feat(mail): deliver email one-time codes over SMTP and add the setup email screen

Felis never actually sent mail: OTP codes for onboarding, email login and
op-login were only written to the felis-api log behind a "demo has no SMTP"
limitation, and the Settings/SMTP flow those comments promised was never
built. Combined with the bootstrap Owner's address being recorded unverified
(87279a1), op-login start always took the anti-enumeration neutral branch and
minted a fake request_id, so the in-game approve inevitably answered "No
pending operator sign-in with that code".

Give the codes a real delivery path, configured in felis.toml rather than a
web settings page so config keeps a single source of truth:

- config: new [smtp] table (host, port defaulting to 587, from, username,
  password_ref). Validation requires a plausible from address and a sane
  port; the password itself never enters the config file.
- internal/mail (new): stdlib net/smtp mailer implementing the api.OTPMailer
  seam. Port 465 dials implicit TLS, other ports upgrade via STARTTLS when
  advertised; AUTH only when a username is configured (PlainAuth itself
  refuses plaintext, so the password cannot leak to a TLS-less relay).
  Ping() proves reachability and credentials without sending mail. The
  message shape (CRLF, Q-encoded bilingual subject) is pinned by test.
- platform: felis-smtp Secret constants and an optional FELIS_SMTP_PASSWORD
  env var on the felis-api Deployment, mirroring felis-uploads-s3.
- cmd/felis api: construct the real mailer when [smtp] is configured; keep
  the log fallback otherwise and say so at startup. Warn when a username is
  set but the credentials env is empty.
- setup TUI: "e" on the summary/status screen opens the email form (host,
  port, from, optional auth). Apply order: Ping preflight, [smtp] into both
  host and pod config files, felis-smtp Secret piped to kubectl via stdin,
  config Secret, felis-api rollout. A failed preflight leaves the install
  untouched. SMTP is deliberately not a wizard rail step: first-run stays
  mail-less by design, and the passkey minted at onboarding is the pre-SMTP
  owner credential.

Also make PGRepo.UserByEmail match case-insensitively (lower(email) =
lower($1)), honoring the interface contract and the users_verified_email_
unique partial index; the fake repo already matched with EqualFold.

Existing installs need the felis-api Deployment manifest re-applied (e.g. a
bootstrap re-run) before the new env var exists; a rollout restart alone
cannot add it.
This commit is contained in:
flyemoji committed 2026-07-20 10:24:52 +09:00
1 parent 7860152f57
commit f0b79e9edd
12 files changed
+730 -10

No files matched your search

+9 -8
View File
@@ -230,22 +230,23 @@ func TestAPIDeployment_UploadsStorage(t *testing.T) {
t.Errorf("uploads mount = %#v, want read-write at %s", m, UploadsLocalPath)
}
// S3 backend: both credential env vars come from the Secret (never literals) and
// are OPTIONAL, so a local install with no such Secret still starts.
for _, ev := range []struct{ name, key string }{
{UploadsS3AccessKeyEnv, UploadsS3SecretAccessKey},
{UploadsS3SecretKeyEnv, UploadsS3SecretSecretKey},
// Credential env vars (S3 backend + SMTP relay) come from their Secrets (never
// literals) and are OPTIONAL, so an install without them still starts.
for _, ev := range []struct{ name, secret, key string }{
{UploadsS3AccessKeyEnv, UploadsS3SecretName, UploadsS3SecretAccessKey},
{UploadsS3SecretKeyEnv, UploadsS3SecretName, UploadsS3SecretSecretKey},
{SMTPPasswordEnv, SMTPSecretName, SMTPSecretPasswordKey},
} {
e := envVar(c.Env, ev.name)
if e == nil || e.ValueFrom == nil || e.ValueFrom.SecretKeyRef == nil {
t.Fatalf("%s must be sourced from a secretKeyRef", ev.name)
}
ref := e.ValueFrom.SecretKeyRef
if ref.Name != UploadsS3SecretName || ref.Key != ev.key {
t.Errorf("%s ref = %s/%s, want %s/%s", ev.name, ref.Name, ref.Key, UploadsS3SecretName, ev.key)
if ref.Name != ev.secret || ref.Key != ev.key {
t.Errorf("%s ref = %s/%s, want %s/%s", ev.name, ref.Name, ref.Key, ev.secret, ev.key)
}
if ref.Optional == nil || !*ref.Optional {
t.Errorf("%s secretKeyRef must be optional (a local install has no such Secret)", ev.name)
t.Errorf("%s secretKeyRef must be optional (an install without it has no such Secret)", ev.name)
}
if e.Value != "" {
t.Errorf("%s must not carry a literal value", ev.name)