Feature/implement token generation and validation for knock emails#6
Merged
Feature/implement token generation and validation for knock emails#6
Conversation
Contributor
There was a problem hiding this comment.
Pull request overview
This pull request implements a token-based authentication system for the SMTP server to control email sending. The implementation generates secure random tokens when users "knock" (request permission), stores them with sender information, and enforces validation checks before allowing emails to be sent.
Key Changes:
- Implements secure token generation using 32-byte random tokens converted to hexadecimal format
- Adds validation checks to reject emails with missing, invalid, or unvalidated tokens
- Returns proper SMTP error code 553 with descriptive messages for validation failures
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
401b21e to
07f9b76
Compare
nfroidure
approved these changes
Nov 25, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request improves the security and flow of the SMTP server's token-based email sending process. The main updates are focused on generating secure tokens, storing them properly, and enforcing validation before allowing email sending.
Token management and validation improvements:
randomBytes, stores it intokenStorewith the sender's address and avalidated: falseflag, and constructs a validation link for the user (src/services/smtpServer.ts).src/services/smtpServer.ts).