# Plan — a replacement for the contact mailer (R-902) The February source is lost (`SEARCH.md`). The running program keeps working; this plan is for a later, attended session. **Nothing here is built or deployed yet.** ## What the running program does (read from the binary and the manifest — not from source) - **Endpoints:** `POST /api/contact` (the Ingress sends `felhom.eu/api/*` here), `GET /healthz` (the probes), `POST /debug/test` (only when `DEBUG=true`; the manifest sets `false`). Listens on `LISTEN_ADDR`, default `:8080`. - **Env:** `RESEND_API_KEY` (from `Secret/resend-api`), `FROM_EMAIL`, `TO_EMAIL`, `ALLOWED_ORIGIN`, `TZ`, `DEBUG`. - **Per form, one mail** via `https://api.resend.com/emails` (Bearer key): from `FROM_EMAIL`, to `TO_EMAIL`, `reply_to` = the visitor, HTML table (`buildEmailHTML`: header „Új üzenet a weboldalról", rows incl. Tárgy, „Csatolmány … %d fájl"), attachments as base64. **Nothing is sent to the visitor.** - **Checks, with Hungarian JSON errors:** CORS to `ALLOWED_ORIGIN`; a per-IP rate limiter („Túl sok kérés…"); a honeypot field `website`; required fields („Kérlek, töltsd ki az összes kötelező mezőt."); name ≤ 200, message ≤ 10 000 characters; e-mail format and length; at most 5 files, ≤ 10 MB each, ≤ 20 MB together; a malformed or too-large request („A kérés mérete túl nagy vagy hibás formátum."). The page shows its own messages, not these. ## The replacement One `main.go` (stdlib only, Go ≥ 1.23), same endpoints, env, limits and mail shape; the rate limit and the template copied from the strings above. Committed to `felhom.eu/contact-mailer/` with `go.mod`, a two-stage `Dockerfile` (the same shape the image record shows: builder at `/build`, alpine runtime, user 1000, `/app`), tests for each refusal, and a `README.md`. The image is built **with a version tag** and pushed to the Gitea registry, so `imagePullPolicy: Never` and the hand import end; the manifest names that tag. ## How to prove it, before switching 1. Unit tests: every refusal above, and the mail body built from a sample form (no network). 2. A second Deployment `contact-mailer-next` (no Ingress), port-forwarded: a real form with one small PDF → one mail arrives at info@ with Reply-To = the sender and the attachment; an 11 MB file → refused; six files → refused. 3. Compare its mail with one from the running program (same fields, same subject line). ## Switch-over (attended) Point the Deployment at the new tag, wait for Ready, send one form from `felhom.eu/kapcsolat` and one from `/en/contact`, read both mails. Roll back = the old manifest line (the old image stays in containerd, and its binary is kept in `documentation/audits/mailer-source-2026-10-08/contact-mailer.bin`). ## One question for the operator Do you still have the February folder on your Windows workstation (`e:\DooPlex Server\…` or a „contact-mailer" folder)? **Pick: look there first** — if it is there, it is committed as it is and this plan shrinks to „rebuild with a version tag". **If you do nothing:** the replacement is written from this page in a later website/ops task.