feat: .NET 9 contact relay (stateless minimal API)

- POST /api/contact: validate -> honeypot -> per-IP rate limit -> SMTP send
- /healthz endpoint; CORS locked to site origin; forwarded-headers for real client IP
- no persistence, no message bodies logged (IP hashed to a short non-reversible marker)
- source-generated JSON; config via env (SMTP + relay settings)
- alpine multi-stage Dockerfile, non-root, healthcheck
- verified: healthz 200, invalid 400, honeypot silent 200, missing-SMTP 502

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
cesnimda
2026-07-04 05:55:20 +02:00
parent 1b5204e7f8
commit 9fa16b650d
6 changed files with 212 additions and 0 deletions
+22
View File
@@ -0,0 +1,22 @@
# syntax=docker/dockerfile:1
# ---- build ----
FROM mcr.microsoft.com/dotnet/sdk:9.0-alpine AS build
WORKDIR /src
COPY ContactRelay.csproj .
RUN dotnet restore
COPY . .
RUN dotnet publish -c Release -o /app --no-restore
# ---- runtime ----
FROM mcr.microsoft.com/dotnet/aspnet:9.0-alpine AS final
WORKDIR /app
RUN addgroup -S app && adduser -S app -G app
COPY --from=build /app .
USER app
ENV ASPNETCORE_URLS=http://+:8081 \
DOTNET_EnableDiagnostics=0
EXPOSE 8081
HEALTHCHECK --interval=30s --timeout=3s --retries=3 \
CMD wget -qO- http://localhost:8081/healthz || exit 1
ENTRYPOINT ["dotnet", "ContactRelay.dll"]