mirror of
https://github.com/fawney19/Aether.git
synced 2026-10-04 08:27:46 +08:00
Merge branch 'pr-503'
# Conflicts: # apps/aether-gateway/src/handlers/admin/provider/summary/value.rs # apps/aether-gateway/src/lib.rs # apps/aether-gateway/src/maintenance/mod.rs # apps/aether-gateway/src/maintenance/runtime/workers.rs # frontend/src/api/endpoints/types/provider.ts
This commit is contained in:
@@ -37,6 +37,7 @@ pub(crate) use self::provider::oauth::runtime::{
|
||||
refresh_provider_oauth_account_state_after_update,
|
||||
};
|
||||
pub(crate) use self::provider::ops::providers::actions::admin_provider_ops_local_action_response;
|
||||
pub(crate) use self::provider::ops::providers::store_admin_provider_ops_balance_cache;
|
||||
pub(crate) use self::provider::pool::config::admin_provider_pool_config;
|
||||
pub(crate) use self::provider::pool_admin::maybe_build_local_admin_pool_response;
|
||||
pub(crate) use self::provider::shared::payloads::{
|
||||
|
||||
@@ -70,7 +70,7 @@ pub(super) async fn read_admin_provider_ops_balance_cache(
|
||||
}
|
||||
}
|
||||
|
||||
pub(super) async fn store_admin_provider_ops_balance_cache(
|
||||
pub(crate) async fn store_admin_provider_ops_balance_cache(
|
||||
state: &AdminAppState<'_>,
|
||||
provider_id: &str,
|
||||
payload: &Value,
|
||||
|
||||
@@ -1,4 +1,7 @@
|
||||
use super::support::{AdminProviderOpsSaveConfigRequest, ADMIN_PROVIDER_OPS_SENSITIVE_FIELDS};
|
||||
use super::support::{
|
||||
AdminProviderOpsQuotaAlertConfigRequest, AdminProviderOpsSaveConfigRequest,
|
||||
ADMIN_PROVIDER_OPS_SENSITIVE_FIELDS,
|
||||
};
|
||||
use crate::handlers::admin::request::AdminAppState;
|
||||
use crate::GatewayError;
|
||||
use aether_admin::provider::ops as admin_provider_ops_pure;
|
||||
@@ -8,6 +11,10 @@ use aether_data_contracts::repository::provider_catalog::{
|
||||
use serde_json::json;
|
||||
use std::time::{SystemTime, UNIX_EPOCH};
|
||||
|
||||
const PROVIDER_OPS_QUOTA_ALERT_DEFAULT_FETCH_INTERVAL_SECS: u64 = 30;
|
||||
const PROVIDER_OPS_QUOTA_ALERT_MIN_FETCH_INTERVAL_SECS: u64 = 30;
|
||||
const PROVIDER_OPS_QUOTA_ALERT_MAX_FETCH_INTERVAL_SECS: u64 = 86_400;
|
||||
|
||||
pub(super) fn admin_provider_ops_config_object(
|
||||
provider: &StoredProviderCatalogProvider,
|
||||
) -> Option<&serde_json::Map<String, serde_json::Value>> {
|
||||
@@ -276,6 +283,7 @@ pub(super) fn build_admin_provider_ops_saved_config_value(
|
||||
)
|
||||
})
|
||||
.collect::<serde_json::Map<String, serde_json::Value>>();
|
||||
let quota_alert = normalize_admin_provider_ops_quota_alert(payload.quota_alert)?;
|
||||
|
||||
Ok(json!({
|
||||
"architecture_id": payload.architecture_id,
|
||||
@@ -287,9 +295,48 @@ pub(super) fn build_admin_provider_ops_saved_config_value(
|
||||
},
|
||||
"actions": actions,
|
||||
"schedule": payload.schedule,
|
||||
"quota_alert": quota_alert,
|
||||
}))
|
||||
}
|
||||
|
||||
fn normalize_admin_provider_ops_quota_alert(
|
||||
request: Option<AdminProviderOpsQuotaAlertConfigRequest>,
|
||||
) -> Result<serde_json::Value, String> {
|
||||
let Some(request) = request else {
|
||||
return Ok(default_admin_provider_ops_quota_alert());
|
||||
};
|
||||
let threshold_amount = request.threshold_amount.unwrap_or(0.0);
|
||||
if threshold_amount < 0.0 {
|
||||
return Err("quota_alert.threshold_amount 必须大于等于 0".to_string());
|
||||
}
|
||||
let fetch_interval_seconds = request
|
||||
.fetch_interval_seconds
|
||||
.unwrap_or(PROVIDER_OPS_QUOTA_ALERT_DEFAULT_FETCH_INTERVAL_SECS);
|
||||
if !(PROVIDER_OPS_QUOTA_ALERT_MIN_FETCH_INTERVAL_SECS
|
||||
..=PROVIDER_OPS_QUOTA_ALERT_MAX_FETCH_INTERVAL_SECS)
|
||||
.contains(&fetch_interval_seconds)
|
||||
{
|
||||
return Err(format!(
|
||||
"quota_alert.fetch_interval_seconds 必须在 {} 到 {} 秒之间",
|
||||
PROVIDER_OPS_QUOTA_ALERT_MIN_FETCH_INTERVAL_SECS,
|
||||
PROVIDER_OPS_QUOTA_ALERT_MAX_FETCH_INTERVAL_SECS
|
||||
));
|
||||
}
|
||||
Ok(json!({
|
||||
"enabled": request.enabled,
|
||||
"threshold_amount": threshold_amount,
|
||||
"fetch_interval_seconds": fetch_interval_seconds,
|
||||
}))
|
||||
}
|
||||
|
||||
fn default_admin_provider_ops_quota_alert() -> serde_json::Value {
|
||||
json!({
|
||||
"enabled": false,
|
||||
"threshold_amount": 0.0,
|
||||
"fetch_interval_seconds": PROVIDER_OPS_QUOTA_ALERT_DEFAULT_FETCH_INTERVAL_SECS,
|
||||
})
|
||||
}
|
||||
|
||||
pub(super) fn resolve_admin_provider_ops_base_url(
|
||||
provider: &StoredProviderCatalogProvider,
|
||||
endpoints: &[StoredProviderCatalogEndpoint],
|
||||
@@ -356,5 +403,10 @@ pub(super) fn build_admin_provider_ops_config_payload(
|
||||
connector.and_then(|connector| connector.get("credentials")),
|
||||
),
|
||||
},
|
||||
"quota_alert": provider_ops_config
|
||||
.get("quota_alert")
|
||||
.filter(|value| value.is_object())
|
||||
.cloned()
|
||||
.unwrap_or_else(default_admin_provider_ops_quota_alert),
|
||||
})
|
||||
}
|
||||
|
||||
@@ -4,4 +4,5 @@ mod config;
|
||||
mod routes;
|
||||
mod support;
|
||||
mod verify;
|
||||
pub(crate) use self::balance_cache::store_admin_provider_ops_balance_cache;
|
||||
pub(super) use self::routes::maybe_build_local_admin_provider_ops_providers_response;
|
||||
|
||||
@@ -33,6 +33,8 @@ pub(super) struct AdminProviderOpsSaveConfigRequest {
|
||||
pub(crate) actions: BTreeMap<String, AdminProviderOpsActionConfigRequest>,
|
||||
#[serde(default)]
|
||||
pub(crate) schedule: BTreeMap<String, String>,
|
||||
#[serde(default)]
|
||||
pub(crate) quota_alert: Option<AdminProviderOpsQuotaAlertConfigRequest>,
|
||||
}
|
||||
|
||||
#[derive(Debug, Deserialize)]
|
||||
@@ -52,6 +54,16 @@ pub(super) struct AdminProviderOpsActionConfigRequest {
|
||||
pub(crate) config: serde_json::Map<String, serde_json::Value>,
|
||||
}
|
||||
|
||||
#[derive(Debug, Deserialize)]
|
||||
pub(super) struct AdminProviderOpsQuotaAlertConfigRequest {
|
||||
#[serde(default)]
|
||||
pub(crate) enabled: bool,
|
||||
#[serde(default, deserialize_with = "deserialize_optional_f64_from_number")]
|
||||
pub(crate) threshold_amount: Option<f64>,
|
||||
#[serde(default)]
|
||||
pub(crate) fetch_interval_seconds: Option<u64>,
|
||||
}
|
||||
|
||||
#[derive(Debug, Deserialize)]
|
||||
pub(super) struct AdminProviderOpsConnectRequest {
|
||||
#[serde(default)]
|
||||
@@ -71,3 +83,28 @@ fn default_admin_provider_ops_architecture_id() -> String {
|
||||
fn default_admin_provider_ops_action_enabled() -> bool {
|
||||
true
|
||||
}
|
||||
|
||||
fn deserialize_optional_f64_from_number<'de, D>(deserializer: D) -> Result<Option<f64>, D::Error>
|
||||
where
|
||||
D: serde::Deserializer<'de>,
|
||||
{
|
||||
let value = Option::<serde_json::Value>::deserialize(deserializer)?;
|
||||
match value {
|
||||
None | Some(serde_json::Value::Null) => Ok(None),
|
||||
Some(serde_json::Value::Number(number)) => number
|
||||
.as_f64()
|
||||
.filter(|value| value.is_finite())
|
||||
.map(Some)
|
||||
.ok_or_else(|| serde::de::Error::custom("expected a finite number")),
|
||||
Some(serde_json::Value::String(raw)) => raw
|
||||
.trim()
|
||||
.parse::<f64>()
|
||||
.ok()
|
||||
.filter(|value| value.is_finite())
|
||||
.map(Some)
|
||||
.ok_or_else(|| serde::de::Error::custom("expected a finite number or numeric string")),
|
||||
Some(_) => Err(serde::de::Error::custom(
|
||||
"expected a finite number or numeric string",
|
||||
)),
|
||||
}
|
||||
}
|
||||
|
||||
@@ -138,6 +138,13 @@ pub(crate) fn build_admin_provider_summary_value(
|
||||
.and_then(|cfg| cfg.get("simulated_cache_enabled"))
|
||||
.and_then(serde_json::Value::as_bool)
|
||||
.unwrap_or(false);
|
||||
let ops_quota_alert_enabled = provider_ops_config
|
||||
.and_then(serde_json::Value::as_object)
|
||||
.and_then(|cfg| cfg.get("quota_alert"))
|
||||
.and_then(serde_json::Value::as_object)
|
||||
.and_then(|cfg| cfg.get("enabled"))
|
||||
.and_then(serde_json::Value::as_bool)
|
||||
.unwrap_or(false);
|
||||
let billing_type = quota_snapshot
|
||||
.map(|quota| quota.billing_type.clone())
|
||||
.or_else(|| provider.billing_type.clone());
|
||||
@@ -197,6 +204,7 @@ pub(crate) fn build_admin_provider_summary_value(
|
||||
"ops_configured": ops_configured,
|
||||
"ops_architecture_id": ops_architecture_id,
|
||||
"kiro_simulated_cache_enabled": kiro_simulated_cache_enabled,
|
||||
"ops_quota_alert_enabled": ops_quota_alert_enabled,
|
||||
"created_at": endpoint_timestamp_or_now(provider.created_at_unix_ms, now_unix_secs),
|
||||
"updated_at": endpoint_timestamp_or_now(provider.updated_at_unix_secs, now_unix_secs),
|
||||
})
|
||||
|
||||
@@ -17,6 +17,7 @@ use crate::handlers::admin::system::shared::settings::{
|
||||
build_admin_system_stats_payload, current_aether_version, fetch_latest_admin_system_release,
|
||||
};
|
||||
use crate::handlers::admin::system::shared::smtp::build_admin_smtp_test_payload;
|
||||
use crate::important_notification::build_important_notification_test_payload;
|
||||
use crate::maintenance::{ManualUsageCleanupMode, ManualUsageCleanupOptions};
|
||||
use crate::GatewayError;
|
||||
use aether_data_contracts::repository::usage::UsageCleanupTargets;
|
||||
@@ -241,6 +242,16 @@ pub(super) async fn maybe_build_local_admin_core_system_response(
|
||||
));
|
||||
}
|
||||
|
||||
if decision.route_kind.as_deref() == Some("important_notification_test")
|
||||
&& request_method == http::Method::POST
|
||||
&& request_path == "/api/admin/system/important-notification/test"
|
||||
{
|
||||
return Ok(Some(
|
||||
Json(build_important_notification_test_payload(state, request_body).await?)
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
|
||||
if decision.route_kind.as_deref() == Some("cleanup") && request_method == http::Method::POST {
|
||||
return Ok(Some(attach_admin_audit_response(
|
||||
Json(build_admin_system_cleanup_payload(state).await?).into_response(),
|
||||
|
||||
@@ -1,5 +1,9 @@
|
||||
use crate::handlers::admin::request::AdminAppState;
|
||||
use crate::handlers::shared::{module_available_from_env, system_config_bool};
|
||||
use crate::important_notification::{
|
||||
important_notification_configured, IMPORTANT_NOTIFICATION_ENABLED_KEY,
|
||||
LEGACY_NOTIFICATION_EMAIL_ENABLED_KEY,
|
||||
};
|
||||
use crate::system_features::ENABLE_MODEL_DIRECTIVES_CONFIG_KEY;
|
||||
use crate::GatewayError;
|
||||
use aether_admin::system as admin_system_kernel;
|
||||
@@ -68,14 +72,14 @@ pub(crate) const ADMIN_MODULE_DEFINITIONS: &[AdminModuleDefinition] = &[
|
||||
admin_menu_order: 59,
|
||||
},
|
||||
AdminModuleDefinition {
|
||||
name: "notification_email",
|
||||
display_name: "异常通知",
|
||||
description: "为 5xx 异常发送邮件通知,可在模块管理中启用或禁用",
|
||||
name: "important_notification",
|
||||
display_name: "重要通知",
|
||||
description: "统一发送邮件和 Server 酱重要通知,供额度提醒等后台任务使用",
|
||||
category: "integration",
|
||||
env_key: "NOTIFICATION_EMAIL_AVAILABLE",
|
||||
env_key: "IMPORTANT_NOTIFICATION_AVAILABLE",
|
||||
default_available: true,
|
||||
admin_route: None,
|
||||
admin_menu_icon: Some("Mail"),
|
||||
admin_route: Some("/admin/modules/important-notification"),
|
||||
admin_menu_icon: Some("BellRing"),
|
||||
admin_menu_group: Some("system"),
|
||||
admin_menu_order: 58,
|
||||
},
|
||||
@@ -150,10 +154,15 @@ pub(crate) struct AdminModuleRuntimeState {
|
||||
oauth_providers: Vec<aether_data::repository::auth_modules::StoredOAuthProviderModuleConfig>,
|
||||
ldap_config: Option<aether_data::repository::auth_modules::StoredLdapModuleConfig>,
|
||||
gemini_files_has_capable_key: bool,
|
||||
smtp_configured: bool,
|
||||
important_notification_configured: bool,
|
||||
}
|
||||
|
||||
pub(crate) fn admin_module_by_name(name: &str) -> Option<&'static AdminModuleDefinition> {
|
||||
let name = if name == "notification_email" {
|
||||
"important_notification"
|
||||
} else {
|
||||
name
|
||||
};
|
||||
ADMIN_MODULE_DEFINITIONS
|
||||
.iter()
|
||||
.find(|module| module.name == name)
|
||||
@@ -170,11 +179,22 @@ pub(crate) fn admin_module_name_from_enabled_path(request_path: &str) -> Option<
|
||||
pub(crate) fn admin_module_enabled_config_key(module: &AdminModuleDefinition) -> String {
|
||||
if module.name == "model_directives" {
|
||||
ENABLE_MODEL_DIRECTIVES_CONFIG_KEY.to_string()
|
||||
} else if module.name == "important_notification" {
|
||||
IMPORTANT_NOTIFICATION_ENABLED_KEY.to_string()
|
||||
} else {
|
||||
format!("module.{}.enabled", module.name)
|
||||
}
|
||||
}
|
||||
|
||||
fn admin_module_available(module: &AdminModuleDefinition) -> bool {
|
||||
if module.name == "important_notification" {
|
||||
let legacy_default =
|
||||
module_available_from_env("NOTIFICATION_EMAIL_AVAILABLE", module.default_available);
|
||||
return module_available_from_env(module.env_key, legacy_default);
|
||||
}
|
||||
module_available_from_env(module.env_key, module.default_available)
|
||||
}
|
||||
|
||||
pub(crate) fn oauth_module_config_is_valid(
|
||||
providers: &[aether_data::repository::auth_modules::StoredOAuthProviderModuleConfig],
|
||||
) -> bool {
|
||||
@@ -221,28 +241,13 @@ pub(crate) async fn build_admin_module_runtime_state(
|
||||
})
|
||||
};
|
||||
|
||||
let smtp_host = state.read_system_config_json_value("smtp_host").await?;
|
||||
let smtp_from_email = state
|
||||
.read_system_config_json_value("smtp_from_email")
|
||||
.await?;
|
||||
let smtp_configured = smtp_host
|
||||
.as_ref()
|
||||
.and_then(serde_json::Value::as_str)
|
||||
.map(str::trim)
|
||||
.filter(|value| !value.is_empty())
|
||||
.is_some()
|
||||
&& smtp_from_email
|
||||
.as_ref()
|
||||
.and_then(serde_json::Value::as_str)
|
||||
.map(str::trim)
|
||||
.filter(|value| !value.is_empty())
|
||||
.is_some();
|
||||
let notification_configured = important_notification_configured(state.app()).await?;
|
||||
|
||||
Ok(AdminModuleRuntimeState {
|
||||
oauth_providers,
|
||||
ldap_config,
|
||||
gemini_files_has_capable_key,
|
||||
smtp_configured,
|
||||
important_notification_configured: notification_configured,
|
||||
})
|
||||
}
|
||||
|
||||
@@ -255,7 +260,7 @@ pub(crate) fn build_admin_module_validation_result(
|
||||
&runtime.oauth_providers,
|
||||
runtime.ldap_config.as_ref(),
|
||||
runtime.gemini_files_has_capable_key,
|
||||
runtime.smtp_configured,
|
||||
runtime.important_notification_configured,
|
||||
)
|
||||
}
|
||||
|
||||
@@ -274,12 +279,19 @@ pub(crate) async fn build_admin_module_status_payload(
|
||||
module: &AdminModuleDefinition,
|
||||
runtime: &AdminModuleRuntimeState,
|
||||
) -> Result<serde_json::Value, GatewayError> {
|
||||
let available = module_available_from_env(module.env_key, module.default_available);
|
||||
let available = admin_module_available(module);
|
||||
let enabled = if available {
|
||||
let enabled = state
|
||||
let enabled_value = state
|
||||
.read_system_config_json_value(&admin_module_enabled_config_key(module))
|
||||
.await?;
|
||||
system_config_bool(enabled.as_ref(), false)
|
||||
let enabled_value = if module.name == "important_notification" && enabled_value.is_none() {
|
||||
state
|
||||
.read_system_config_json_value(LEGACY_NOTIFICATION_EMAIL_ENABLED_KEY)
|
||||
.await?
|
||||
} else {
|
||||
enabled_value
|
||||
};
|
||||
system_config_bool(enabled_value.as_ref(), false)
|
||||
} else {
|
||||
false
|
||||
};
|
||||
|
||||
@@ -1,14 +1,10 @@
|
||||
use crate::email_delivery::{probe_smtp_connection, system_config_u16, SmtpDeliveryConfig};
|
||||
use crate::handlers::admin::request::AdminAppState;
|
||||
use crate::handlers::shared::{system_config_bool, system_config_string};
|
||||
use crate::GatewayError;
|
||||
use axum::body::Bytes;
|
||||
use base64::Engine;
|
||||
use serde::Deserialize;
|
||||
use serde_json::json;
|
||||
use std::io::{BufRead, Write};
|
||||
use std::time::Duration;
|
||||
|
||||
const SMTP_TIMEOUT_SECS: u64 = 30;
|
||||
|
||||
#[derive(Debug, Default, Deserialize)]
|
||||
struct AdminSmtpTestRequest {
|
||||
@@ -53,12 +49,12 @@ pub(crate) async fn build_admin_smtp_test_payload(
|
||||
}));
|
||||
}
|
||||
|
||||
let result = tokio::task::spawn_blocking(move || test_smtp_connection_blocking(config))
|
||||
.await
|
||||
.map_err(|err| GatewayError::Internal(err.to_string()))?;
|
||||
let result = probe_smtp_connection(config.into_delivery_config()).await;
|
||||
Ok(match result {
|
||||
Ok(()) => json!({ "success": true, "message": "SMTP 连接测试成功" }),
|
||||
Err(error) => json!({ "success": false, "message": translate_smtp_error(&error) }),
|
||||
Err(error) => {
|
||||
json!({ "success": false, "message": translate_smtp_error(&smtp_gateway_error_message(&error)) })
|
||||
}
|
||||
})
|
||||
}
|
||||
|
||||
@@ -94,8 +90,8 @@ async fn resolve_admin_smtp_config(
|
||||
port: request
|
||||
.smtp_port
|
||||
.as_ref()
|
||||
.map(|value| system_config_u16(value, 587))
|
||||
.unwrap_or_else(|| system_config_u16_opt(smtp_port.as_ref(), 587)),
|
||||
.map(|value| system_config_u16(Some(value), 587))
|
||||
.unwrap_or_else(|| system_config_u16(smtp_port.as_ref(), 587)),
|
||||
user: request
|
||||
.smtp_user
|
||||
.as_ref()
|
||||
@@ -130,6 +126,21 @@ async fn resolve_admin_smtp_config(
|
||||
})
|
||||
}
|
||||
|
||||
impl ResolvedSmtpConfig {
|
||||
fn into_delivery_config(self) -> SmtpDeliveryConfig {
|
||||
SmtpDeliveryConfig {
|
||||
host: self.host.unwrap_or_default(),
|
||||
port: self.port,
|
||||
user: self.user,
|
||||
password: self.password,
|
||||
use_tls: self.use_tls,
|
||||
use_ssl: self.use_ssl,
|
||||
from_email: self.from_email.unwrap_or_default(),
|
||||
from_name: self.from_name,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn missing_smtp_fields(config: &ResolvedSmtpConfig) -> Vec<&'static str> {
|
||||
let mut fields = Vec::new();
|
||||
if config
|
||||
@@ -171,178 +182,13 @@ fn missing_smtp_fields(config: &ResolvedSmtpConfig) -> Vec<&'static str> {
|
||||
fields
|
||||
}
|
||||
|
||||
fn system_config_u16_opt(value: Option<&serde_json::Value>, default: u16) -> u16 {
|
||||
value
|
||||
.map(|value| system_config_u16(value, default))
|
||||
.unwrap_or(default)
|
||||
}
|
||||
|
||||
fn system_config_u16(value: &serde_json::Value, default: u16) -> u16 {
|
||||
match value {
|
||||
serde_json::Value::Number(value) => value
|
||||
.as_u64()
|
||||
.and_then(|value| u16::try_from(value).ok())
|
||||
.unwrap_or(default),
|
||||
serde_json::Value::String(value) => value.trim().parse::<u16>().unwrap_or(default),
|
||||
_ => default,
|
||||
fn smtp_gateway_error_message(error: &GatewayError) -> String {
|
||||
match error {
|
||||
GatewayError::Internal(message) => message.clone(),
|
||||
_ => format!("{error:?}"),
|
||||
}
|
||||
}
|
||||
|
||||
fn build_tls_config() -> std::sync::Arc<rustls::ClientConfig> {
|
||||
let _ = rustls::crypto::ring::default_provider().install_default();
|
||||
let root_store =
|
||||
rustls::RootCertStore::from_iter(webpki_roots::TLS_SERVER_ROOTS.iter().cloned());
|
||||
std::sync::Arc::new(
|
||||
rustls::ClientConfig::builder()
|
||||
.with_root_certificates(root_store)
|
||||
.with_no_client_auth(),
|
||||
)
|
||||
}
|
||||
|
||||
fn resolve_server_name(host: &str) -> Result<rustls::pki_types::ServerName<'static>, String> {
|
||||
let host = host.trim().trim_start_matches('[').trim_end_matches(']');
|
||||
if let Ok(ip) = host.parse::<std::net::IpAddr>() {
|
||||
return Ok(rustls::pki_types::ServerName::from(ip));
|
||||
}
|
||||
rustls::pki_types::ServerName::try_from(host.to_string()).map_err(|err| err.to_string())
|
||||
}
|
||||
|
||||
fn connect_tcp_stream(config: &ResolvedSmtpConfig) -> Result<std::net::TcpStream, String> {
|
||||
let host = config.host.as_deref().unwrap_or_default();
|
||||
let stream =
|
||||
std::net::TcpStream::connect((host, config.port)).map_err(|err| err.to_string())?;
|
||||
stream
|
||||
.set_read_timeout(Some(Duration::from_secs(SMTP_TIMEOUT_SECS)))
|
||||
.map_err(|err| err.to_string())?;
|
||||
stream
|
||||
.set_write_timeout(Some(Duration::from_secs(SMTP_TIMEOUT_SECS)))
|
||||
.map_err(|err| err.to_string())?;
|
||||
Ok(stream)
|
||||
}
|
||||
|
||||
fn wrap_tls_stream(
|
||||
stream: std::net::TcpStream,
|
||||
host: &str,
|
||||
) -> Result<rustls::StreamOwned<rustls::ClientConnection, std::net::TcpStream>, String> {
|
||||
let server_name = resolve_server_name(host)?;
|
||||
let connection = rustls::ClientConnection::new(build_tls_config(), server_name)
|
||||
.map_err(|err| err.to_string())?;
|
||||
Ok(rustls::StreamOwned::new(connection, stream))
|
||||
}
|
||||
|
||||
fn smtp_read_response<T: BufRead>(reader: &mut T) -> Result<(u16, String), String> {
|
||||
let mut message = String::new();
|
||||
let code = loop {
|
||||
let mut line = String::new();
|
||||
let bytes = reader.read_line(&mut line).map_err(|err| err.to_string())?;
|
||||
if bytes == 0 {
|
||||
return Err("smtp connection closed unexpectedly".to_string());
|
||||
}
|
||||
let trimmed = line.trim_end_matches(['\r', '\n']).to_string();
|
||||
if trimmed.len() < 3 {
|
||||
return Err("invalid smtp response".to_string());
|
||||
}
|
||||
let parsed_code = trimmed[..3].parse::<u16>().map_err(|err| err.to_string())?;
|
||||
let continuation = trimmed.as_bytes().get(3).copied() == Some(b'-');
|
||||
if !message.is_empty() {
|
||||
message.push('\n');
|
||||
}
|
||||
message.push_str(&trimmed);
|
||||
if !continuation {
|
||||
break parsed_code;
|
||||
}
|
||||
};
|
||||
Ok((code, message))
|
||||
}
|
||||
|
||||
fn smtp_expect<T: BufRead>(reader: &mut T, allowed_codes: &[u16]) -> Result<String, String> {
|
||||
let (code, message) = smtp_read_response(reader)?;
|
||||
if allowed_codes.contains(&code) {
|
||||
return Ok(message);
|
||||
}
|
||||
Err(format!("unexpected smtp response {code}: {message}"))
|
||||
}
|
||||
|
||||
fn smtp_write_line<T: Write>(writer: &mut T, line: &str) -> Result<(), String> {
|
||||
writer
|
||||
.write_all(line.as_bytes())
|
||||
.map_err(|err| err.to_string())?;
|
||||
writer.write_all(b"\r\n").map_err(|err| err.to_string())?;
|
||||
writer.flush().map_err(|err| err.to_string())
|
||||
}
|
||||
|
||||
fn smtp_send_command<S: std::io::Read + Write>(
|
||||
reader: &mut std::io::BufReader<S>,
|
||||
command: &str,
|
||||
allowed_codes: &[u16],
|
||||
) -> Result<String, String> {
|
||||
smtp_write_line(reader.get_mut(), command)?;
|
||||
smtp_expect(reader, allowed_codes)
|
||||
}
|
||||
|
||||
fn smtp_authenticate<S: std::io::Read + Write>(
|
||||
reader: &mut std::io::BufReader<S>,
|
||||
config: &ResolvedSmtpConfig,
|
||||
) -> Result<(), String> {
|
||||
let Some(username) = config
|
||||
.user
|
||||
.as_deref()
|
||||
.map(str::trim)
|
||||
.filter(|value| !value.is_empty())
|
||||
else {
|
||||
return Ok(());
|
||||
};
|
||||
let password = config.password.as_deref().unwrap_or_default();
|
||||
smtp_send_command(reader, "AUTH LOGIN", &[334])?;
|
||||
smtp_send_command(
|
||||
reader,
|
||||
&base64::engine::general_purpose::STANDARD.encode(username.as_bytes()),
|
||||
&[334],
|
||||
)?;
|
||||
smtp_send_command(
|
||||
reader,
|
||||
&base64::engine::general_purpose::STANDARD.encode(password.as_bytes()),
|
||||
&[235],
|
||||
)?;
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn smtp_probe<S: std::io::Read + Write>(
|
||||
reader: &mut std::io::BufReader<S>,
|
||||
config: &ResolvedSmtpConfig,
|
||||
) -> Result<(), String> {
|
||||
smtp_send_command(reader, "EHLO aether.local", &[250])?;
|
||||
smtp_authenticate(reader, config)?;
|
||||
let _ = smtp_send_command(reader, "QUIT", &[221]);
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn test_smtp_connection_blocking(config: ResolvedSmtpConfig) -> Result<(), String> {
|
||||
if config.use_ssl {
|
||||
let stream = connect_tcp_stream(&config)?;
|
||||
let tls_stream = wrap_tls_stream(stream, config.host.as_deref().unwrap_or_default())?;
|
||||
let mut reader = std::io::BufReader::new(tls_stream);
|
||||
smtp_expect(&mut reader, &[220])?;
|
||||
return smtp_probe(&mut reader, &config);
|
||||
}
|
||||
|
||||
let stream = connect_tcp_stream(&config)?;
|
||||
let mut reader = std::io::BufReader::new(stream);
|
||||
smtp_expect(&mut reader, &[220])?;
|
||||
smtp_send_command(&mut reader, "EHLO aether.local", &[250])?;
|
||||
if config.use_tls {
|
||||
smtp_send_command(&mut reader, "STARTTLS", &[220])?;
|
||||
let stream = reader.into_inner();
|
||||
let tls_stream = wrap_tls_stream(stream, config.host.as_deref().unwrap_or_default())?;
|
||||
let mut reader = std::io::BufReader::new(tls_stream);
|
||||
return smtp_probe(&mut reader, &config);
|
||||
}
|
||||
|
||||
smtp_authenticate(&mut reader, &config)?;
|
||||
let _ = smtp_send_command(&mut reader, "QUIT", &[221]);
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn translate_smtp_error(error: &str) -> String {
|
||||
let error_lower = error.to_ascii_lowercase();
|
||||
|
||||
|
||||
@@ -1,11 +1,11 @@
|
||||
use super::{
|
||||
decrypt_catalog_secret_with_fallbacks, escape_admin_email_template_html, json,
|
||||
read_admin_email_template_payload, render_admin_email_template_html, system_config_bool,
|
||||
system_config_string, system_config_u16, AppState, GatewayError,
|
||||
escape_admin_email_template_html, json, read_admin_email_template_payload,
|
||||
render_admin_email_template_html, system_config_string, AppState, GatewayError,
|
||||
AUTH_EMAIL_VERIFICATION_PREFIX, AUTH_EMAIL_VERIFIED_PREFIX, AUTH_EMAIL_VERIFIED_TTL_SECS,
|
||||
AUTH_SMTP_TIMEOUT_SECS,
|
||||
};
|
||||
use base64::Engine;
|
||||
use crate::email_delivery::{
|
||||
read_smtp_delivery_config, send_smtp_email, ComposedEmail, SmtpDeliveryConfig,
|
||||
};
|
||||
|
||||
#[derive(Debug, Clone, serde::Serialize, serde::Deserialize)]
|
||||
pub(super) struct StoredAuthEmailVerificationCode {
|
||||
@@ -13,25 +13,8 @@ pub(super) struct StoredAuthEmailVerificationCode {
|
||||
pub(super) created_at: String,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone)]
|
||||
pub(super) struct AuthSmtpConfig {
|
||||
pub(super) host: String,
|
||||
pub(super) port: u16,
|
||||
pub(super) user: Option<String>,
|
||||
pub(super) password: Option<String>,
|
||||
pub(super) use_tls: bool,
|
||||
pub(super) use_ssl: bool,
|
||||
pub(super) from_email: String,
|
||||
pub(super) from_name: String,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone)]
|
||||
pub(super) struct AuthComposedEmail {
|
||||
pub(super) to_email: String,
|
||||
pub(super) subject: String,
|
||||
pub(super) html_body: String,
|
||||
pub(super) text_body: String,
|
||||
}
|
||||
pub(super) type AuthSmtpConfig = SmtpDeliveryConfig;
|
||||
pub(super) type AuthComposedEmail = ComposedEmail;
|
||||
|
||||
pub(super) fn auth_email_verification_key(email: &str) -> String {
|
||||
format!("{AUTH_EMAIL_VERIFICATION_PREFIX}{email}")
|
||||
@@ -84,25 +67,6 @@ fn render_auth_template_string(
|
||||
Ok(rendered)
|
||||
}
|
||||
|
||||
fn auth_encode_mime_header(value: &str) -> String {
|
||||
if value.is_ascii() {
|
||||
return value.to_string();
|
||||
}
|
||||
format!(
|
||||
"=?UTF-8?B?{}?=",
|
||||
base64::engine::general_purpose::STANDARD.encode(value.as_bytes())
|
||||
)
|
||||
}
|
||||
|
||||
fn auth_wrap_base64(value: &str) -> String {
|
||||
let mut wrapped = String::new();
|
||||
for chunk in value.as_bytes().chunks(76) {
|
||||
wrapped.push_str(std::str::from_utf8(chunk).unwrap_or_default());
|
||||
wrapped.push_str("\r\n");
|
||||
}
|
||||
wrapped
|
||||
}
|
||||
|
||||
fn auth_build_verification_text_body(
|
||||
app_name: &str,
|
||||
email: &str,
|
||||
@@ -114,244 +78,6 @@ fn auth_build_verification_text_body(
|
||||
)
|
||||
}
|
||||
|
||||
fn auth_build_tls_config() -> std::sync::Arc<rustls::ClientConfig> {
|
||||
let _ = rustls::crypto::ring::default_provider().install_default();
|
||||
let root_store =
|
||||
rustls::RootCertStore::from_iter(webpki_roots::TLS_SERVER_ROOTS.iter().cloned());
|
||||
let config = rustls::ClientConfig::builder()
|
||||
.with_root_certificates(root_store)
|
||||
.with_no_client_auth();
|
||||
std::sync::Arc::new(config)
|
||||
}
|
||||
|
||||
fn auth_resolve_server_name(
|
||||
host: &str,
|
||||
) -> Result<rustls::pki_types::ServerName<'static>, GatewayError> {
|
||||
let host = host.trim().trim_start_matches('[').trim_end_matches(']');
|
||||
if let Ok(ip) = host.parse::<std::net::IpAddr>() {
|
||||
return Ok(rustls::pki_types::ServerName::from(ip));
|
||||
}
|
||||
rustls::pki_types::ServerName::try_from(host.to_string())
|
||||
.map_err(|err| GatewayError::Internal(err.to_string()))
|
||||
}
|
||||
|
||||
fn auth_connect_tcp_stream(config: &AuthSmtpConfig) -> Result<std::net::TcpStream, GatewayError> {
|
||||
let stream = std::net::TcpStream::connect((config.host.as_str(), config.port))
|
||||
.map_err(|err| GatewayError::Internal(err.to_string()))?;
|
||||
stream
|
||||
.set_read_timeout(Some(std::time::Duration::from_secs(AUTH_SMTP_TIMEOUT_SECS)))
|
||||
.map_err(|err| GatewayError::Internal(err.to_string()))?;
|
||||
stream
|
||||
.set_write_timeout(Some(std::time::Duration::from_secs(AUTH_SMTP_TIMEOUT_SECS)))
|
||||
.map_err(|err| GatewayError::Internal(err.to_string()))?;
|
||||
Ok(stream)
|
||||
}
|
||||
|
||||
fn auth_wrap_tls_stream(
|
||||
stream: std::net::TcpStream,
|
||||
host: &str,
|
||||
) -> Result<rustls::StreamOwned<rustls::ClientConnection, std::net::TcpStream>, GatewayError> {
|
||||
let server_name = auth_resolve_server_name(host)?;
|
||||
let connection = rustls::ClientConnection::new(auth_build_tls_config(), server_name)
|
||||
.map_err(|err| GatewayError::Internal(err.to_string()))?;
|
||||
Ok(rustls::StreamOwned::new(connection, stream))
|
||||
}
|
||||
|
||||
fn auth_smtp_read_response<T: std::io::BufRead>(
|
||||
reader: &mut T,
|
||||
) -> Result<(u16, String), GatewayError> {
|
||||
let mut message = String::new();
|
||||
let code = loop {
|
||||
let parsed_code;
|
||||
let continuation;
|
||||
let trimmed;
|
||||
{
|
||||
let mut line = String::new();
|
||||
let bytes = reader
|
||||
.read_line(&mut line)
|
||||
.map_err(|err| GatewayError::Internal(err.to_string()))?;
|
||||
if bytes == 0 {
|
||||
return Err(GatewayError::Internal(
|
||||
"smtp connection closed unexpectedly".to_string(),
|
||||
));
|
||||
}
|
||||
trimmed = line.trim_end_matches(['\r', '\n']).to_string();
|
||||
if trimmed.len() < 3 {
|
||||
return Err(GatewayError::Internal("invalid smtp response".to_string()));
|
||||
}
|
||||
parsed_code = trimmed[..3]
|
||||
.parse::<u16>()
|
||||
.map_err(|err| GatewayError::Internal(err.to_string()))?;
|
||||
continuation = trimmed.as_bytes().get(3).copied() == Some(b'-');
|
||||
}
|
||||
if !message.is_empty() {
|
||||
message.push('\n');
|
||||
}
|
||||
message.push_str(&trimmed);
|
||||
if !continuation {
|
||||
break parsed_code;
|
||||
}
|
||||
};
|
||||
Ok((code, message))
|
||||
}
|
||||
|
||||
fn auth_smtp_expect<T: std::io::BufRead>(
|
||||
reader: &mut T,
|
||||
allowed_codes: &[u16],
|
||||
) -> Result<String, GatewayError> {
|
||||
let (code, message) = auth_smtp_read_response(reader)?;
|
||||
if allowed_codes.contains(&code) {
|
||||
return Ok(message);
|
||||
}
|
||||
Err(GatewayError::Internal(format!(
|
||||
"unexpected smtp response {code}: {message}"
|
||||
)))
|
||||
}
|
||||
|
||||
fn auth_smtp_write_line<T: std::io::Write>(writer: &mut T, line: &str) -> Result<(), GatewayError> {
|
||||
writer
|
||||
.write_all(line.as_bytes())
|
||||
.map_err(|err| GatewayError::Internal(err.to_string()))?;
|
||||
writer
|
||||
.write_all(b"\r\n")
|
||||
.map_err(|err| GatewayError::Internal(err.to_string()))?;
|
||||
writer
|
||||
.flush()
|
||||
.map_err(|err| GatewayError::Internal(err.to_string()))
|
||||
}
|
||||
|
||||
fn auth_smtp_send_command<S: std::io::Read + std::io::Write>(
|
||||
reader: &mut std::io::BufReader<S>,
|
||||
command: &str,
|
||||
allowed_codes: &[u16],
|
||||
) -> Result<String, GatewayError> {
|
||||
auth_smtp_write_line(reader.get_mut(), command)?;
|
||||
auth_smtp_expect(reader, allowed_codes)
|
||||
}
|
||||
|
||||
fn auth_build_email_message(config: &AuthSmtpConfig, email: &AuthComposedEmail) -> String {
|
||||
let boundary = format!("aether-{}", uuid::Uuid::new_v4().simple());
|
||||
let text_body = auth_wrap_base64(
|
||||
&base64::engine::general_purpose::STANDARD.encode(email.text_body.as_bytes()),
|
||||
);
|
||||
let html_body = auth_wrap_base64(
|
||||
&base64::engine::general_purpose::STANDARD.encode(email.html_body.as_bytes()),
|
||||
);
|
||||
let from_header = if config.from_name.trim().is_empty() {
|
||||
format!("<{}>", config.from_email)
|
||||
} else {
|
||||
format!(
|
||||
"{} <{}>",
|
||||
auth_encode_mime_header(config.from_name.trim()),
|
||||
config.from_email
|
||||
)
|
||||
};
|
||||
format!(
|
||||
"From: {from_header}\r\nTo: <{to_email}>\r\nSubject: {subject}\r\nMIME-Version: 1.0\r\nContent-Type: multipart/alternative; boundary=\"{boundary}\"\r\n\r\n--{boundary}\r\nContent-Type: text/plain; charset=\"utf-8\"\r\nContent-Transfer-Encoding: base64\r\n\r\n{text_body}--{boundary}\r\nContent-Type: text/html; charset=\"utf-8\"\r\nContent-Transfer-Encoding: base64\r\n\r\n{html_body}--{boundary}--\r\n",
|
||||
to_email = email.to_email,
|
||||
subject = auth_encode_mime_header(&email.subject),
|
||||
)
|
||||
}
|
||||
|
||||
fn auth_smtp_authenticate<S: std::io::Read + std::io::Write>(
|
||||
reader: &mut std::io::BufReader<S>,
|
||||
config: &AuthSmtpConfig,
|
||||
) -> Result<(), GatewayError> {
|
||||
let Some(username) = config
|
||||
.user
|
||||
.as_deref()
|
||||
.map(str::trim)
|
||||
.filter(|value| !value.is_empty())
|
||||
else {
|
||||
return Ok(());
|
||||
};
|
||||
let password = config.password.as_deref().unwrap_or("");
|
||||
auth_smtp_send_command(reader, "AUTH LOGIN", &[334])?;
|
||||
auth_smtp_send_command(
|
||||
reader,
|
||||
&base64::engine::general_purpose::STANDARD.encode(username.as_bytes()),
|
||||
&[334],
|
||||
)?;
|
||||
auth_smtp_send_command(
|
||||
reader,
|
||||
&base64::engine::general_purpose::STANDARD.encode(password.as_bytes()),
|
||||
&[235],
|
||||
)?;
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn auth_smtp_deliver_message<S: std::io::Read + std::io::Write>(
|
||||
reader: &mut std::io::BufReader<S>,
|
||||
config: &AuthSmtpConfig,
|
||||
email: &AuthComposedEmail,
|
||||
) -> Result<(), GatewayError> {
|
||||
auth_smtp_send_command(
|
||||
reader,
|
||||
&format!("MAIL FROM:<{}>", config.from_email),
|
||||
&[250],
|
||||
)?;
|
||||
auth_smtp_send_command(
|
||||
reader,
|
||||
&format!("RCPT TO:<{}>", email.to_email),
|
||||
&[250, 251],
|
||||
)?;
|
||||
auth_smtp_send_command(reader, "DATA", &[354])?;
|
||||
let message = auth_build_email_message(config, email);
|
||||
reader
|
||||
.get_mut()
|
||||
.write_all(message.as_bytes())
|
||||
.map_err(|err| GatewayError::Internal(err.to_string()))?;
|
||||
reader
|
||||
.get_mut()
|
||||
.write_all(b"\r\n.\r\n")
|
||||
.map_err(|err| GatewayError::Internal(err.to_string()))?;
|
||||
reader
|
||||
.get_mut()
|
||||
.flush()
|
||||
.map_err(|err| GatewayError::Internal(err.to_string()))?;
|
||||
let _ = auth_smtp_expect(reader, &[250])?;
|
||||
let _ = auth_smtp_send_command(reader, "QUIT", &[221]);
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn auth_smtp_send_message<S: std::io::Read + std::io::Write>(
|
||||
reader: &mut std::io::BufReader<S>,
|
||||
config: &AuthSmtpConfig,
|
||||
email: &AuthComposedEmail,
|
||||
) -> Result<(), GatewayError> {
|
||||
auth_smtp_send_command(reader, "EHLO aether.local", &[250])?;
|
||||
auth_smtp_authenticate(reader, config)?;
|
||||
auth_smtp_deliver_message(reader, config, email)
|
||||
}
|
||||
|
||||
fn send_auth_email_blocking(
|
||||
config: AuthSmtpConfig,
|
||||
email: AuthComposedEmail,
|
||||
) -> Result<(), GatewayError> {
|
||||
if config.use_ssl {
|
||||
let stream = auth_connect_tcp_stream(&config)?;
|
||||
let tls_stream = auth_wrap_tls_stream(stream, &config.host)?;
|
||||
let mut reader = std::io::BufReader::new(tls_stream);
|
||||
let _ = auth_smtp_expect(&mut reader, &[220])?;
|
||||
return auth_smtp_send_message(&mut reader, &config, &email);
|
||||
}
|
||||
|
||||
let stream = auth_connect_tcp_stream(&config)?;
|
||||
let mut reader = std::io::BufReader::new(stream);
|
||||
let _ = auth_smtp_expect(&mut reader, &[220])?;
|
||||
let _ = auth_smtp_send_command(&mut reader, "EHLO aether.local", &[250])?;
|
||||
if config.use_tls {
|
||||
let _ = auth_smtp_send_command(&mut reader, "STARTTLS", &[220])?;
|
||||
let stream = reader.into_inner();
|
||||
let tls_stream = auth_wrap_tls_stream(stream, &config.host)?;
|
||||
let mut reader = std::io::BufReader::new(tls_stream);
|
||||
return auth_smtp_send_message(&mut reader, &config, &email);
|
||||
}
|
||||
|
||||
auth_smtp_authenticate(&mut reader, &config)?;
|
||||
auth_smtp_deliver_message(&mut reader, &config, &email)
|
||||
}
|
||||
|
||||
pub(super) async fn read_auth_email_verification_code(
|
||||
state: &AppState,
|
||||
email: &str,
|
||||
@@ -423,40 +149,7 @@ pub(super) async fn store_auth_email_verification_code(
|
||||
pub(super) async fn read_auth_smtp_config(
|
||||
state: &AppState,
|
||||
) -> Result<Option<AuthSmtpConfig>, GatewayError> {
|
||||
let smtp_host = state.read_system_config_json_value("smtp_host").await?;
|
||||
let smtp_from_email = state
|
||||
.read_system_config_json_value("smtp_from_email")
|
||||
.await?;
|
||||
let Some(host) = system_config_string(smtp_host.as_ref()) else {
|
||||
return Ok(None);
|
||||
};
|
||||
let Some(from_email) = system_config_string(smtp_from_email.as_ref()) else {
|
||||
return Ok(None);
|
||||
};
|
||||
let smtp_port = state.read_system_config_json_value("smtp_port").await?;
|
||||
let smtp_user = state.read_system_config_json_value("smtp_user").await?;
|
||||
let smtp_password = state.read_system_config_json_value("smtp_password").await?;
|
||||
let smtp_use_tls = state.read_system_config_json_value("smtp_use_tls").await?;
|
||||
let smtp_use_ssl = state.read_system_config_json_value("smtp_use_ssl").await?;
|
||||
let smtp_from_name = state
|
||||
.read_system_config_json_value("smtp_from_name")
|
||||
.await?;
|
||||
|
||||
let password = system_config_string(smtp_password.as_ref()).map(|value| {
|
||||
decrypt_catalog_secret_with_fallbacks(state.encryption_key(), &value).unwrap_or(value)
|
||||
});
|
||||
|
||||
Ok(Some(AuthSmtpConfig {
|
||||
host,
|
||||
port: system_config_u16(smtp_port.as_ref(), 587),
|
||||
user: system_config_string(smtp_user.as_ref()),
|
||||
password,
|
||||
use_tls: system_config_bool(smtp_use_tls.as_ref(), true),
|
||||
use_ssl: system_config_bool(smtp_use_ssl.as_ref(), false),
|
||||
from_email,
|
||||
from_name: system_config_string(smtp_from_name.as_ref())
|
||||
.unwrap_or_else(|| "Aether".to_string()),
|
||||
}))
|
||||
read_smtp_delivery_config(state).await
|
||||
}
|
||||
|
||||
pub(super) async fn auth_email_app_name(state: &AppState) -> Result<String, GatewayError> {
|
||||
@@ -516,27 +209,20 @@ pub(super) async fn send_auth_email(
|
||||
if record_auth_email_delivery_for_tests(
|
||||
state,
|
||||
json!({
|
||||
"to_email": email.to_email,
|
||||
"subject": email.subject,
|
||||
"html_body": email.html_body,
|
||||
"text_body": email.text_body,
|
||||
"to_email": email.to_email.clone(),
|
||||
"subject": email.subject.clone(),
|
||||
"html_body": email.html_body.clone(),
|
||||
"text_body": email.text_body.clone(),
|
||||
}),
|
||||
) {
|
||||
return Ok(());
|
||||
}
|
||||
|
||||
tokio::task::spawn_blocking(move || send_auth_email_blocking(config, email))
|
||||
.await
|
||||
.map_err(|err| GatewayError::Internal(err.to_string()))?
|
||||
send_smtp_email(config, email).await
|
||||
}
|
||||
|
||||
pub(super) async fn auth_registration_email_configured(
|
||||
state: &AppState,
|
||||
) -> Result<bool, GatewayError> {
|
||||
let smtp_host = state.read_system_config_json_value("smtp_host").await?;
|
||||
let smtp_from_email = state
|
||||
.read_system_config_json_value("smtp_from_email")
|
||||
.await?;
|
||||
Ok(system_config_string(smtp_host.as_ref()).is_some()
|
||||
&& system_config_string(smtp_from_email.as_ref()).is_some())
|
||||
Ok(read_smtp_delivery_config(state).await?.is_some())
|
||||
}
|
||||
|
||||
@@ -121,7 +121,6 @@ pub(super) const AUTH_REFRESH_TOKEN_EXPIRATION_DAYS: i64 = 7;
|
||||
pub(super) const AUTH_EMAIL_VERIFICATION_PREFIX: &str = "email:verification:";
|
||||
pub(super) const AUTH_EMAIL_VERIFIED_PREFIX: &str = "email:verified:";
|
||||
pub(super) const AUTH_EMAIL_VERIFIED_TTL_SECS: u64 = 3600;
|
||||
pub(super) const AUTH_SMTP_TIMEOUT_SECS: u64 = 30;
|
||||
|
||||
pub(crate) fn build_auth_json_response(
|
||||
status: http::StatusCode,
|
||||
|
||||
@@ -254,6 +254,11 @@ pub(crate) fn admin_proxy_local_requires_buffered_body(
|
||||
| (Some("system_manage"), http::Method::PUT, Some("config_set"))
|
||||
| (Some("system_manage"), http::Method::PUT, Some("email_template_set"))
|
||||
| (Some("system_manage"), http::Method::POST, Some("email_template_preview"))
|
||||
| (
|
||||
Some("system_manage"),
|
||||
http::Method::POST,
|
||||
Some("important_notification_test"),
|
||||
)
|
||||
| (
|
||||
Some("provider_models_manage"),
|
||||
http::Method::POST,
|
||||
|
||||
Reference in New Issue
Block a user