Compare commits

..

17 commits

Author SHA1 Message Date
mplorentz
051c1e88fb Rate-limit confirmation emails and restore daily/weekly digest cron
- Add last_confirm_sent_at to subscriptions, with a migration for
  existing databases. registerSubscription now sends at most one
  confirmation email per 10 minutes per subscription, so a page-refresh
  or client retry storm can't spam an inbox. The cooldown resets when
  the address changes or a tombstoned row is reactivated (fresh key),
  so genuinely new addresses always get an email immediately.
- Restore getCronExpression to the documented daily (17:00 UTC) and
  weekly (Monday 17:00 UTC) schedules with the 6-field cron syntax the
  cron package expects, fixing the pre-existing reschedule tests that the
  'run every minute' testing hack had broken.
- Add confirm-email-cooldown.test.ts covering first send, refresh storms,
  frequency changes, email changes, reactivation, and the 10-minute constant.
2026-09-22 12:31:33 -04:00
mplorentz
81f5602ce4 Merge remote-tracking branch 'origin/main' into cron-minutely 2026-09-22 10:58:30 -04:00
mplorentz
5675ebdf52 fix reactivating old rows 2026-09-21 11:26:26 -04:00
mplorentz
fd815282c2 Re-activate tomstoned subscriptions when email is the same 2026-09-21 10:05:53 -04:00
mplorentz
3a7d0d110a Merge branch 'cron-minutely' of ssh://forgejo.lorentz.is:4201/matt/mailship into cron-minutely 2026-09-18 13:11:58 -04:00
mplorentz
8ebee878cb Merge remote-tracking branch 'origin/main' into cron-minutely 2026-09-18 13:11:51 -04:00
hudson
395b192432 Set trust proxy so NIP-98 URL matching works behind traefik (X-Forwarded-Proto) 2026-09-16 15:15:06 -04:00
mplorentz
dd90386fb6 Merge branch 'main' into cron-minutely 2026-09-16 14:07:25 -04:00
mplorentz
ce59c15819 dedupe and serialize subscription writes. 2026-09-03 13:42:50 -04:00
mplorentz
db490f5c99 Merge branch 'main' into cron-minutely 2026-09-03 12:00:22 -04:00
mplorentz
bb1a7982dc Merge branch 'main' into cron-minutely 2026-08-27 15:23:24 -04:00
mplorentz
29111e117c Merge branch 'main' into cron-minutely 2026-08-27 14:51:14 -04:00
mplorentz
2644310bfa Merge branch 'main' into cron-minutely 2026-08-27 11:28:12 -04:00
mplorentz
082b442f16 Update subscription confirmation email template 2026-08-27 10:17:06 -04:00
mplorentz
0eaf2a9895 Merge branch 'main' into cron-minutely 2026-08-26 17:58:03 -04:00
mplorentz
cdabec2a92 log errors 2026-08-25 15:15:33 -04:00
mplorentz
291f92c37e Run cron every minute for testing 2026-08-25 14:53:03 -04:00
8 changed files with 31 additions and 244 deletions

View file

@ -51,30 +51,15 @@ Flotilla ──HTTP──▶ Mailship (PUT /subscription/email)
### PUT /subscription/email
Idempotently register or update an email subscription. Re-sends the confirmation
email only when the subscription is new or the email address changed; a frequency
or schedule change keeps the existing confirmation. The pubkey is extracted from
the NIP-98 Authorization header — the body does not include a `pubkey` field.
change keeps the existing confirmation. The pubkey is extracted from the NIP-98
Authorization header — the body does not include a `pubkey` field.
```
Body: { email, frequency, hour?, minute?, dayOfWeek?, timezone? }
Body: { email, frequency }
Auth: NIP-98 (Nostr <base64> Authorization header)
Response: { key, callback }
```
**Optional schedule fields (defaults: `hour=17`, `minute=0`, `timezone="UTC"`):**
| Field | Type | Constraints | Default |
|---|---|---|---|
| `hour` | integer | 0–23 | `17` |
| `minute` | integer | 0–59 | `0` |
| `dayOfWeek` | integer | 1=Mon … 7=Sun (0 also accepted as Sun); only valid when `frequency="weekly"` | `1` (Monday) for weekly, omitted for daily |
| `timezone` | string | IANA timezone name, e.g. `"America/New_York"` | `"UTC"` |
When omitted, each field falls back to its default. `dayOfWeek` is silently
ignored for daily frequency (the stored value is `NULL`).
**DOW convention:** `dayOfWeek` follows cron: 1=Monday, 2=Tuesday, …, 7=Sunday.
`0` is also accepted as Sunday (standard cron alias).
### GET /subscription/email
Look up an existing subscription for the authenticated pubkey, so clients can
avoid re-registering (and re-confirming) when settings haven't changed.
@ -82,7 +67,7 @@ Returns 404 if none exists.
```
Auth: NIP-98 (Nostr <base64> Authorization header)
Response: { key, callback, email, frequency, hour, minute, dayOfWeek, timezone, confirmed }
Response: { key, callback, email, frequency, confirmed }
```
### DELETE /subscription/:key

View file

@ -13,10 +13,6 @@ export type RegisterSubscriptionParams = {
pubkey: string
email: string
frequency: string
hour?: number
minute?: number
dayOfWeek?: number
timezone?: string
}
// Floor on how often a confirmation email can be sent for the same subscription.
@ -26,8 +22,8 @@ export const CONFIRM_EMAIL_COOLDOWN_SECONDS = 10 * 60
export const registerSubscription = instrument(
'actions.registerSubscription',
async ({ pubkey, email, frequency, hour, minute, dayOfWeek, timezone }: RegisterSubscriptionParams) => {
const sub = await db.insertSubscription(pubkey, email, frequency, hour, minute, dayOfWeek, timezone)
async ({ pubkey, email, frequency }: RegisterSubscriptionParams) => {
const sub = await db.insertSubscription(pubkey, email, frequency)
const callback = `${process.env.BASE_URL}/notify/${sub.id}`
if (!sub.confirmed_at) {

View file

@ -4,10 +4,6 @@ export type Subscription = {
pubkey: string
email: string
frequency: string
hour: number
minute: number
day_of_week?: number
timezone: string
created_at: number
confirmed_at?: number
unsubscribed_at?: number
@ -23,40 +19,14 @@ export const getSubscriptionError = (sub: Subscription) => {
if (!['daily', 'weekly'].includes(sub.frequency)) {
return 'Frequency must be "daily" or "weekly"'
}
if (sub.hour < 0 || sub.hour > 23 || !Number.isInteger(sub.hour)) {
return 'Hour must be an integer between 0 and 23'
}
if (sub.minute < 0 || sub.minute > 59 || !Number.isInteger(sub.minute)) {
return 'Minute must be an integer between 0 and 59'
}
if (sub.frequency === 'weekly') {
if (sub.day_of_week === undefined || sub.day_of_week === null) {
return 'dayOfWeek is required for weekly frequency'
}
const dow = sub.day_of_week
if (dow < 0 || dow > 7 || !Number.isInteger(dow)) {
return 'dayOfWeek must be an integer between 0 and 7 (1=Mon, 7=Sun, 0=Sun)'
}
}
if (!sub.timezone || typeof sub.timezone !== 'string') {
return 'A valid IANA timezone is required'
}
try {
Intl.DateTimeFormat(undefined, { timeZone: sub.timezone })
} catch {
return `"${sub.timezone}" is not a valid IANA timezone`
}
}
export const getCronExpression = (frequency: string, hour = 17, minute = 0, dayOfWeek?: number) => {
if (frequency === 'daily') {
return `0 ${minute} ${hour} * * *`
export const getCronExpression = (frequency: string, hour = 17, minute = 0) => {
// Daily: fire at 17:00 UTC. Weekly: fire Monday (day-of-week 1) at 17:00 UTC.
// The `cron` package uses 6-field syntax (leading field is seconds).
if (frequency === 'weekly') {
return `0 ${minute} ${hour} * * 1`
}
// Weekly: default to Monday (1) when not specified
return `0 ${minute} ${hour} * * ${dayOfWeek ?? 1}`
return `0 ${minute} ${hour} * * *`
}

View file

@ -9,7 +9,7 @@ import type { Subscription } from './alert.js'
const DATA_DIR = process.env.DATA_DIR || '.'
const db = new sqlite3.Database(DATA_DIR + '/mailship.db')
type Param = number | string | boolean | null | undefined
type Param = number | string | boolean
type Row = Record<string, any>
@ -58,10 +58,6 @@ export const migrate = () =>
pubkey TEXT NOT NULL,
email TEXT NOT NULL,
frequency TEXT NOT NULL DEFAULT 'daily',
hour INTEGER NOT NULL DEFAULT 17,
minute INTEGER NOT NULL DEFAULT 0,
day_of_week INTEGER,
timezone TEXT NOT NULL DEFAULT 'UTC',
created_at INTEGER NOT NULL,
confirmed_at INTEGER,
unsubscribed_at INTEGER,
@ -121,20 +117,6 @@ export const migrate = () =>
WHERE unsubscribed_at IS NULL
`
)
// Idempotent migration: add schedule columns to existing databases.
// ALTER TABLE ADD COLUMN fails if the column already exists, so we
// run each one and ignore "duplicate column" errors.
const addCol = (colDef: string) =>
run(`ALTER TABLE subscriptions ADD COLUMN ${colDef}`).catch((err: any) => {
if (!err?.message?.includes('duplicate column')) throw err
})
await addCol('hour INTEGER NOT NULL DEFAULT 17')
await addCol('minute INTEGER NOT NULL DEFAULT 0')
await addCol('day_of_week INTEGER')
await addCol("timezone TEXT NOT NULL DEFAULT 'UTC'")
resolve()
})
} catch (err) {
@ -152,30 +134,19 @@ const parseSubscription = (row: any): Subscription | undefined => {
export const updateSubscription = instrument(
'database.updateSubscription',
async (existing: Subscription, email: string, frequency: string, hour?: number, minute?: number, dayOfWeek?: number, timezone?: string) => {
const scheduleChanged =
(hour !== undefined && hour !== existing.hour) ||
(minute !== undefined && minute !== existing.minute) ||
(dayOfWeek !== undefined && dayOfWeek !== existing.day_of_week) ||
(timezone !== undefined && timezone !== existing.timezone)
if (existing.email === email && existing.frequency === frequency && !scheduleChanged) {
async (existing: Subscription, email: string, frequency: string) => {
if (existing.email === email && existing.frequency === frequency) {
return existing
}
const hr = hour ?? existing.hour
const mn = minute ?? existing.minute
const dow = dayOfWeek ?? existing.day_of_week
const tz = timezone ?? existing.timezone
// Update by id, not pubkey, so tombstoned rows for the same account are never
// re-activated alongside this one (the unique index would reject that anyway).
if (existing.email === email) {
return parseSubscription(
await get(
`UPDATE subscriptions SET frequency = ?, hour = ?, minute = ?, day_of_week = ?, timezone = ?, unsubscribed_at = NULL
`UPDATE subscriptions SET frequency = ?, unsubscribed_at = NULL
WHERE id = ? RETURNING *`,
[frequency, hr, mn, dow, tz, existing.id]
[frequency, existing.id]
)
)
}
@ -184,9 +155,9 @@ export const updateSubscription = instrument(
// cooldown or the new address would inherit the old one's lockout.
return parseSubscription(
await get(
`UPDATE subscriptions SET email = ?, frequency = ?, hour = ?, minute = ?, day_of_week = ?, timezone = ?, confirmed_at = NULL, unsubscribed_at = NULL, last_confirm_sent_at = NULL
`UPDATE subscriptions SET email = ?, frequency = ?, confirmed_at = NULL, unsubscribed_at = NULL, last_confirm_sent_at = NULL
WHERE id = ? RETURNING *`,
[email, frequency, hr, mn, dow, tz, existing.id]
[email, frequency, existing.id]
)
)
}
@ -223,11 +194,11 @@ const reactivateSubscription = async (tombstoned: Subscription, frequency: strin
export const insertSubscription = instrument(
'database.insertSubscription',
async (pubkey: string, email: string, frequency: string, hour?: number, minute?: number, dayOfWeek?: number, timezone?: string) => {
async (pubkey: string, email: string, frequency: string) => {
const existing = await getSubscriptionByPubkey(pubkey)
if (existing) {
return assertResult(await updateSubscription(existing, email, frequency, hour, minute, dayOfWeek, timezone))
return assertResult(await updateSubscription(existing, email, frequency))
}
// No active row. If this account previously subscribed to this email and
@ -256,18 +227,14 @@ export const insertSubscription = instrument(
return assertResult(
parseSubscription(
await get(
`INSERT INTO subscriptions (id, key, pubkey, email, frequency, hour, minute, day_of_week, timezone, created_at)
VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?) RETURNING *`,
`INSERT INTO subscriptions (id, key, pubkey, email, frequency, created_at)
VALUES (?, ?, ?, ?, ?, ?) RETURNING *`,
[
crypto.randomUUID(),
crypto.randomBytes(32).toString('hex'),
pubkey,
email,
frequency,
hour ?? 17,
minute ?? 0,
dayOfWeek ?? null,
timezone ?? 'UTC',
now(),
]
)
@ -281,7 +248,7 @@ export const insertSubscription = instrument(
const concurrent = await getSubscriptionByPubkey(pubkey)
if (concurrent) {
return assertResult(await updateSubscription(concurrent, email, frequency, hour, minute, dayOfWeek, timezone))
return assertResult(await updateSubscription(concurrent, email, frequency))
}
}

View file

@ -186,10 +186,6 @@ addRoute('get', '/subscription/email', async (req: Request, res: Response) => {
callback,
email: sub.email,
frequency: sub.frequency,
hour: sub.hour,
minute: sub.minute,
dayOfWeek: sub.day_of_week,
timezone: sub.timezone,
confirmed: Boolean(sub.confirmed_at),
})
})
@ -198,7 +194,7 @@ addRoute('get', '/subscription/email', async (req: Request, res: Response) => {
// auth proving the caller controls the pubkey — the pubkey is extracted from
// the auth event, not from the request body.
addRoute('put', '/subscription/email', async (req: Request, res: Response) => {
const { email, frequency, hour, minute, dayOfWeek, timezone } = req.body
const { email, frequency } = req.body
const pubkey = await verifyNip98Auth(req)
@ -214,38 +210,8 @@ addRoute('put', '/subscription/email', async (req: Request, res: Response) => {
return res.status(400).json({ error: 'Frequency must be "daily" or "weekly"' })
}
// Validate optional schedule fields
if (hour !== undefined) {
if (!Number.isInteger(hour) || hour < 0 || hour > 23) {
return res.status(400).json({ error: 'Hour must be an integer between 0 and 23' })
}
}
if (minute !== undefined) {
if (!Number.isInteger(minute) || minute < 0 || minute > 59) {
return res.status(400).json({ error: 'Minute must be an integer between 0 and 59' })
}
}
if (dayOfWeek !== undefined) {
if (frequency !== 'weekly') {
return res.status(400).json({ error: 'dayOfWeek is only valid for weekly frequency' })
}
if (!Number.isInteger(dayOfWeek) || dayOfWeek < 0 || dayOfWeek > 7) {
return res.status(400).json({ error: 'dayOfWeek must be an integer between 0 and 7 (1=Mon, 7=Sun, 0=Sun)' })
}
}
if (timezone !== undefined) {
try {
Intl.DateTimeFormat(undefined, { timeZone: timezone })
} catch {
return res.status(400).json({ error: `"${timezone}" is not a valid IANA timezone` })
}
}
try {
const result = await registerSubscription({ pubkey, email, frequency, hour, minute, dayOfWeek, timezone })
const result = await registerSubscription({ pubkey, email, frequency })
res.json(result)
} catch (error: any) {
// The subscription was still created, but sending the confirmation email

View file

@ -49,7 +49,7 @@ export const runJob = async (sub: Subscription) => {
}
const createJob = (sub: Subscription) => {
const cron = getCronExpression(sub.frequency, sub.hour, sub.minute, sub.day_of_week)
const cron = getCronExpression(sub.frequency)
const run = async () => {
// Re-fetch the subscription to pick up the latest last_digest_at.
@ -64,7 +64,7 @@ const createJob = (sub: Subscription) => {
cronTime: cron,
onTick: run,
start: true,
timeZone: sub.timezone ?? 'UTC',
timeZone: 'UTC',
})
}

View file

@ -1,97 +0,0 @@
import { describe, it, expect, beforeAll, afterAll } from 'vitest'
import * as db from '../src/database.js'
import { registerSubscription } from '../src/actions.js'
import { getCronExpression } from '../src/alert.js'
import { getJobCronSource, removeJob } from '../src/worker/email.js'
import { registerSubscription as regSub } from '../src/worker/index.js'
const pubkey = 'schedule-test-' + Date.now()
const email = 'schedule-test-' + Date.now() + '@example.com'
let sub: any = null
describe('Schedule fields', () => {
beforeAll(async () => {
await db.migrate()
})
it('inserts subscription with custom hour/minute/timezone', async () => {
const s = await db.insertSubscription(pubkey, email, 'daily', 7, 30, undefined, 'America/New_York')
expect(s).toBeTruthy()
expect(s!.hour).toBe(7)
expect(s!.minute).toBe(30)
expect(s!.timezone).toBe('America/New_York')
expect(s!.day_of_week).toBeNull()
sub = s
})
it('inserts subscription with custom weekly dayOfWeek', async () => {
const pk2 = 'schedule-test-weekly-' + Date.now()
const em2 = pk2 + '@example.com'
const s = await db.insertSubscription(pk2, em2, 'weekly', 9, 0, 6, 'UTC')
expect(s).toBeTruthy()
expect(s!.hour).toBe(9)
expect(s!.minute).toBe(0)
expect(s!.day_of_week).toBe(6)
expect(s!.timezone).toBe('UTC')
})
it('inserts subscription with defaults when schedule omitted', async () => {
const pk3 = 'schedule-test-defaults-' + Date.now()
const em3 = pk3 + '@example.com'
const s = await db.insertSubscription(pk3, em3, 'daily')
expect(s).toBeTruthy()
expect(s!.hour).toBe(17)
expect(s!.minute).toBe(0)
expect(s!.timezone).toBe('UTC')
expect(s!.day_of_week).toBeNull()
})
it('getCronExpression returns daily with custom hour/minute', () => {
expect(getCronExpression('daily', 7, 30)).toBe('0 30 7 * * *')
})
it('getCronExpression returns weekly with custom dayOfWeek', () => {
expect(getCronExpression('weekly', 9, 0, 6)).toBe('0 0 9 * * 6')
})
it('getCronExpression defaults to Monday for weekly', () => {
expect(getCronExpression('weekly', 17, 0)).toBe('0 0 17 * * 1')
})
it('confirms and registers job with custom schedule', async () => {
// Confirm the daily subscription created above
const confirmed = await db.confirmSubscription(sub.key)
expect(confirmed).toBeTruthy()
sub = confirmed!.sub
regSub(sub)
const dailySource = getJobCronSource(sub.id)
// Expect 0 30 7 * * * (from custom hour=7, minute=30)
expect(dailySource).toBe('0 30 7 * * *')
})
it('updateSubscription preserves schedule fields through frequency change', async () => {
const updated = await db.updateSubscription(sub, email, 'weekly', undefined, undefined, 2, undefined)
expect(updated).toBeTruthy()
expect(updated!.frequency).toBe('weekly')
// hour/minute should keep the previously set values (7/30) since we passed undefined
expect(updated!.hour).toBe(7)
expect(updated!.minute).toBe(30)
expect(updated!.day_of_week).toBe(2)
expect(updated!.timezone).toBe('America/New_York')
})
it('registerSubscription preserves schedule fields', async () => {
await registerSubscription({ pubkey, email, frequency: 'daily', hour: 10, minute: 15, timezone: 'Europe/London' })
const reloaded = await db.getSubscriptionByPubkey(pubkey)
expect(reloaded).toBeTruthy()
expect(reloaded!.hour).toBe(10)
expect(reloaded!.minute).toBe(15)
expect(reloaded!.timezone).toBe('Europe/London')
})
})
afterAll(async () => {
const updated = await db.getSubscriptionByPubkey(pubkey)
if (updated) removeJob(updated)
})