R-764: wger sends its mail through the box's relay (smtp_mapping, plaintext :2526, ENABLE_EMAIL gate; hidden app, 9202 boots owed)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-05 21:15:50 +02:00
parent 1968527a86
commit db88ee94f6
4 changed files with 28 additions and 4 deletions
+3 -3
View File
@@ -1,6 +1,6 @@
# EXISTING APPS — what the catalog already shows, per checklist group
> Generated by `scripts/onboarding_gaps.py` from committed files (catalog `febf58c`). **Do not edit by hand.**
> Generated by `scripts/onboarding_gaps.py` from committed files (catalog `b95f854`). **Do not edit by hand.**
> Read only: nothing was re-tested. A cell is what a FILE says, not a measurement made today. The 53 apps
> published before the checklist (2026-10-01) are exempt from the onboarding gate; this page is information,
> not work (operator default 2026-10-01, may be reversed).
@@ -19,7 +19,7 @@
| 7 Mail | — | not countable from files: whether an app WANTS mail is not recorded; the mapped count is below |
| 8 Text and listing | 52 / 53 | English block, tagline + use_cases + first_steps, listed in README, a FIRST-ADMIN row |
Mail: 6 app(s) carry `smtp_mapping`.
Mail: 7 app(s) carry `smtp_mapping`.
## Found while computing this page
@@ -82,6 +82,6 @@ Mail: 6 app(s) carry `smtp_mapping`.
| vaultwarden | yes | no DB sidecar | sweep clean | class 1, read only | yes | no watch | 0 proven step(s), fixture | smtp mapped | yes |
| vikunja | yes | no DB sidecar | sweep undetermined | class 4, measured + setup_gate/signup_block/after_setup | hc missing | no watch | 0 proven step(s), fixture | — | yes |
| wanderer | yes | no DB sidecar | sweep undetermined | class 4, measured + signup_block/after_setup | yes | no watch | 0 proven step(s), no fixture | — | yes |
| wger | — (hidden) | no DB sidecar | sweep undetermined | class 3, measured + after_install | yes | watched 50% | 1 proven step(s), fixture | — | yes |
| wger | — (hidden) | no DB sidecar | sweep undetermined | class 3, measured + after_install | yes | watched 50% | 1 proven step(s), fixture | smtp mapped | yes |
| wishlist | yes | no DB sidecar | sweep undetermined | class 4, measured + setup_gate/signup_block | yes | watched 36% | 1 proven step(s), fixture | — | yes |
| zipline | yes | engine rules hold | sweep undetermined | class 4, measured + setup_gate | yes | watched 34%, mem_limit≠sum | 2 proven step(s), fixture | — | yes |
+1 -1
View File
@@ -63,7 +63,7 @@ Measured on 9202 2026-10-01 from the drill catalog (e9f50b5, wger template ident
6.3 | open | not measured for wger: no forced-fail undo (R-759)
6.4 | done | felhom.eu/documentation/audits/more-night-apps-2026-09-30/bench/apps/wger/bench/evidence/MV-wger/verdict.json — no mark: no file changed at start
6.5 | done | felhom.eu/documentation/audits/new-app-checklist-2026-10-01/B/B1-upstream-reads.txt — `x.y` + `x.y.0`, stable 2.1 -> 2.7; pre-releases carry `-dev`/`-alpha` suffixes
7.1 | open | wger has a mail switch (`ENABLE_EMAIL`) and no `smtp_mapping`; its mail goes to the console, so a password-reset mail never leaves the box (R-764; C2)
7.1 | open | wger has a mail switch (`ENABLE_EMAIL`) and no `smtp_mapping`; its mail goes to the console, so a password-reset mail never leaves the box (R-764; C2) — fix written 2026-10-05 (`smtp_mapping`, plaintext :2526, `ENABLE_EMAIL` gate); the 9202 boots (mail off, mail on + a reset mail received) are still owed
8.1 | done | felhom.eu/documentation/audits/new-app-checklist-2026-10-01/B/B3-gates-now.txt — copy-i18n exit 0
8.2 | open | not read on 9202's app page this session; `add_people` is absent (R-759)
8.3 | done | felhom.eu/documentation/audits/new-app-checklist-2026-10-01/B/B1-upstream-reads.txt — wger-logo.png and screenshot-1 answer 200
+11
View File
@@ -87,6 +87,17 @@ after_install:
command: ["python3", "-c", "import os, sys; sys.path.insert(0, '/home/wger/src'); os.chdir('/home/wger/src'); os.environ.setdefault('DJANGO_SETTINGS_MODULE', 'settings.main'); import django; django.setup(); from django.contrib.auth.models import User; u = User.objects.get(username='admin'); u.set_password(sys.argv[1]); u.save(); print('FELHOM_AFTER_INSTALL_OK')", "${ADMIN_PASSWORD}"]
success: "FELHOM_AFTER_INSTALL_OK"
# --- App-email (password reset) through the box's mail relay; plaintext :2526 (see the compose comment, R-764) ---
smtp_mapping:
tls_mode: plaintext
host_var: EMAIL_HOST
port_var: EMAIL_PORT
from_var: FROM_EMAIL
from_local: wger
extra:
# The gate: wger reads the EMAIL_* group only when this is true (compose default False = mail off).
ENABLE_EMAIL: "True"
# --- Controller-side health probe ---
healthcheck:
checks:
+13
View File
@@ -58,6 +58,19 @@ services:
# settings/main.py as env.bool (wger 2.7 L179-180); the sign-up view then redirects to the features page.
- ALLOW_REGISTRATION=False
- ALLOW_GUEST_USERS=False
# R-764 (2026-10-05): mail through the box's relay (smtp_mapping in .felhom.yml, tls_mode plaintext -> :2526).
# wger 2.7 settings/main.py:162 reads the EMAIL_* group ONLY when ENABLE_EMAIL is true, and then env.str() with
# no default on EMAIL_HOST_USER / EMAIL_HOST_PASSWORD — so both stay defined-EMPTY here (the relay takes no
# login; an absent one would stop wger at start). ENABLE_EMAIL is the gate: False unless the mail toggle injects
# "True". EMAIL_USE_TLS False: Django's STARTTLS verifies the certificate and the relay's is self-signed.
- ENABLE_EMAIL=${ENABLE_EMAIL:-False}
- EMAIL_HOST=${EMAIL_HOST:-}
- EMAIL_PORT=${EMAIL_PORT:-2526}
- EMAIL_HOST_USER=
- EMAIL_HOST_PASSWORD=
- EMAIL_USE_TLS=False
- EMAIL_USE_SSL=False
- FROM_EMAIL=${FROM_EMAIL:-wger Workout Manager <wger@example.com>}
- DJANGO_DB_ENGINE=django.db.backends.sqlite3
- DJANGO_DB_DATABASE=/home/wger/db/database.sqlite
- DJANGO_DB_USER=wger