Phase 4: applications + SASL (sasldb2) + sender_login_maps

Adds application accounts bound to domains: a SASL login/password in
sasldb2, a per-application address mode (wildcard @domain or an explicit
list), and matching smtpd_sender_login_maps bindings — with create,
list, edit-mode, delete and password regeneration (spec 4.1, 5.1,
7.2.5-9). Generated passwords are shown exactly once and never stored in
plaintext (7.6.1).

- internal/store/applications.go: transactional CRUD; globally unique
  login; ListBindings (address->login) as the map source; logins-by-
  domain for pre-cascade SASL cleanup.
- internal/app: saslpasswd2 wrapper (password via stdin, login as a
  whitelisted argv element, no shell — 7.6.3); strong base64url password;
  address validation that enforces domain ownership before any config
  write (7.6.2); service orchestrating store + sasldb2 + map with full
  rollback on partial failure.
- internal/postfix: sender_login_maps regenerated as a pure function of
  the registry (many-to-one logins merged per address), atomic write,
  injection backstop (7.6.4).
- Postfix reload, corrected: `postfix start-fg` forks a separate master,
  so signalling the supervised process never reaches it. Reload now runs
  the canonical `postfix reload` via a one-shot supervisord program the
  unprivileged panel triggers over the group control socket. Verified in
  mail.log.
- domain.Service.Delete purges the domain's SASL accounts, then cascades,
  then rebuilds the sender map and reloads; manual reload now covers both
  OpenDKIM and Postfix.
- web: application management in the domain page, one-time credential
  shown inline; postfix joins the selfpost group and entrypoint normalises
  /data/sasl and /data/postfix (setgid, group-readable) with self-heal.

Verified on the dev server: gofmt/vet/test green, image builds, and a
container e2e covers the full application lifecycle, domain-delete
cascade, restart persistence, and a real postfix reload.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-07-12 21:18:10 +03:00
parent a7a5ad3f91
commit c6eeb30258
24 changed files with 2156 additions and 51 deletions
+89 -2
View File
@@ -11,6 +11,20 @@
<a class="back" href="/">&larr; All domains</a>
{{if .Flash}}<div class="flash">{{.Flash}}</div>{{end}}
{{if .NewCred}}
<div class="card credential">
<h2>New application password</h2>
<p class="muted">This password is shown <strong>once only</strong> and is not
stored. Copy it now — if it is lost, regenerate a new one.</p>
<label>Login</label>
<span class="code">{{.NewCred.Login}}</span>
<label>Password</label>
<span class="code">{{.NewCred.Password}}</span>
</div>
{{end}}
<div class="card">
<h2>DKIM DNS record</h2>
<p class="muted">Publish this TXT record in the DNS for <strong>{{.Domain.Name}}</strong>.
@@ -31,8 +45,81 @@
<div class="card">
<h2>Applications</h2>
<p class="muted">{{.Domain.AppCount}} application(s) bound to this domain.
Creating and managing applications arrives in the next phase.</p>
<p class="muted">Each application is a SASL login/password an app or script
uses to send mail as this domain. A login may send from any address of the
domain (<em>wildcard</em>) or only from a fixed list of addresses.</p>
{{if .Apps}}
<table>
<thead>
<tr><th>Login</th><th>Mode</th><th>Addresses</th><th></th></tr>
</thead>
<tbody>
{{range .Apps}}
<tr>
<td class="code">{{.Login}}</td>
<td>{{if eq .AddressMode $.Wildcard}}Any address (@{{$.Domain.Name}}){{else}}List{{end}}</td>
<td class="muted">
{{if eq .AddressMode $.Wildcard}}*@{{$.Domain.Name}}{{else}}
{{range $i, $a := .Addresses}}{{if $i}}, {{end}}{{$a}}{{end}}
{{end}}
</td>
<td class="actions">
<details>
<summary>Edit mode</summary>
<form method="post" action="/applications/{{.ID}}/mode">
<label>Address mode</label>
<select name="mode">
<option value="{{$.Wildcard}}" {{if eq .AddressMode $.Wildcard}}selected{{end}}>Any address of the domain</option>
<option value="{{$.List}}" {{if eq .AddressMode $.List}}selected{{end}}>Specific addresses (list)</option>
</select>
<label>Addresses (for list mode; one per line or comma-separated)</label>
<textarea name="addresses" rows="3" placeholder="alerts@{{$.Domain.Name}}">{{range $i, $a := .Addresses}}{{if $i}}
{{end}}{{$a}}{{end}}</textarea>
<button type="submit">Save mode</button>
</form>
</details>
<form class="inline" method="post" action="/applications/{{.ID}}/password"
onsubmit="return confirm('Regenerate the password for {{.Login}}? The current password stops working immediately.')">
<button type="submit">New password</button>
</form>
<form class="inline" method="post" action="/applications/{{.ID}}/delete"
onsubmit="return confirm('Delete application {{.Login}}? Its credentials stop working immediately.')">
<button type="submit" class="danger">Delete</button>
</form>
</td>
</tr>
{{end}}
</tbody>
</table>
{{else}}
<p class="muted">No applications yet. Create one below.</p>
{{end}}
</div>
<div class="card">
<h2>Add an application</h2>
<form method="post" action="/domains/{{.Domain.ID}}/applications">
<label for="login">Login</label>
<input id="login" name="login" type="text" placeholder="prod-server"
autocomplete="off" autocapitalize="none" spellcheck="false"
value="{{.FormLogin}}" required>
<label for="mode">Address mode</label>
<select id="mode" name="mode">
<option value="{{.Wildcard}}" {{if eq .FormMode .Wildcard}}selected{{end}}>Any address of the domain</option>
<option value="{{.List}}" {{if eq .FormMode .List}}selected{{end}}>Specific addresses (list)</option>
</select>
<label for="addresses">Addresses (for list mode; one per line or comma-separated)</label>
<textarea id="addresses" name="addresses" rows="3"
placeholder="alerts@{{.Domain.Name}}">{{.FormAddrs}}</textarea>
{{if .Error}}<p class="error">{{.Error}}</p>{{end}}
<button type="submit">Create application</button>
</form>
<p class="muted">A strong password is generated and shown once. The login must
be unique across all domains and may contain letters, digits, '.', '-' and '_'.</p>
</div>
<div class="card">
+18
View File
@@ -56,6 +56,24 @@
@media (prefers-color-scheme: dark) { .code { background: #14171a !important; border-color: #2b3138 !important; } }
h2 { font-size: 1.05rem; margin: 0 0 0.4rem; }
.back { display: inline-block; margin-bottom: 1rem; }
select, textarea {
width: 100%; padding: 0.55rem 0.7rem; font-size: 1rem;
border: 1px solid #cfd4da; border-radius: 6px; background: #fff; color: inherit;
font-family: inherit;
}
textarea { resize: vertical; }
@media (prefers-color-scheme: dark) {
select, textarea { background: #14171a !important; color: inherit !important; border-color: #2b3138 !important; }
}
button.danger { background: #b42318; }
button.danger:hover { background: #912018; }
form.inline button.danger { background: none; color: #b42318; }
form.inline button.danger:hover { background: none; }
td.actions form.inline, td.actions details { margin-left: 0.6rem; }
details summary { cursor: pointer; color: #2563eb; font-weight: 600; }
details form { margin-top: 0.6rem; }
.credential { border-color: #f5c518; background: #fffbeb; }
@media (prefers-color-scheme: dark) { .credential { background: #2a2408 !important; border-color: #6b5a10 !important; } }
</style>
</head>
<body>