email: the From address is duplicated across two repos with nothing keeping them in sync #113

Stängd
öppnade 2026-07-31 00:36:19 +00:00 av supernaut · 0 kommentarer
Ägare

The From address for outbound mail is defined in two repositories with nothing asserting they
agree:

  • bitborg-web — EMAIL_FROM in src/lib/email.ts, a hardcoded constant, deliberately not
    env-configurable ("an env var here could send as an unverified domain").
  • bitborg-infra — forgejo_mailer_from in ansible/group_vars/all/vars.yml, plus
    alerts@ senders in the monitoring roles, plus a comment in
    roles/web/templates/bitborg-web.container.j2 that describes the portal's hardcoded value.

This already broke once

On 2026-07-31 the sending domain moved from email.gitborg.se to mail.gitborg.se. Infra was
updated; the portal was not. The infra template comment was even updated to say
"From is fixed to no-reply@mail.gitborg.se in app code" while the app code still read
email.gitborg.se — a comment asserting a fact about another repo, with no mechanism to check it.

The failure would have been near-silent and delivery-shaped: the portal keeps sending, Sweego
either rejects the unverified sending domain or the mail fails DKIM alignment. The affected path
is the sign-up credential-reset email, so sign-ups complete but the user never receives the link.
Nothing in CI or at boot would have caught it. Fixed in the commit that filed this issue; the
coupling remains.

Options

  1. Assert at boot. Keep the constant, but validate it at startup against an allowlist supplied
    by infra as env (e.g. EMAIL_FROM_ALLOWED_DOMAINS). Refuse to start, or refuse to send, on a
    mismatch. Preserves the "not configurable" property while making drift loud.
  2. Env var with an allowlist. Inject EMAIL_FROM from infra as the single source of truth,
    validated at boot against a compiled-in allowlist so a typo cannot send as an arbitrary domain.
    Removes the duplication rather than detecting it.
  3. CI assertion. A check that greps the infra forgejo_mailer_from and this constant and fails
    if the domains differ. Cheapest, but cross-repo CI coupling is awkward and it only runs in CI.

Option 1 is probably the best trade: it keeps the security property that motivated hardcoding,
needs no cross-repo CI, and converts a silent delivery failure into a loud startup failure.

Whatever is chosen, the DNS facts belong in the check's error message — the sending domain needs a
Sweego DKIM delegation (sweego1._domainkey.<domain>) to be verified, so "domain not in allowlist"
should hint at that.

Done when

Changing the sending domain in one repo and not the other causes a visible, immediate failure
rather than undelivered mail.

The From address for outbound mail is defined in two repositories with nothing asserting they agree: - `bitborg-web` — `EMAIL_FROM` in `src/lib/email.ts`, a hardcoded constant, deliberately not env-configurable ("an env var here could send as an unverified domain"). - `bitborg-infra` — `forgejo_mailer_from` in `ansible/group_vars/all/vars.yml`, plus `alerts@` senders in the monitoring roles, plus a comment in `roles/web/templates/bitborg-web.container.j2` that *describes* the portal's hardcoded value. ## This already broke once On 2026-07-31 the sending domain moved from `email.gitborg.se` to `mail.gitborg.se`. Infra was updated; the portal was not. The infra template comment was even updated to say *"From is fixed to no-reply@mail.gitborg.se in app code"* while the app code still read `email.gitborg.se` — a comment asserting a fact about another repo, with no mechanism to check it. The failure would have been near-silent and delivery-shaped: the portal keeps sending, Sweego either rejects the unverified sending domain or the mail fails DKIM alignment. The affected path is the sign-up credential-reset email, so sign-ups complete but the user never receives the link. Nothing in CI or at boot would have caught it. Fixed in the commit that filed this issue; the coupling remains. ## Options 1. **Assert at boot.** Keep the constant, but validate it at startup against an allowlist supplied by infra as env (e.g. `EMAIL_FROM_ALLOWED_DOMAINS`). Refuse to start, or refuse to send, on a mismatch. Preserves the "not configurable" property while making drift loud. 2. **Env var with an allowlist.** Inject `EMAIL_FROM` from infra as the single source of truth, validated at boot against a compiled-in allowlist so a typo cannot send as an arbitrary domain. Removes the duplication rather than detecting it. 3. **CI assertion.** A check that greps the infra `forgejo_mailer_from` and this constant and fails if the domains differ. Cheapest, but cross-repo CI coupling is awkward and it only runs in CI. Option 1 is probably the best trade: it keeps the security property that motivated hardcoding, needs no cross-repo CI, and converts a silent delivery failure into a loud startup failure. Whatever is chosen, the DNS facts belong in the check's error message — the sending domain needs a Sweego DKIM delegation (`sweego1._domainkey.<domain>`) to be verified, so "domain not in allowlist" should hint at that. ## Done when Changing the sending domain in one repo and not the other causes a visible, immediate failure rather than undelivered mail.
supernaut lade till detta till projektet Bitborg Web 2026-07-31 00:36:49 +00:00
Logga in för att delta i denna konversation.
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-web#113
Ingen beskrivning angiven.