fix(mail): prove SMTP deliverability before saving, and stop losing the relay
A live install passed the SMTP setup screen and then failed every one-time
code with a bare `internal error`. Four separate defects had to line up for
that, and each is fixed here.
The relay was configured with `from = noreply@<domain-A>` on an account
authenticated as `<user>@<domain-B>`. Providers that validate sender identity
— Fastmail among them — answer MAIL FROM with an unconditional 250 and only
refuse at end-of-DATA. Ping stopped at NOOP, so it never saw the refusal: the
wizard reported success, wrote the config, rolled felis-api, and every OTP
afterwards died at w.Close().
Ping now runs the same transaction a real code takes — connect, (STARTTLS,)
AUTH, MAIL FROM, RCPT TO, DATA — delivering one self-test message to the From
address, and SendOTP and Ping share deliver() so the check cannot drift from
the thing it checks. The self-test recipient cannot cause a false negative:
an authenticated submission relay accepts RCPT for any destination by
definition, while the sender identity it does validate is exactly what we
want tested. The setup screen now says a message will be sent, names the
address it went to, and warns that From must be an address the account is
allowed to send as.
A relay refusal also answered 500 `internal`, which reads as a broken panel
and sends the operator hunting through handler code instead of their [smtp]
block. It is now 502 `mail_undeliverable`, mapped inside deliverOTP so all
four doors that mail a code (onboarding, email login, op-login, migrate
step-up) answer alike. The relay's own text stays out of the response — it
can name the SMTP account, and these routes are reachable by any signed-in
player — and goes to the log instead.
writeError logged nothing when it collapsed an unmapped error to 500, so an
operator holding an `internal error` had nothing to grep for and diagnosis
degraded into guessing against a live install. It now logs the method, path,
wrapped chain and the same request_id the caller is shown.
Finally, write_felis_toml regenerated the config wholesale and never emitted
[smtp], so re-running the installer — the documented way to update felis-api —
silently erased a working relay and reverted OTP delivery to the no-Mailer
path, logging codes instead of sending them. It now carries the block forward,
cached on first read because the host toml is clobbered before the pod toml is
written. Same defect family as the root_domain loss fixed in ecbeb20: a
generated file holding a hand-set value with no carry-forward.
Tests cover the case a MAIL FROM probe cannot see: a fake relay that answers
250 to MAIL FROM and 550 at end-of-DATA must fail both Ping and SendOTP, and
the 502 must carry a distinct machine code without leaking the relay's text.
This commit is contained in:
8 files changed
+346
-35
No files matched your search
+18
-6
@@ -89,7 +89,7 @@ func (m *smtpModel) build() *huh.Form {
|
||||
return m.sized(newFelisForm(huh.NewGroup(
|
||||
huh.NewNote().
|
||||
Title("Email (SMTP)").
|
||||
Description("The relay Felis mails one-time codes through — email verification, email login and operator sign-in all need it. The password goes into a Kubernetes Secret; only the other fields are written to felis.toml."),
|
||||
Description("The relay Felis mails one-time codes through — email verification, email login and operator sign-in all need it. The password goes into a Kubernetes Secret; only the other fields are written to felis.toml. Saving sends one self-test message to the From address: nothing is written unless it is delivered."),
|
||||
huh.NewInput().
|
||||
Title("SMTP host").
|
||||
Description("Your provider's relay, e.g. smtp.gmail.com or smtp.mailgun.org.").
|
||||
@@ -102,7 +102,7 @@ func (m *smtpModel) build() *huh.Form {
|
||||
Validate(validateSMTPPort),
|
||||
huh.NewInput().
|
||||
Title("From address").
|
||||
Description("The sender codes are mailed as, e.g. felis@your-domain.").
|
||||
Description("The sender codes are mailed as, e.g. felis@your-domain. It must be an address this account is allowed to send as — providers reject a From on a domain you have not verified with them, and they usually do it only after the message body, not when you connect.").
|
||||
Value(&m.in.from).
|
||||
Validate(validateSMTPFrom),
|
||||
huh.NewInput().
|
||||
@@ -225,11 +225,14 @@ func (m *smtpModel) normalizeInputs() {
|
||||
func (m *smtpModel) View() string {
|
||||
switch m.step {
|
||||
case esWorking:
|
||||
return " " + m.sp.View() + " " + tuiHint.Render("Verifying the relay, saving email settings and rolling the API…") + "\n"
|
||||
return " " + m.sp.View() + " " + tuiHint.Render("Delivering a self-test message, saving email settings and rolling the API…") + "\n"
|
||||
case esDone:
|
||||
var b strings.Builder
|
||||
b.WriteString(tuiSuccessBanner("Email configured — codes are now mailed.") + "\n\n")
|
||||
b.WriteString(tuiInfo("Relay → "+smtpDetail(m.in)) + "\n")
|
||||
// Named because it is checkable: the operator can open that inbox and see the
|
||||
// proof, rather than taking "configured" on faith.
|
||||
b.WriteString(tuiHint.Render("A self-test message was delivered to "+m.in.from+".") + "\n")
|
||||
b.WriteString("\n" + tuiAction("enter", "continue"))
|
||||
return b.String()
|
||||
case esError:
|
||||
@@ -290,9 +293,18 @@ func currentSMTPInputs() smtpInputs {
|
||||
}
|
||||
|
||||
// applySMTPConfig proves the relay works, then persists it and rolls felis-api:
|
||||
// Ping (connect/STARTTLS/AUTH, no mail sent) → [smtp] into both config files →
|
||||
// the felis-smtp Secret → the config Secret → rollout. A failed Ping leaves the
|
||||
// install untouched, so a typo dies at the keyboard, not at a player's OTP.
|
||||
// Ping (a full transaction — connect/STARTTLS/AUTH/MAIL FROM/RCPT/DATA, which
|
||||
// delivers one self-test message to the From address) → [smtp] into both config
|
||||
// files → the felis-smtp Secret → the config Secret → rollout. A failed Ping
|
||||
// leaves the install untouched, so a bad relay dies at the keyboard, not at a
|
||||
// player's OTP.
|
||||
//
|
||||
// Ping really sends, because a cheaper probe cannot answer the question this
|
||||
// screen exists to answer. Relays that validate sender identity — Fastmail, and
|
||||
// it is not alone — return an unconditional 250 to MAIL FROM and only refuse at
|
||||
// end-of-DATA. The earlier connect/AUTH/NOOP check therefore accepted a From on
|
||||
// a domain the account could not send as, wrote the config, and left every OTP
|
||||
// failing afterwards with this screen reporting success.
|
||||
func applySMTPConfig(ctx context.Context, in smtpInputs) error {
|
||||
port, err := strconv.Atoi(in.port)
|
||||
if err != nil {
|
||||
|
||||
Reference in new issue
Block a user