notify.Mailer's dead-letter path logs the plaintext recipient after
MaxAttempts consecutive failures (internal/notify/notify.go:56,
slog.Warn("notification dead-lettered", "recipient", ...)).
Pre-existing, and every queued mail type already hits it — notifications and
deps/worker both route through the same queue. But it is a step down for login
links specifically: #155 deliberately logged user.ID rather than the address on
send failure, and #159 routing that mail through the queue reintroduces the
address on this path.
Not an enumeration channel: it fires only after five consecutive delivery failures, which is a relay outage rather than anything a caller can trigger.
Fix is a decision about the shared queue rather than about login links: log the recipient's user id where the queue knows it, or hash the address, or accept it and say why in the threat model. Whichever, it should be one rule for every mail type, not a special case.
closed by commit f6981be6cb by cmc: notify, web, wiki: log dead-lettered mail by queue row, not recipient
2026-09-06 18:22 UTC