• 1.1.0 1cd3cb9a2e

    1.1.0 Stable

    astelm released this 2026-10-05 21:12:26 +03:00 | 1 commits to main since this release

    What's Changed

    Full Changelog: v1.0.0...1.1.0

    • migrate configuration from JSON to YAML
    • add HTTP Basic Auth for web interface
    • move HTML, CSS and JS to external web directory
    • cache web assets in memory on startup
    • remove absolute filesystem paths from web API
    • add path traversal protection
    • improve SMTP and HTTP server shutdown
    • improve service command argument handling
    • add Windows and Linux Makefile builds

    Release 1.1.0

    Version 1.1.0 introduces a new YAML-based configuration format, improved web interface deployment, HTTP authentication, safer email access, and improved application lifecycle handling.

    Configuration

    The application configuration format has been changed from JSON to YAML.

    The default configuration file is now:

    config.yaml

    Configuration is divided into separate smtp and web sections.

    Example:

    smtp:
      listen_address: 0.0.0.0
      listen_port: 25
      storage_dir: emails
      domain_name: mail.example.com
      max_message_size: 52428800
      enable_auth: true
    
    web:
      enabled: true
      port: 8089
      directory: web
    
      basic_auth:
        enabled: true
        username: admin
        password: change-me
    

    Relative paths such as emails and web are resolved relative to the application executable.

    Web interface

    The web interface is no longer embedded into the application binary.

    The following files are stored in the external web directory:

    web/
    ├── index.html
    ├── app.css
    ├── app.js
    └── tailwind.js
    

    All web interface files are loaded into memory once when the application starts. This allows the interface to be modified without rebuilding the Go application while avoiding filesystem access for every HTTP request.

    Changes to files in the web directory require an application/service restart.

    The application no longer requires Internet access for UI assets. Tailwind, application JavaScript, and CSS are all provided locally.

    HTTP Basic Authentication

    HTTP Basic Authentication has been added for the web interface.

    When enabled, authentication protects the complete HTTP interface, including:

    /
    /static/*
    /api/*
    

    Credentials are configured using:

    web:
      basic_auth:
        enabled: true
        username: admin
        password: change-me
    

    SMTP AUTH behavior remains unchanged and is independent from HTTP Basic Authentication.

    Improved email file security

    The web interface no longer exposes absolute filesystem paths.

    Previously, email API requests could operate on filesystem paths supplied by the client.

    Version 1.1.0 uses relative email identifiers such as:

    2026-10-05/20261005_120000.000_sender_example.com.eml
    

    The server validates email identifiers and only permits access to .eml files located inside the configured storage_dir.

    This prevents path traversal and arbitrary filesystem access through the email API.

    Web UI improvements

    The web interface has been reorganized into separate HTML, CSS, and JavaScript files.

    Additional improvements include:

    • removal of inline application event handlers;
    • email operations now use safe email IDs instead of filesystem paths;
    • improved keyboard interaction for email entries;
    • isolated email rendering inside sandboxed iframes;
    • improved iframe resizing;
    • local Tailwind JavaScript;
    • improved handling of missing web resources;
    • cached web resources loaded at application startup.

    Service lifecycle improvements

    SMTP and HTTP servers now support cleaner shutdown behavior.

    The SMTP listener is explicitly closed when the service stops.

    SMTP accept loops correctly exit when the listener is closed instead of continuously logging errors.

    If WebServer startup fails after SMTP startup, the SMTP server is stopped to avoid leaving the application partially running.

    Command-line argument handling was also improved.

    The following now works correctly:

    ric930-fake-smtp -config config.yaml install
    

    The -config option is no longer interpreted as a service-control command.

    Build improvements

    A Makefile has been added for Windows and Linux builds.

    Available targets include:

    make build-linux
    make build-windows
    make build-all
    make clean
    make check
    make tidy
    

    Build artifacts are placed in:

    builds/
    ├── linux/
    └── windows/
    

    Each build directory contains the application binary, config.yaml, and the complete web directory.

    Upgrade notes

    Version 1.1.0 is not configuration-compatible with the previous JSON configuration format.

    Before upgrading, convert the existing JSON configuration to the new YAML structure.

    Also make sure that the web directory is deployed next to the application binary.

    The default HTTP Basic Auth password should be changed before deployment.

    Downloads