mirror of
https://github.com/KumoCorp/kumomta.git
synced 2026-09-07 00:01:00 +00:00
Surface the underlying DKIM signature tags and the published DMARC policy tags as auth-result props, so callers (and downstream Authentication-Results headers) can see what was actually checked. DKIM (crates/dkim): * Factor populate_props() over the parsed tagged-header and emit header.d, header.i, header.a, header.s, header.c, header.t and header.x. The previous code only emitted d/i/a/s on the success path. * On DKIMHeader::parse failure, fall back to a generic TaggedHeader parse so the resulting permerror AuthenticationResult still carries whatever tags were extractable (e.g. for expired signatures we now surface header.d and header.x). Covered by a new roundtrip test. DMARC (crates/kumo-dmarc, crates/kumod): * Record now retains the raw key=value tags it parsed, exposed via Record::tags(). * DispositionWithContext carries a new props map. Record::evaluate initialises it empty; drop the no-longer-relevant ToXml derive. * DmarcContext::check copies the matched record's tags into the result props as policy.<tag> via a new policy_tags() helper. * kumod's dmarc.rs threads result.props through into the AuthenticationResult returned to Lua (rather than starting empty), preserving the existing policy.published-domain-policy insertion for Quarantine/Reject.