package config import "testing" // Confirms docs/MAIL_SETUP.md is telling the truth about the committed `.env`: // a sender is set, a host is not, and the server therefore reports mail OFF with // a reason naming the variable — rather than trying and failing to send. func TestCommittedEnvLeavesMailOffWithAReason(t *testing.T) { t.Setenv("MAIL_HOST", "") t.Setenv("MAIL_PORT", "587") t.Setenv("MAIL_FROM", "care@nearledaily.com") t.Setenv("MAIL_FROM_NAME", "Nearle") t.Setenv("MAIL_CONSOLE_URL", "https://app.nearledaily.com") cfg := MailFromEnv() if cfg.Enabled() { t.Fatal("mail reported as enabled with no host") } if cfg.Why() == "" || cfg.Why()[:9] != "MAIL_HOST" { t.Fatalf("the reason does not name the missing variable: %q", cfg.Why()) } // And with the Postal host supplied from .env.secrets, it comes on and the // link points at the MERCHANT console. t.Setenv("MAIL_HOST", "postal.nearledaily.com") on := MailFromEnv() if !on.Enabled() { t.Fatalf("still off with a host set: %s", on.Why()) } if got := on.InviteLink("i1.abc.def"); got != "https://app.nearledaily.com/set-password?t=i1.abc.def" { t.Fatalf("the invitation would point at %q", got) } if on.Address() != "postal.nearledaily.com:587" { t.Fatalf("wrong SMTP address: %q", on.Address()) } } /* ── Google App Passwords ────────────────────────────────────────────────── */ func TestAGoogleAppPasswordSurvivesBeingPastedWithItsSpaces(t *testing.T) { // Google shows it as "abcd efgh ijkl mnop". The spaces are presentation. // Pasted verbatim they reach Gmail, which refuses the login — reported as // "the mail server refused our credentials", sending somebody to revoke a // password that was fine. t.Setenv("MAIL_HOST", "smtp.gmail.com") t.Setenv("MAIL_PORT", "587") t.Setenv("MAIL_USERNAME", "care@nearledaily.com") t.Setenv("MAIL_PASSWORD", "abcd efgh ijkl mnop") t.Setenv("MAIL_FROM", "care@nearledaily.com") t.Setenv("MAIL_CONSOLE_URL", "https://app.nearledaily.com") if got := MailFromEnv().Password; got != "abcdefghijklmnop" { t.Fatalf("password reached the relay as %q", got) } } func TestAnAlreadyCleanAppPasswordIsUntouched(t *testing.T) { t.Setenv("MAIL_HOST", "smtp.gmail.com") t.Setenv("MAIL_PASSWORD", "abcdefghijklmnop") if got := MailFromEnv().Password; got != "abcdefghijklmnop" { t.Fatalf("got %q", got) } } func TestAnotherRelaysPasswordIsNeverEdited(t *testing.T) { // A secret is a secret. Another relay's password may legitimately contain a // space, and stripping it there turns a working credential into a silent // authentication failure — this bug pointed the other way. for _, host := range []string{"smtp.sendgrid.net", "email-smtp.ap-south-1.amazonaws.com", "postal.nearledaily.com"} { t.Setenv("MAIL_HOST", host) t.Setenv("MAIL_PASSWORD", "two words here x") if got := MailFromEnv().Password; got != "two words here x" { t.Errorf("%s: password was edited to %q", host, got) } } } func TestSomethingThatIsNotAnAppPasswordIsLeftAlone(t *testing.T) { // Only the exact shape Google issues — sixteen alphanumerics — is treated // as display formatting. Anything else is somebody's real password. t.Setenv("MAIL_HOST", "smtp.gmail.com") for _, password := range []string{ "short one", // not 16 after stripping "a much longer pass phrase here", // not 16 "abcd efgh ijkl mno!", // punctuation: not an App Password } { t.Setenv("MAIL_PASSWORD", password) if got := MailFromEnv().Password; got != password { t.Errorf("%q was rewritten to %q", password, got) } } }