SMTP mail support and admin pwd change working updated TODO.md

This commit is contained in:
2026-08-29 20:58:53 +03:00
parent dd6445547b
commit 84f6eea43c
2 changed files with 4 additions and 2 deletions
+2
View File
@@ -68,6 +68,8 @@ python ./scripts/send-test-email.py --to you@example.com
The command works on Windows, Linux, and macOS. It prints `SMTP_TEST_SENT_TO=<address>` only after the SMTP server accepts the message. Confirm the message arrives, then use **Forgot your password?** in the application to verify a real reset email and link. The existing PowerShell alternative remains available as `./scripts/test-smtp.ps1 -To you@example.com`. The command works on Windows, Linux, and macOS. It prints `SMTP_TEST_SENT_TO=<address>` only after the SMTP server accepts the message. Confirm the message arrives, then use **Forgot your password?** in the application to verify a real reset email and link. The existing PowerShell alternative remains available as `./scripts/test-smtp.ps1 -To you@example.com`.
SMTP connection and delivery have been verified for the current deployment environment.
## Production notes ## Production notes
Put this service behind a TLS reverse proxy for `eternityproject.fi` (for example Caddy or Nginx). Set a strong unique `SECRET_KEY`; the Compose file intentionally refuses to start without it. Back up the `eternity_data` Docker volume, which contains accounts and posts. Put this service behind a TLS reverse proxy for `eternityproject.fi` (for example Caddy or Nginx). Set a strong unique `SECRET_KEY`; the Compose file intentionally refuses to start without it. Back up the `eternity_data` Docker volume, which contains accounts and posts.
+2 -2
View File
@@ -4,8 +4,8 @@
- [x] Local accounts, administrator approval, and TOTP MFA. - [x] Local accounts, administrator approval, and TOTP MFA.
- [x] QR-based MFA enrollment for iPhone and Android authenticators. - [x] QR-based MFA enrollment for iPhone and Android authenticators.
- [x] Email addresses, member password changes, and expiring password-reset links. - [x] Email addresses, member password changes, and expiring password-reset links.
- [ ] Configure production SMTP credentials and verify outgoing email delivery. Run `python ./scripts/check-smtp.py`, then `python ./scripts/send-test-email.py --to you@example.com`; complete after the delivery test in [README.md](README.md) is received. - [x] Configure production SMTP credentials and verify outgoing email delivery.
- [ ] Run `./scripts/rotate-admin.ps1` on Windows or `sh ./scripts/rotate-admin.sh` on Linux/macOS, then sign in as `admin` and scan the new MFA QR code to complete authenticator enrollment. - [x] Rotate the initial `admin` password and enroll its authenticator.
- [x] Add CSRF protection to all state-changing forms. - [x] Add CSRF protection to all state-changing forms.
- [ ] Add automated database backups and test restoration. - [ ] Add automated database backups and test restoration.
- [ ] Configure TLS reverse proxy and production domain for `eternityproject.fi`. - [ ] Configure TLS reverse proxy and production domain for `eternityproject.fi`.