mirror of
https://github.com/dreamhunter2333/cloudflare_temp_email.git
synced 2026-09-04 23:17:34 +08:00
feat: add STARTTLS support for SMTP proxy server (#876)
* feat: add STARTTLS support for SMTP proxy server Add smtp_tls_cert and smtp_tls_key environment variables to enable STARTTLS on the SMTP proxy server, matching existing IMAP TLS support. Closes #249 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * test: add E2E tests for SMTP/IMAP STARTTLS - Add smtp-proxy-tls service with self-signed certs in docker-compose - Add smtp-tls.spec.ts: SMTP STARTTLS send plain/HTML/auth tests - Add imap-tls.spec.ts: IMAP STARTTLS login/list/select/fetch tests - Register smtp-proxy project in playwright.config.ts - Wait for TLS proxy readiness in docker-entrypoint.sh Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: enforce auth over TLS when STARTTLS is configured - Set auth_require_tls conditionally based on tls_context presence - Disable insecure SSLv2/SSLv3 protocols in TLS context Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: replace cert-gen service with inline cert generation The cert-gen one-shot container was exiting immediately after generating certificates, triggering --abort-on-container-exit and stopping all services before tests could run. Replace with an entrypoint script in smtp-proxy-tls that generates the self-signed cert before starting the proxy server. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
8341cae28f
commit
8cf1150b15
@@ -58,17 +58,21 @@ services:
|
||||
| `proxy_url` | `http://localhost:8787` | Worker backend URL |
|
||||
| `port` | `8025` | SMTP port |
|
||||
| `imap_port` | `11143` | IMAP port |
|
||||
| `imap_tls_cert` | empty | TLS certificate file path (PEM), enables STARTTLS when configured |
|
||||
| `imap_tls_key` | empty | TLS private key file path (PEM) |
|
||||
| `smtp_tls_cert` | empty | SMTP TLS certificate file path (PEM), enables STARTTLS when configured |
|
||||
| `smtp_tls_key` | empty | SMTP TLS private key file path (PEM) |
|
||||
| `imap_tls_cert` | empty | IMAP TLS certificate file path (PEM), enables STARTTLS when configured |
|
||||
| `imap_tls_key` | empty | IMAP TLS private key file path (PEM) |
|
||||
| `imap_cache_size` | `500` | Max cached messages per mailbox |
|
||||
| `imap_http_timeout` | `30.0` | Backend HTTP request timeout (seconds) |
|
||||
|
||||
## Enabling STARTTLS
|
||||
|
||||
Configure `imap_tls_cert` and `imap_tls_key` environment variables to enable STARTTLS support for the IMAP server.
|
||||
Configure the TLS certificate environment variables for SMTP and/or IMAP to enable STARTTLS support. SMTP and IMAP can share the same certificate.
|
||||
|
||||
```bash
|
||||
# .env example
|
||||
smtp_tls_cert=/path/to/cert.pem
|
||||
smtp_tls_key=/path/to/key.pem
|
||||
imap_tls_cert=/path/to/cert.pem
|
||||
imap_tls_key=/path/to/key.pem
|
||||
```
|
||||
@@ -77,6 +81,8 @@ In Docker Compose:
|
||||
|
||||
```yaml
|
||||
environment:
|
||||
- smtp_tls_cert=/certs/cert.pem
|
||||
- smtp_tls_key=/certs/key.pem
|
||||
- imap_tls_cert=/certs/cert.pem
|
||||
- imap_tls_key=/certs/key.pem
|
||||
volumes:
|
||||
|
||||
Reference in New Issue
Block a user