- internal/logging now wraps log/slog; logging.format json/text finally
works (json is the documented default). Same exported API.
- New internal/metrics: /metrics on the configured metrics port with
notification gauges by status/type, queue depth, and HTTP request
count/duration labeled by mux route pattern; sampled from service
stats so the service layer stays metrics-agnostic.
- Standard grpc.health.v1 health service registered (k8s gRPC probes);
gRPC MaxRecvMsgSize bounded to match the REST 1 MB body limit.
- Dedicated health listener on health_check.port serving /health and
/readyz (probes now work in grpc-only mode); metrics, health, and
REST servers all shut down gracefully.
- main wires retry backoff, CORS, readiness checks, and TLS from config.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- CORS config is now actually applied to the router (the middleware
existed but was never wired); preflight returns 204 for allowed
origins and 403 with no CORS headers for disallowed ones.
- /readyz runs real dependency checks (queue, auth database) and
returns 503 with per-component detail when not ready; exported
handlers support dedicated health listeners.
- Optional server.tls (cert_file/key_file) for REST and gRPC, validated
at config load.
- 5xx responses no longer echo internal error details; not-found and
already-sent map to 404/409 on cancel/retry.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Copy discipline for notifications: the store, the queue, workers, and
API callers each own clones; no notification object is shared across
goroutines (races previously flagged by -race between workers mutating
Status/RetryCount and handlers JSON-encoding the same pointer).
- Retry progress derives from QueueMessage.Attempt so it survives
requeues; exponential backoff (1s base, 30s cap) honors the documented
queue.retry_backoff setting instead of hammering failing providers in a
tight loop; shutdown abandons pending backoff waits cleanly.
- Stop() cancels a service-lifetime context so idle workers blocked in
Dequeue exit immediately instead of waiting out their poll timeout.
- LocalQueue no longer holds its mutex while sending on the queue
channel (Enqueue/Nack) — with a full buffer this deadlocked the entire
worker pool, since draining requires the same mutex.
- Tenant scoping: notifications are stamped with the caller's ClientID;
non-admin clients can only read/cancel/retry their own (cross-tenant
access reports not-found to avoid leaking existence).
- Sentinel errors ErrNotificationNotFound/ErrNotificationAlreadySent.
- New race, backoff, and tenant-scoping test suites.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
govulncheck flagged GO-2026-5026/GO-2026-4918 (x/net) and GO-2026-4762
(grpc); both now at patched versions.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Validate all recipients with net/mail.ParseAddress; reject CR/LF.
- RFC 2047 (Q-encoding) for Subject and FromName so CRLF and non-ASCII
cannot break out of headers.
- Honor use_tls: implicit TLS on port 465 with certificate verification;
otherwise document the opportunistic-STARTTLS path.
- Table-driven tests for validation, injection neutralization, and
multipart building.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Store SHA-256 digests (key_hash + key_preview) instead of raw keys, in
both the in-memory store and Postgres; migrate legacy plaintext rows in
place and drop the plaintext column.
- Fix TEXT[] scans that failed at runtime (missing pq.Array) in
GetKey/ListKeys/LoadAllKeys.
- Load persisted keys at startup (InitializeFromDatabase was never called)
and fall back to the database on cache miss, so issued keys survive
restarts.
- Make HybridKeyStore.CreateKey genuinely write-through: cache is only
updated after a successful DB write.
- Guard nil database backend (auth enabled without DB previously panicked
on key creation) and degrade to in-memory operation.
- Persist bootstrap admin keys when a database is configured.
- Record real audit-log details as JSON and log audit failures instead of
silently dropping them; add DB pool limits and ping timeout.
- Sentinel errors matched with errors.Is; unit tests for hashing,
write-through ordering, DB fallback, and nil-DB operation.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Replace the k8s/-centric deployment section with a provider-agnostic
GitOps pattern (Kustomize base+overlay, pinned tags, operator-managed
secrets, Gateway API routing) and demote k8s/ to reference examples.
Gitignore docs/WEBUI_PLAN.md: this repo is public and that doc holds
private infrastructure details (now relocated to the private gitops repo).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Build on the native host arch (--platform=$BUILDPLATFORM) and cross-compile
the static binary per target via buildx-provided TARGETOS/TARGETARCH, so
`make docker-build` with REGISTRY set produces linux/amd64 + linux/arm64
images without emulating the Go toolchain under QEMU. Also correct the CMD
comment to the real env var (NOTIFIER_SERVER_MODE).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Document the previously-missing endpoints (GET /api/v1/notifiers and the
/api/v1/admin/keys management routes), mark the gRPC API and API-key auth
as implemented, and add an Authentication section plus links to the docs
guides. Fix incorrect examples: the env prefix is NOTIFIER_ (so
NOTIFIER_SERVER_MODE, not SERVER_MODE) and the multi-arch build var is
REGISTRY (not DOCKER_REGISTRY).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Setting REGISTRY now switches `make docker-build` from a single-arch
local build to a multi-arch (linux/amd64+linux/arm64) buildx build
that pushes $REGISTRY/$IMAGE:$VERSION and :latest. The redundant
docker-buildx target is removed. Bump the builder base image to
golang:1.25-alpine so protoc-gen-go-grpc@latest installs cleanly.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Callers can now supply a plain-text Body alongside an HTML html_body;
the SMTP sender emits multipart/alternative using both verbatim instead
of auto-stripping HTML to derive the plain-text fallback. The legacy
content_type=HTML path is preserved (deprecated) for existing callers.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Guard against nil result before accessing result.Error in processNotification,
and add NtfyNotifier.Validate override so DefaultTopic is considered before
rejecting notifications with zero recipients.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Use typed context key for auth context to prevent collisions (auth.go)
- Eliminate nested locking in CheckRateLimit to prevent potential deadlock (auth.go)
- Add 1MB request body size limit middleware to prevent DoS (router.go)
- Return proper gRPC status codes instead of nil errors on failures (handler.go)
- Use key name instead of raw API key in admin URL paths to prevent secret leakage (keys.go, router.go, keystore_db.go, keystore_hybrid.go)
- Enforce RBAC authorization in service Send/SendBatch for both REST and gRPC (service.go)
- Pin runtime Docker image to alpine:3.21 for reproducible builds (Dockerfile)
- Enable readOnlyRootFilesystem with /tmp emptyDir in k8s deployment (deployment.yaml)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Normalize content_type to lowercase before processing to handle case-insensitive input (e.g., "HTML", "Html")
- Add validation in Validate() to ensure only valid content types are accepted
- Return descriptive error message if invalid content type is provided
- Fix condition in ToNotification() to properly detect and default content type
- Update SMTP notifier auto-detection to work correctly when content type is not explicitly set
Issues fixed:
1. Dynamically detecting content type now works correctly (was always defaulting to "text")
2. Client can now specify content type in request as "HTML", "html", or "Html" - all work
3. Invalid content types are rejected with clear error messages
4. Auto-detection still works if neither explicit type nor valid HTML markers are found
Example scenarios:
- No content_type field: auto-detects based on body (checks for <, <html, <!DOCTYPE, <p>, <div>, <br>)
- content_type: "html": sends as HTML with multipart/alternative
- content_type: "HTML": normalized to "html", sends as HTML
- content_type: "invalid": returns validation error
- content_type: "text": explicitly sends as plain text, skips auto-detection
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
- Change IsAuthorized() to use deny-by-default when RBAC is enabled
- If ANY authorization rules are configured, only notifiers with explicit allowed_roles are accessible
- Notifiers without rules are denied access when RBAC is active
- If NO rules are configured, maintain open access for backward compatibility
- Add HasRules() helper method to check if RBAC is enabled
This fixes the issue where notifiers WITHOUT allowed_roles were being returned instead of
the notifiers WITH matching allowed_roles. Now when RBAC is configured:
- Only notifiers with explicit rules that match the user's roles are returned
- All other notifiers are hidden from the client
Example: If only email has allowed_roles=['admin'] and user has role 'admin':
- OLD: email ✓, stdout ✓ (WRONG - stdout should be hidden)
- NEW: email ✓, stdout ✗ (CORRECT - only email is returned)
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
- Add SanitizeDatabaseURL() function to config package that redacts passwords from database connection URLs
- Handles various URL formats: postgresql, mysql, etc.
- Correctly handles passwords containing special characters including @ symbols by using LastIndex
- Update startup logging in cmd/server/main.go to use sanitized database URL
- Add comprehensive tests covering various URL formats and edge cases
This ensures sensitive database credentials are not exposed in application logs.
- Add LDFLAGS_BASE for version info only, LDFLAGS for production (with -s -w optimization), and LDFLAGS_DEV for development
- Create 'build' target (production) that strips symbols, reducing binary size by ~30% (56MB -> 39MB)
- Create 'build-dev' target (development) that keeps debug symbols for profiling
- Update 'docker-build' to pass BUILD_FLAGS="-s -w" for optimized production images
- Create 'docker-build-dev' target that builds development images with notifier:latest-dev tag and no optimization
- Update Dockerfile to accept and use BUILD_FLAGS argument in build stage
- All targets now clearly indicate their optimization level in output messages
After conflict resolution from rebase, some imports were accidentally
removed and the CORS middleware function was eliminated but still
referenced by tests. This commit:
- Adds fmt import to api/rest/keys.go (used for error messages)
- Adds gorilla/mux import to cmd/server/main.go (used for router type)
- Restores newCORSMiddleware function to api/rest/router.go for test compatibility
- Formats code with gofmt
The Docker build was failing because protobuf-generated code wasn't
available during compilation. Changes made:
- Added protoc and protobuf-dev packages to build dependencies
- Installed protoc-gen-go and protoc-gen-go-grpc plugins
- Added make proto-gen step to generate pb files before build
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
Add comprehensive improvements across REST and gRPC APIs:
- Add structured logging for all notification operations
- Implement HTML email support with multipart/alternative MIME
- Add CC and BCC recipient support for email notifications
- Add GetNotifiers endpoint to query available notifier configurations
- Support configurable From name in SMTP configuration
- Auto-detect content type (text vs HTML) in notification bodies
- Improve error handling and validation across all endpoints
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>