This website requires JavaScript.
Explore
Help
Sign In
starred
/
warmbly
Watch
1
Star
0
Fork
0
mirror of
https://github.com/warmbly/warmbly.git
synced
2026-10-03 08:02:04 +00:00
Code
Issues
Packages
Projects
Releases
Wiki
Activity
Files
80ecadb1e65a71fc2280883e6161ca8fd6a3abd4
warmbly
/
cmd
/
backend
T
History
Matthew Meszaros
d99a09825f
feat: run one inbox placement test across many sending mailboxes as a placement batch (issue
#736
): server-side sender scopes (a campaign's senders or the whole workspace, filtered by provider, domain, tag and untested days) and sampling (random, percent stratified by provider or domain, per domain, per provider) snapshotted at creation, a runner that starts senders under per-workspace and instance-wide concurrency and a start rate with defer or skip for unavailable mailboxes, aggregate placement by sending domain, sending provider and recipient provider, fleet coverage, cancel, credits agreed per batch, org transfer, operator settings in the admin panel, dashboard pages and dialog, CLI commands, agent tools, OpenAPI and docs
2026-09-29 10:19:46 -07:00
..
boot.go
feat: address the CodeRabbit review: render EMAIL_BRAND_NAME in every transactional template body and subject instead of a hardcoded product name, name FRONTEND_BASE_URL as the source when emailed links come from it, warn on an insecure effective dashboard URL even when APP_URL was inferred rather than configured, and correct the unsubscribe guide's claim that an unset API_PUBLIC_URL disables link minting
2026-09-09 06:52:37 -07:00
envsample
feat: complete the ADA CASA v2.1.1 AL1 control set across authentication, sessions, access control, cryptography, input validation and configuration, adding a breached-password denylist and per-account login throttling, enforced multi-factor authentication on the admin panel, step-up confirmation before an action that mints a lasting credential, purpose-scoped session tokens, single-use TOTP steps, tenant verification on every cross-referenced identifier, security headers on every surface, encrypted webhook signing secrets, per-organization idempotency, PKCE and a minimal two-scope Gmail consent on the mailbox OAuth flow, bounded spreadsheet and archive decoding, a patched Go toolchain with govulncheck in CI, and the evidence pack under compliance/casa
2026-09-19 08:18:35 +02:00
main.go
feat: run one inbox placement test across many sending mailboxes as a placement batch (issue
#736
): server-side sender scopes (a campaign's senders or the whole workspace, filtered by provider, domain, tag and untested days) and sampling (random, percent stratified by provider or domain, per domain, per provider) snapshotted at creation, a runner that starts senders under per-workspace and instance-wide concurrency and a start rate with defer or skip for unavailable mailboxes, aggregate placement by sending domain, sending provider and recipient provider, fleet coverage, cancel, credits agreed per batch, org transfer, operator settings in the admin panel, dashboard pages and dialog, CLI commands, agent tools, OpenAPI and docs
2026-09-29 10:19:46 -07:00
oauth_base_url_test.go
feat: build the Gmail and Outlook mailbox-connect redirect_uri from API_PUBLIC_URL instead of API_HOST, which is the listener's bind address and stays 0.0.0.0:8080 in a container, so every self-hosted OAuth connect sent Google and Microsoft a redirect_uri that is not even an absolute URI and was rejected with invalid_request before the account picker appeared, adding an oauthPublicBaseURL helper next to the existing oidcRedirectURL that reads the same already-documented variable and falls back to a browsable
http://localhost:PORT
derived from the bind address (mapping the 0.0.0.0, :: and bare-port wildcard forms to localhost, and passing through a value that is already a URL) so a stock local install emits exactly the
http://localhost:8080/addresses/google/callback
the guide tells operators to register, plus a test pinning the resolution order and the root-registered callback path, and a deployment-guide note naming API_PUBLIC_URL as the variable that has to match the registered URI (
#116
)
2026-08-16 07:45:54 +02:00
sso_redirect_test.go
feat: build the browser half of social sign-in, which was never wired: GOOGLE_CLIENT_ID was read at boot and made the login screen render a Google button, but the button opened a popup at /auth/google/login which no route served, and authService.GoogleAuth/AppleAuth had no caller anywhere in the codebase; internal/app/socialauth now runs Google and Apple through the flow generic OIDC already used (one-time state, PKCE, nonce, id_token verified against the provider JWKS, identity keyed on issuer and subject, JIT provisioning, the ban and 2FA gates), the redirect URI defaults to API_PUBLIC_URL/v1/auth/<provider>/callback and is logged at boot because registering the dashboard origin instead is the mistake that produces a valid OAuth client and a dead button, /auth/config advertises only providers the backend can actually complete, the SSO landing page no longer swallows a two_fa_required response, and OIDC_PROVIDER_NAME finally reaches the button it documents
2026-08-28 01:33:08 -07:00