fix(email): the sender refusal now says how to fix it #144

Sammanfogat
supernaut sammanfogade 1 incheckning från fix/sender-check-hint in i main 2026-08-01 14:53:53 +00:00
Ägare

Closes #113 — mostly as already-done, plus the one part of it that was still missing.

#113 was already implemented

The cross-repo drift the issue describes is already guarded, using the issue's own recommended option 1
("assert at boot / refuse to send"). EMAIL_FROM stays hardcoded, keeping the security property that
motivated hardcoding, and senderAllowed() in src/lib/email.ts checks it against
EMAIL_FROM_ALLOWED_DOMAINS, which bitborg-infra supplies
(roles/web/templates/bitborg-web.container.j2, group_vars/all/vars.yml). The check refuses before
contacting the provider, and unset is deliberately distinct from not-allowed so a rollout does not
look like a fault. All of that is on main already and covered by tests.

What was missing

The issue's last paragraph asked for something that had not been done:

Whatever is chosen, the DNS facts belong in the check's error message — the sending domain needs a
Sweego DKIM delegation (sweego1._domainkey.<domain>) to be verified, so "domain not in allowlist"
should hint at that.

The message was sender no-reply@… is not an allowed sending domain and nothing more. That matters
because of who reads it and when: the affected path is the sign-up credential-reset mail, so the symptom
is a sign-up that completed while the user never received their link. Someone is debugging that under
time pressure, and "not allowed" names neither what was allowed nor what makes a domain allowable.

Two things have to be true for a sending domain to work — infra must list it, and the provider must have
verified it via a DKIM delegation. The message now carries both, including the exact DNS record for the
offending domain:

sender no-reply@mail.gitborg.se is not an allowed sending domain (allowed: other.test) — the sending
domain must be listed in EMAIL_FROM_ALLOWED_DOMAINS and verified in Sweego with a DKIM delegation at
sweego1._domainkey.mail.gitborg.se

Written test-first: the assertion was added and observed failing against the old message before the
message changed.

Verified

pnpm test 169 passed / 16 files · pnpm check 0 errors, 0 warnings · eslint and stylelint clean ·
prettier clean.

Closes #113 — **mostly as already-done**, plus the one part of it that was still missing. ## #113 was already implemented The cross-repo drift the issue describes is already guarded, using the issue's own recommended option 1 ("assert at boot / refuse to send"). `EMAIL_FROM` stays hardcoded, keeping the security property that motivated hardcoding, and `senderAllowed()` in `src/lib/email.ts` checks it against `EMAIL_FROM_ALLOWED_DOMAINS`, which bitborg-infra supplies (`roles/web/templates/bitborg-web.container.j2`, `group_vars/all/vars.yml`). The check refuses **before** contacting the provider, and `unset` is deliberately distinct from `not-allowed` so a rollout does not look like a fault. All of that is on `main` already and covered by tests. ## What was missing The issue's last paragraph asked for something that had not been done: > Whatever is chosen, the DNS facts belong in the check's error message — the sending domain needs a > Sweego DKIM delegation (`sweego1._domainkey.<domain>`) to be verified, so "domain not in allowlist" > should hint at that. The message was `sender no-reply@… is not an allowed sending domain` and nothing more. That matters because of who reads it and when: the affected path is the sign-up credential-reset mail, so the symptom is a sign-up that completed while the user never received their link. Someone is debugging that under time pressure, and "not allowed" names neither what *was* allowed nor what makes a domain allowable. Two things have to be true for a sending domain to work — infra must list it, and the provider must have verified it via a DKIM delegation. The message now carries both, including the exact DNS record for the offending domain: ```text sender no-reply@mail.gitborg.se is not an allowed sending domain (allowed: other.test) — the sending domain must be listed in EMAIL_FROM_ALLOWED_DOMAINS and verified in Sweego with a DKIM delegation at sweego1._domainkey.mail.gitborg.se ``` Written test-first: the assertion was added and observed failing against the old message before the message changed. ## Verified `pnpm test` 169 passed / 16 files · `pnpm check` 0 errors, 0 warnings · eslint and stylelint clean · prettier clean.
supernaut lade till 1 incheckning 2026-08-01 14:48:28 +00:00
fix(email): the sender refusal now says how to fix it
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m18s
c64d9a64ae
The check refused a disallowed sending domain with 'is not an allowed sending
domain' and nothing else. Whoever reads that line is looking at a sign-up that
completed while its credential-reset mail never arrived, and the message named
neither what was allowed nor what makes a domain allowable.

Two things must be true: infra must list the domain in
EMAIL_FROM_ALLOWED_DOMAINS, and the provider must have verified it with a DKIM
delegation. The message now carries both, including the exact DNS record for the
offending domain.
supernaut sammanfogade incheckning b932268e6d till main 2026-08-01 14:53:53 +00:00
supernaut tog bort grenen fix/sender-check-hint 2026-08-01 14:53:53 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-web!144
Ingen beskrivning angiven.