Each entry in email_allowlist.json is treated as a re.fullmatch pattern (case-insensitive). Allows domain wildcards, plus-addressing, and any variation expressible as a regex. Invalid patterns are logged and skipped. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
83 lines
2.7 KiB
Python
83 lines
2.7 KiB
Python
"""
|
|
Notification tools — proactively send messages to user channels.
|
|
|
|
nc_talk_send routes through notification.py → channels.json.
|
|
email_send uses the server SMTP config from .env (smtp_server, smtp_from_*).
|
|
"""
|
|
|
|
import asyncio
|
|
import json
|
|
import logging
|
|
import re
|
|
|
|
from config import settings
|
|
from persona import get_user
|
|
|
|
logger = logging.getLogger(__name__)
|
|
|
|
|
|
def _load_allowlist(username: str) -> list[str]:
|
|
"""Load the per-user email allowlist. Returns empty list if not configured."""
|
|
path = settings.home_root() / username / "email_allowlist.json"
|
|
try:
|
|
return [str(p).strip() for p in json.loads(path.read_text()) if str(p).strip()]
|
|
except FileNotFoundError:
|
|
return []
|
|
except Exception as e:
|
|
logger.warning("failed to read email_allowlist.json for %s: %s", username, e)
|
|
return []
|
|
|
|
|
|
def _email_allowed(address: str, patterns: list[str]) -> bool:
|
|
"""Return True if address matches any pattern (regex, case-insensitive full match)."""
|
|
addr = address.strip()
|
|
for pattern in patterns:
|
|
try:
|
|
if re.fullmatch(pattern, addr, re.IGNORECASE):
|
|
return True
|
|
except re.error:
|
|
logger.warning("invalid regex in email allowlist: %r", pattern)
|
|
return False
|
|
|
|
|
|
async def email_send(to: str, subject: str, body: str) -> str:
|
|
"""Send an email via the server's configured SMTP account."""
|
|
username = get_user()
|
|
allowlist = _load_allowlist(username)
|
|
|
|
if not allowlist:
|
|
return (
|
|
"Email blocked — no allowlist configured. "
|
|
f"Add allowed patterns to home/{username}/email_allowlist.json as a JSON array."
|
|
)
|
|
if not _email_allowed(to, allowlist):
|
|
return f"Email blocked — {to} does not match any allowed pattern for {username}."
|
|
|
|
from email_utils import send_email
|
|
ok = await asyncio.to_thread(
|
|
send_email,
|
|
to_email=to,
|
|
subject=subject,
|
|
body_text=body,
|
|
body_html=body.replace("\n", "<br>"),
|
|
)
|
|
if ok:
|
|
return f"Email sent to {to}."
|
|
return "Failed to send email — check SMTP configuration in .env."
|
|
|
|
|
|
async def nc_talk_send(message: str) -> str:
|
|
"""Send a message to the user via their configured notification channel.
|
|
|
|
Channel is resolved from the user's channels.json (notification_channel key).
|
|
Falls back to Nextcloud Talk if configured. No-op if no channel is set.
|
|
"""
|
|
from notification import notify
|
|
username = get_user()
|
|
try:
|
|
await notify(username, message)
|
|
return f"Message sent to {username}'s notification channel."
|
|
except Exception as e:
|
|
logger.warning("nc_talk_send error for %s: %s", username, e)
|
|
return f"Failed to send notification: {e}"
|