Relay transactional email through Salesforce instead of SMTP

Our SMTP host's IP reputation gets its mail blocked by allowlist-based
receivers (t-online.de). Route voucher confirmations, account activation
and password-reset mail through the Salesforce org's MTA + DKIM instead,
via a new EmailSendResource Apex REST endpoint.

- common/salesforce.client.ts: shared client-credentials access (token
  cache + retry-once-on-401), extracted from the newsletter sync so it is
  no longer duplicated
- common.mail.nodemailer.ts -> common.mail.ts: posts to the org endpoint,
  never throws on a delivery failure (logs + returns a boolean), retries
  once on a transient failure, base64-encodes attachments with a 3 MB cap
- drop the nodemailer dependency
- fixes activation/reset email failures that previously threw after the
  transaction had already committed
- tickets.confirmation-email.ts: shared confirmation-email builder used by
  both the public redeem path and a new admin resend action
- redemptions gain a confirmation_email_status column (migration 003) so
  the admin UI can flag a failed send; POST
  /tickets/admin/redemptions/:id/resend-confirmation rebuilds and resends

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-08-30 15:50:47 +02:00
parent 3c4f3331d8
commit 69904b749c
15 changed files with 690 additions and 141 deletions
+115
View File
@@ -0,0 +1,115 @@
// common.mail relays one email through the Salesforce org (see
// src/common/common.mail.ts). These tests mock the shared Salesforce client so
// no network is touched, and check: the payload shape, base64 attachment
// encoding, the attachment size cap, the retry-once-on-transient-failure
// behaviour, and that a delivery failure is swallowed (returns false, never
// throws).
jest.mock('../../src/common/salesforce.client');
jest.mock('../../src/middleware/logger', () => ({
__esModule: true,
default: {info: jest.fn(), warn: jest.fn(), error: jest.fn()}
}));
import {MailService} from '../../src/common/common.mail';
import {salesforceApexRestPost, salesforceEnabled} from '../../src/common/salesforce.client';
const mockPost = salesforceApexRestPost as jest.Mock;
const mockEnabled = salesforceEnabled as jest.Mock;
const httpError = (status: number, body?: any): any => {
const err: any = new Error('request failed with ' + status);
err.response = {status, data: body};
return err;
};
beforeEach(() => {
jest.clearAllMocks();
mockEnabled.mockReturnValue(true);
mockPost.mockResolvedValue({status: 'SENT'});
});
describe('MailService.sendMail', () => {
it('returns false without a callout when Salesforce is disabled', async () => {
mockEnabled.mockReturnValue(false);
const result = await MailService.sendMail('guest@example.com', 'Hi', 'Hallo');
expect(result).toBe(false);
expect(mockPost).not.toHaveBeenCalled();
});
it('posts the email to the Apex REST endpoint and returns true on success', async () => {
const result = await MailService.sendMail('guest@example.com', 'Bestätigung', 'Hallo', {html: '<p>Hallo</p>'});
expect(result).toBe(true);
expect(mockPost).toHaveBeenCalledWith('/services/apexrest/email/send', {
to: 'guest@example.com',
subject: 'Bestätigung',
textBody: 'Hallo',
htmlBody: '<p>Hallo</p>',
attachments: []
});
});
it('sends htmlBody as null when no HTML is given', async () => {
await MailService.sendMail('guest@example.com', 'Hi', 'Hallo');
expect(mockPost).toHaveBeenCalledWith('/services/apexrest/email/send', expect.objectContaining({htmlBody: null}));
});
it('base64-encodes attachments', async () => {
await MailService.sendMail('guest@example.com', 'Hi', 'Hallo', {
attachments: [{filename: 'konzert.ics', content: 'BEGIN:VCALENDAR', contentType: 'text/calendar'}]
});
expect(mockPost).toHaveBeenCalledWith(
'/services/apexrest/email/send',
expect.objectContaining({
attachments: [{
filename: 'konzert.ics',
contentType: 'text/calendar',
contentBase64: Buffer.from('BEGIN:VCALENDAR', 'utf-8').toString('base64')
}]
})
);
});
it('rejects an attachment over the size cap without sending', async () => {
const huge = Buffer.alloc(3 * 1024 * 1024 + 1);
const result = await MailService.sendMail('guest@example.com', 'Hi', 'Hallo', {
attachments: [{filename: 'big.pdf', content: huge}]
});
expect(result).toBe(false);
expect(mockPost).not.toHaveBeenCalled();
});
it('retries once on a 5xx and returns false when the retry also fails', async () => {
mockPost.mockRejectedValue(httpError(503));
const result = await MailService.sendMail('guest@example.com', 'Hi', 'Hallo');
expect(result).toBe(false);
expect(mockPost).toHaveBeenCalledTimes(2);
});
it('retries once on a network error (no response) then succeeds', async () => {
mockPost.mockRejectedValueOnce(new Error('socket hang up')).mockResolvedValueOnce({status: 'SENT'});
const result = await MailService.sendMail('guest@example.com', 'Hi', 'Hallo');
expect(result).toBe(true);
expect(mockPost).toHaveBeenCalledTimes(2);
});
it('does not retry on a 4xx (e.g. the 429 limit response) and returns false', async () => {
mockPost.mockRejectedValue(httpError(429, {errorCode: 'LIMIT_REACHED'}));
const result = await MailService.sendMail('guest@example.com', 'Hi', 'Hallo');
expect(result).toBe(false);
expect(mockPost).toHaveBeenCalledTimes(1);
});
});