c6eeb30258
Adds application accounts bound to domains: a SASL login/password in sasldb2, a per-application address mode (wildcard @domain or an explicit list), and matching smtpd_sender_login_maps bindings — with create, list, edit-mode, delete and password regeneration (spec 4.1, 5.1, 7.2.5-9). Generated passwords are shown exactly once and never stored in plaintext (7.6.1). - internal/store/applications.go: transactional CRUD; globally unique login; ListBindings (address->login) as the map source; logins-by- domain for pre-cascade SASL cleanup. - internal/app: saslpasswd2 wrapper (password via stdin, login as a whitelisted argv element, no shell — 7.6.3); strong base64url password; address validation that enforces domain ownership before any config write (7.6.2); service orchestrating store + sasldb2 + map with full rollback on partial failure. - internal/postfix: sender_login_maps regenerated as a pure function of the registry (many-to-one logins merged per address), atomic write, injection backstop (7.6.4). - Postfix reload, corrected: `postfix start-fg` forks a separate master, so signalling the supervised process never reaches it. Reload now runs the canonical `postfix reload` via a one-shot supervisord program the unprivileged panel triggers over the group control socket. Verified in mail.log. - domain.Service.Delete purges the domain's SASL accounts, then cascades, then rebuilds the sender map and reloads; manual reload now covers both OpenDKIM and Postfix. - web: application management in the domain page, one-time credential shown inline; postfix joins the selfpost group and entrypoint normalises /data/sasl and /data/postfix (setgid, group-readable) with self-heal. Verified on the dev server: gofmt/vet/test green, image builds, and a container e2e covers the full application lifecycle, domain-delete cascade, restart persistence, and a real postfix reload. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
132 lines
5.0 KiB
HTML
132 lines
5.0 KiB
HTML
{{define "content"}}
|
|
<div class="topbar">
|
|
<h1>{{.Domain.Name}}</h1>
|
|
<div class="actions muted">
|
|
<span>{{.User}}</span>
|
|
<form class="inline" method="post" action="/logout">
|
|
<button type="submit">Sign out</button>
|
|
</form>
|
|
</div>
|
|
</div>
|
|
|
|
<a class="back" href="/">← All domains</a>
|
|
|
|
{{if .Flash}}<div class="flash">{{.Flash}}</div>{{end}}
|
|
|
|
{{if .NewCred}}
|
|
<div class="card credential">
|
|
<h2>New application password</h2>
|
|
<p class="muted">This password is shown <strong>once only</strong> and is not
|
|
stored. Copy it now — if it is lost, regenerate a new one.</p>
|
|
<label>Login</label>
|
|
<span class="code">{{.NewCred.Login}}</span>
|
|
<label>Password</label>
|
|
<span class="code">{{.NewCred.Password}}</span>
|
|
</div>
|
|
{{end}}
|
|
|
|
<div class="card">
|
|
<h2>DKIM DNS record</h2>
|
|
<p class="muted">Publish this TXT record in the DNS for <strong>{{.Domain.Name}}</strong>.
|
|
It is not a secret and can be viewed at any time.</p>
|
|
|
|
<label>Host / name</label>
|
|
<span class="code">{{.Record.Name}}</span>
|
|
|
|
<label>Type</label>
|
|
<span class="code">TXT</span>
|
|
|
|
<label>Value</label>
|
|
<span class="code">{{.Record.Value}}</span>
|
|
|
|
<p class="muted">Also configure SPF and DMARC for the domain (see the
|
|
documentation). Mail is signed with selector <strong>{{.Domain.DKIMSelector}}</strong>.</p>
|
|
</div>
|
|
|
|
<div class="card">
|
|
<h2>Applications</h2>
|
|
<p class="muted">Each application is a SASL login/password an app or script
|
|
uses to send mail as this domain. A login may send from any address of the
|
|
domain (<em>wildcard</em>) or only from a fixed list of addresses.</p>
|
|
|
|
{{if .Apps}}
|
|
<table>
|
|
<thead>
|
|
<tr><th>Login</th><th>Mode</th><th>Addresses</th><th></th></tr>
|
|
</thead>
|
|
<tbody>
|
|
{{range .Apps}}
|
|
<tr>
|
|
<td class="code">{{.Login}}</td>
|
|
<td>{{if eq .AddressMode $.Wildcard}}Any address (@{{$.Domain.Name}}){{else}}List{{end}}</td>
|
|
<td class="muted">
|
|
{{if eq .AddressMode $.Wildcard}}*@{{$.Domain.Name}}{{else}}
|
|
{{range $i, $a := .Addresses}}{{if $i}}, {{end}}{{$a}}{{end}}
|
|
{{end}}
|
|
</td>
|
|
<td class="actions">
|
|
<details>
|
|
<summary>Edit mode</summary>
|
|
<form method="post" action="/applications/{{.ID}}/mode">
|
|
<label>Address mode</label>
|
|
<select name="mode">
|
|
<option value="{{$.Wildcard}}" {{if eq .AddressMode $.Wildcard}}selected{{end}}>Any address of the domain</option>
|
|
<option value="{{$.List}}" {{if eq .AddressMode $.List}}selected{{end}}>Specific addresses (list)</option>
|
|
</select>
|
|
<label>Addresses (for list mode; one per line or comma-separated)</label>
|
|
<textarea name="addresses" rows="3" placeholder="alerts@{{$.Domain.Name}}">{{range $i, $a := .Addresses}}{{if $i}}
|
|
{{end}}{{$a}}{{end}}</textarea>
|
|
<button type="submit">Save mode</button>
|
|
</form>
|
|
</details>
|
|
<form class="inline" method="post" action="/applications/{{.ID}}/password"
|
|
onsubmit="return confirm('Regenerate the password for {{.Login}}? The current password stops working immediately.')">
|
|
<button type="submit">New password</button>
|
|
</form>
|
|
<form class="inline" method="post" action="/applications/{{.ID}}/delete"
|
|
onsubmit="return confirm('Delete application {{.Login}}? Its credentials stop working immediately.')">
|
|
<button type="submit" class="danger">Delete</button>
|
|
</form>
|
|
</td>
|
|
</tr>
|
|
{{end}}
|
|
</tbody>
|
|
</table>
|
|
{{else}}
|
|
<p class="muted">No applications yet. Create one below.</p>
|
|
{{end}}
|
|
</div>
|
|
|
|
<div class="card">
|
|
<h2>Add an application</h2>
|
|
<form method="post" action="/domains/{{.Domain.ID}}/applications">
|
|
<label for="login">Login</label>
|
|
<input id="login" name="login" type="text" placeholder="prod-server"
|
|
autocomplete="off" autocapitalize="none" spellcheck="false"
|
|
value="{{.FormLogin}}" required>
|
|
|
|
<label for="mode">Address mode</label>
|
|
<select id="mode" name="mode">
|
|
<option value="{{.Wildcard}}" {{if eq .FormMode .Wildcard}}selected{{end}}>Any address of the domain</option>
|
|
<option value="{{.List}}" {{if eq .FormMode .List}}selected{{end}}>Specific addresses (list)</option>
|
|
</select>
|
|
|
|
<label for="addresses">Addresses (for list mode; one per line or comma-separated)</label>
|
|
<textarea id="addresses" name="addresses" rows="3"
|
|
placeholder="alerts@{{.Domain.Name}}">{{.FormAddrs}}</textarea>
|
|
|
|
{{if .Error}}<p class="error">{{.Error}}</p>{{end}}
|
|
<button type="submit">Create application</button>
|
|
</form>
|
|
<p class="muted">A strong password is generated and shown once. The login must
|
|
be unique across all domains and may contain letters, digits, '.', '-' and '_'.</p>
|
|
</div>
|
|
|
|
<div class="card">
|
|
<h2>Danger zone</h2>
|
|
<p class="muted">Deleting this domain also deletes its DKIM key and every
|
|
application bound to it.</p>
|
|
<a class="danger" href="/domains/{{.Domain.ID}}/delete">Delete domain</a>
|
|
</div>
|
|
{{end}}
|