Encrypted mailbox primitives
Optional SDK mailbox envelopes, attachment validation and key wrapping.
Enable the feature explicitly
The mailbox Cargo feature enables weave_sdk::mailbox and its loom-encrypt dependency. It is not part of the default SDK surface.
weave-sdk = { path = "../weave/libs/weave-sdk", features = ["mailbox"] }Follow the envelope boundary
MailboxPath::new validates mailbox paths. Canonical mailbox roots and private-path checks separate public artifacts from private material. Key wrappers and message structures validate sizes and content metadata before serialization or encryption.
Use the exact mailbox declarations for encrypt_message_v1, decrypt_mailbox_field, content-key wrapping/unwrapping, attachment validation and message identifiers. The caller supplies verified recipient keys and key custody; a public file pin does not grant mailbox read authority.
Handle validation/decryption errors as failures. Do not log secret content keys or plaintext fields. Connect transport only after the recipient's identity, authority and feature availability are established.