Skip to content

mailsec: customer sample submission CLI and SDK - #411

Merged
maximelb merged 8 commits into
masterfrom
fbE/sample-submission
Oct 2, 2026
Merged

maximelb merged 8 commits into
masterfrom
fbE/sample-submission

Conversation

@maximelb

@maximelb maximelb commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

What

Adds customer sample submission to the limacharlie mailsec CLI and the Mailsec SDK.

An organization that has opted in (a mailsec_policy record of type sample_sharing, off by default) can let an analyst copy one message at a time to LimaCharlie so detection can improve, then list and withdraw what it sent.

  • limacharlie mailsec message submit-sample <msg_uuid> --category missed_threat|false_positive|other --reason "..."
  • limacharlie mailsec message withdraw-sample <msg_uuid> [--reason ...]
  • limacharlie mailsec submission list [--category --since --until --limit --cursor]
  • limacharlie mailsec submission get <id> (includes recorded access times for the copy)
  • limacharlie mailsec submission withdraw <id>
  • SDK: submit_sample, withdraw_sample, list_submissions, get_submission, withdraw_submission.

Behaviour worth knowing

  • Help text (--help and --ai-help) states plainly that submitting sends the message to LimaCharlie, what is kept, for how long (400 days), restricted access and recorded history, and how to withdraw.
  • Category (closed list) and reason (required, trimmed, 1 to 1024 characters) are checked locally, so a typo never leaves the machine. --limit is 1 to 200.
  • A refused submission (not opted in, no store in the datacenter, raw copy aged out) is reported like any other failed action. If it arrives as a response carrying result: failed, the CLI prints it untouched, explains on stderr, and exits 1 so a script cannot mistake it for success.
  • An unknown submission id is not an error: submission get prints submission: null and submission withdraw prints withdrawn: false; the CLI says so on stderr and exits 0.
  • Mailsec.act_on_message refuses submit_sample, so the generic action path cannot skip the category and reason.
  • submission list prints a stderr note when the org has not opted in or the datacenter has no store, so an empty list is not ambiguous.

Risk

Additive only: new methods and commands, one new guard in act_on_message for the new action name. Needs an API release that serves the new routes; against an older API the new commands return the server's 404/400.

Tests

pytest tests/unit/ tests/microbenchmarks/ passes (4711 passed, 6 existing skips). New SDK tests (routes, bodies, validation, escaping) and CLI tests (parsing, exit codes, stderr notes, --ai-help) fail with the feature reverted (43 failures). Also updated: command lint, discovery profile, CLI reference, SDK reference, changelog.

🤖 Generated with Claude Code

@maximelb

Copy link
Copy Markdown
Contributor Author

/lc-review

lcbill
lcbill previously approved these changes Sep 30, 2026
@maximelb

Copy link
Copy Markdown
Contributor Author

/lc-review

lcbill
lcbill previously approved these changes Sep 30, 2026
@maximelb

maximelb commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

/lc-review

lcbill
lcbill previously approved these changes Oct 1, 2026
@maximelb

maximelb commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

/lc-review

lcbill
lcbill previously approved these changes Oct 1, 2026
@maximelb

maximelb commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

/lc-review

1 similar comment
@maximelb

maximelb commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

/lc-review

lcbill
lcbill previously approved these changes Oct 1, 2026
lcbill
lcbill previously approved these changes Oct 1, 2026
@maximelb

maximelb commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

/lc-review

@maximelb

maximelb commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

/lc-review

lcbill
lcbill previously approved these changes Oct 1, 2026
lcbill
lcbill previously approved these changes Oct 1, 2026
maximelb and others added 7 commits October 1, 2026 23:57
…submission list/get/withdraw)

An organization that has opted in can copy one message at a time to
LimaCharlie to help improve detection, then list and withdraw what it sent.
Adds the SDK methods and CLI commands with local validation of the category
and reason, a non-zero exit on a refused submission, docs and tests.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…on ids are not errors

Follows the updated wire contract: the policy record type is sample_sharing,
GET /submissions/{id} of an unknown id returns submission: null, and DELETE of
an unknown or already-withdrawn id returns withdrawn: false. The CLI says so on
stderr instead of treating either as a failure.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@maximelb
maximelb merged commit 8e5587a into master Oct 2, 2026
6 checks passed
@maximelb
maximelb deleted the fbE/sample-submission branch October 2, 2026 00:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants