Dead-lettered mail logs the recipient address #173

closed cmc opened this on 2026-09-05 19:44 UTC · milestone security

Discussion

cmc 2026-09-05 19:44 UTC

notify.Mailer's dead-letter path logs the plaintext recipient after MaxAttempts consecutive failures (internal/notify/notify.go:56, slog.Warn("notification dead-lettered", "recipient", ...)).

Pre-existing, and every queued mail type already hits it — notifications and deps/worker both route through the same queue. But it is a step down for login links specifically: #155 deliberately logged user.ID rather than the address on send failure, and #159 routing that mail through the queue reintroduces the address on this path.

Not an enumeration channel: it fires only after five consecutive delivery failures, which is a relay outage rather than anything a caller can trigger.

Fix is a decision about the shared queue rather than about login links: log the recipient's user id where the queue knows it, or hash the address, or accept it and say why in the threat model. Whichever, it should be one rule for every mail type, not a special case.

Ref #155, #159.

closed by commit f6981be6cb by cmc: notify, web, wiki: log dead-lettered mail by queue row, not recipient

2026-09-06 18:22 UTC