1
0
mirror of git://f0xx.org/ac/ac-deploy synced 2026-07-29 05:38:25 +03:00

cluster0: auth-email bearer + shorten verify URLs in outbound mail

ShortLinksRepository::shortenForOutbound; ensure-auth-email-bearer.sh;
verify-mail-lab sends shortened s.f0xx.org link in verify email body.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Anton Afanasyeu
2026-06-23 18:37:24 +02:00
parent 3d66edb405
commit aa55e03fbd
8 changed files with 111 additions and 6 deletions

View File

@@ -122,6 +122,8 @@ if [ -n "$_MSMTP_PASS" ]; then
MAIL_FROM="${MAIL_FROM:-Android Cast <bestcastr@gmail.com>}"
fi
unset _MSMTP_PASS
AUTH_BEARER_ID="$(read_secret URL_SHORTENER_AUTH_BEARER_ID 2>/dev/null || true)"
[ -n "$AUTH_BEARER_ID" ] || AUTH_BEARER_ID="${URL_SHORTENER_AUTH_BEARER_ID:-0}"
mkdir -p "${COMPOSED}/config"
log "write composed config.php base_path=${ISSUES_BASE}"
cat > "${COMPOSED}/config/config.php" <<PHP
@@ -174,6 +176,7 @@ return [
'url_shortener' => [
'enabled' => true,
'public_base' => '${SHORT_LINKS_PUBLIC_BASE}',
'auth_bearer_id' => ${AUTH_BEARER_ID:-0},
'db' => [
'mysql' => [
'host' => '${DB_HOST}',

View File

@@ -0,0 +1,24 @@
#!/bin/sh
# Mint auth-email bearer for outbound mail short links; store id in secrets + config.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
# shellcheck source=/dev/null
. "$ROOT/scripts/lib/common.sh"
load_cluster_env
COMPOSED="${COMPOSE_BACKEND:-/var/www/ac/composed/backend}"
SCRIPT="${COMPOSED}/scripts/ensure_auth_email_bearer.php"
[ -f "$SCRIPT" ] || SCRIPT="${ROOT}/lab-seeds/backend/scripts/ensure_auth_email_bearer.php"
[ -f "$SCRIPT" ] || die "ensure_auth_email_bearer.php missing"
BEARER_ID="$(php83 "$SCRIPT" 2>/dev/null | tail -1)"
[ -n "$BEARER_ID" ] && [ "$BEARER_ID" -gt 0 ] 2>/dev/null || die "could not mint auth-email bearer"
SECRETS="${CAST_CLUSTER_ROOT}/secrets.lab.env"
if [ -f "$SECRETS" ]; then
grep -v '^URL_SHORTENER_AUTH_BEARER_ID=' "$SECRETS" > /tmp/secrets.new || true
echo "URL_SHORTENER_AUTH_BEARER_ID=${BEARER_ID}" >> /tmp/secrets.new
mv /tmp/secrets.new "$SECRETS"
chmod 600 "$SECRETS"
fi
log "ensure-auth-email-bearer_ok id=${BEARER_ID}"

View File

@@ -197,7 +197,7 @@ load_secrets_lab() {
_k="${_line%%=*}"
_v="${_line#*=}"
case "$_k" in
MAIL_*|MSMTP_*|SMTP_*|AUTH_*|GITEA_*|WG_*|RSSH_*)
MAIL_*|MSMTP_*|SMTP_*|AUTH_*|GITEA_*|WG_*|RSSH_*|URL_SHORTENER_*)
export "$_k=$_v"
;;
esac

View File

@@ -16,16 +16,19 @@ COMPOSED="${COMPOSE_BACKEND:-/var/www/ac/composed/backend}"
export MAIL_TEST_TO="$TO"
PHP="${PHP_BIN:-php83}"
command -v "$PHP" >/dev/null 2>&1 || PHP=php
_origin="${LAB_PUBLIC_ORIGIN:-https://acl0.f0xx.org}"
_token="lab-smoke-$(date +%s)"
_long="${_origin%/}/app/androidcast_project/issues/verify-email?token=${_token}"
export MAIL_TEST_LONG="$_long"
_out="$("$PHP" -r '
require "'"${COMPOSED}"'/src/bootstrap.php";
$to = getenv("MAIL_TEST_TO") ?: "";
$origin = rtrim((string) cfg("public_origin", "https://acl0.f0xx.org"), "/");
$base = rtrim((string) cfg("base_path", ""), "/");
$ok = AuthMailer::sendVerifyEmail($to, $origin . $base . "/verify-email?token=lab-smoke");
$long = getenv("MAIL_TEST_LONG") ?: "";
$ok = AuthMailer::sendVerifyEmail($to, $long);
echo $ok ? "mail_ok" : "mail_fail";
' 2>&1)" || _out="mail_fail"
log "$_out to=$TO"
log "$_out to=$TO long=$_long"
case "$_out" in
mail_ok) exit 0 ;;
*) exit 1 ;;