Replace the RFC 5322 mega-regexp with net/mail.ParseAddress, which is the standard library's address parser and far easier to audit. A bare address is required: inputs with a display name, angle brackets, a comment, or trailing content are rejected, as is an address list. Behaviour change: ParseAddress does not require the domain to contain a dot, so "alice@localhost" now validates. Layer Match or a DNS lookup on top if a stricter domain is needed. Also rewrites FuzzEmail, which previously asserted that *every* input is invalid, into checks that Email never returns an unexpected error type, never panics, and gives a stable verdict. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
26 lines
699 B
Go
26 lines
699 B
Go
package validate
|
|
|
|
import (
|
|
"net/mail"
|
|
)
|
|
|
|
var (
|
|
ErrInvalidEmail = NewError("invalid email address")
|
|
)
|
|
|
|
// Email validates an email address using net/mail.ParseAddress.
|
|
//
|
|
// Only a bare address is accepted (alice@example.com). Anything with a
|
|
// display name, angle brackets, a comment, or trailing content is rejected,
|
|
// as is a list of addresses. Note that ParseAddress does not require the
|
|
// domain to have a dot, so "alice@localhost" is considered valid; layer on
|
|
// Match or a DNS check if you need to be stricter.
|
|
func Email(value string) error {
|
|
addr, err := mail.ParseAddress(value)
|
|
if err != nil || addr.Name != "" || addr.Address != value {
|
|
return ErrInvalidEmail
|
|
}
|
|
|
|
return nil
|
|
}
|