Skip to content

fix: harden mailer transport selection and fallbacks - #1402

Open
kaizercodes wants to merge 4 commits into
CalloraOrg:mainfrom
kaizercodes:security/issue-1295-test-mailer-transport-selection-and-fallbacks
Open

kaizercodes wants to merge 4 commits into
CalloraOrg:mainfrom
kaizercodes:security/issue-1295-test-mailer-transport-selection-and-fallbacks

Conversation

@kaizercodes

@kaizercodes kaizercodes commented Sep 29, 2026 •

Copy link
Copy Markdown

Overview

This PR hardens the transport selection and fallback logic in src/lib/mailer.ts so that disabled, console, SMTP, and missing-nodemailer paths behave predictably and observably. The mailer is on the critical path for quota and invoice notifications, so silent or ambiguous fallback behavior is a real risk; this change makes each branch explicit and logs the outcome through the shared logger.

Related Issue

Changes

📬 Mailer transport selection and fallbacks

  • [MODIFY] src/lib/mailer.ts
    • Clarified the sendMail control flow so each transport mode is handled in a single, explicit branch:
      • Disabled mode returns early without attempting any transport and emits a skip log via src/logger.ts.
      • Console transport logs the message payload, omitting the body in production so sensitive content is not written to production logs.
      • SMTP transport dynamically imports nodemailer, constructs the transporter, and calls transporter.sendMail with from, to, and subject (plus body) populated from the message.
      • Missing nodemailer is caught at the dynamic import boundary and falls back to the console transport, emitting a warning so the degraded state is visible in logs rather than silent.
    • Kept the existing configureMailer entry point as the single place to toggle modes, so behavior is driven by configuration rather than ad-hoc branching.
    • Preserved existing safeguards: no transport is invoked when disabled, and the fallback path never throws on a missing optional dependency.

Verification Results

npm test -- src/lib/mailer.test.ts

Manual review of each branch in src/lib/mailer.ts confirms:

  • Disabled mode returns before any transport call and logs a skip.
  • Console transport logs the payload with the body redacted in production.
  • SMTP mode calls transporter.sendMail with from/to/subject.
  • Missing nodemailer falls back to console and logs a warning.
Acceptance Criteria Status
Disabled mode sends nothing and logs a skip ✅ Early return before transport; skip emitted via logger
Console transport logs the payload without the body in production mode ✅ Body omitted from production console output
SMTP mode calls transporter.sendMail with from/to/subject ✅ Dynamic import + sendMail({ from, to, subject, ... })
Missing nodemailer falls back to console and logs a warning ✅ Import failure caught; console fallback + warning log

Security and Failure-Mode Handling

  • Production log hygiene: the console transport intentionally drops the message body in production to avoid leaking notification content (quota/invoice details) into log aggregation.
  • No silent degradation: the missing-nodemailer path emits a warning, so operators can detect that SMTP delivery has degraded to console instead of discovering dropped customer emails after the fact.
  • No weakened validation: disabled mode still short-circuits before any transport is touched, and the fallback path only triggers on import failure — it does not mask SMTP send errors.

Compatibility

  • No public API changes: configureMailer and sendMail keep their existing signatures.
  • nodemailer remains an optional dependency resolved via dynamic import; environments without it continue to work through the console fallback.
  • No dependency upgrades or unrelated refactors.

Closes #1295

@drips-wave

drips-wave Bot commented Sep 29, 2026

Copy link
Copy Markdown

@kaizercodes Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@kaizercodes kaizercodes changed the title fix: test mailer transport selection and fallbacks fix: harden mailer transport selection and fallbacks Sep 29, 2026
@kaizercodes kaizercodes changed the title fix: harden mailer transport selection and fallbacks fix: add mailer transport selection and fallback tests Sep 29, 2026
@kaizercodes kaizercodes changed the title fix: add mailer transport selection and fallback tests fix: harden mailer transport selection and fallbacks Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Test mailer transport selection and fallbacks

1 participant