Relay transactional email through Salesforce instead of SMTP #9

Merged
Paddy merged 2 commits from feature/email-via-salesforce into master 2026-08-31 16:17:59 +00:00
Owner
No description provided.
Paddy added 2 commits 2026-08-31 16:16:06 +00:00
Our SMTP host's IP reputation gets its mail blocked by allowlist-based
receivers (t-online.de). Route voucher confirmations, account activation
and password-reset mail through the Salesforce org's MTA + DKIM instead,
via a new EmailSendResource Apex REST endpoint.

- common/salesforce.client.ts: shared client-credentials access (token
  cache + retry-once-on-401), extracted from the newsletter sync so it is
  no longer duplicated
- common.mail.nodemailer.ts -> common.mail.ts: posts to the org endpoint,
  never throws on a delivery failure (logs + returns a boolean), retries
  once on a transient failure, base64-encodes attachments with a 3 MB cap
- drop the nodemailer dependency
- fixes activation/reset email failures that previously threw after the
  transaction had already committed
- tickets.confirmation-email.ts: shared confirmation-email builder used by
  both the public redeem path and a new admin resend action
- redemptions gain a confirmation_email_status column (migration 003) so
  the admin UI can flag a failed send; POST
  /tickets/admin/redemptions/:id/resend-confirmation rebuilds and resends

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Review follow-up:
- tickets.confirmation-email.ts: a failed .ics generation was swallowed
  silently; log a warning (the email still goes out without the
  attachment)
- test/common/salesforce.client.test.ts: direct coverage for the shared
  client's token cache and retry-once-on-401 (previously exercised only
  indirectly through the newsletter sync test)

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Paddy merged commit 449edd6c68 into master 2026-08-31 16:17:59 +00:00
Sign in to join this conversation.