mailsec: customer sample submission CLI and SDK - #411
Merged
Merged
Conversation
Contributor
Author
|
/lc-review |
lcbill
previously approved these changes
Sep 30, 2026
Contributor
Author
|
/lc-review |
lcbill
previously approved these changes
Sep 30, 2026
Contributor
Author
|
/lc-review |
lcbill
previously approved these changes
Oct 1, 2026
Contributor
Author
|
/lc-review |
lcbill
previously approved these changes
Oct 1, 2026
Contributor
Author
|
/lc-review |
1 similar comment
Contributor
Author
|
/lc-review |
lcbill
previously approved these changes
Oct 1, 2026
lcbill
previously approved these changes
Oct 1, 2026
Contributor
Author
|
/lc-review |
Contributor
Author
|
/lc-review |
lcbill
previously approved these changes
Oct 1, 2026
lcbill
previously approved these changes
Oct 1, 2026
…submission list/get/withdraw) An organization that has opted in can copy one message at a time to LimaCharlie to help improve detection, then list and withdraw what it sent. Adds the SDK methods and CLI commands with local validation of the category and reason, a non-zero exit on a refused submission, docs and tests. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…on ids are not errors
Follows the updated wire contract: the policy record type is sample_sharing,
GET /submissions/{id} of an unknown id returns submission: null, and DELETE of
an unknown or already-withdrawn id returns withdrawn: false. The CLI says so on
stderr instead of treating either as a failure.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
maximelb
force-pushed
the
fbE/sample-submission
branch
from
October 1, 2026 23:57
2383cac to
f636ed4
Compare
lcbill
approved these changes
Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Adds customer sample submission to the
limacharlie mailsecCLI and theMailsecSDK.An organization that has opted in (a
mailsec_policyrecord of typesample_sharing, off by default) can let an analyst copy one message at a time to LimaCharlie so detection can improve, then list and withdraw what it sent.limacharlie mailsec message submit-sample <msg_uuid> --category missed_threat|false_positive|other --reason "..."limacharlie mailsec message withdraw-sample <msg_uuid> [--reason ...]limacharlie mailsec submission list [--category --since --until --limit --cursor]limacharlie mailsec submission get <id>(includes recorded access times for the copy)limacharlie mailsec submission withdraw <id>submit_sample,withdraw_sample,list_submissions,get_submission,withdraw_submission.Behaviour worth knowing
--helpand--ai-help) states plainly that submitting sends the message to LimaCharlie, what is kept, for how long (400 days), restricted access and recorded history, and how to withdraw.--limitis 1 to 200.result: failed, the CLI prints it untouched, explains on stderr, and exits 1 so a script cannot mistake it for success.submission getprintssubmission: nullandsubmission withdrawprintswithdrawn: false; the CLI says so on stderr and exits 0.Mailsec.act_on_messagerefusessubmit_sample, so the generic action path cannot skip the category and reason.submission listprints a stderr note when the org has not opted in or the datacenter has no store, so an empty list is not ambiguous.Risk
Additive only: new methods and commands, one new guard in
act_on_messagefor the new action name. Needs an API release that serves the new routes; against an older API the new commands return the server's 404/400.Tests
pytest tests/unit/ tests/microbenchmarks/passes (4711 passed, 6 existing skips). New SDK tests (routes, bodies, validation, escaping) and CLI tests (parsing, exit codes, stderr notes,--ai-help) fail with the feature reverted (43 failures). Also updated: command lint, discovery profile, CLI reference, SDK reference, changelog.🤖 Generated with Claude Code