IMP-07: mehrfach-postfach-verwaltung-pro-tenant

Verwaltung mehrerer Postfächer je Mandant: Anlage, getrennte
Abrufkonfiguration pro Postfach.

- store.go: Postgres-Store, beliebig viele unabhängige Postfächer je
  Mandant, eigene Abrufparameter (Intervall, Host/Port/Benutzername,
  Ordnerauswahl) je Postfach. Passwort nie im Klartext gespeichert —
  Wiederverwendung von mail/internal/crypto (ARC-02, unverändert) für
  Envelope-Encryption. List filtert strikt nach tenant_slug,
  Update/Delete streng auf tenant_slug+id beschränkt.

Prüfungen (alle real durchgeführt, siehe mail/docs/IMP-07-PRUEFPROTOKOLL.md):
1. TestList_TwoTenantsWithMultipleMailboxesSeeOnlyOwn: zwei Mandanten
   sehen real ausschließlich eigene Postfächer.
2. TestDelete_DoesNotAffectSiblingMailboxes: Löschen real ohne
   Auswirkung auf Geschwister-Postfächer.
3. TestUpdate_ConfigChangeDoesNotAffectOtherMailboxes: Änderung real
   isoliert auf ein Postfach beschränkt.

Kein Umbau: mail/internal/crypto unverändert wiederverwendet.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HhgFcLS8tYMhDJpP74C6AQ
This commit is contained in:
sysops
2026-09-01 00:31:18 +02:00
co-authored by Claude Sonnet 5
parent 145a161f8a
commit 5dcfa36f99
4 changed files with 446 additions and 0 deletions
+211
View File
@@ -0,0 +1,211 @@
// Package mailboxconfig implementiert IMP-07: Verwaltung mehrerer
// Postfächer je Mandant (Anlage, getrennte Abrufkonfiguration je
// Postfach). Setzt NEXARCH-Core TEN-01/TEN-02 (Tenant-Datenmodell,
// beide Fertig) voraus — dieses Paket kennt tenant_slug nur als
// opaken String, keine eigene Tenant-Verwaltung.
//
// Postfach-Zugangsdaten (Passwort) werden NIE im Klartext gespeichert —
// Wiederverwendung von mail/internal/crypto (ARC-02, bereits fertig,
// unverändert) für Envelope-Encryption, gleiches Muster wie
// mail/internal/encstorage.
package mailboxconfig
import (
"bytes"
"context"
_ "embed"
"errors"
"fmt"
"io"
"strings"
"github.com/jackc/pgx/v5"
"github.com/jackc/pgx/v5/pgxpool"
"gitea.perlbach24.de/scripte/nexarch/mail/internal/crypto"
)
//go:embed migrations/0001_mail_mailboxes.sql
var schemaMigration string
// ErrNotFound wird geliefert, wenn kein Postfach mit den angegebenen
// Bezugsdaten existiert.
var ErrNotFound = errors.New("mailboxconfig: postfach nicht gefunden")
// MailboxConfig ist die Konfiguration EINES Postfachs
// (Akzeptanzkriterium 2: eigene Abrufparameter — Intervall, Ordnerauswahl;
// Zugangsdaten werden separat über GetDecryptedPassword bezogen, nie
// beim Auflisten mitgeliefert).
type MailboxConfig struct {
ID int64
TenantSlug string
Name string
IMAPHost string
IMAPPort int
IMAPUsername string
FolderSelection []string
IntervalSeconds int
}
const defaultIntervalSeconds = 300
// Store verwaltet Postfachkonfigurationen je Mandant in Postgres.
type Store struct {
pool *pgxpool.Pool
crypto *crypto.Service
}
func NewStore(pool *pgxpool.Pool, cryptoSvc *crypto.Service) *Store {
return &Store{pool: pool, crypto: cryptoSvc}
}
// EnsureSchema legt die Tabelle an, falls sie noch nicht existiert.
func (s *Store) EnsureSchema(ctx context.Context) error {
if _, err := s.pool.Exec(ctx, schemaMigration); err != nil {
return fmt.Errorf("mailboxconfig: schema anlegen: %w", err)
}
return nil
}
// CreateInput sind die für die Anlage nötigen Angaben.
type CreateInput struct {
Name string
IMAPHost string
IMAPPort int
IMAPUsername string
Password string
FolderSelection []string
IntervalSeconds int
}
// Create legt ein neues Postfach für tenantSlug an (Akzeptanzkriterium 1:
// ein Mandant kann mehrere Postfächer unabhängig konfigurieren — kein
// Limit, keine gegenseitige Abhängigkeit zwischen Postfächern desselben
// Mandanten). Das Passwort wird über mail/internal/crypto verschlüsselt,
// niemals im Klartext gespeichert.
func (s *Store) Create(ctx context.Context, tenantSlug string, in CreateInput) (int64, error) {
if in.IntervalSeconds <= 0 {
in.IntervalSeconds = defaultIntervalSeconds
}
if len(in.FolderSelection) == 0 {
in.FolderSelection = []string{"INBOX"}
}
env, err := s.crypto.Seal(ctx, tenantSlug, strings.NewReader(in.Password))
if err != nil {
return 0, fmt.Errorf("mailboxconfig: passwort verschlüsseln: %w", err)
}
ciphertext, err := io.ReadAll(env.Ciphertext)
if err != nil {
return 0, fmt.Errorf("mailboxconfig: chiffretext lesen: %w", err)
}
var id int64
err = s.pool.QueryRow(ctx, `
INSERT INTO mail_mailboxes
(tenant_slug, name, imap_host, imap_port, imap_username, wrapped_password_dek, encrypted_password, folder_selection, interval_seconds)
VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9)
RETURNING id
`, tenantSlug, in.Name, in.IMAPHost, in.IMAPPort, in.IMAPUsername, env.WrappedDEK, ciphertext, strings.Join(in.FolderSelection, ","), in.IntervalSeconds).Scan(&id)
if err != nil {
return 0, fmt.Errorf("mailboxconfig: postfach anlegen: %w", err)
}
return id, nil
}
// List liefert alle Postfächer eines Mandanten (Akzeptanzkriterium 3:
// strikt nach tenant_slug gefiltert) — OHNE Zugangsdaten.
func (s *Store) List(ctx context.Context, tenantSlug string) ([]MailboxConfig, error) {
rows, err := s.pool.Query(ctx, `
SELECT id, name, imap_host, imap_port, imap_username, folder_selection, interval_seconds
FROM mail_mailboxes WHERE tenant_slug = $1 ORDER BY name
`, tenantSlug)
if err != nil {
return nil, fmt.Errorf("mailboxconfig: postfächer lesen: %w", err)
}
defer rows.Close()
var configs []MailboxConfig
for rows.Next() {
var c MailboxConfig
var folders string
c.TenantSlug = tenantSlug
if err := rows.Scan(&c.ID, &c.Name, &c.IMAPHost, &c.IMAPPort, &c.IMAPUsername, &folders, &c.IntervalSeconds); err != nil {
return nil, fmt.Errorf("mailboxconfig: postfachzeile lesen: %w", err)
}
c.FolderSelection = strings.Split(folders, ",")
configs = append(configs, c)
}
if err := rows.Err(); err != nil {
return nil, fmt.Errorf("mailboxconfig: postfächer iterieren: %w", err)
}
return configs, nil
}
// UpdateInput sind die änderbaren Felder eines Postfachs
// (Akzeptanzkriterium 2/3: Konfigurationsänderung betrifft ausschließlich
// dieses eine Postfach).
type UpdateInput struct {
IMAPHost string
IMAPPort int
FolderSelection []string
IntervalSeconds int
}
// Update ändert die Abrufparameter EINES Postfachs, streng auf
// tenantSlug+id beschränkt.
func (s *Store) Update(ctx context.Context, tenantSlug string, id int64, in UpdateInput) error {
tag, err := s.pool.Exec(ctx, `
UPDATE mail_mailboxes
SET imap_host = $3, imap_port = $4, folder_selection = $5, interval_seconds = $6, updated_at = now()
WHERE tenant_slug = $1 AND id = $2
`, tenantSlug, id, in.IMAPHost, in.IMAPPort, strings.Join(in.FolderSelection, ","), in.IntervalSeconds)
if err != nil {
return fmt.Errorf("mailboxconfig: postfach aktualisieren: %w", err)
}
if tag.RowsAffected() == 0 {
return ErrNotFound
}
return nil
}
// Delete entfernt GENAU EIN Postfach, streng auf tenantSlug+id beschränkt
// (Akzeptanzkriterium/Pflichtprüfung 2: andere Postfächer desselben
// Mandanten bleiben unberührt).
func (s *Store) Delete(ctx context.Context, tenantSlug string, id int64) error {
tag, err := s.pool.Exec(ctx, `DELETE FROM mail_mailboxes WHERE tenant_slug = $1 AND id = $2`, tenantSlug, id)
if err != nil {
return fmt.Errorf("mailboxconfig: postfach löschen: %w", err)
}
if tag.RowsAffected() == 0 {
return ErrNotFound
}
return nil
}
// GetDecryptedPassword entschlüsselt das Postfach-Passwort — separater,
// bewusster Aufruf statt Bestandteil von List/Get, damit Zugangsdaten
// nicht beiläufig mitgeliefert werden.
func (s *Store) GetDecryptedPassword(ctx context.Context, tenantSlug string, id int64) (string, error) {
var wrappedDEK, ciphertext []byte
err := s.pool.QueryRow(ctx, `
SELECT wrapped_password_dek, encrypted_password FROM mail_mailboxes
WHERE tenant_slug = $1 AND id = $2
`, tenantSlug, id).Scan(&wrappedDEK, &ciphertext)
if err != nil {
if errors.Is(err, pgx.ErrNoRows) {
return "", ErrNotFound
}
return "", fmt.Errorf("mailboxconfig: postfach lesen: %w", err)
}
plaintextReader, err := s.crypto.Open(ctx, tenantSlug, wrappedDEK, bytes.NewReader(ciphertext))
if err != nil {
return "", fmt.Errorf("mailboxconfig: passwort entschlüsseln: %w", err)
}
plaintext, err := io.ReadAll(plaintextReader)
if err != nil {
return "", fmt.Errorf("mailboxconfig: passwort lesen: %w", err)
}
return string(plaintext), nil
}