cesnimda 626a9f8454 fix(security): Phase 4 edge hardening + SSRF egress guard
Backend security fixes from the Phase 1 register / Phase 2 roadmap (PR1 + V-01):

- V-01 SSRF: new SafeHttpGuard validates outbound unsubscribe URLs (scheme allowlist
  + DNS-resolve-and-block private/loopback/link-local/ULA/metadata ranges), wired into
  UnsubscribeService; the "unsubscribe" HttpClient now disables auto-redirect so a
  validated external URL can't 3xx into an internal target. +33 unit tests.
- V-04: session cookie SecurePolicy=Always in non-dev (SameAsRequest in dev).
- V-06: UseExceptionHandler/ProblemDetails in prod; Cleanup/Unsubscribe no longer
  echo ex.Message to clients (logged server-side, generic message returned).
- V-08: ForwardedHeaders trusted only from configurable KnownNetworks (default private
  ranges) + ForwardLimit, instead of trusting any client. New ForwardedHeaders config.
- V-09: returnUrl validated with Url.IsLocalUrl (no open redirect via OAuth flow).
- V-10: SearchService clamps Page/PageSize (<=200); Analytics clamps take/days.
- V-11: baseline security headers (nosniff, X-Frame-Options DENY, Referrer-Policy,
  COOP) + HSTS in prod.
- V-13: /app/info discloses only devMode to anonymous callers unless dev mode is on.
- V-12: API container runs as non-root 'app' user (keys dir pre-owned).
- V-03: Postgres + API ports bound to 127.0.0.1; POSTGRES_PASSWORD now required (no
  weak default fallback).

API compatibility preserved (clamps not rejections; error-body shape changes only on
failure paths). No DB migrations. Build + all 33 unit tests green. V-15 (MailKit
NU1902) persists across versions and the SMTP path is default-off — tracked, not bumped.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-01 00:15:04 +02:00
2026-06-30 15:53:32 +02:00
2026-06-30 15:53:32 +02:00
2026-06-30 15:53:32 +02:00
2026-06-30 15:53:32 +02:00

InboxIntel — Inbox Intelligence Platform

A Gmail analytics, cleanup, and automation app. Connects via Google OAuth2, syncs your inbox into PostgreSQL, and gives you a draggable analytics dashboard, safe bulk cleanup, unsubscribe management, optional AI analysis, advanced search, and PDF/CSV/JSON exports.

This repository is a full-stack scaffold structured for the 15-step implementation plan. Every layer is wired and compiles; the business logic is functional, with a few integration points (Gmail parsing edge cases, AI prompt tuning) intentionally left as clearly-marked extension points.

Architecture

Clean Architecture across four backend projects plus a React SPA:

src/
  InboxIntel.Domain          Entities + enums. No external dependencies.
  InboxIntel.Application      Service interfaces, DTOs, validators, query parser.
  InboxIntel.Infrastructure   EF Core, Gmail client, sync worker, AI, export.
  InboxIntel.Api              ASP.NET Core Web API: auth, controllers, DI, Serilog.
frontend/                     React + Vite dashboard (Chart.js, react-grid-layout).
tests/                        Unit + integration test projects.

Dependency rule: Api -> Infrastructure -> Application -> Domain. Controllers contain no business logic; they delegate to Application-layer service interfaces resolved through DI.

See docs/ARCHITECTURE.md for the full design, data model, and request flow.

Tech stack

.NET 8 / ASP.NET Core, EF Core + Npgsql (PostgreSQL), Hosted background worker, Serilog, FluentValidation, Polly (retry + backoff), Google.Apis.Gmail, QuestPDF/CsvHelper for exports, React 18 + Vite + Chart.js + react-grid-layout.

cp .env.example .env          # then fill in Google OAuth credentials
docker compose up --build

Services: PostgreSQL (5432), API (8080), frontend (8081). Optional reverse proxy:

docker compose --profile proxy up --build   # everything on port 80

The API applies EF migrations automatically on startup (Database:AutoMigrate).

Running locally (without Docker)

  1. Start PostgreSQL and set the connection string in src/InboxIntel.Api/appsettings.Development.json.

  2. Create the initial migration and database:

    dotnet tool install --global dotnet-ef
    dotnet ef migrations add InitialCreate \
      -p src/InboxIntel.Infrastructure -s src/InboxIntel.Api
    dotnet ef database update -p src/InboxIntel.Infrastructure -s src/InboxIntel.Api
    
  3. Run the API and the frontend:

    dotnet run --project src/InboxIntel.Api        # http://localhost:5080
    cd frontend && npm install && npm run dev      # http://localhost:5173
    

Google OAuth2 setup

Create an OAuth client (type: Web application) in the Google Cloud Console. Add the Gmail API. Authorized redirect URI: http://localhost:5080/signin-google (dev) and your production URL. Put the client id/secret in .env or user-secrets. Scopes requested: openid email profile gmail.readonly gmail.modify (no send scope).

Security notes

OAuth refresh tokens are encrypted at rest with the ASP.NET Core Data Protection API (AES) and never logged. Keys persist to a mounted /keys volume. All destructive cleanup and unsubscribe actions require an explicit Confirmed flag and a server-side preview. The AI layer is advisory only — it never performs destructive actions.

Tests

dotnet test

Unit tests cover the Gmail query parser and unsubscribe extraction; integration tests boot the API host and assert authorization is enforced.

S
Description
No description provided
Readme 1.2 MiB
Languages
C# 63.4%
JavaScript 29.5%
CSS 5.6%
PowerShell 0.6%
Dockerfile 0.4%
Other 0.5%