NAME

Mail::SpamAssassin::Handler::ICS - A MIME-part handler for text/calendar parts

SYNOPSIS

loadhandler  Mail::SpamAssassin::Handler::ICS

icstext  RULE_NAME  /pattern/modifiers

body  ICS_MANY_ATTENDEES  eval:check_ics_attendee_count('50')
body  ICS_RANDOM_DTSTART  eval:check_ics_random_start_time()

DESCRIPTION

This handler parses each iCalendar part and renders the text of every event's SUMMARY and DESCRIPTION into the message body, so ordinary body rules can match it. The same text can additionally be matched with the new icstext rule type, which sees the invite text on its own -- so a word can be scored differently inside an invite than in the surrounding body. Links found in the URL, ATTACH and LOCATION properties are added to the URI detail list (type ics). It also counts ATTENDEE properties and flags events whose DTSTART has a non-zero seconds component (a fingerprint of machine-generated / bulk invites, since human and most-client invites round to :00) -- see "EVAL RULES".

RETURNS

This handler returns one text/html sub-part for each HTML-typed property found, or an empty list if there are none.

ICS TEXT RULES

icstext  RULENAME  /regex/modifiers
score    RULENAME  1.0
describe RULENAME  ICS event text matching /regex/

These rules behave like rawbody rules and support the multiple and maxhits=N tflags. By default a rule stops at its first match. icstext matches only the invite text; to run one of the eval rules below, use a body rule.

EVAL RULES

check_ics_attendee_count(MIN, [MAX])

  body RULENAME  eval:check_ics_attendee_count(<min>,[max])
     min: required, invites contain at least x ATTENDEE properties in total
     max: optional, if specified, must not contain more than x ATTENDEE properties

check_ics_random_start_time()

  body RULENAME  eval:check_ics_random_start_time()

     Fires if any event's DTSTART has a non-zero seconds component
     (e.g. DTSTART:20250610T120005Z) -- a fingerprint of a machine-generated
     start time, since human and most-client invites round to whole minutes.

check_ics_event_prop(NAME, REGEX)

  body RULENAME  eval:check_ics_event_prop('ATTACH', 'ENCODING=BASE64')

     Fires if any calendar event has a property named NAME (case-insensitive)
     whose content matches REGEX.  The leading property NAME is stripped -- REGEX
     sees "params:value" (or just "value" when the property has no parameters) --
     so a rule for the DESCRIPTION value need not skip past a "DESCRIPTION:"
     prefix.  REGEX is a regular expression; the surrounding /.../ delimiters are
     optional, so 'ENCODING=BASE64' and '/ENCODING=BASE64/' are equivalent -- use
     the delimited form when you need flags (e.g. '/foo/i').  Note that even
     without delimiters it is still a regex, not a literal substring:
     metacharacters such as . | ( ) are active.  Because the parameters are
     retained, REGEX can still match them as well as the value -- e.g.
     ENCODING=BASE64, VALUE=BINARY, FMTTYPE=image/png.  Useful for finding
     invites that carry inline attachments or images.

URI DETAILS

This handler creates a new "ics" URI type. You can detect URIs found in calendar invites using the URIDetail plugin. For example:

uri-detail RULENAME  type =~ /^ics$/  raw =~ /^https?:\/\/bit\.ly\//