Skip to content

feat(plugins): add host SMTP mail capability - #559

Open
7heMech wants to merge 1 commit into
CoreBunch:mainfrom
7heMech:feat/plugin-smtp-mail
Open

7heMech wants to merge 1 commit into
CoreBunch:mainfrom
7heMech:feat/plugin-smtp-mail

Conversation

@7heMech

@7heMech 7heMech commented Sep 23, 2026 •

Copy link
Copy Markdown

Summary

Add a host-managed SMTP capability for server plugins. Plugins can store mailbox credentials in encrypted secret settings, declare allowed SMTP hosts, and send mail through api.cms.mail.send. The host enforces the new permission, validates the request, resolves and pins a public address, and requires TLS (465) or STARTTLS (587). The plugin install review displays allowed SMTP hosts.

This supports email plugin without a separate webhook relay.

Verification

  • bun run build — passed
  • bun run lint — passed
  • bun run bootstrap:check — passed
  • Focused SMTP, manifest, permission review, RPC registry, and sandbox invariant tests — passed
  • bun test — 7,055 passed; three failures: the sandbox RPC target list (fixed after the run and verified in isolation), circular dependency check (15-second test timeout; direct Madge run found no cycles), and an unrelated step-up auth test (5-second timeout, reproduced in isolation)

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednodemailer@​10.0.10961009896100

View full report

@7heMech

7heMech commented Sep 23, 2026 •

Copy link
Copy Markdown
Author

Well, an agent straight up did this when I told it I want SMTP plugin, but it is reasonable also hopefully hopefully Bun.SMTP gets implemented soon so no nodemailer dep.

@7heMech
7heMech marked this pull request as ready for review September 23, 2026 07:53

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant