tracker
All repositories: gitoria
5.6 KB
# `hl:smtp` — sending mailAn SMTP **submission client**. Server realm. Mission 137.```hybrielimport { Mailer } from 'hl:smtp'm = new Mailer("mail.example.com", 587, {user = "[email protected]"pass = "…""from" = "[email protected]"})m.send({ to = "[email protected]"; subject = "Hello"; text = "Hi there" })for (r of m.results()) {console.log(r.ok + " " + r.code + " " + r.message)}```## `new Mailer(host, port, options)``host` / `port` / `options` are the first three declared properties, so thepositional form above reads as written (SPEC.md "The file root is theconstructor").| option | default | meaning ||---|---|---|| `"from"` / `sender` | — | the envelope sender and the `From:` header. A mailer without one constructs; a `send()` whose message names no sender either is refused at that call. || `user` / `pass` | — | credentials; absent = no AUTH at all || `tls` | `"starttls"` | `"starttls"` · `"implicit"` (SMTPS, port 465) · `"none"` || `auth` | `"auto"` | `"auto"` (PLAIN unless only LOGIN is offered) · `"plain"` · `"login"` · `"none"` || `caFile` | — | an EXTRA trust anchor beside the system store — a private CA, or a test fixture's certificate || `verify` | `true` | peer chain + hostname. `false` is an explicit opt-out and is logged at every handshake || `allowInsecureAuth` | `false` | permit AUTH on a connection that never became TLS || `timeout` | `30000` | milliseconds, bounding the connect and every read/write || `helo` | `"localhost"` | the EHLO name and the `Message-ID` domain |**`from` is a reserved word** in Hybriel (`import X from './x.hl'`), so the keyis written quoted — `"from" = …`. `sender` is the same field under a bareidentifier; use whichever reads better.## `m.send(message)` — non-blocking| key | meaning ||---|---|| `to` | one address, or a list of them — ONE message, several `RCPT TO` || `subject` | ASCII passes through; anything else becomes an RFC 2047 encoded-word || `text` | the `text/plain` part || `html` | the `text/html` part; with both, a `multipart/alternative` body || `"from"` / `sender` | overrides the mailer's sender for this message |Returns a **job id**. The conversation runs on the mailer's own worker threadand the answer arrives later.Everything that can fail LOCALLY is decided before the job leaves — on thecaller's thread, so it is a **located error at the caller's line**, catchable via`on Error(e)` like any other plugin failure:* a CR or LF in `to`, `"from"` or `subject` — **header injection is refused, neverstripped and never escaped.** `subject = "hi\r\nBcc: everyone@…"` is how acontact form becomes an open relay; silently dropping the bytes would deliver amessage the author did not write.* an address carrying `<`, `>` or whitespace, or no `@` at all* an empty recipient list, a message with neither `text` nor `html`## The result`m.results()` is the mailer's ONE result source. Drain it (`for (r ofm.results())`, which ENDS when every accepted send has been answered — that iswhat lets a mail-only script terminate), or hand it to the event loop with`m.deliver()` and handle `on m.sent(r)` / `on m.failed(r)`. Use one or the other:they take from the same queue, and asking for both is a refusal.```{ id, ok, code, stage, message, secure, to }````stage` names the step that answered: `connect`, `greeting`, `ehlo`, `starttls`,`auth`, `mail`, `rcpt`, `data`, `body`, `done`. `secure` says whether the messagewas written inside TLS. A server's own refusal text arrives in `message`verbatim.`m.pending()` is how many sends have not been answered; `m.close()` stops theworker (a job already in conversation finishes — abandoning a socket between`DATA` and its `250` is how a message gets delivered twice).## What it does on the wire`EHLO` · optional `STARTTLS` + a re-issued `EHLO` inside TLS (RFC 3207 §4.2 —capabilities learned in the clear are discarded) · `AUTH PLAIN` (RFC 4616) or`AUTH LOGIN` · `MAIL FROM` · one `RCPT TO` per recipient (a rejected recipientfails the whole send) · `DATA` · the message · `QUIT`.CRLF discipline and **dot-stuffing** (RFC 5321 §4.5.2) are applied to the wholepayload: a body line beginning with `.` is sent as `..`, or it truncates themail. Headers written: `From`, `To`, `Subject`, `Date`, `Message-ID`,`MIME-Version`, `Content-Type`, `Content-Transfer-Encoding: 8bit`.## TLSThere is **no TLS implementation in this plugin.** It calls the client half of`plugins/http/tls_common.zig` — the same dlopen'd OpenSSL the HTTP servers use(mission 121, extended in 137). `native/test_smtp.sh` carries the grep gate thatkeeps it that way.## Not in scope* **Receiving** (IMAP/POP) — a different protocol and a different plugin.* **DKIM signing** — later. It needs a key store and a canonicalisation pass overthe rendered message; the rendering seam is `renderMessage` in `smtp.zig` andthe signature would be one more header written there.* **Queuing and retry** — the app's business. A `4xx` result is a retryable oneand the app knows what its retry policy is; a library that retried on its ownwould send twice the moment the app also did.* **`cc` / `bcc` headers, attachments** — not written. Extra recipients go in`to`; an attachment needs a `multipart/mixed` builder that does not exist yet.## Tests`bash native/test_smtp.sh` (61 checks). The only peer is`tests/native/plugins/045_smtp_fixture.js`, a local fixture that asserts theexact wire; **no test in this repo ever contacts a real mail server.** Ports comefrom `HL_SMTP_PORT_BASE` (default 14700) and the harness moves itself rather thantouching a listener it did not start.
Branches
- mainmain branch
Latest commits
- 749019b0Merge t19 (tracker#19 franchises + timelines) into main (mission 070): conflicts README/STATUS/show.hl/project.hl/browser.mjs/faketmdb.mjs, both sides kept; franchise/timeline pages get #20's typed heading (Franchise | …, Timeline | …), their title links via titlePath (/movies|/series|/shows); the collection seed waits for repair, kinds and credits too; franchises.mjs URLs + 2 new checks; gates browser 323/0, kinds 32/0, franchises 50/0mre
- daf49feaMerge t20 (tracker#20 typed headings + #21 series/shows split) into main (mission 070): conflicts README/STATUS/show.hl/project.hl/search.hl/components/search.hl/browser.mjs/faketmdb.mjs, both sides kept; clock order backfill → repair → kinds → credits; withDetailsFields stores tmdbType + kind; gates: browser.mjs URLs → /series|/movies, typed h1 selectors; kinds.mjs repair/credits off, fixture name = seed name; browser 323/0, kinds 32/0mre
- 20e09d89Merge t18 (tracker#18 delta sync) into main (mission 070): conflicts README/STATUS/show.hl/project.hl/browser.mjs, both sides kept; pageShowOf summary = summaryOfmre
- f83571c3tracker#18 (mission 067): daily sync by change lists — TMDB /tv|movie/changes (since the stored day, paged) + TVmaze /updates/shows → only our changed titles (followed: full step, unfollowed: light step — changed seasons, no TVmaze), full walk on first run / gap > 14 days / failed list; show record refreshed (title, tmdbSummary, tagline, status, genres …; renamed titles re-indexed); summary = the creator's own text (page: summary > tmdbSummary > tvmazeSummary), one-time clear of copied summaries (9,647 on the live copy); gate 261, tests/realdata-018*.mjs, README + STATUSmre
- 1ed5457etracker#20 + #21 (mission 068): typed headings "<Type> | <name>" in type colours; TV titles split into Series (/series) and Shows (/shows) by TMDB type + Reality/Talk/News genres — kind stored by sync/import/adult backfill + new kind backfill (resumes), /movies/<slug>, /shows/<slug> of a series/movie → 301, /my/series + /my/shows, home 5 tiles + 3 rows, search/filmography labels; gates kinds 32 + browser 266, tests/realdata-068.mjs, tools/count-kinds.hl, docs/kinds.md, README + STATUSmre
- f2b00674Merge t26 (tracker#26 + #28) into main (mission 062): short ids for every new person (castPersonId, guest route), guest stars stored on the title and created as people only when opened (/person/tmdb/<id>?show=<id> → 302), lean watch/follow clicks (showRow a small object, cast/crew from the slug, watches cached per user, face rows only after a season toggle); gate 311, tests/realdata-062.mjs, README + STATUSmre
- 0553b51ftracker#19 (mission 066): franchises and timelines — tables, /franchises, /franchises/<slug>, /timelines/<slug> (Timeline | Release sort, series by last episode), the Prequel | Timeline | Sequel widget with the franchise above, the creator's editor, TMDB collection seed in the app (resumes, paced); gate tests/franchises.mjs 48/0 + browser.mjs 266/0, tests/realdata-066.mjs, docs/franchises.md, README + STATUSmre
- fa1f9dfatracker#29 (mission 063): unwatched check muted grey outline + check (accent only on hover), watched stays solid — no code regression, the accent outline read as ticked; gate checks real checks visibly (computed style + screenshot pixel) on /my/unwatched, show, movie, /my/movies; gate 266, tests/realdata-063.mjs, README + STATUSmre
- 10bb3f93tracker#28 (mission 061): full cast (all seasons, main cast by episodes, guest stars) + crew (created by, directed by, written by, screenplay, story, music) — stored by the details completion, the daily sync, the search import (one details request) and a background credits job (resumes, RSS limit); show page collapsed after 20 with client-side Show all; showBySlug via a slug map; gate 249, tests/realdata-028.mjs, README + STATUSmre
- d8b12d67tracker#27 (mission 060): short ids for movies, series and persons — old 702 kept (data/old-short-ids.json), new random [a-z0-9]{5} unique across both, claimed at creation, background backfill (resumes), shown under poster/photo, /<shortId> → 301; gate 259, tests/realdata-060*, README + STATUSmre
- 25a50bc4tracker#26 (mission 059): titles from a filmography are completed — on open (skeleton, step-wise face showComplete, no reload) and by the in-app details repair (resumes, TMDB-paced, series in parts); cast from TMDB credits; gate 231, tests/realdata-026.mjs, README + STATUSmre
- f14db671tracker#22-#25 (mission 058): episode air dates, season check = all episodes watched, movie watched check (+ /my/movies count), /genres/<genre> pages (movies + series, newest first, paginated); gate 238, tests/realdata-058.mjs, README + STATUSmre
- 1704ec45tracker#17 (mission 057): season caret down/up, skeleton rows while a season loads, sessionless showSeasonEpisodes face (no page re-mount), client-only close; gate 214, tests/realdata-057.mjs, README + STATUSmre
- f2fe3e36mission 056: README + STATUS (merge, fixes, Hybriel 8590df63, real-data check), tests/realdata-056.mjs, tools/check-public-slugs.hlmre
- f40c250emission 056: re-vendor hybriel master 8590df63 (#121, #122); an adult title's page is Not found for non-followers; gate: leave the page before stopping the servermre
- 2b7fdd6cmission 056: signed-out header one row on phones ("Log in", nowrap), backfill skips adult titles' posters, gate checksmre
- 2c53d5efMerge branch 't16-person' (tracker#16 person pages) into main; filmography shows only public titles (054 adult flag), gate race fix (backfill start line)mre
- c171227emission 054: hide adult/unknown titles from the public lists and the search; in-app adult-flag backfill (TMDB details + poster per title, resumes), gate + real-data proofmre
- 139fafd8tracker#16: short bio (4 lines, click = all), real-data check script, README + STATUSmre
- 93be9476tracker#16: person pages /person/<slug> with the filmography fetched from TMDB on the first visit (step by step), gatemre