diff --git a/backend/accounts-service/src/mail/layout.rs b/backend/accounts-service/src/mail/layout.rs new file mode 100644 index 00000000..136112f4 --- /dev/null +++ b/backend/accounts-service/src/mail/layout.rs @@ -0,0 +1,110 @@ +use super::templates::escape_html; + +/// Everything one transactional email needs. All strings are static copy +/// except `url`, but every field still goes through `escape_html` so a future +/// edit cannot open an HTML-injection hole. +pub struct Card<'a> { + pub lang: &'a str, + pub preheader: &'a str, + /// Small pill above the title ("Security", "Welcome"). + pub badge: &'a str, + pub title: &'a str, + pub paragraphs: &'a [&'a str], + pub button: &'a str, + pub url: &'a str, + pub expiry: &'a str, + pub copy_hint: &'a str, + pub ignore_note: &'a str, + pub footer: &'a str, + pub site_url: &'a str, +} + +const BG: &str = "#070b0c"; +const CARD: &str = "#0d1416"; +const TEXT: &str = "#e7eef0"; +const MUTED: &str = "#8fa3a8"; +const ACCENT: &str = "#be185d"; +const ACCENT_SOFT: &str = "#f472b6"; +const BORDER: &str = "#1f2d31"; +const CODE_BG: &str = "#111a1d"; +const FONT: &str = "-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,Helvetica,Arial,sans-serif"; +const MONO: &str = "SFMono-Regular,Consolas,'Liberation Mono',Menlo,monospace"; + +/// Table-based, inline-styled HTML (the only layout every mail client +/// renders): 600 px card, gradient banner, bulletproof button, a separate +/// copyable link block, hidden preheader. The palette is dark on purpose, so +/// Gmail's and Outlook's automatic dark mode has nothing left to invert. +pub fn html(c: &Card) -> String { + let url = escape_html(c.url); + let paragraphs: String = c + .paragraphs + .iter() + .map(|p| { + format!( + "
{}
", + escape_html(p) + ) + }) + .collect(); + format!( + "\ +\ +\ +\
+
|
Кто-то запросил сброс пароля LoVisual.
\ -Если это были вы, нажмите кнопку (действует 30 минут):
\ - \ -Если нет — просто проигнорируйте письмо, пароль не менялся.
", - &url, - ), + &layout::Card { + lang: "ru", + preheader: "Ссылка действует 30 минут. Если это были не вы, ничего делать не нужно.", + badge: "Безопасность", + title: "Сброс пароля", + paragraphs: &[ + "Мы получили запрос на сброс пароля для вашего аккаунта LoVisual.", + "Нажмите кнопку ниже, чтобы придумать новый пароль.", + ], + button: "Сбросить пароль", + url: &url, + expiry: "Ссылка действует 30 минут и срабатывает один раз.", + copy_hint: "Кнопка не работает? Скопируйте ссылку и вставьте её в адресную строку браузера:", + ignore_note: "Если вы не запрашивали сброс, просто проигнорируйте письмо: пароль останется прежним.", + footer: "Это автоматическое письмо от LoVisual, отвечать на него не нужно.", + site_url: &site, + }, ), - Lang::En => build( + Lang::En => render( "LoVisual password reset", - format!( - "Someone requested a password reset for LoVisual.\n\ - If it was you, open the link (valid for 30 minutes):\n{url}\n\n\ - If not, just ignore this email - the password was not changed." - ), - html_body( - "Someone requested a password reset for LoVisual.
\ -If it was you, press the button (valid for 30 minutes):
\ - \ -If not, just ignore this email - the password was not changed.
", - &url, - ), + &layout::Card { + lang: "en", + preheader: "The link is valid for 30 minutes. If it was not you, no action is needed.", + badge: "Security", + title: "Reset your password", + paragraphs: &[ + "We received a request to reset the password of your LoVisual account.", + "Press the button below to choose a new password.", + ], + button: "Reset password", + url: &url, + expiry: "The link is valid for 30 minutes and works only once.", + copy_hint: "Button not working? Copy the link and paste it into your browser's address bar:", + ignore_note: "If you did not request a reset, just ignore this email: your password stays the same.", + footer: "This is an automated email from LoVisual, no need to reply.", + site_url: &site, + }, ), } } @@ -91,36 +100,47 @@ pub fn reset_email(lang: Lang, base_url: &str, token: &str) -> EmailContent { /// Address verification: one button, 24-hour token. pub fn verify_email(lang: Lang, base_url: &str, token: &str) -> EmailContent { let url = link(base_url, "/verify", token); + let site = site_url(base_url); match lang { - Lang::Ru => build( + Lang::Ru => render( "Подтверждение почты LoVisual", - format!( - "Добро пожаловать в LoVisual!\n\ - Подтвердите почту по ссылке (действует 24 часа):\n{url}\n\n\ - Без подтверждения нельзя привязать мод к аккаунту." - ), - html_body( - "Добро пожаловать в LoVisual!
\ -Подтвердите почту по ссылке (действует 24 часа):
\ - \ -Без подтверждения нельзя привязать мод к аккаунту.
", - &url, - ), + &layout::Card { + lang: "ru", + preheader: "Подтвердите почту, чтобы привязать мод к аккаунту. Ссылка действует 24 часа.", + badge: "Добро пожаловать", + title: "Подтвердите почту", + paragraphs: &[ + "Спасибо за регистрацию в LoVisual!", + "Подтвердите адрес почты, чтобы привязать мод к аккаунту и публиковать свои конфиги.", + ], + button: "Подтвердить почту", + url: &url, + expiry: "Ссылка действует 24 часа и срабатывает один раз.", + copy_hint: "Кнопка не работает? Скопируйте ссылку и вставьте её в адресную строку браузера:", + ignore_note: "Если вы не регистрировались в LoVisual, просто проигнорируйте письмо.", + footer: "Это автоматическое письмо от LoVisual, отвечать на него не нужно.", + site_url: &site, + }, ), - Lang::En => build( + Lang::En => render( "LoVisual email verification", - format!( - "Welcome to LoVisual!\n\ - Verify your email via the link (valid for 24 hours):\n{url}\n\n\ - Device linking stays locked until the address is verified." - ), - html_body( - "Welcome to LoVisual!
\ -Verify your email via the link (valid for 24 hours):
\ - \ -Device linking stays locked until the address is verified.
", - &url, - ), + &layout::Card { + lang: "en", + preheader: "Verify your email to link the mod to your account. The link is valid for 24 hours.", + badge: "Welcome", + title: "Verify your email", + paragraphs: &[ + "Thanks for signing up for LoVisual!", + "Verify your email address to link the mod to your account and publish your configs.", + ], + button: "Verify email", + url: &url, + expiry: "The link is valid for 24 hours and works only once.", + copy_hint: "Button not working? Copy the link and paste it into your browser's address bar:", + ignore_note: "If you did not sign up for LoVisual, just ignore this email.", + footer: "This is an automated email from LoVisual, no need to reply.", + site_url: &site, + }, ), } } @@ -167,4 +187,54 @@ mod tests { assert!(reset.html.contains("/reset-password?token=")); assert!(verify.html.contains("/verify?token=")); } + + #[test] + fn link_is_shown_as_button_and_as_separate_copyable_text() { + let mail = reset_email(Lang::Ru, BASE, TOKEN); + let url = format!("https://visual.loki-code.dev/reset-password?token={TOKEN}"); + assert_eq!( + mail.html.matches(url.as_str()).count(), + 3, + "2x href + 1x visible text" + ); + assert!( + mail.text.lines().any(|l| l == url), + "plain text keeps the URL alone on a line" + ); + } + + #[test] + fn copy_has_no_em_dash_and_ships_a_preheader() { + for lang in [Lang::Ru, Lang::En] { + for mail in [ + reset_email(lang, BASE, TOKEN), + verify_email(lang, BASE, TOKEN), + ] { + assert!(!mail.html.contains('\u{2014}') && !mail.text.contains('\u{2014}')); + assert!(mail.html.contains("display:none;max-height:0")); + } + } + } + + /// `MAIL_PREVIEW_DIR=/tmp/mail cargo test mail_previews` writes the four + /// emails as .html files for eyeballing; a no-op otherwise. + #[test] + fn mail_previews() { + let Some(dir) = std::env::var_os("MAIL_PREVIEW_DIR") else { + return; + }; + std::fs::create_dir_all(&dir).unwrap(); + for (name, mail) in [ + ("reset-ru", reset_email(Lang::Ru, BASE, TOKEN)), + ("reset-en", reset_email(Lang::En, BASE, TOKEN)), + ("verify-ru", verify_email(Lang::Ru, BASE, TOKEN)), + ("verify-en", verify_email(Lang::En, BASE, TOKEN)), + ] { + std::fs::write( + std::path::Path::new(&dir).join(format!("{name}.html")), + mail.html, + ) + .unwrap(); + } + } }