Add transactional emails (SMTP) and planner features (no-go areas, notes, crash recovery)

Transactional emails:
- Add nodemailer SMTP email module with dev-mode console logging
- Magic link template and welcome template with HTML + plain text
- Wire sendMagicLink into login flow, sendWelcome into registration
- Update privacy page and deploy docs for SMTP configuration

Planner features:
- No-go areas: draw polygons on map (leaflet-geoman), synced via Yjs,
  passed to BRouter as nogos parameter, route recomputes on change
- Session notes: collaborative Y.Text textarea in sidebar tab
- Crash recovery: periodic localStorage save of Yjs state, restore on reconnect
- Rate limit session creation (10/IP/hour) in /new route

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
Ullrich Schäfer 2026-03-26 01:00:42 +01:00
parent 05b5f6febf
commit 0a8dd0b766
No known key found for this signature in database
GPG key ID: A32FF691A0F752D9
27 changed files with 1030 additions and 69 deletions

View file

@ -42,6 +42,26 @@ systemctl start fail2ban
fail2ban-client status sshd
```
## Email (SMTP)
Transactional emails (magic link login, welcome) require an SMTP server.
Set these env vars on the server (used by docker-compose):
```bash
# SMTP connection URL (any provider: Mailgun, SES, Postfix relay, etc.)
export SMTP_URL="smtp://user:pass@smtp.example.com:587"
# Optional: override sender address (defaults to noreply@trails.cool)
export SMTP_FROM="trails.cool <noreply@trails.cool>"
```
DNS records for deliverability (add to your domain's DNS):
- **SPF**: `v=spf1 include:_spf.your-smtp-provider.com ~all`
- **DKIM**: Provider-specific TXT record for email signing
- **DMARC**: `v=DMARC1; p=quarantine; rua=mailto:dmarc@trails.cool`
In dev mode, emails are logged to console instead of sent (no SMTP needed).
## SSH Hardening
Already in place: