feat: .NET 9 contact relay (stateless minimal API)

- POST /api/contact: validate -> honeypot -> per-IP rate limit -> SMTP send
- /healthz endpoint; CORS locked to site origin; forwarded-headers for real client IP
- no persistence, no message bodies logged (IP hashed to a short non-reversible marker)
- source-generated JSON; config via env (SMTP + relay settings)
- alpine multi-stage Dockerfile, non-root, healthcheck
- verified: healthz 200, invalid 400, honeypot silent 200, missing-SMTP 502

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
cesnimda
2026-07-04 05:55:20 +02:00
parent 1b5204e7f8
commit 9fa16b650d
6 changed files with 212 additions and 0 deletions
+5
View File
@@ -0,0 +1,5 @@
bin/
obj/
**/appsettings.*.local.json
Dockerfile
.dockerignore