diff --git a/website/BACKEND_DESIGN.md b/website/BACKEND_DESIGN.md index 4bf9c9a..2d947be 100644 --- a/website/BACKEND_DESIGN.md +++ b/website/BACKEND_DESIGN.md @@ -234,10 +234,13 @@ who"; `activity_log` provides the history feed. ## 7. Email -`utils/mailer.js` (nodemailer) configured from `SMTP_HOST/PORT/USER/PASS`, sending to -`CONTACT_TO` (default UOMysticmoon@gmail.com). No Gmail password in code — env only. -If SMTP is unconfigured, `POST /public/contact` returns `{fallback:"mailto", email}` so the -client renders a `mailto:` link instead. Site mode changes / errors never leak SMTP creds. +`utils/mailer.js` (nodemailer) sends through **Gmail over OAuth2 (SMTP XOAUTH2)**, configured in +Admin → Settings → Email — not env. The mailbox is authorized by an in-app "Connect Gmail" consent +flow (`/admin/email/*`) that captures a refresh token, stored AES-GCM-encrypted in the `email_config` +singleton (never returned over the API). The OAuth client id/secret are reused from the `google` +auth-providers row. Recipient is the `contact_email` site setting. If email is unconfigured/disabled, +`POST /public/contact` returns `{fallback:"mailto", email}` so the client renders a `mailto:` link +instead. Errors never leak credentials. --- @@ -287,11 +290,7 @@ COOKIE_SECURE=true COOKIE_NAME=uomm_token ADMIN_USERNAME= ADMIN_PASSWORD= -SMTP_HOST= -SMTP_PORT=587 -SMTP_USER= -SMTP_PASS= -CONTACT_TO=UOMysticmoon@gmail.com +# Email: configured in Admin → Settings → Email (Gmail OAuth2), not via env CLIENT_ORIGIN=http://localhost:5173 ```