EMAIL-WP-0005-T02: add GreenMail test harness
Adds tests/harness/docker-compose.yml running GreenMail 2.1.12 (digest-pinned) with SMTP 3025, IMAP 3143 and the API bound to 127.0.0.1 only, plus a config/harness-imap.yml scanner profile and harness README. Auth is disabled and no users are declared, so a mailbox is created on first login and per-test users need no provisioning. GreenMail standalone offers no STARTTLS, only plaintext or implicit TLS, while SMTPProvider hardcoded starttls() -- so no send could reach it. SMTPProvider now takes a security mode via EMAIL_CONNECT_SMTP_SECURITY, defaulting to starttls. plaintext is refused for any non-loopback host, and hostnames are never resolved to decide that, so a misconfigured deployment fails at startup rather than sending credentials in the clear. Trusting GreenMail's self-signed cert was rejected as the wider risk; see DECISIONS.md. Verified end to end against the live harness: SMTPProvider.send -> GreenMail -> ImapMailboxSource, and the documented scan-mailbox CLI. Suite: 52 passed with the harness down. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
86f22c2e65
commit
89fd13ac2d
8 changed files with 329 additions and 4 deletions
38
tests/harness/docker-compose.yml
Normal file
38
tests/harness/docker-compose.yml
Normal file
|
|
@ -0,0 +1,38 @@
|
|||
# Local mail server for email-connect integration tests (EMAIL-WP-0005-T02).
|
||||
#
|
||||
# GreenMail serves SMTP and IMAP from one container and creates the declared
|
||||
# accounts at startup, which is what the scanner's IMAP source and the
|
||||
# transactional service's SMTP provider need.
|
||||
#
|
||||
# Everything here is test-only. The credentials below are deliberately
|
||||
# non-secret and belong in the repo; real provider material is routed through
|
||||
# OpenBao (see .claude/rules/credential-routing.md) and must never appear here.
|
||||
services:
|
||||
greenmail:
|
||||
image: greenmail/standalone:2.1.12@sha256:9f32971b4f25d32b4de6fa2e297423768441c65e4541f6aecd7631c890a229a7
|
||||
container_name: email-connect-harness
|
||||
# Loopback-only bindings. The harness accepts unauthenticated-ish test
|
||||
# traffic and must never be reachable from the network.
|
||||
ports:
|
||||
- "127.0.0.1:3025:3025" # SMTP
|
||||
- "127.0.0.1:3143:3143" # IMAP
|
||||
- "127.0.0.1:8080:8080" # GreenMail API (readiness, purge)
|
||||
environment:
|
||||
GREENMAIL_OPTS: >-
|
||||
-Dgreenmail.setup.test.smtp
|
||||
-Dgreenmail.setup.test.imap
|
||||
-Dgreenmail.hostname=0.0.0.0
|
||||
-Dgreenmail.auth.disabled
|
||||
-Dgreenmail.verbose
|
||||
# The image ships no curl/wget/nc, so readiness is probed with bash's
|
||||
# /dev/tcp against both mail ports.
|
||||
healthcheck:
|
||||
test:
|
||||
- CMD
|
||||
- bash
|
||||
- -c
|
||||
- "exec 3<>/dev/tcp/127.0.0.1/3025 && exec 4<>/dev/tcp/127.0.0.1/3143"
|
||||
interval: 2s
|
||||
timeout: 3s
|
||||
retries: 30
|
||||
start_period: 5s
|
||||
Loading…
Add table
Add a link
Reference in a new issue