fix(email): send portal mail from mail.gitborg.se #114
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-web!114
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/mail-domain-sender"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
The sending domain moved from
email.gitborg.setomail.gitborg.se. Only bitborg-infra wasupdated; the portal's From address is hardcoded here and not env-configurable on purpose, so no
Ansible run could reach it. Every portal mail would still have gone out as
no-reply@email.gitborg.se.Why this matters
The old address is now unauthenticated. Verified against live DNS:
sweego1._domainkey.mail.gitborg.se…-dkim.sweego.co, validv=DKIM1key_dmarc.mail.gitborg.sev=DMARC1; p=none;email.gitborg.seSo Sweego is likely to reject the send as an unverified sending domain, and anything that did get
through would fail DKIM alignment. The affected path is the sign-up credential-reset email: the
sign-up completes, the account is provisioned, and the user never receives the link to set a
password. Failure is silent from the user's side.
p=nonemeans nothing is being rejected on policy grounds, which makes this quieter, not safer.Changes
src/lib/email.ts—EMAIL_FROM→no-reply@mail.gitborg.se; comments corrected and the DKIMlocation recorded.
README.md,.env.example— same address in prose.The underlying coupling
The From address lives in two repos with nothing asserting they agree: this constant, and
forgejo_mailer_fromin bitborg-infra. The infra template comment was even updated to say "From isfixed to no-reply@mail.gitborg.se in app code" while the app code still read
email.gitborg.se— acomment asserting a fact about another repo, unchecked by anything.
Tracked in #113, which proposes boot-time validation against an infra-supplied allowlist: it keeps
the security property that motivated hardcoding, needs no cross-repo CI, and turns a silent delivery
failure into a loud startup failure.
Verification
pnpm check— 0 errors (113 files). The three warnings are pre-existing: a deprecatedastro:schemazimport and two unusedgetRelativeLocaleUrlimports in the signup pages.the reissued SMTP credentials) before mail can be tested. After both land: trigger a sign-up and
confirm the received headers show
d=mail.gitborg.sewithdkim=pass.Merge order
Independent of the infra PR — but the portal keeps sending from a dead domain until this one
deploys, so it should not wait on it.