7b4549a35d
Phase 13. Two new packages and one new screen. internal/health owns the shared status vocabulary (ok/warn/error/unknown) and the local checks: supervisord's process table, TLS certificate expiry and the two milter sockets. Each check reports a problem as a status rather than an error, so one broken component costs a line and not the page. internal/dnscheck does the read-only lookups: forward-confirmed reverse DNS for SELFPOST_HOSTNAME, and per-domain DKIM (compared against the key this server actually signs with), SPF and DMARC. Every check is bounded by a timeout and cached, and the resolver sits behind an interface so the tests drive every branch without touching the network. The SPF check is deliberately shallow: it looks for a mechanism literally covering the server's address and does not follow include:/redirect=, so a record that authorises us through an include is reported as "cannot tell" rather than as a failure. /status renders both, with the local checks in an HTMX-polled fragment and the DNS lookups behind a Re-check button, and becomes the panel's landing page: / now redirects there and the domain list lives at /domains. The Reload button moves onto /status, where it reads as what it is — a drift-recovery for the daemons — with text explaining what it regenerates. A template test fails on any remaining href="/" so a stale link cannot silently land on the wrong screen. Also fixes a defect this made visible: the panel could never read the mail queue in the documented deployment. postqueue relies on its setgid-postdrop bit, which the compose file's no-new-privileges disables, so the Queue screen always said "Could not read the mail queue" — including in the released 1.0.0 image. The panel user is now a real member of postdrop, which needs no setgid transition. Verified in a container on the dev server against real DNS: PTR matching (selfpost.example.com) and not matching (example.com), DKIM absent and mismatched, SPF absent and via include:, DMARC p=quarantine/p=reject/absent, and a resolver timeout degrading to "unknown" without hanging the page. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
116 lines
4.3 KiB
Go
116 lines
4.3 KiB
Go
package web
|
|
|
|
import (
|
|
"bytes"
|
|
"fmt"
|
|
"html/template"
|
|
"net/http"
|
|
)
|
|
|
|
// templates holds the parsed page and fragment templates. Each page is parsed
|
|
// together with the shared base layout so {{ template "base" . }} works.
|
|
// Fragments (HTMX polling targets, spec 7.1) are parsed standalone, without
|
|
// the layout, so they can be swapped into an existing page as an HTML snippet
|
|
// rather than a full document. Rendering always goes through html/template,
|
|
// which auto-escapes all interpolated data regardless (spec 7.6.7).
|
|
type templates struct {
|
|
pages map[string]*template.Template
|
|
fragments map[string]*template.Template
|
|
}
|
|
|
|
// pageFiles maps a logical page name to its template files. Every page
|
|
// composes with layout.html; pages that embed a polling fragment (spec 7.1)
|
|
// list that fragment's file too, so the same {{define}} block renders both
|
|
// the initial page and the fragment's own refresh responses identically.
|
|
var pageFiles = map[string][]string{
|
|
"setup": {"templates/setup.html"},
|
|
"login": {"templates/login.html"},
|
|
"dashboard": {"templates/dashboard.html"},
|
|
"account": {"templates/account.html"},
|
|
"backup": {"templates/backup.html"},
|
|
"domain_detail": {"templates/domain_detail.html"},
|
|
"domain_delete": {"templates/domain_delete.html"},
|
|
"sendlog": {"templates/sendlog.html", "templates/sendlog_rows.html"},
|
|
"queue": {"templates/queue.html", "templates/queue_body.html"},
|
|
"logtail": {"templates/logtail.html", "templates/logtail_body.html"},
|
|
"status": {"templates/status.html", "templates/status_body.html"},
|
|
}
|
|
|
|
// fragmentFiles maps a fragment name (also its {{define}} block name) to its
|
|
// template file, for standalone rendering by the HTMX polling endpoints.
|
|
var fragmentFiles = map[string]string{
|
|
"sendlog_rows": "templates/sendlog_rows.html",
|
|
"queue_body": "templates/queue_body.html",
|
|
"logtail_body": "templates/logtail_body.html",
|
|
"status_body": "templates/status_body.html",
|
|
}
|
|
|
|
func loadTemplates() (*templates, error) {
|
|
t := &templates{
|
|
pages: make(map[string]*template.Template),
|
|
fragments: make(map[string]*template.Template),
|
|
}
|
|
for name, files := range pageFiles {
|
|
patterns := append([]string{"templates/layout.html"}, files...)
|
|
tmpl, err := template.New("layout.html").ParseFS(assetsFS, patterns...)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("parse template %s: %w", name, err)
|
|
}
|
|
t.pages[name] = tmpl
|
|
}
|
|
for name, file := range fragmentFiles {
|
|
tmpl, err := template.ParseFS(assetsFS, file)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("parse fragment %s: %w", name, err)
|
|
}
|
|
t.fragments[name] = tmpl
|
|
}
|
|
return t, nil
|
|
}
|
|
|
|
// render writes a page using the base layout. Rendering to a buffer first means
|
|
// a template error yields a clean 500 instead of a half-written page.
|
|
func (s *Server) render(w http.ResponseWriter, status int, page string, data any) {
|
|
tmpl, ok := s.tmpl.pages[page]
|
|
if !ok {
|
|
http.Error(w, "template not found", http.StatusInternalServerError)
|
|
return
|
|
}
|
|
// The layout's navigation compares .Active against each item, so the key
|
|
// must exist on every authenticated page. Defaulting it here keeps a page
|
|
// that forgets it from failing to render — it simply highlights nothing.
|
|
if m, ok := data.(map[string]any); ok {
|
|
if _, has := m["Active"]; !has {
|
|
m["Active"] = ""
|
|
}
|
|
}
|
|
var buf bytes.Buffer
|
|
if err := tmpl.ExecuteTemplate(&buf, "layout.html", data); err != nil {
|
|
logf("panel: render %s: %v", page, err)
|
|
http.Error(w, "internal error", http.StatusInternalServerError)
|
|
return
|
|
}
|
|
w.Header().Set("Content-Type", "text/html; charset=utf-8")
|
|
w.WriteHeader(status)
|
|
_, _ = buf.WriteTo(w)
|
|
}
|
|
|
|
// renderFragment writes an HTMX polling fragment as a bare HTML snippet, with
|
|
// no surrounding layout (spec 7.1: fragment endpoints return HTML, not JSON).
|
|
func (s *Server) renderFragment(w http.ResponseWriter, status int, name string, data any) {
|
|
tmpl, ok := s.tmpl.fragments[name]
|
|
if !ok {
|
|
http.Error(w, "template not found", http.StatusInternalServerError)
|
|
return
|
|
}
|
|
var buf bytes.Buffer
|
|
if err := tmpl.ExecuteTemplate(&buf, name, data); err != nil {
|
|
logf("panel: render fragment %s: %v", name, err)
|
|
http.Error(w, "internal error", http.StatusInternalServerError)
|
|
return
|
|
}
|
|
w.Header().Set("Content-Type", "text/html; charset=utf-8")
|
|
w.WriteHeader(status)
|
|
_, _ = buf.WriteTo(w)
|
|
}
|