mirror of
https://github.com/openclaw/openclaw.git
synced 2026-08-27 21:07:01 -06:00
77746299ea
* refactor(imap): consume the core identifier-authentication scale Use the SDK type and canonical strength comparator instead of the private SenderStrength vocabulary and index ordering. Bind config values to the SDK union with a compile-time exhaustiveness check, preserving all config keys. Classify unproven From ownership, including no-evidence and DMARC temperror results, as unverified. Only an explicit unverified minimum gains admission; the default verified floor and asserted minimum keep their behavior. Keep existing token admission and thrown-authenticator retries unchanged. Document the remaining mutable token/early-rejection paths and expose only the canonical comparator through the SDK, with packaged-consumer coverage. The IMAP introduction has no stable release contract. * docs(security): record landed sender-auth mitigations in the threat atlas Record the graded exact-pair identifier-authentication gate and inert mutable allowFrom audit findings. Mark R-008 implemented in core while retaining per-channel verified adoption and downstream mappers as remaining work. Keep the existing atlas structure and Medium residual risk.