feat(email): native SMTP-listener ingress (A3)
Some checks failed
CI / Rust — fmt, clippy, test (push) Failing after 33m37s
CI / Dashboard — check (push) Successful in 9m49s

An opt-in receive-only SMTP listener (PICLOUD_SMTP_BIND) so an MX can point
straight at PiCloud. It speaks minimal SMTP (HELO/EHLO/MAIL/RCPT/DATA/RSET/
NOOP/QUIT), resolves each RCPT TO mailbox to the app-owned email trigger that
claims it, and inserts an Email outbox row the dispatcher fires — the same tail
as the HMAC webhook, unchanged.

- migration 0076: email_trigger_details.inbound_address (case-insensitively
  unique among app triggers) + TriggerRepo::email_inbound_target_by_address /
  SmtpInboundTarget; the interactive create-email API accepts inbound_address.
- crates/picloud/src/smtp.rs: a small tokio accept loop + session state machine
  + a testable deliver() core + a minimal RFC-5322 header/body split. DATA is
  size-capped with dot-unstuffing; no AUTH/STARTTLS (TLS terminates upstream —
  the recipient address + per-app isolation are the boundary).
- spawned in run_server alongside axum::serve, sharing the pool, on the same
  shutdown signal.

Pinned by a picloud integration test (deliver → one Email outbox row for a
known mailbox, none for an unknown one) + smtp.rs unit tests (address parse,
header/body split). Multipart/MIME decoding is a documented follow-up.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
MechaCat02
2026-07-16 21:01:46 +02:00
parent 0dd03af0c6
commit dbdd398d90
11 changed files with 557 additions and 6 deletions

View File

@@ -183,6 +183,7 @@ table: email_trigger_details
inbound_secret_encrypted: bytea NULL
inbound_secret_nonce: bytea NULL
inbound_secret_version: smallint NOT NULL default=0
inbound_address: text NULL
table: execution_logs
id: uuid NOT NULL default=gen_random_uuid()
@@ -614,6 +615,7 @@ indexes on docs_trigger_details:
docs_trigger_details_pkey: public.docs_trigger_details USING btree (trigger_id)
indexes on email_trigger_details:
email_trigger_details_inbound_address_uidx: public.email_trigger_details USING btree (lower(inbound_address)) WHERE (inbound_address IS NOT NULL)
email_trigger_details_pkey: public.email_trigger_details USING btree (trigger_id)
indexes on execution_logs:
@@ -1151,3 +1153,4 @@ constraints on workflows:
0073: interceptors
0074: interceptor phase
0075: interceptor timeout
0076: email inbound address