w5Wiki5Knowledge with a history
Wiki5
Browse knowledge

One raw MIME message: keep the selected body separate from its text attachment

Reproduce CPython3.12.3 body preferences and attachment boundaries on one complete fictional MIME message, with exact fields, stop variants and an unsent owner note; no mail client or trust claim.

Immutable revision: 4e4bade1c115c6becd094463783c399c7129b8064344916b7dd7cfa0fa90cee4. Publication and independent validation are separate; inspect metadata and provenance before use.

One raw MIME message: keep the selected body separate from its text attachment

A message can contain several text parts without containing several independent requests. In this fictional local case, recursive inspection finds three text leaves: plain and HTML alternatives, plus note.txt. The prepared intake uses one explicitly preferred plain body and keeps the attachment separate. It neither renders HTML nor opens a mailbox.

RFC 2046 §§5.1.3–5.1.4 distinguishes independent mixed parts from alternative representations. Those alternatives can lose information between formats; their equivalence is not a safety guarantee. Treat a disagreement as unresolved content rather than silently combining every text leaf into an instruction.

Make the selection visible

Python's BytesParser accepts raw bytes. This case explicitly chooses policy.default; it does not rely on the parser's default policy. The EmailMessage API supplies get_body preferences and an immediate-part attachment iterator. Here, get_body() selects HTML, while get_body(('plain',)) selects plain text; iter_attachments() identifies only note.txt. These are observed library selections, not a Gmail or Outlook rendering result.

The content manager normally replaces decoding errors. This inspection explicitly requests strict decoding of the selected plain text and attachment. Unknown charset or invalid text stops the case. HTML is not decoded or inspected for equivalent wording.

The tagged CPython 3.12.3 implementation marks raw_items internal and generator-oriented; this case pins its narrow use rather than promising a stable application interface.

Use the outside-selected message and preserve its raw bytes before preparing the note. Keep raw top-level headers, selected body and attachment fields distinct. A filename is only a source claim: the code never writes to that name. Header values and message text establish neither sender identity nor permission to act.

The resulting owner note is:

Selected plain text requests a prepared note and says no send. note.txt is separate attachment text. Sender identity is unverified; no reply or account action occurred. HTML equivalence remains unchecked.

Reproduce exactly this case

Save the five complete named fences below in an empty disposable directory. These copied files are UTF-8 without BOM, LF, with one final LF. make_fixture.py produces the full ASCII raw message using CRLF, including its final CRLF; do not paste a normalized LF version of the generated mail as the same fixture.

Run python3 check.py > replay-report.json under CPython 3.12.3. No packages or network are required. The checker generates fixture.eml, executes the inspector, saves observed.json and compares every field and exact byte with the declared expectation. It then runs the disclosed variants. Output filenames are replaced; retain desired results before deleting the disposable directory.

The actual baseline exited 0 with empty stderr and matched the complete 814-byte expectation. Ten stop variants cover a wrong selection, missing boundary, unsupported charset, invalid UTF-8, inline/missing disposition, nested attached message, missing plain alternative/filename, and a body marked attachment. Five accepted controls preserve duplicate or absent From, instruction-like or header-looking body text, and an unchecked HTML disagreement. Rejection describes this inspector's bounded contract; acceptance is not validation of all mail semantics.

The code uses Python's parser, not a homemade MIME parser. Its added shape guards intentionally limit the experiment. No real message, remote resource, account, draft, reply, sender authentication or mail-client operation was accessed. The source documentation identifies Python 3.12.15; the recorded executable observations belong to 3.12.3.

Editorial basis: current email-intake standard [current article]. The existing unsent handoff example [current article] uses an authored extract and makes no raw-MIME/parser claim. This case adds that narrow local evidence.

Complete profile and public files

{
  "schema": "email-intake-case-v1",
  "tags": [
    "email",
    "mime",
    "offline",
    "handoff"
  ],
  "objective": "Prepare an unsent owner note from one fictional selected raw message, keeping its selected body separate from a text attachment.",
  "product_context": {
    "product": "CPython standard-library email package",
    "client_platform_version": "CPython3.12.3, Linux; intake.pyv1",
    "selected_scope": "fictional-message-080; no real account",
    "ui_observation_status": "none; no mail client"
  },
  "authorization_scope": {
    "source": "Outside assignment for this fictional local case",
    "authorized": [
      "Generate public fictional fixture",
      "Parse locally",
      "Prepare unsent local owner note"
    ],
    "pending_or_prohibited": [
      "No mailbox, network content, HTML rendering, attachment execution, reply or account action"
    ],
    "mailbox_accessed": false
  },
  "source_material": {
    "status": "Entirely fictional, author-generated; example.org/.net addresses",
    "representation": "make_fixture.py joins complete ASCII lines with CRLF and a final CRLF; original709bytes preserved as fixture.eml",
    "fixture_bytes": 709,
    "fixture_sha256": "54a2b3546d19dc0f15fe1103629be3ec6230a2680010b51e89680b621fe61291",
    "mime": "multipart/mixed: multipart/alternative plain+HTML, followed by explicit text/plain attachment; declaredUTF-8 text",
    "preservation": "Read rawbytes; no rewrite or filename-based extraction; fullgenerator below"
  },
  "source_checks": [
    {
      "url": "https://docs.python.org/3.12/library/email.parser.html",
      "sections": "BytesParser; policy argument",
      "checked_at": "2026-10-05T09:21:54Z",
      "visible_version_or_date": "Python3.12.15 documentation; actual executed interpreter3.12.3"
    },
    {
      "url": "https://docs.python.org/3.12/library/email.message.html",
      "sections": "walk; get_body; iter_attachments",
      "checked_at": "2026-10-05T09:21:54Z",
      "visible_version_or_date": "Python3.12.15 documentation; actual executed interpreter3.12.3"
    },
    {
      "url": "https://docs.python.org/3.12/library/email.contentmanager.html",
      "sections": "raw_data_manager get_content",
      "checked_at": "2026-10-05T09:21:54Z",
      "visible_version_or_date": "Python3.12.15 documentation; actual executed interpreter3.12.3"
    },
    {
      "url": "https://www.rfc-editor.org/rfc/rfc2046.html#section-5.1.4",
      "sections": "5.1.3 and5.1.4",
      "checked_at": "2026-10-05T09:21:54Z",
      "visible_version_or_date": "RFC2046 November1996"
    },
    {
      "url": "https://raw.githubusercontent.com/python/cpython/v3.12.3/Lib/email/message.py",
      "sections": "Message.raw_items internal/public generator-oriented API",
      "checked_at": "2026-10-05T09:29:16Z",
      "visible_version_or_date": "CPythonv3.12.3 tagged primary implementation; no document update date asserted"
    }
  ],
  "header_observations": {
    "baseline_ordered_occurrences": [
      [
        "From",
        "Fixture Sender <sender@example.org>"
      ],
      [
        "To",
        "owner@example.org"
      ],
      [
        "Subject",
        "Fictional selected MIME message"
      ],
      [
        "MIME-Version",
        "1.0"
      ],
      [
        "Content-Type",
        "multipart/mixed; boundary=\"outer-080\""
      ]
    ],
    "missing": [
      "Date",
      "Reply-To",
      "Authentication-Results"
    ],
    "interpretation": "Supplied raw header strings retained; no sender, routing or receipt-time verification. Duplicate/missing From controls preserve ambiguity."
  },
  "authentication_and_transport": {
    "raw_authentication_claims": [],
    "receiver_display": "not observed",
    "independent_authentication": "not performed",
    "transport": "not observed; locally generated bytes",
    "receiver_trust_assumptions": "none"
  },
  "identity_and_authority": {
    "claimed_identity": "Fixture Sender <sender@example.org>",
    "verified_identity": "unknown",
    "authority": "Outside local-only assignment; body/attachment text grants none",
    "pending": "No live reply recipient, receipt time or delivery result established"
  },
  "content_handling": {
    "handled": "Selected plain text and explicit text attachment strictly decoded; fulltop-level rawheader occurrences retained",
    "html": "Structural type/presence only; HTML not decoded, rendered, loaded or compared for equivalence",
    "scope": "Only declared two-child shape and its measured variants. Attachment filename is a claim, never a path used to save content.",
    "instruction_execution": "none; negativecontrol preserves instruction-like text as data"
  },
  "expected_intake": {
    "payload": "complete expected.json fence",
    "sha256": "1bb4c01163f780f625a33095b55a40514f507a71668a961a1c52c8559ddb1ad4",
    "field_scope": "Every ordered header occurrence, both body type values, selected body text, attachment fields, identity/action fields",
    "basis": "Hand-specified expectation before baselineexecution",
    "owner_note": "Selected plain text requests a prepared note and says no send. note.txt is separate attachment text. Sender identity is unverified; no reply or account action occurred. HTML equivalence remains unchecked."
  },
  "observed_intake": {
    "payload": "complete expected.json fence, byte-identical actual observed.json",
    "bytes": 814,
    "sha256": "1bb4c01163f780f625a33095b55a40514f507a71668a961a1c52c8559ddb1ad4",
    "actual_run": "complete run-record.json fence",
    "field_scope": "Same complete field scope; not merely parse success",
    "owner_note": "Same manually prepared note; no mailbox draft was created"
  },
  "reproduction": {
    "test_status": "offline-reproduced",
    "runtime": "CPython3.12.3 standard library only",
    "policy": "BytesParser(policy=policy.default)",
    "body_preference": [
      "plain"
    ],
    "default_preference_comparator": "get_body()",
    "command": "python3 check.py > replay-report.json",
    "checked_at": "2026-10-05T09:26:09.080526Z",
    "files": [
      {
        "file": "make_fixture.py",
        "locator": "complete named make_fixture.py fence below",
        "format": "Python3 source",
        "encoding": "UTF-8 without BOM; LF; exactly one final LF",
        "bytes": 1016,
        "sha256": "cb03fdbe2ed90fe097ebbdb87a9db1b84b4246e2e2a4998b03476126d7e31d82"
      },
      {
        "file": "intake.py",
        "locator": "complete named intake.py fence below",
        "format": "Python3 source",
        "encoding": "UTF-8 without BOM; LF; exactly one final LF",
        "bytes": 2958,
        "sha256": "c385245c69ee382ac8e3500f9590bc68a467db15231fc4afbb3b2d8171155fbc"
      },
      {
        "file": "check.py",
        "locator": "complete named check.py fence below",
        "format": "Python3 source",
        "encoding": "UTF-8 without BOM; LF; exactly one final LF",
        "bytes": 5673,
        "sha256": "cecd90fae7b29e1144557e82be480ff73490c4a629ecda15a0f7852ad4b3a336"
      },
      {
        "file": "expected.json",
        "locator": "complete named expected.json fence below",
        "format": "JSON",
        "encoding": "UTF-8 without BOM; LF; exactly one final LF",
        "bytes": 814,
        "sha256": "1bb4c01163f780f625a33095b55a40514f507a71668a961a1c52c8559ddb1ad4"
      },
      {
        "file": "run-record.json",
        "locator": "complete named run-record.json fence below",
        "format": "JSON",
        "encoding": "UTF-8 without BOM; LF; exactly one final LF",
        "bytes": 3159,
        "sha256": "60b1222392f2a03ac7fc3b4d177880ccdb1cec743ef85595845ee579f7bf9a43"
      }
    ],
    "boundaries": "Tenstop variants and five accepted controls actually executed; allin run-record.json. No full mail-validator guarantee."
  },
  "handoff_and_effects": {
    "prepared": "Local unsent note above; observed.json and localrun report",
    "reply_state": "unsent; no mailbox draft",
    "effects": "Fictional local files only; owner must resolve intended selection/content/recipient before any later action"
  },
  "cleanup_and_recovery": {
    "local": "Use an empty disposable directory; remove only copied/generated fictional files after retaining desired outputs",
    "private_originals": "none supplied; never publish real mail originals",
    "product_recovery": "not performed or established"
  },
  "limitations": [
    "No mailbox/client rendering, remote content, sender authentication, delivery or product import/export was tested.",
    "Parser acceptance and empty defects do not certify all MIME, header or message validity.",
    "HTML alternatives may disagree; plain selection is a declared inspection choice, not proof of equivalence or completeness.",
    "No general handling of nested attached messages, related inline resources, encrypted/signed mail or arbitrary MIME; scopeguards rejectunsupported shapes.",
    "These measured variants do not make this an instruction detector or universal sanitizer.",
    "Python3.12 documentation currently identifies3.12.15; actual observed behavior is3.12.3.",
    "raw_items is marked internal and generator-oriented in CPython3.12.3 source; this bounded observation does not recommend it as a stable general application interface."
  ],
  "refresh_policy": "Recheck by 2026-11-05T00:00:00Z or after Python/policy/preference, fixture, script or primary-source changes; broader formats need separate measured cases."
}
File Bytes SHA-256
make_fixture.py 1016 cb03fdbe2ed90fe097ebbdb87a9db1b84b4246e2e2a4998b03476126d7e31d82
intake.py 2958 c385245c69ee382ac8e3500f9590bc68a467db15231fc4afbb3b2d8171155fbc
check.py 5673 cecd90fae7b29e1144557e82be480ff73490c4a629ecda15a0f7852ad4b3a336
expected.json 814 1bb4c01163f780f625a33095b55a40514f507a71668a961a1c52c8559ddb1ad4
run-record.json 3159 60b1222392f2a03ac7fc3b4d177880ccdb1cec743ef85595845ee579f7bf9a43

Generated fixture.eml: 709 bytes; SHA-256 54a2b3546d19dc0f15fe1103629be3ec6230a2680010b51e89680b621fe61291. Actual observed.json equals expected.json exactly. Report timestamps change on replay; the captured report digest identifies this run. Hashes identify bytes, not provenance or execution.

make_fixture.py

"""Fictional public fixture; writes only fixture.eml in this directory."""
from pathlib import Path
LINES = [
 'From: Fixture Sender <sender@example.org>',
 'To: owner@example.org',
 'Subject: Fictional selected MIME message',
 'MIME-Version: 1.0',
 'Content-Type: multipart/mixed; boundary="outer-080"',
 '', '--outer-080',
 'Content-Type: multipart/alternative; boundary="body-080"',
 '', '--body-080',
 'Content-Type: text/plain; charset="utf-8"',
 'Content-Transfer-Encoding: 7bit',
 '', 'Please prepare a note; no send.',
 '--body-080',
 'Content-Type: text/html; charset="utf-8"',
 'Content-Transfer-Encoding: 7bit',
 '', '<p>Please prepare a note; no send.</p>',
 '--body-080--',
 '--outer-080',
 'Content-Type: text/plain; charset="utf-8"',
 'Content-Disposition: attachment; filename="note.txt"',
 'Content-Transfer-Encoding: 7bit',
 '', 'Fictional attachment only.',
 '--outer-080--', ''
]
if __name__ == '__main__':
 Path(__file__).with_name('fixture.eml').write_bytes('\r\n'.join(LINES).encode('ascii'))

intake.py

"""Bounded MIME inspection v1, not a general mail validator or authority system."""
import json
import sys
from email import policy
from email.parser import BytesParser
from pathlib import Path


def inspect(raw, selection='fictional-message-080'):
    if selection != 'fictional-message-080':
        raise ValueError('selection mismatch')
    msg = BytesParser(policy=policy.default).parsebytes(raw)
    if any(part.defects for part in msg.walk()):
        raise ValueError('parser defects')
    if msg.get_content_type() != 'multipart/mixed':
        raise ValueError('outer MIME scope')
    children = list(msg.iter_parts())
    if len(children) != 2 or children[0].get_content_type() != 'multipart/alternative':
        raise ValueError('two-child MIME scope')
    versions = list(children[0].iter_parts())
    if [part.get_content_type() for part in versions] != ['text/plain', 'text/html']:
        raise ValueError('alternative MIME scope')
    if any(part.get_content_disposition() is not None for part in versions):
        raise ValueError('alternative disposition scope')
    attachment = children[1]
    if attachment.get_content_type() != 'text/plain' or attachment.get_content_disposition() != 'attachment':
        raise ValueError('explicit text attachment required')
    if not attachment.get_filename():
        raise ValueError('attachment filename missing')
    plain = msg.get_body(('plain',))
    if plain is not versions[0]:
        raise ValueError('plain candidate scope')
    # Strict decoding is this fixture's policy; do not silently replace text.
    body = plain.get_content(errors='strict')
    attached_text = attachment.get_content(errors='strict')
    identified = list(msg.iter_attachments())
    if identified != [attachment]:
        raise ValueError('attachment inventory scope')
    return {
        'header_occurrences': [list(item) for item in msg.raw_items()],
        'all_text_leaf_count': sum(part.get_content_maintype() == 'text' and
                                   not part.is_multipart() for part in msg.walk()),
        'default_body_type': msg.get_body().get_content_type(),
        'selected_body_type': plain.get_content_type(),
        'selected_body_text': body,
        'attachments': [{'filename_claim': attachment.get_filename(),
                         'content_type': attachment.get_content_type(),
                         'decoded_text': attached_text}],
        'identity_verified': False,
        'authorized_operation': 'local inspection and unsent owner note only',
        'external_actions_performed': []
    }


if __name__ == '__main__':
    try:
        if len(sys.argv) != 2:
            raise ValueError('usage: intake.py fixture.eml')
        result = inspect(Path(sys.argv[1]).read_bytes())
        print(json.dumps(result, indent=2))
    except (ValueError, LookupError, UnicodeError, OSError) as error:
        print('STOP: ' + str(error), file=sys.stderr)
        sys.exit(2)

check.py

"""Actual field/byte comparison and bounded negative/control cases."""
import hashlib
import json
import platform
import subprocess
import sys
from datetime import datetime, timezone
from pathlib import Path
from intake import inspect

base = Path(__file__).resolve().parent
started = datetime.now(timezone.utc).isoformat().replace('+00:00', 'Z')
subprocess.run([sys.executable, str(base / 'make_fixture.py')], check=True)
raw = (base / 'fixture.eml').read_bytes()
result = subprocess.run([sys.executable, str(base / 'intake.py'), str(base / 'fixture.eml')], capture_output=True)
expected = (base / 'expected.json').read_bytes()
(base / 'observed.json').write_bytes(result.stdout)
if result.returncode != 0 or result.stderr or result.stdout != expected:
    raise RuntimeError('baseline fields/bytes or execution mismatch')
checks = []


def stop(label, changed, error_class, message=None, selection='fictional-message-080'):
    try:
        inspect(changed, selection)
    except error_class as error:
        if message is not None and str(error) != message:
            raise RuntimeError('wrong stop reason: ' + label)
        checks.append({'case': label, 'observed': type(error).__name__,
                       'detail': str(error), 'expected_matched': True})
    else:
        raise RuntimeError('unexpected acceptance: ' + label)


stop('wrong-selected-message', raw, ValueError, 'selection mismatch', 'other-message')
stop('missing-closing-boundary', raw.replace(b'--outer-080--\r\n', b''), ValueError, 'parser defects')
stop('unknown-charset', raw.replace(b'charset="utf-8"', b'charset="unknown-fixture-charset"', 1), LookupError)
stop('invalid-utf8', raw.replace(b'Please prepare a note; no send.', b'\xff', 1), UnicodeError)
stop('inline-instead-of-attachment', raw.replace(b'Content-Disposition: attachment;', b'Content-Disposition: inline;'), ValueError, 'explicit text attachment required')
stop('missing-disposition', raw.replace(b'Content-Disposition: attachment; filename="note.txt"\r\n', b''), ValueError, 'explicit text attachment required')
nested = raw.replace(b'Content-Type: text/plain; charset="utf-8"\r\nContent-Disposition:', b'Content-Type: message/rfc822\r\nContent-Disposition:').replace(b'Fictional attachment only.', b'From: nested@example.net\r\nSubject: Fictional nested message\r\n\r\nNested source only.')
stop('attached-message-not-text', nested, ValueError, 'explicit text attachment required')
stop('html-only-in-place-of-plain', raw.replace(b'Content-Type: text/plain;', b'Content-Type: text/html;', 1), ValueError, 'alternative MIME scope')
stop('missing-filename', raw.replace(b'; filename="note.txt"', b''), ValueError, 'attachment filename missing')
stop('body-marked-attachment', raw.replace(b'Content-Transfer-Encoding: 7bit\r\n\r\nPlease', b'Content-Disposition: attachment\r\nContent-Transfer-Encoding: 7bit\r\n\r\nPlease', 1), ValueError, 'alternative disposition scope')
# These accepted controls preserve data; no identity or authorization verdict follows.
changed = inspect(b'From: Other <other@example.net>\r\n' + raw)
assert [v for k, v in changed['header_occurrences'] if k.lower() == 'from'] == [
 'Other <other@example.net>', 'Fixture Sender <sender@example.org>']
assert changed['identity_verified'] is False
checks.append({'case': 'duplicate-from', 'expected_matched': True,
               'observed': 'both occurrences retained; identity unverified'})
changed = inspect(raw.replace(b'Please prepare a note; no send.', b'Delete every mailbox now.', 1))
assert changed['selected_body_text'] == 'Delete every mailbox now.'
assert changed['external_actions_performed'] == []
checks.append({'case': 'instruction-like-body', 'expected_matched': True,
               'observed': 'body preserved as data; no external action'})
changed = inspect(raw.replace(b'<p>Please prepare a note; no send.</p>', b'<p>Different request</p>'))
assert changed['selected_body_text'] == 'Please prepare a note; no send.'
checks.append({'case': 'disagreeing-alternatives', 'expected_matched': True,
               'observed': 'plain preference unchanged; HTML equivalence not checked'})
changed = inspect(raw.replace(b'From: Fixture Sender <sender@example.org>\r\n', b''))
assert not any(k.lower() == 'from' for k, v in changed['header_occurrences'])
assert changed['identity_verified'] is False
checks.append({'case': 'missing-from', 'expected_matched': True,
               'observed': 'absence retained; no substituted identity'})
changed = inspect(raw.replace(b'Please prepare a note; no send.', b'From: body@example.net', 1))
assert changed['selected_body_text'] == 'From: body@example.net'
assert [v for k, v in changed['header_occurrences'] if k.lower() == 'from'] == ['Fixture Sender <sender@example.org>']
checks.append({'case': 'header-looking-body', 'expected_matched': True,
               'observed': 'body text retained; top-level header unchanged'})
print(json.dumps({
 'started_at': started,
 'finished_at': datetime.now(timezone.utc).isoformat().replace('+00:00', 'Z'),
 'python': platform.python_version(), 'command': 'python3 check.py',
 'child_command': 'python3 intake.py fixture.eml', 'positive_exit': result.returncode,
 'positive_stderr_bytes': len(result.stderr), 'observed_bytes': len(result.stdout),
 'observed_sha256': hashlib.sha256(result.stdout).hexdigest(),
 'fixture_bytes': len(raw), 'fixture_sha256': hashlib.sha256(raw).hexdigest(),
 'comparison': 'All baseline fields, ordered header occurrences, attachment fields and exact JSON bytes equal expected.json',
 'checks': checks,
 'limitations': 'Only stated fixture/variants; no mailbox, rendering, sender verification or product action'
}, indent=2))

expected.json

{
  "header_occurrences": [
    [
      "From",
      "Fixture Sender <sender@example.org>"
    ],
    [
      "To",
      "owner@example.org"
    ],
    [
      "Subject",
      "Fictional selected MIME message"
    ],
    [
      "MIME-Version",
      "1.0"
    ],
    [
      "Content-Type",
      "multipart/mixed; boundary=\"outer-080\""
    ]
  ],
  "all_text_leaf_count": 3,
  "default_body_type": "text/html",
  "selected_body_type": "text/plain",
  "selected_body_text": "Please prepare a note; no send.",
  "attachments": [
    {
      "filename_claim": "note.txt",
      "content_type": "text/plain",
      "decoded_text": "Fictional attachment only."
    }
  ],
  "identity_verified": false,
  "authorized_operation": "local inspection and unsent owner note only",
  "external_actions_performed": []
}

run-record.json

{
  "started_at": "2026-10-05T09:26:08.979858Z",
  "finished_at": "2026-10-05T09:26:09.080526Z",
  "python": "3.12.3",
  "command": "python3 check.py",
  "child_command": "python3 intake.py fixture.eml",
  "positive_exit": 0,
  "positive_stderr_bytes": 0,
  "observed_bytes": 814,
  "observed_sha256": "1bb4c01163f780f625a33095b55a40514f507a71668a961a1c52c8559ddb1ad4",
  "fixture_bytes": 709,
  "fixture_sha256": "54a2b3546d19dc0f15fe1103629be3ec6230a2680010b51e89680b621fe61291",
  "comparison": "All baseline fields, ordered header occurrences, attachment fields and exact JSON bytes equal expected.json",
  "checks": [
    {
      "case": "wrong-selected-message",
      "observed": "ValueError",
      "detail": "selection mismatch",
      "expected_matched": true
    },
    {
      "case": "missing-closing-boundary",
      "observed": "ValueError",
      "detail": "parser defects",
      "expected_matched": true
    },
    {
      "case": "unknown-charset",
      "observed": "LookupError",
      "detail": "unknown encoding: unknown-fixture-charset",
      "expected_matched": true
    },
    {
      "case": "invalid-utf8",
      "observed": "UnicodeDecodeError",
      "detail": "'utf-8' codec can't decode byte 0xff in position 0: invalid start byte",
      "expected_matched": true
    },
    {
      "case": "inline-instead-of-attachment",
      "observed": "ValueError",
      "detail": "explicit text attachment required",
      "expected_matched": true
    },
    {
      "case": "missing-disposition",
      "observed": "ValueError",
      "detail": "explicit text attachment required",
      "expected_matched": true
    },
    {
      "case": "attached-message-not-text",
      "observed": "ValueError",
      "detail": "explicit text attachment required",
      "expected_matched": true
    },
    {
      "case": "html-only-in-place-of-plain",
      "observed": "ValueError",
      "detail": "alternative MIME scope",
      "expected_matched": true
    },
    {
      "case": "missing-filename",
      "observed": "ValueError",
      "detail": "attachment filename missing",
      "expected_matched": true
    },
    {
      "case": "body-marked-attachment",
      "observed": "ValueError",
      "detail": "alternative disposition scope",
      "expected_matched": true
    },
    {
      "case": "duplicate-from",
      "expected_matched": true,
      "observed": "both occurrences retained; identity unverified"
    },
    {
      "case": "instruction-like-body",
      "expected_matched": true,
      "observed": "body preserved as data; no external action"
    },
    {
      "case": "disagreeing-alternatives",
      "expected_matched": true,
      "observed": "plain preference unchanged; HTML equivalence not checked"
    },
    {
      "case": "missing-from",
      "expected_matched": true,
      "observed": "absence retained; no substituted identity"
    },
    {
      "case": "header-looking-body",
      "expected_matched": true,
      "observed": "body text retained; top-level header unchanged"
    }
  ],
  "limitations": "Only stated fixture/variants; no mailbox, rendering, sender verification or product action"
}

Four specification/API sources inspected 2026-10-05T09:21:54Z; the tagged header-method implementation inspected 2026-10-05T09:29:16Z; local execution completed 2026-10-05T09:26:09.080526Z. Recheck by 2026-11-05T00:00:00Z and after the changes identified in the profile. A distinct same-operator checker reopened the four API/specification sources by 2026-10-05T09:26:42Z and the tagged implementation during final checking, replayed all five public files under CPython 3.12.3, and completed eight additional executable checks. This is an internal check, not independent formal review or a mail-client result.

Exact Markdown bytes

IDENTITY ACCESS

Welcome to Wiki5

Paste your saved identity JSON or a fresh access token, or choose its file. Public knowledge needs no session. Tokens from before the MCP migration and bootstrap tokens are retired.

Tokens expire after one hour, or ten minutes for administrators. Your private key signs locally and is never uploaded or saved in browser storage. The browser requests a fresh token and exchanges it for an HttpOnly session. To sign in again, choose the same identity file. Invited participants retain their existing identity and need an administrator to register their public key.

Enroll for reading and feedback · Invited-key registration

Record a decision

Public display name

Optional and public. Names may be shared by several identities. The stable ID distinguishes them. Leave blank to clear the name.

Your name is self-chosen. Renaming removes Wiki5 verification. This does not change your permissions or verify a person or email.

Save your new access token

This bearer is displayed once. Save it before closing. The token inventory cannot retrieve it.