Files
felhom.eu/documentation/audits/mailer-source-2026-10-08/PLAN-replacement.md
T

3.1 KiB

Plan — a replacement for the contact mailer (R-902)

The February source is lost (SEARCH.md). The running program keeps working; this plan is for a later, attended session. Nothing here is built or deployed yet.

What the running program does (read from the binary and the manifest — not from source)

  • Endpoints: POST /api/contact (the Ingress sends felhom.eu/api/* here), GET /healthz (the probes), POST /debug/test (only when DEBUG=true; the manifest sets false). Listens on LISTEN_ADDR, default :8080.
  • Env: RESEND_API_KEY (from Secret/resend-api), FROM_EMAIL, TO_EMAIL, ALLOWED_ORIGIN, TZ, DEBUG.
  • Per form, one mail via https://api.resend.com/emails (Bearer key): from FROM_EMAIL, to TO_EMAIL, reply_to = the visitor, HTML table (buildEmailHTML: header „Új üzenet a weboldalról", rows incl. Tárgy, „Csatolmány … %d fájl"), attachments as base64. Nothing is sent to the visitor.
  • Checks, with Hungarian JSON errors: CORS to ALLOWED_ORIGIN; a per-IP rate limiter („Túl sok kérés…"); a honeypot field website; required fields („Kérlek, töltsd ki az összes kötelező mezőt."); name ≤ 200, message ≤ 10 000 characters; e-mail format and length; at most 5 files, ≤ 10 MB each, ≤ 20 MB together; a malformed or too-large request („A kérés mérete túl nagy vagy hibás formátum."). The page shows its own messages, not these.

The replacement

One main.go (stdlib only, Go ≥ 1.23), same endpoints, env, limits and mail shape; the rate limit and the template copied from the strings above. Committed to felhom.eu/contact-mailer/ with go.mod, a two-stage Dockerfile (the same shape the image record shows: builder at /build, alpine runtime, user 1000, /app), tests for each refusal, and a README.md. The image is built with a version tag and pushed to the Gitea registry, so imagePullPolicy: Never and the hand import end; the manifest names that tag.

How to prove it, before switching

  1. Unit tests: every refusal above, and the mail body built from a sample form (no network).
  2. A second Deployment contact-mailer-next (no Ingress), port-forwarded: a real form with one small PDF → one mail arrives at info@ with Reply-To = the sender and the attachment; an 11 MB file → refused; six files → refused.
  3. Compare its mail with one from the running program (same fields, same subject line).

Switch-over (attended)

Point the Deployment at the new tag, wait for Ready, send one form from felhom.eu/kapcsolat and one from /en/contact, read both mails. Roll back = the old manifest line (the old image stays in containerd, and its binary is kept in documentation/audits/mailer-source-2026-10-08/contact-mailer.bin).

One question for the operator

Do you still have the February folder on your Windows workstation (e:\DooPlex Server\… or a „contact-mailer" folder)? Pick: look there first — if it is there, it is committed as it is and this plan shrinks to „rebuild with a version tag". If you do nothing: the replacement is written from this page in a later website/ops task.