sig_dashes: the signature is introduced by a line
360    /// holding "-- ". True unless set otherwise, as in mutt.
361    pub sig_dashes: Option<bool>,
362    /// mutt's $sig_on_top: the signature goes above the quoted
363    /// original rather than below it. Off by default, as in mutt.
364    pub sig_on_top: Option<bool>,
365    /// mutt's $hostname: the host in a generated Message-ID. The
366    /// system hostname when unset.
367    pub hostname: Option<String>,
368    /// mutt's $user_agent: add a `User-Agent: rmut/VERSION` header to
369    /// outgoing mail. Off by default, as neomutt has it.
370    pub user_agent: Option<bool>,
371    /// mutt's $abort_nosubject: a draft with an empty subject.
372    /// "ask-yes" (the default) asks with Enter aborting, "ask-no"
373    /// asks with Enter sending it on, "yes" aborts without asking,
374    /// "no" never asks.
375    pub abort_nosubject: Option<String>,
376    /// mutt's $abort_unmodified: the first editor pass came back with
377    /// the body untouched, so the draft is dropped. True unless set
378    /// otherwise, as in mutt; only the first edit is checked.
379    pub abort_unmodified: Option<bool>,
380    /// mutt's $askcc / $askbcc: ask for those recipients when a draft
381    /// is started, prefilled with what a group reply worked out.
382    pub ask_cc: bool,
383    pub ask_bcc: bool,
384    /// mutt's $autoedit (needs edit_headers): skip every initial
385    /// prompt and question, straight into the editor; the compose
386    /// menu follows as usual.
387    pub autoedit: bool,
388    /// mutt's $copy: false skips the sent copy (Fcc) entirely; an
389    /// Fcc set in the compose menu still wins.
390    pub copy: Option<bool>,
391    /// mutt's `lists`: address patterns naming mailing lists you know
392    /// of. They drive `~l`, the `L` list-reply target, and the
393    /// Mail-Followup-To rmut sets on mail to a list.
394    pub lists: Vec<String>,
395    /// mutt's `subscribe`: lists you are on. Subscribed lists count as
396    /// known lists too, and a reply to one leaves your own address out
397    /// of Mail-Followup-To, so the list copy is the only one you get.
398    pub subscribed: Vec<String>,
399    /// mutt's `alternates`: regexes matching your other addresses
400    /// (aliases, an old domain, a role address). They join the
401    /// identity addresses everywhere rmut asks "is this me?": `~p`
402    /// and `~P`, the `+`/`T`/`C`/`F` index marks, reverse_name, the
403    /// group-reply dedup, and Mail-Followup-To.
404    pub alternates: Vec<String>,
405    /// mutt's `my_hdr`: header lines added to every draft, e.g.
406    /// "Organization: Acme" or "Bcc: me@example.com". One naming a
407    /// header rmut already wrote replaces it (so `From:` and
408    /// `Reply-To:` win); To/Cc/Bcc gain the address instead.
409    pub my_hdr: Vec<String>,
410    /// mutt's $metoo: keep your own address among a group reply's
411    /// recipients instead of dropping it.
412    pub metoo: bool,
413    /// mutt's $text_flowed: outgoing text/plain is declared
414    /// `format=flowed` and space-stuffed (RFC 3676), so a reader can
415    /// rewrap it. The paragraphs themselves come from your editor,
416    /// which has to leave a trailing space on a line that continues.
417    pub text_flowed: bool,
418    /// Shell command run when new mail arrives (neomutt's
419    /// new_mail_command): `%f` = the mailbox, `%n` = how many, e.g.
420    /// "notify-send 'rmut: %n new in %f'". Fire-and-forget.
421    pub new_mail_command: Option<String>,
422    /// mutt's $delete (a quadoption): what `$` and quitting do with
423    /// messages marked for deletion. "ask" (the default) asks, with
424    /// Enter taking the yes; "yes" purges them without asking; "no"
425    /// never purges, so the marks stay for a later change of mind.
426    pub delete: Option<String>,
427    /// neomutt's $abort_noattach: what to do when the body mentions
428    /// an attachment and none is attached. "no" (the default) never
429    /// checks, "ask" asks before sending, "yes" refuses the send.
430    /// neomutt's ask-yes / ask-no both import as "ask".
431    pub abort_noattach: Option<String>,
432    /// neomutt's $abort_noattach_regex: what counts as mentioning one.
433    /// Case-insensitive; the default is
434    /// `\b(attach|attached|attaching|attachment|attachments)\b`.
435    pub attach_keyword: Option<String>,
436    /// Seconds a sent message waits before it actually goes out, so
437    /// `z` can take it back (rmut's own; mutt sends at once). 0 is
438    /// off. A held message is sent when the timer runs out or when
439    /// rmut exits; batch sends (-s and friends) never hold.
440    pub undo_send: u64,
441}
442
443#[derive(Debug, Clone, Default, Deserialize)]
444#[serde(default)]
445pub struct Index {
446    pub format: Option<String>,
447    /// Initial sort: date/from/subject/size/threads, "reverse-" prefix
448    /// allowed (the `o` menu can still change it at runtime).
449    pub sort: Option<String>,
450    /// "last-date-sent" orders threads by their newest message instead
451    /// of the default oldest-first.
452    pub sort_aux: Option<String>,
453    /// chrono strftime string for the index date column (mutt's
454    /// date_format), e.g. "%d.%m.%Y"; default "%b %e", like mutt's
455    /// index date.
456    pub date_format: Option<String>,
457    /// mutt's $collapse_unread (default true, as in mutt): a thread
458    /// holding unread mail folds like any other. False leaves those
459    /// threads open when everything else folds.
460    pub collapse_unread: Option<bool>,
461    /// mutt's $uncollapse_jump: unfolding a thread puts the cursor on
462    /// its first unread message.
463    pub uncollapse_jump: bool,
464    /// mutt's $hide_thread_subject: a thread reply whose subject
465    /// matches its parent's shows a blank subject (just the tree
466    /// arrow). Off by default here, where mutt has it on, so rmut's
467    /// look is unchanged unless asked.
468    pub hide_thread_subject: Option<bool>,
469    /// mutt's $uncollapse_new: a collapsed thread that receives a new
470    /// message unfolds. True unless set otherwise, as in mutt.
471    pub uncollapse_new: Option<bool>,
472    /// mutt's $strict_threads: thread by In-Reply-To and References
473    /// only. False (the default, as in mutt) also groups a root whose
474    /// subject repeats one already in the mailbox, which is what
475    /// threads mail that arrives without those headers at all.
476    pub strict_threads: Option<bool>,
477    /// mutt's $sort_re: the subject grouping only takes a root whose
478    /// subject carries the $reply_regexp prefix. True by default, as
479    /// in mutt; false groups any equal subject, unrelated "hi" mail
480    /// included.
481    pub sort_re: Option<bool>,
482}
483
484#[derive(Debug, Clone, Default, Deserialize)]
485#[serde(default)]
486pub struct Pager {
487    /// Lines of the message index kept visible above the pager.
488    pub index_lines: u16,
489    /// Lines of overlap when paging (mutt's pager_context).
490    pub context: usize,
491    /// mutt's $search_context: lines of context kept above a pager
492    /// search hit scrolled toward the top. Default 0.
493    pub search_context: usize,
494    /// mutt's $quote_regexp: classifies quoted body lines (depth =
495    /// quote characters in the match). Default `^([ \t]*[|>:}#])+`.
496    pub quote_regexp: Option<String>,
497    /// mutt's ignore list: header-name prefixes hidden from the brief
498    /// view (`*` = all). Unset keeps the classic view (everything
499    /// hidden except Date/From/To/Cc/Subject).
500    pub ignore: Option<Vec<String>>,
501    /// mutt's unignore list: prefixes shown even when ignored.
502    pub unignore: Option<Vec<String>>,
503    /// mutt's hdr_order: name prefixes sorting the brief view;
504    /// unlisted headers follow in message order.
505    pub hdr_order: Option<Vec<String>>,
506    /// mutt's $pager_format for the pager's bottom line; the default
507    /// reproduces the classic "---Message n/m: subject -- NN%".
508    pub format: Option<String>,
509    /// mutt's $wrap: wrap body text at N columns (negative = a right
510    /// margin of |N|); unset wraps at the window width.
511    pub wrap: Option<i64>,
512    /// mutt's $tilde: pad the rows below end-of-message with ~.
513    pub tilde: bool,
514    /// mutt's $pager_stop: paging past the end of a message stays
515    /// put instead of opening the next one.
516    pub pager_stop: bool,
517    /// mutt's $markers (default true, as in mutt): the `+` at the
518    /// start of a wrapped continuation line.
519    pub markers: Option<bool>,
520    /// mutt's $smart_wrap (default true, as in mutt): wrapped lines
521    /// break at a word boundary rather than at the column.
522    pub smart_wrap: Option<bool>,
523    /// mutt's $reflow_text (default true): a `format=flowed` part is
524    /// put back into paragraphs and wrapped at the display width
525    /// instead of keeping the sender's line breaks.
526    pub reflow_text: Option<bool>,
527    /// mutt's alternative_order: MIME types, most wanted first, that
528    /// decide which part of a multipart/alternative shows. `text/*`
529    /// wildcards allowed; consulted before the auto_view filters and
530    /// the built-in text ranking.
531    pub alternative_order: Vec<String>,
532}
533
534/// How long to wait on the network before saying so. A mail client
535/// that blocks has nothing to draw and no keys to read, so these are
536/// short by default: an unreachable server should cost seconds, not
537/// the OS default of about two minutes.
538#[derive(Debug, Clone, Deserialize)]
539#[serde(default)]
540pub struct Net {
541    /// Seconds to wait for a connection (mutt's $connect_timeout).
542    /// 0 waits as long as the OS does.
543    pub connect_timeout: u64,
544    /// Seconds to wait for data on a live connection. Never off:
545    /// IMAP IDLE uses it as its heartbeat, and anything under five
546    /// seconds is treated as five.
547    pub timeout: u64,
548    /// mutt's $ssl_usesystemcerts: trust the OS certificate store on
549    /// top of the built-in Mozilla roots. On by default, as in mutt.
550    pub system_cas: bool,
551    /// mutt's $certificate_file: a PEM file of extra roots to trust
552    /// (a private CA, a self-signed server's own cert). Added to the
553    /// Mozilla roots, never replacing them.
554    pub certificate_file: Option<String>,
555}
556
557impl Default for Net {
558    fn default() -> Self {
559        Net {
560            connect_timeout: 10,
561            timeout: 30,
562            system_cas: true,
563            certificate_file: None,
564        }
565    }
566}
567
568#[derive(Debug, Clone, Deserialize)]
569#[serde(default)]
570pub struct Ui {
571    pub theme: Option<String>,
572    /// mutt's status_format for the bottom line (see
573    /// format::DEFAULT_STATUS_FORMAT for the specifiers).
574    pub status_format: Option<String>,
575    /// Ring the terminal bell on error statuses (mutt's $beep).
576    pub beep: bool,
577    /// mutt's $beep_new: ring it when mail arrives, too. Off by
578    /// default, as in mutt.
579    pub beep_new: bool,
580    /// mutt's $wait_key: a shell escape ends with "Press Enter to
581    /// continue", so whatever it printed can be read before the
582    /// index paints over it. True unless set otherwise, as in mutt.
583    pub wait_key: Option<bool>,
584    /// mutt's $ts_enabled: set the terminal title (and icon) while
585    /// running. Off by default, as in mutt.
586    pub set_title: Option<bool>,
587    /// mutt's $ts_status_format: the title's format, the same
588    /// specifiers as status_format. Defaults to "rmut: %f".
589    pub title_format: Option<String>,
590    /// mutt's $history_file: where prompt history persists across
591    /// sessions. Unset means in-memory only, as rmut was before.
592    pub history_file: Option<String>,
593    /// mutt's $status_on_top: the status bar (and message line) sit at
594    /// the top, under the help bar, rather than the bottom. Off by
595    /// default, as in mutt.
596    pub status_on_top: Option<bool>,
597    /// mutt's $arrow_cursor: mark the selected row with an arrow
598    /// instead of reverse video. Off by default, as in mutt.
599    pub arrow_cursor: Option<bool>,
600    /// mutt's $menu_scroll: the index scrolls a line at a time when
601    /// the cursor leaves the screen; false shows the next page
602    /// instead. On by default here (rmut always scrolled), where mutt
603    /// pages.
604    pub menu_scroll: Option<bool>,
605    /// mutt's $menu_context: lines kept in view beyond the cursor
606    /// when the index scrolls or pages. 0 by default.
607    pub menu_context: usize,
608    /// mutt's $menu_move_off: the last message may scroll up past
609    /// the bottom of the screen; false keeps the index bottom-stuck
610    /// once it fills the screen. True unless set otherwise.
611    pub menu_move_off: Option<bool>,
612    /// mutt's $help: the key-help bar on the top line. True unless
613    /// set otherwise.
614    pub help: Option<bool>,
615    /// mutt's $sort_browser: the folder browser's order: "alpha" (the
616    /// default), "count" / "unread" (by new-mail count), "date" (by
617    /// the maildir's change time), "unsorted" (as configured, then as
618    /// found). A "reverse-" prefix flips it. "size" reads as alpha.
619    pub sort_browser: Option<String>,
620    /// mutt's $error_history: how many past errors error-history
621    /// shows. 0 disables it. 30 by default, as in mutt.
622    pub error_history: usize,
623    /// mutt's $status_chars: the characters `%r` shows for the
624    /// mailbox state — [0] unchanged, [1] changed (needs sync), [2]
625    /// read-only. Unset keeps rmut's own (nothing / `*` / `%`).
626    pub status_chars: Option<String>,
627    /// mutt's $save_history: entries kept per history bucket in the
628    /// file. Defaults to 100 (rmut's in-memory cap).
629    pub save_history: Option<usize>,
630}
631
632impl Default for Ui {
633    fn default() -> Self {
634        Ui {
635            theme: None,
636            status_format: None,
637            beep: true,
638            beep_new: false,
639            wait_key: None,
640            set_title: None,
641            title_format: None,
642            history_file: None,
643            save_history: None,
644            status_on_top: None,
645            arrow_cursor: None,
646            menu_scroll: None,
647            menu_context: 0,
648            menu_move_off: None,
649            help: None,
650            sort_browser: None,
651            error_history: 30,
652            status_chars: None,
653        }
654    }
655}
656
657/// One `[[color_index]]` rule (mutt's `color index FG BG PATTERN`):
658/// index lines whose message matches `pattern` take these colors.
659/// First matching rule wins; rules are checked in config order.
660#[derive(Debug, Clone, Default, Deserialize)]
661#[serde(default)]
662pub struct ColorRule {
663    pub pattern: String,
664    pub fg: Option<String>,
665    pub bg: Option<String>,
666}
667
668/// The window front end (rmut-egui). The terminal front end never
669/// reads these.
670#[derive(Debug, Clone, Default, Deserialize)]
671#[serde(default)]
672pub struct Gui {
673    /// Text size in points (14 when unset). Ctrl+= / Ctrl+- / Ctrl+0
674    /// zoom the whole window at runtime on top of this.
675    pub size: Option<f32>,
676    /// Path to a .ttf/.otf file used as the window's monospace face
677    /// (egui's built-in face when unset).
678    pub font: Option<String>,
679    /// The terminal emulator that hosts $EDITOR and `!` commands
680    /// ($TERMINAL, then foot/alacritty/kitty/xterm, when unset).
681    pub terminal: Option<String>,
682    /// The window canvas: what the text sits on and its default ink
683    /// (named colors or `#rrggbb`; a dark gray on off-white unset).
684    pub background: Option<String>,
685    pub foreground: Option<String>,
686    /// "builtin" opens drafts in the window's own text editor;
687    /// anything else (the default) hosts $EDITOR in the terminal.
688    pub editor: Option<String>,
689    /// The message body in a proportional face; the index, headers
690    /// and indented (preformatted) lines stay monospace.
691    pub proportional: Option<bool>,
692    /// Window-only overrides of `[colors]`, same keys and values
693    /// (plus `#rrggbb`): the window can wear its own palette while
694    /// the terminal keeps the shared one.
695    pub colors: HashMap<String, String>,
696}
697
698/// The optional left pane listing `mail.mailboxes` with new-mail
699/// counts (toggle with B at runtime).
700#[derive(Debug, Clone, Deserialize)]
701#[serde(default)]
702pub struct Sidebar {
703    pub visible: bool,
704    pub width: u16,
705}
706
707impl Default for Sidebar {
708    fn default() -> Self {
709        Sidebar {
710            visible: false,
711            width: 24,
712        }
713    }
714}
715
716#[derive(Debug, Clone, Default, Deserialize)]
717#[serde(default)]
718pub struct Keys {
719    pub index: HashMap<String, String>,
720    pub pager: HashMap<String, String>,
721}
722
723/// One remote account: IMAP for reading, SMTP for sending. The
724/// password comes from `password_command` (preferred) or, when you
725/// accept a secret sitting in the config file, a literal `password`.
726#[derive(Debug, Clone, Deserialize)]
727pub struct Account {
728    pub name: String,
729    pub user: String,
730    /// Shell command whose first stdout line is the password
731    /// (pass(1)-style). Wins over `password` when both are set.
732    pub password_command: Option<String>,
733    /// Plaintext password. Convenient, but anyone who can read the
734    /// config can read your mail, so keep it at mode 600.
735    pub password: Option<String>,
736    pub imap_host: Option<String>,
737    #[serde(default = "default_imap_port")]
738    pub imap_port: u16,
739    /// Encrypt IMAP (default): TLS from the first byte on port 993,
740    /// STARTTLS on any other port. Disabling is for tests only.
741    #[serde(default = "default_true")]
742    pub imap_tls: bool,
743    pub smtp_host: Option<String>,
744    #[serde(default = "default_smtp_port")]
745    pub smtp_port: u16,
746    /// Encrypt SMTP (default): implicit TLS on port 465, STARTTLS
747    /// otherwise. Disabling is for tests only.
748    #[serde(default = "default_true")]
749    pub smtp_tls: bool,
750    /// "password" (default), "xoauth2", or "oauthbearer". The OAuth
751    /// mechanisms authenticate with an access token from
752    /// `token_command` instead of a password.
753    pub auth: Option<String>,
754    /// Shell command whose first stdout line is a *fresh* OAuth access
755    /// token (refresh is its business: oauth2ms, mutt_oauth2.py, ...).
756    /// Run for every connection; tokens expire, so it is never cached.
757    pub token_command: Option<String>,
758    /// IMAP folder that receives the Fcc copy of sent mail.
759    #[serde(default = "default_sent_folder")]
760    pub sent_folder: String,
761    /// From identity when composing from this account's mailboxes,
762    /// e.g. identity = { name = "Jane Work", email = "jane@work.example.com" }.
763    pub identity: Option<Identity>,
764}
765
766/// PGP via gpg(1). Decrypt/verify happens automatically when a viewed
767/// message is PGP; signing and encrypting are chosen at the send
768/// prompt. Passphrases are gpg-agent's business; rmut never sees them.
769#[derive(Debug, Clone, Deserialize)]
770#[serde(default)]
771pub struct Pgp {
772    /// The gpg executable (a name looked up in $PATH or a full path).
773    pub command: String,
774    /// Signing key for --local-user; gpg's default key when unset.
775    pub sign_key: Option<String>,
776    /// Preselect signing / encrypting for new drafts (the compose menu's
777    /// security menu can still change it per message).
778    pub sign_by_default: bool,
779    pub encrypt_by_default: bool,
780    /// mutt's $crypt_replysign: a reply to a signed message defaults
781    /// to signed. $crypt_replyencrypt: a reply to an encrypted one
782    /// defaults to encrypted (on in mutt, off here until asked).
783    /// $crypt_replysignencrypted: a reply to signed-and-encrypted
784    /// mail defaults to signed too. All off by default.
785    pub reply_sign: bool,
786    pub reply_encrypt: bool,
787    pub reply_sign_encrypted: bool,
788}
789
790impl Default for Pgp {
791    fn default() -> Self {
792        Pgp {
793            command: "gpg".into(),
794            sign_key: None,
795            sign_by_default: false,
796            encrypt_by_default: false,
797            reply_sign: false,
798            reply_encrypt: false,
799            reply_sign_encrypted: false,
800        }
801    }
802}
803
804fn default_imap_port() -> u16 {
805    993
806}
807
808fn default_smtp_port() -> u16 {
809    587
810}
811
812fn default_true() -> bool {
813    true
814}
815
816fn default_sent_folder() -> String {
817    "Sent".into()
818}
819
820/// How an account authenticates, from its `auth` key.
821#[derive(Clone, Copy, PartialEq, Eq, Debug)]
822pub enum AuthKind {
823    Password,
824    XOAuth2,
825    OAuthBearer,
826}
827
828impl AuthKind {
829    pub fn sasl_name(self) -> &'static str {
830        match self {
831            AuthKind::Password => "PLAIN",
832            AuthKind::XOAuth2 => "XOAUTH2",
833            AuthKind::OAuthBearer => "OAUTHBEARER",
834        }
835    }
836
837    /// The SASL initial response (before base64): RFC 7628 for
838    /// OAUTHBEARER, the Google shape for XOAUTH2.
839    pub fn initial_response(self, user: &str, token: &str, host: &str, port: u16) -> String {
840        match self {
841            AuthKind::XOAuth2 => format!("user={user}\x01auth=Bearer {token}\x01\x01"),
842            AuthKind::OAuthBearer => {
843                format!("n,a={user},\x01host={host}\x01port={port}\x01auth=Bearer {token}\x01\x01")
844            }
845            AuthKind::Password => String::new(),
846        }
847    }
848}
849
850/// First stdout line of a credential command.
851fn first_line_of(command: &str, what: &str, name: &str) -> Result<String> {
852    let out = std::process::Command::new("sh")
853        .arg("-c")
854        .arg(command)
855        .output()
856        .with_context(|| format!("running {what} for account {name}"))?;
857    ensure!(
858        out.status.success(),
859        "{what} for account {name} exited with {}",
860        out.status
861    );
862    let secret = String::from_utf8_lossy(&out.stdout)
863        .lines()
864        .next()
865        .unwrap_or("")
866        .to_string();
867    ensure!(
868        !secret.is_empty(),
869        "{what} for account {name} printed nothing"
870    );
871    Ok(secret)
872}
873
874impl Account {
875    /// First stdout line of `password_command`, or the stored
876    /// `password` when no command is configured.
877    pub fn password(&self) -> Result<String> {
878        let Some(command) = &self.password_command else {
879            return self
880                .password
881                .clone()
882                .filter(|p| !p.is_empty())
883                .with_context(|| {
884                    format!(
885                        "account {} has neither password_command nor password",
886                        self.name
887                    )
888                });
889        };
890        first_line_of(command, "password command", &self.name)
891    }
892
893    pub fn auth_kind(&self) -> Result<AuthKind> {
894        match self.auth.as_deref() {
895            None | Some("password") => Ok(AuthKind::Password),
896            Some("xoauth2") => Ok(AuthKind::XOAuth2),
897            Some("oauthbearer") => Ok(AuthKind::OAuthBearer),
898            Some(other) => anyhow::bail!("unknown auth {other:?} for account {}", self.name),
899        }
900    }
901
902    /// The credential matching `auth_kind`: the password, or a fresh
903    /// access token from `token_command`.
904    pub fn secret(&self) -> Result<String> {
905        match self.auth_kind()? {
906            AuthKind::Password => self.password(),
907            _ => {
908                let command = self.token_command.as_deref().with_context(|| {
909                    format!(
910                        "account {} has auth = oauth but no token_command",
911                        self.name
912                    )
913                })?;
914                first_line_of(command, "token command", &self.name)
915            }
916        }
917    }
918}
919
920impl Config {
921    pub fn account(&self, name: &str) -> Option<&Account> {
922        self.accounts.iter().find(|a| a.name == name)
923    }
924
925    /// The identity for a draft, layered like mutt hooks: `[identity]`,
926    /// then the account's, then every matching `[[identities]]` rule in
927    /// order (a later rule overrides an earlier one; unset fields keep
928    /// the value below). `rcpts` are the draft's bare recipient
929    /// addresses, empty when they are not known yet, which makes
930    /// recipient rules not match.
931    /// Every known mailing-list pattern (`lists` plus `subscribed`),
932    /// compiled for matching against addresses.
933    pub fn list_matchers(&self) -> Vec<crate::pattern::Matcher> {
934        self.mail
935            .lists
936            .iter()
937            .chain(&self.mail.subscribed)
938            .map(|spec| crate::pattern::Matcher::new(spec))
939            .collect()
940    }
941
942    /// The `subscribed` half on its own, for the Mail-Followup-To rule.
943    pub fn subscribed_matchers(&self) -> Vec<crate::pattern::Matcher> {
944        self.mail
945            .subscribed
946            .iter()
947            .map(|spec| crate::pattern::Matcher::new(spec))
948            .collect()
949    }
950
951    /// mutt's `alternates`, compiled for matching against a bare
952    /// address.
953    pub fn alternate_matchers(&self) -> Vec<crate::pattern::Matcher> {
954        self.mail
955            .alternates
956            .iter()
957            .map(|spec| crate::pattern::Matcher::new(spec))
958            .collect()
959    }
960
961    pub fn identity_for(
962        &self,
963        folder: &str,
964        rcpts: &[String],
965        account: Option<&Account>,
966    ) -> Identity {
967        let mut id = self.identity.clone();
968        let mut overlay = |name: &Option<String>, email: &Option<String>| {
969            if name.is_some() {
970                id.name = name.clone();
971            }
972            if email.is_some() {
973                id.email = email.clone();
974            }
975        };
976        if let Some(acct) = account.and_then(|a| a.identity.as_ref()) {
977            overlay(&acct.name, &acct.email);
978        }
979        for rule in &self.identities {
980            let folder_ok = rule.folder.as_deref().is_none_or(|g| glob_match(g, folder));
981            let recipient_ok = rule
982                .recipient
983                .as_deref()
984                .is_none_or(|g| rcpts.iter().any(|r| glob_match(g, r)));
985            if folder_ok && recipient_ok {
986                overlay(&rule.name, &rule.email);
987            }
988        }
989        id
990    }
991}
992
993/// Glob match: `*` spans anything, everything else is literal;
994/// case-insensitive, anchored at both ends.
995pub fn glob_match(pattern: &str, text: &str) -> bool {
996    let p: Vec<char> = pattern.to_lowercase().chars().collect();
997    let t: Vec<char> = text.to_lowercase().chars().collect();
998    let (mut pi, mut ti) = (0usize, 0usize);
999    let mut star: Option<(usize, usize)> = None;
1000    while ti < t.len() {
1001        if pi < p.len() && p[pi] == '*' {
1002            star = Some((pi, ti));
1003            pi += 1;
1004        } else if pi < p.len() && p[pi] == t[ti] {
1005            pi += 1;
1006            ti += 1;
1007        } else if let Some((sp, st)) = star {
1008            // Backtrack: let the last * swallow one more character.
1009            pi = sp + 1;
1010            ti = st + 1;
1011            star = Some((sp, st + 1));
1012        } else {
1013            return false;
1014        }
1015    }
1016    while pi < p.len() && p[pi] == '*' {
1017        pi += 1;
1018    }
1019    pi == p.len()
1020}
1021
1022/// mutt's `+x` / `=x`: a mailbox named under $folder. `=` or `+`
1023/// alone is $folder itself; anything else, and any name at all when
1024/// no folder is configured, comes back untouched. This runs on every
1025/// mailbox rmut is handed, typed or configured, before anything
1026/// tries to read it as a path or an imap: spec.
1027pub fn expand_folder(spec: &str, folder: Option<&str>) -> String {
1028    let Some(rest) = spec.strip_prefix(['=', '+']) else {
1029        return spec.to_string();
1030    };
1031    let Some(folder) = folder
1032        .map(|f| f.trim_end_matches('/'))
1033        .filter(|f| !f.is_empty())
1034    else {
1035        return spec.to_string();
1036    };
1037    match rest.is_empty() {
1038        true => folder.to_string(),
1039        false => format!("{folder}/{rest}"),
1040    }
1041}
1042
1043impl Config {
1044    /// Expand `=x` / `+x` in every mailbox the config names, so the
1045    /// rest of the program only ever sees real paths and imap: specs.
1046    /// Idempotent: an expanded name no longer starts with = or +.
1047    pub fn expand_folders(&mut self) {
1048        let folder = self.mail.folder.clone();
1049        let folder = folder.as_deref();
1050        let one = |slot: &mut Option<String>| {
1051            if let Some(v) = slot {
1052                *v = expand_folder(v, folder);
1053            }
1054        };
1055        one(&mut self.mail.sent);
1056        one(&mut self.mail.postponed);
1057        one(&mut self.mail.trash);
1058        one(&mut self.mail.save);
1059        for m in &mut self.mail.mailboxes {
1060            *m = expand_folder(m, folder);
1061        }
1062        for hook in &mut self.fcc_hooks {
1063            hook.mailbox = expand_folder(&hook.mailbox, folder);
1064        }
1065    }
1066}
1067
1068pub fn path() -> Option<PathBuf> {
1069    if let Ok(p) = std::env::var("RMUT_CONFIG") {
1070        return Some(PathBuf::from(p));
1071    }
1072    std::env::var("HOME")
1073        .ok()
1074        .map(|h| PathBuf::from(h).join(".config/rmut/config.toml"))
1075}
1076
1077/// Load the config; a missing file is fine (defaults), a broken file
1078/// returns defaults plus a warning to show the user.
1079pub fn load_default() -> (Config, Option<String>) {
1080    let Some(p) = path() else {
1081        return (Config::default(), None);
1082    };
1083    let Ok(text) = std::fs::read_to_string(&p) else {
1084        return (Config::default(), None);
1085    };
1086    match toml::from_str::<Config>(&text) {
1087        Ok(cfg) => {
1088            let warning = secret_exposed(&cfg, &p);
1089            (cfg, warning)
1090        }
1091        Err(err) => {
1092            let first = err
1093                .to_string()
1094                .lines()
1095                .next()
1096                .unwrap_or("parse error")
1097                .to_string();
1098            (
1099                Config::default(),
1100                Some(format!("config ignored ({}): {first}", p.display())),
1101            )
1102        }
1103    }
1104}
1105
1106/// A plaintext `password` in a config anyone can read is the one
1107/// mistake worth interrupting for: the file holds the keys to the
1108/// mail. Says so once at startup, and only when the bits are
1109/// actually open, so a 600 config stays quiet.
1110fn secret_exposed(cfg: &Config, path: &std::path::Path) -> Option<String> {
1111    use std::os::unix::fs::PermissionsExt;
1112    let holds_password = cfg
1113        .accounts
1114        .iter()
1115        .any(|a| a.password.as_ref().is_some_and(|p| !p.is_empty()));
1116    if !holds_password {
1117        return None;
1118    }
1119    let mode = std::fs::metadata(path).ok()?.permissions().mode();
1120    if mode & 0o077 == 0 {
1121        return None;
1122    }
1123    // The imperative first: the message line clips at the window
1124    // edge, and the path is usually the long part.
1125    Some(format!(
1126        "chmod 600 {} (it holds a password and others can read it)",
1127        path.display()
1128    ))
1129}
1130
1131impl Identity {
1132    /// "Name <email>" / "email" for the From header, if configured.
1133    pub fn from_line(&self) -> Option<String> {
1134        match (&self.name, &self.email) {
1135            (Some(n), Some(e)) => Some(format!("{n} <{e}>")),
1136            (None, Some(e)) => Some(e.clone()),
1137            _ => None,
1138        }
1139    }
1140}
1141
1142#[cfg(test)]
1143mod tests {
1144    use super::*;
1145
1146    #[test]
1147    fn a_readable_config_holding_a_password_warns() {
1148        use std::os::unix::fs::PermissionsExt;
1149        let tmp = tempfile::tempdir().unwrap();
1150        let path = tmp.path().join("config.toml");
1151        std::fs::write(&path, "").unwrap();
1152        let with_password: Config = toml::from_str(
1153            r#"
1154            [[accounts]]
1155            name = "work"
1156            user = "jane"
1157            password = "hunter2"
1158            "#,
1159        )
1160        .unwrap();
1161        let with_command: Config = toml::from_str(
1162            r#"
1163            [[accounts]]
1164            name = "work"
1165            user = "jane"
1166            password_command = "gpg -q -d ~/.config/rmut/imap.gpg"
1167            "#,
1168        )
1169        .unwrap();
1170
1171        let mode =
1172            |m: u32| std::fs::set_permissions(&path, std::fs::Permissions::from_mode(m)).unwrap();
1173        mode(0o644);
1174        let warning = secret_exposed(&with_password, &path).expect("a warning");
1175        assert!(warning.starts_with("chmod 600 "), "{warning}");
1176        // Shut when the bits are shut, and when there is no secret to
1177        // expose in the first place.
1178        mode(0o600);
1179        assert!(secret_exposed(&with_password, &path).is_none());
1180        mode(0o644);
1181        assert!(secret_exposed(&with_command, &path).is_none());
1182        assert!(secret_exposed(&Config::default(), &path).is_none());
1183    }
1184
1185    #[test]
1186    fn folder_shorthand_expands_everywhere_a_mailbox_is_named() {
1187        assert_eq!(expand_folder("=archive", Some("~/Mail")), "~/Mail/archive");
1188        assert_eq!(expand_folder("+archive", Some("~/Mail/")), "~/Mail/archive");
1189        // = or + alone is $folder itself.
1190        assert_eq!(expand_folder("=", Some("~/Mail")), "~/Mail");
1191        // An IMAP account works as $folder, so =x is one of its folders.
1192        assert_eq!(
1193            expand_folder("=Archive", Some("imap:work")),
1194            "imap:work/Archive"
1195        );
1196        // Nothing to expand, or nowhere to expand to: untouched.
1197        assert_eq!(expand_folder("~/other", Some("~/Mail")), "~/other");
1198        assert_eq!(expand_folder("=archive", None), "=archive");
1199        assert_eq!(expand_folder("=archive", Some("")), "=archive");
1200
1201        let mut cfg: Config = toml::from_str(
1202            r#"
1203            [mail]
1204            folder = "~/Mail"
1205            mailboxes = ["=inbox", "~/elsewhere"]
1206            sent = "+sent"
1207            trash = "=Trash"
1208            [[fcc_hooks]]
1209            pattern = "~A"
1210            mailbox = "=work"
1211            "#,
1212        )
1213        .unwrap();
1214        cfg.expand_folders();
1215        assert_eq!(cfg.mail.mailboxes, ["~/Mail/inbox", "~/elsewhere"]);
1216        assert_eq!(cfg.mail.sent.as_deref(), Some("~/Mail/sent"));
1217        assert_eq!(cfg.mail.trash.as_deref(), Some("~/Mail/Trash"));
1218        assert_eq!(cfg.fcc_hooks[0].mailbox, "~/Mail/work");
1219        // Idempotent: an expanded name no longer starts with = or +.
1220        cfg.expand_folders();
1221        assert_eq!(cfg.mail.trash.as_deref(), Some("~/Mail/Trash"));
1222    }
1223
1224    #[test]
1225    fn parses_partial_config() {
1226        let cfg: Config = toml::from_str(
1227            r#"
1228            [identity]
1229            name = "Jane"
1230            email = "jane@x"
1231            [mail]
1232            mailboxes = ["~/Maildir"]
1233            sendmail = "/bin/true"
1234            [keys.index]
1235            sync = "w"
1236            "#,
1237        )
1238        .unwrap();
1239        assert_eq!(cfg.identity.from_line().as_deref(), Some("Jane <jane@x>"));
1240        assert_eq!(cfg.mail.mailboxes, vec!["~/Maildir"]);
1241        assert_eq!(cfg.mail.sendmail.as_deref(), Some("/bin/true"));
1242        assert_eq!(cfg.keys.index.get("sync").map(String::as_str), Some("w"));
1243        assert!(cfg.ui.theme.is_none());
1244    }
1245
1246    #[test]
1247    fn empty_and_unknown_keys_are_fine() {
1248        let cfg: Config = toml::from_str("").unwrap();
1249        assert!(cfg.identity.from_line().is_none());
1250        let cfg: Config = toml::from_str("[future]\nx = 1\n").unwrap();
1251        assert!(cfg.mail.mailboxes.is_empty());
1252        assert!(cfg.accounts.is_empty());
1253    }
1254
1255    #[test]
1256    fn parses_accounts_with_defaults() {
1257        let cfg: Config = toml::from_str(
1258            r#"
1259            [[accounts]]
1260            name = "work"
1261            user = "jane@example.com"
1262            password_command = "pass show mail/work"
1263            imap_host = "imap.example.com"
1264            smtp_host = "smtp.example.com"
1265
1266            [[accounts]]
1267            name = "test"
1268            user = "u"
1269            password_command = "true"
1270            imap_host = "localhost"
1271            imap_port = 10143
1272            imap_tls = false
1273            smtp_port = 465
1274            sent_folder = "INBOX/Sent"
1275            "#,
1276        )
1277        .unwrap();
1278        let work = cfg.account("work").unwrap();
1279        assert_eq!(work.imap_port, 993);
1280        assert_eq!(work.smtp_port, 587);
1281        assert!(work.imap_tls && work.smtp_tls);
1282        assert_eq!(work.sent_folder, "Sent");
1283        let test = cfg.account("test").unwrap();
1284        assert_eq!(test.imap_port, 10143);
1285        assert!(!test.imap_tls);
1286        assert!(test.smtp_host.is_none());
1287        assert_eq!(test.sent_folder, "INBOX/Sent");
1288        assert!(cfg.account("nope").is_none());
1289    }
1290
1291    #[test]
1292    fn pgp_section_defaults_and_overrides() {
1293        let cfg: Config = toml::from_str("").unwrap();
1294        assert_eq!(cfg.pgp.command, "gpg");
1295        assert!(cfg.pgp.sign_key.is_none());
1296        assert!(!cfg.pgp.sign_by_default && !cfg.pgp.encrypt_by_default);
1297        let cfg: Config = toml::from_str(
1298            "[pgp]\ncommand = \"gpg2\"\nsign_key = \"jane@x\"\nsign_by_default = true\n",
1299        )
1300        .unwrap();
1301        assert_eq!(cfg.pgp.command, "gpg2");
1302        assert_eq!(cfg.pgp.sign_key.as_deref(), Some("jane@x"));
1303        assert!(cfg.pgp.sign_by_default && !cfg.pgp.encrypt_by_default);
1304    }
1305
1306    #[test]
1307    fn account_missing_required_field_fails_parse() {
1308        assert!(toml::from_str::<Config>("[[accounts]]\nname = \"x\"\n").is_err());
1309    }
1310
1311    fn test_account() -> Account {
1312        Account {
1313            name: "t".into(),
1314            user: "u".into(),
1315            password_command: None,
1316            password: None,
1317            imap_host: None,
1318            imap_port: 993,
1319            imap_tls: true,
1320            smtp_host: None,
1321            smtp_port: 587,
1322            smtp_tls: true,
1323            auth: None,
1324            token_command: None,
1325            sent_folder: "Sent".into(),
1326            identity: None,
1327        }
1328    }
1329
1330    #[test]
1331    fn glob_match_star_and_case() {
1332        assert!(glob_match("*", "anything"));
1333        assert!(glob_match("*work*", "/home/jane/Maildir/work-stuff"));
1334        assert!(glob_match("*@work.example.com", "Jane@Work.Example.Com"));
1335        assert!(glob_match("imap:work/*", "imap:work/INBOX"));
1336        assert!(!glob_match("*@work.example.com", "jane@example.com"));
1337        assert!(!glob_match("work", "workplace")); // anchored
1338        assert!(glob_match("a*b*c", "aXbYc"));
1339        assert!(!glob_match("a*b*c", "aXcYb"));
1340    }
1341
1342    #[test]
1343    fn identity_layers_like_hooks() {
1344        let cfg: Config = toml::from_str(
1345            r#"
1346            [identity]
1347            name = "Jane"
1348            email = "jane@example.com"
1349            reverse_name = true
1350
1351            [[identities]]
1352            folder = "*work*"
1353            email = "jane@work.example.com"
1354
1355            [[identities]]
1356            recipient = "*@club.example.com"
1357            name = "Jenny"
1358
1359            [[accounts]]
1360            name = "acct"
1361            user = "u"
1362            imap_host = "h"
1363            identity = { name = "Jane Acct", email = "acct@example.com" }
1364            "#,
1365        )
1366        .unwrap();
1367        assert!(cfg.identity.reverse_name);
1368        // No match: the global identity as-is.
1369        let id = cfg.identity_for("~/Maildir", &[], None);
1370        assert_eq!(id.from_line().as_deref(), Some("Jane <jane@example.com>"));
1371        // Folder rule overrides the email, keeps the name.
1372        let id = cfg.identity_for("~/Maildir/work", &[], None);
1373        assert_eq!(
1374            id.from_line().as_deref(),
1375            Some("Jane <jane@work.example.com>")
1376        );
1377        // Recipient rule overlays the name; needs a matching recipient.
1378        let rcpts = vec!["bob@club.example.com".to_string()];
1379        let id = cfg.identity_for("~/Maildir", &rcpts, None);
1380        assert_eq!(id.from_line().as_deref(), Some("Jenny <jane@example.com>"));
1381        let id = cfg.identity_for("~/Maildir", &[], None);
1382        assert_eq!(id.name.as_deref(), Some("Jane"));
1383        // The account identity sits between global and the rules.
1384        let account = cfg.account("acct").unwrap();
1385        let id = cfg.identity_for("imap:acct/INBOX", &[], Some(account));
1386        assert_eq!(
1387            id.from_line().as_deref(),
1388            Some("Jane Acct <acct@example.com>")
1389        );
1390        let id = cfg.identity_for("imap:acct/work", &[], Some(account));
1391        assert_eq!(
1392            id.from_line().as_deref(),
1393            Some("Jane Acct <jane@work.example.com>")
1394        );
1395    }
1396
1397    #[test]
1398    fn password_command_takes_first_line() {
1399        let account = |cmd: &str| Account {
1400            password_command: Some(cmd.into()),
1401            ..test_account()
1402        };
1403        assert_eq!(
1404            account("printf 'secret\\nrest\\n'").password().unwrap(),
1405            "secret"
1406        );
1407        assert!(account("false").password().is_err());
1408        assert!(account("true").password().is_err()); // empty output
1409    }
1410
1411    #[test]
1412    fn auth_kinds_and_token_command() {
1413        let acct = test_account();
1414        assert_eq!(acct.auth_kind().unwrap(), AuthKind::Password);
1415        let oauth = Account {
1416            auth: Some("oauthbearer".into()),
1417            token_command: Some("printf 'tok123\\nrest\\n'".into()),
1418            ..test_account()
1419        };
1420        assert_eq!(oauth.auth_kind().unwrap(), AuthKind::OAuthBearer);
1421        assert_eq!(oauth.secret().unwrap(), "tok123");
1422        let no_command = Account {
1423            auth: Some("xoauth2".into()),
1424            ..test_account()
1425        };
1426        assert!(
1427            no_command
1428                .secret()
1429                .unwrap_err()
1430                .to_string()
1431                .contains("no token_command")
1432        );
1433        let bad = Account {
1434            auth: Some("kerberos".into()),
1435            ..test_account()
1436        };
1437        assert!(bad.auth_kind().is_err());
1438        // "password" is an explicit spelling of the default.
1439        let explicit = Account {
1440            auth: Some("password".into()),
1441            password: Some("pw".into()),
1442            ..test_account()
1443        };
1444        assert_eq!(explicit.secret().unwrap(), "pw");
1445    }
1446
1447    #[test]
1448    fn oauth_initial_responses() {
1449        assert_eq!(
1450            AuthKind::XOAuth2.initial_response("jane", "tok", "imap.example.com", 993),
1451            "user=jane\x01auth=Bearer tok\x01\x01"
1452        );
1453        assert_eq!(
1454            AuthKind::OAuthBearer.initial_response("jane", "tok", "imap.example.com", 993),
1455            "n,a=jane,\x01host=imap.example.com\x01port=993\x01auth=Bearer tok\x01\x01"
1456        );
1457    }
1458
1459    #[test]
1460    fn stored_password_and_precedence() {
1461        let stored = Account {
1462            password: Some("hunter2".into()),
1463            ..test_account()
1464        };
1465        assert_eq!(stored.password().unwrap(), "hunter2");
1466        // A configured command wins over the stored password.
1467        let both = Account {
1468            password_command: Some("echo from-command".into()),
1469            password: Some("hunter2".into()),
1470            ..test_account()
1471        };
1472        assert_eq!(both.password().unwrap(), "from-command");
1473        let neither = test_account();
1474        assert!(neither.password().is_err());
1475        let cfg: Config = toml::from_str(
1476            "[[accounts]]\nname = \"x\"\nuser = \"u\"\npassword = \"pw\"\nimap_host = \"h\"\n",
1477        )
1478        .unwrap();
1479        assert_eq!(cfg.account("x").unwrap().password().unwrap(), "pw");
1480    }
1481}