Email was the one sidecar built inside out. The platform held ~1,800 lines — the per-account
SQLite store, all 14 HTTP routes, account CRUD, resync, IMAP validation — while the 314-line
sidecar was a scheduler that reached BACK into the platform to do anything
(`import { performResync } from '../../api/email/resync'`).
The sidecar now serves its own HTTP listener and announces `email:server`, and
/api/email/* on the platform is createSidecarProxy like every other one: 1,801 lines down
to 22, with no mail knowledge left in it — not a message, not a folder, not a credential.
The routes moved verbatim, Hono and all. http.ts only reconstructs what the platform's
middleware used to provide: `user` on the context, from the X-Officer-User header the proxy
injects (trusted because this server binds loopback), and an error handler that turns
custom-errors into status codes.
The /email/events SSE stream went with them, which removes a whole round trip: the IDLE
watcher used to send `email:new` over the registration socket so the platform could push to
its SSE clients. Those clients are here now, so it calls broadcastEmailNew in-process and
`email:new` is gone from the wire protocol.
DELIBERATELY NOT DONE YET, and left backwards on purpose rather than half-moved:
- The two sync handlers (email-sync 381 lines, gmail-sync 712) still run in the platform's
queue and now import the store from its new home — a platform → sidecar import, which is
the wrong direction and is temporary. Moving them is option (A) from the plan: the sidecar
schedules its own syncs, independent of the platform Jobs list.
- accounts.ts still imports queue/init to enqueue a sync and to report sync status, and
index.ts still carries the queue-over-WS shim that inversion needs.
- The three channel handlers still open the mail store directly rather than asking over HTTP.
Two things worth knowing while testing: a from-scratch sync holds a proxied request open
well past the 60s idle default, hence timeoutSeconds on the proxy; and `gmail-sync` is
hardcoded in all three channel handlers even though the only account is provider=gmail with
auth_type=password, which routes to IMAP — so "sync emails" from a chat channel is
almost certainly already broken, and folds into the next stage.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
55 lines
1.5 KiB
TypeScript
55 lines
1.5 KiB
TypeScript
type ValidateImapParams = {
|
|
host: string;
|
|
port: number;
|
|
secure: boolean;
|
|
user: string;
|
|
pass?: string;
|
|
accessToken?: string;
|
|
};
|
|
|
|
type ValidateImapResult = { ok: true; folderCount: number } | { ok: false; error: string };
|
|
|
|
export async function validateImapConnection(params: ValidateImapParams): Promise<ValidateImapResult> {
|
|
const { ImapFlow } = await import('imapflow');
|
|
|
|
const auth: { user: string; pass?: string; accessToken?: string } = { user: params.user };
|
|
if (params.accessToken) {
|
|
auth.accessToken = params.accessToken;
|
|
} else if (params.pass) {
|
|
auth.pass = params.pass;
|
|
} else {
|
|
return { ok: false, error: 'No authentication credentials provided' };
|
|
}
|
|
|
|
const client = new ImapFlow({
|
|
host: params.host,
|
|
port: params.port,
|
|
secure: params.secure,
|
|
auth,
|
|
logger: false,
|
|
greetingTimeout: 60_000,
|
|
socketTimeout: 60_000,
|
|
});
|
|
|
|
try {
|
|
const result = await Promise.race([
|
|
(async () => {
|
|
await client.connect();
|
|
const folders = await client.list();
|
|
await client.logout();
|
|
return { ok: true as const, folderCount: folders.length };
|
|
})(),
|
|
new Promise<ValidateImapResult>((_, reject) =>
|
|
setTimeout(() => reject(new Error('Connection timed out')), 90_000),
|
|
),
|
|
]);
|
|
return result;
|
|
} catch (err) {
|
|
try {
|
|
client.close();
|
|
} catch {}
|
|
const message = err instanceof Error ? err.message : 'Connection failed';
|
|
return { ok: false, error: message };
|
|
}
|
|
}
|