3849c16666
b3 of the multi-provider email roadmap. Adds ImapConnection model + table (reconciler pattern, SQLite+MySQL), ImapService (MailKit-backed IMAP client), ImapProvider implementing the existing IEmailProvider contract unchanged, and ImapController for credential-based connect (no OAuth — user supplies host/username/password directly, verified by a live connect before storage). Scope, documented inline with ponytail: comments: - INBOX only, no multi-folder support. - Thread grouping approximates the References/In-Reply-To chain root rather than the IMAP THREAD extension, which not every server implements. - External message ids are IMAP UIDs, scoped to the connection's current UIDVALIDITY. Security: ran the security-audit skill against this diff (credential handling + arbitrary-host connect is exactly the class of change the standing security gate exists for). Found and fixed a real SSRF: the connect endpoint let an authenticated user point the server at an arbitrary host:port with no internal-range check, and connect-vs-auth failure was distinguishable to the caller -- together a working oracle to fingerprint internal services (loopback/RFC1918/link-local/cloud metadata) from the server's network position. Fixed with EnsureHostIsExternalAsync (DNS-resolve + reject internal ranges, re-checked on every reconnect to close the DNS-rebinding gap) and a single generic failure message that no longer distinguishes connect vs auth failure. 7 regression tests added. Dependency: MailKit 4.17.0 (MIT license) on JobTrackerBackend.csproj -- stdlib has no IMAP client; hand-rolling IMAP4rev1 (TLS, SASL, MIME parsing) would be a large, security-sensitive protocol implementation nobody asked for, so this is the correct dependency, not a stdlib substitute. 168/168 green (161 existing + 7 new SSRF regression tests; the earlier 14 IMAP feature tests are included in the 161). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
21 lines
828 B
C#
21 lines
828 B
C#
namespace JobTrackerApi.Models;
|
|
|
|
public sealed class ImapConnection
|
|
{
|
|
public int Id { get; set; }
|
|
public string OwnerUserId { get; set; } = "";
|
|
public string Host { get; set; } = "";
|
|
public int Port { get; set; } = 993;
|
|
public bool UseSsl { get; set; } = true;
|
|
public string Username { get; set; } = "";
|
|
public string EncryptedPassword { get; set; } = "";
|
|
public DateTimeOffset ConnectedAt { get; set; } = DateTimeOffset.UtcNow;
|
|
public DateTimeOffset? LastSyncedAt { get; set; }
|
|
public DateTimeOffset? LastSyncAttemptedAt { get; set; }
|
|
public DateTimeOffset? LastSyncSucceededAt { get; set; }
|
|
public string? LastSyncMode { get; set; }
|
|
public string? LastSyncSource { get; set; }
|
|
public string? LastSyncStatus { get; set; }
|
|
public string? LastSyncError { get; set; }
|
|
}
|