The journal-milter, until now a pure monitor, now refuses a message with a
4xx tempfail (RespTempFail/451) at MAIL FROM when a per-domain or per-
application limit is exceeded. Key is the client IP; the count is
COUNT(DISTINCT queue_id) over a sliding window reusing the send log; the
limit applies only when a non-empty IP binding matches the client (empty
binding => level-1 only, per spec 7.4). Enforcement is fail-open on the
milter's own errors — a limiter malfunction never blocks mail, and Postfix's
level-1 anvil limit stays the independent backstop. Refused messages are
recorded in send_log with status "rejected" for UI visibility.
- store/ratelimits.go: RateLimit type (+Active/AllowsIP), id-keyed get/set/
delete for the panel, name/login-keyed lookup + windowed distinct-message
count for the milter, DeleteRateLimitsForDomain. No migration — the
rate_limits table has existed since Phase 2.
- milter: enforce at MailFrom, fail-open helper overLimit, InsertRejected.
- web: server-side validated IP/ceiling/window forms on the domain page and
per application; routes POST /domains/{id}/ratelimit and
/applications/{aid}/ratelimit. Milter reads rows live, so no reload.
- domain/app services clear limits on deletion (rate_limits has no FK cascade).
Unit tests + container e2e (p8) green: refusal on both scopes, unregistered
IP ignored, fail-open with the panel stopped.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Adds application accounts bound to domains: a SASL login/password in
sasldb2, a per-application address mode (wildcard @domain or an explicit
list), and matching smtpd_sender_login_maps bindings — with create,
list, edit-mode, delete and password regeneration (spec 4.1, 5.1,
7.2.5-9). Generated passwords are shown exactly once and never stored in
plaintext (7.6.1).
- internal/store/applications.go: transactional CRUD; globally unique
login; ListBindings (address->login) as the map source; logins-by-
domain for pre-cascade SASL cleanup.
- internal/app: saslpasswd2 wrapper (password via stdin, login as a
whitelisted argv element, no shell — 7.6.3); strong base64url password;
address validation that enforces domain ownership before any config
write (7.6.2); service orchestrating store + sasldb2 + map with full
rollback on partial failure.
- internal/postfix: sender_login_maps regenerated as a pure function of
the registry (many-to-one logins merged per address), atomic write,
injection backstop (7.6.4).
- Postfix reload, corrected: `postfix start-fg` forks a separate master,
so signalling the supervised process never reaches it. Reload now runs
the canonical `postfix reload` via a one-shot supervisord program the
unprivileged panel triggers over the group control socket. Verified in
mail.log.
- domain.Service.Delete purges the domain's SASL accounts, then cascades,
then rebuilds the sender map and reloads; manual reload now covers both
OpenDKIM and Postfix.
- web: application management in the domain page, one-time credential
shown inline; postfix joins the selfpost group and entrypoint normalises
/data/sasl and /data/postfix (setgid, group-readable) with self-heal.
Verified on the dev server: gofmt/vet/test green, image builds, and a
container e2e covers the full application lifecycle, domain-delete
cascade, restart persistence, and a real postfix reload.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>