-
1.1.0 Stable
released this
2026-10-05 21:12:26 +03:00 | 1 commits to main since this releaseWhat's Changed
Full Changelog: v1.0.0...1.1.0
- migrate configuration from JSON to YAML
- add HTTP Basic Auth for web interface
- move HTML, CSS and JS to external web directory
- cache web assets in memory on startup
- remove absolute filesystem paths from web API
- add path traversal protection
- improve SMTP and HTTP server shutdown
- improve service command argument handling
- add Windows and Linux Makefile builds
Release 1.1.0
Version 1.1.0 introduces a new YAML-based configuration format, improved web interface deployment, HTTP authentication, safer email access, and improved application lifecycle handling.
Configuration
The application configuration format has been changed from JSON to YAML.
The default configuration file is now:
config.yamlConfiguration is divided into separate
smtpandwebsections.Example:
smtp: listen_address: 0.0.0.0 listen_port: 25 storage_dir: emails domain_name: mail.example.com max_message_size: 52428800 enable_auth: true web: enabled: true port: 8089 directory: web basic_auth: enabled: true username: admin password: change-meRelative paths such as
emailsandwebare resolved relative to the application executable.Web interface
The web interface is no longer embedded into the application binary.
The following files are stored in the external
webdirectory:web/ ├── index.html ├── app.css ├── app.js └── tailwind.jsAll web interface files are loaded into memory once when the application starts. This allows the interface to be modified without rebuilding the Go application while avoiding filesystem access for every HTTP request.
Changes to files in the
webdirectory require an application/service restart.The application no longer requires Internet access for UI assets. Tailwind, application JavaScript, and CSS are all provided locally.
HTTP Basic Authentication
HTTP Basic Authentication has been added for the web interface.
When enabled, authentication protects the complete HTTP interface, including:
/ /static/* /api/*Credentials are configured using:
web: basic_auth: enabled: true username: admin password: change-meSMTP AUTH behavior remains unchanged and is independent from HTTP Basic Authentication.
Improved email file security
The web interface no longer exposes absolute filesystem paths.
Previously, email API requests could operate on filesystem paths supplied by the client.
Version 1.1.0 uses relative email identifiers such as:
2026-10-05/20261005_120000.000_sender_example.com.emlThe server validates email identifiers and only permits access to
.emlfiles located inside the configuredstorage_dir.This prevents path traversal and arbitrary filesystem access through the email API.
Web UI improvements
The web interface has been reorganized into separate HTML, CSS, and JavaScript files.
Additional improvements include:
- removal of inline application event handlers;
- email operations now use safe email IDs instead of filesystem paths;
- improved keyboard interaction for email entries;
- isolated email rendering inside sandboxed iframes;
- improved iframe resizing;
- local Tailwind JavaScript;
- improved handling of missing web resources;
- cached web resources loaded at application startup.
Service lifecycle improvements
SMTP and HTTP servers now support cleaner shutdown behavior.
The SMTP listener is explicitly closed when the service stops.
SMTP accept loops correctly exit when the listener is closed instead of continuously logging errors.
If WebServer startup fails after SMTP startup, the SMTP server is stopped to avoid leaving the application partially running.
Command-line argument handling was also improved.
The following now works correctly:
ric930-fake-smtp -config config.yaml installThe
-configoption is no longer interpreted as a service-control command.Build improvements
A Makefile has been added for Windows and Linux builds.
Available targets include:
make build-linux make build-windows make build-all make clean make check make tidyBuild artifacts are placed in:
builds/ ├── linux/ └── windows/Each build directory contains the application binary,
config.yaml, and the completewebdirectory.Upgrade notes
Version 1.1.0 is not configuration-compatible with the previous JSON configuration format.
Before upgrading, convert the existing JSON configuration to the new YAML structure.
Also make sure that the
webdirectory is deployed next to the application binary.The default HTTP Basic Auth password should be changed before deployment.
Downloads