Adds FileSender as a Thunderbird FileLink provider, so large attachments are sent as download links instead of attached directly. Works with any FileSender (https://filesender.org) instance you have an account on.
A Thunderbird add-on that attaches large files to your emails as https://filesender.org download links instead of attaching them directly. It works with any FileSender instance you have an account on.
Version Information
Version 1.0.1
69.8 KiB
Works with
Thunderbird 128.0 and later
Fixed
With more than one FileSender account in Thunderbird, removing an attachment uploaded with one account could delete the upload of another account's attachment, whose link then stopped working. Aborting an upload or answering "reuse the link?" could also reach the other account's file. The uploads of each account are now kept apart. A base URL written with an upper-case scheme (HTTPS://...) made every request fail as "credentials rejected". The 16 px icon now shows the envelope like the other sizes.
Added
The account settings warn when the base URL differs from the address the FileSender server declares (for example a host name alias): its links are on that address and would not be reused.
Security
A previous link is reused only if it is under the account's base URL, so the download token of another server's link is never sent to the configured server (for example after changing the base URL of an account). Requests to FileSender no longer follow redirects, which could send the file content to another address. Upload errors show only the FileSender error code, never free text from the server or a proxy. The instance configuration is never downloaded over plain http://. Download links without an http(s) scheme are ignored.
FileLink for FileSender needs the following to upload attachments to the FileSender instance you configure:
- The instance's base URL, your FileSender identifier and your FileSender API key. - Optionally, a sender email address (one of your FileSender account's own addresses). - Your default upload options (expiry, notification and encryption preferences).
This data is entered by you, in the add-on's account settings page, and is stored only in Thunderbird's local extension storage (`storage.local`) on your own computer. It is never sent anywhere except to the FileSender instance you configured, as part of signing and authenticating the upload requests you initiate.
While an upload is pending, the add-on also keeps a short-lived local record (in `storage.session`, cleared when Thunderbird restarts) of which transfers it created for which draft emails, so it can delete a transfer if you discard the email without sending it, and reuse a link if you attach the same file again.
## What this add-on does NOT do
- It does not send any data to its developers or to any third party other than the FileSender instance you yourself configured. - It does not read or transmit the content of your emails. It only observes whether a message was sent, saved or discarded, to decide whether to keep or delete a transfer. - It does not use analytics, telemetry, tracking or advertising of any kind. - It does not set cookies. - Optional password-based encryption is performed entirely on your device (WebCrypto); the password is never stored, never logged and never included in the email. You are responsible for sharing it with your recipients through a separate channel.
## Logging
The add-on can optionally print debug logs to its own console, off by default. When enabled, API keys, signatures, upload tokens and email addresses are masked or redacted before being logged, so that a log can be safely copied into a bug report. Logs stay on your device; the add-on never transmits them anywhere.
## Network requests
The only network requests this add-on makes are to the FileSender instance whose URL you entered in the account settings: to read its public configuration, to sign and upload files, and to check your account status ("Test connection"). All requests require `https://`; an `http://` instance URL is refused.
## Contact
Questions about this policy or the add-on's data handling can be sent through the project's GitHub repository issue tracker.
Some add-ons ask for permission to perform certain functions (example: a tab management add-on will ask permission to access your browser’s tab system).
Since you’re in control of your Thunderbird, the choice to grant or deny these requests is yours. Accepting permissions does not inherently compromise your browser’s performance or security, but in some rare cases risk may be involved.