Files
sso-manager-node/nodejs/models/email.js
T
wmantly ed62e70678 Stop the notification Compose form from defaulting to "email everyone"
The Compose form's "Send to" radio group had "All active users" checked
by default with no confirmation before Send -- anyone opening the
Dashboard to see how the feature works, typing a test subject/message,
and clicking Send would broadcast to every active user. Remove the
default (a target must now be explicitly chosen) and require a confirm
step before actually sending to "all" or "all_active".

Also add a hard safety net in models/email.js: Mail.send is a no-op
under NODE_ENV=test, so the automated test suite (which exercises the
real notification/password-reset/invite/OTP-by-email routes with
NODE_ENV=test) can never deliver real mail regardless of what recipient
list a test resolves.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-15 17:02:57 -04:00

66 lines
1.8 KiB
JavaScript

'use strict';
const nodemailer = require('nodemailer');
const mustache = require('mustache');
const conf = require('@simpleworkjs/conf');
var Mail = {};
Mail.send = function(to, subject, message, from){
// Never let the automated test suite deliver real mail — tests run against
// this app's real routes (notification broadcast, password reset, invite,
// OTP-by-email, …) with NODE_ENV=test, and any of them resolving a real
// recipient list must not actually hit SMTP. Tests already tolerate this
// (see e.g. tests/misc.test.js: "SMTP failure is non-fatal") since none
// assert on real delivery.
if(conf.environment === 'test'){
return Promise.resolve({accepted: [], rejected: [], response: 'skipped: NODE_ENV=test'});
}
return new Promise(function(resolve, reject){
var transportOpts = {
host: conf.smtp.host || 'localhost',
port: conf.smtp.port || 25,
secure: conf.smtp.secure !== undefined ? conf.smtp.secure : false
};
if (conf.smtp.user && conf.smtp.pass) {
transportOpts.auth = {
user: conf.smtp.user,
pass: conf.smtp.pass
};
}
var transporter = nodemailer.createTransport(transportOpts);
var mailOpts = {
from: from || conf.smtp.from || `${conf.name} Accounts <noreply@theta42.com>`,
to: to,
subject: subject,
html: message
};
transporter.sendMail(mailOpts, function(err, info){
if (err) {
reject(err);
} else {
resolve(info);
}
});
});
};
Mail.sendTemplate = async function(to, template, context, from){
context.name = conf.name;
template = require(`../views/email_templates/${template}`);
await Mail.send(
to,
mustache.render(template.subject, context),
mustache.render(template.message, context),
from || (template.from && mustache.render(template.message, context))
)
};
module.exports = {Mail};