Mail — Shared Inbox and Send API
services/mail is the single service that reads and sends herbmail.com mail.
Every reader goes through it rather than to the mail schema directly.
Routes
| Route | Caller | Auth |
|---|---|---|
/mail/inbox, /mail/threads, /mail/threads/{id}, /mail/messages/{id}, /mail/me | web, Rareicon, any signed-in client | the user’s own Supabase JWT, passed through to Postgres |
/mail/send, /mail/friends | the same | the same |
/hooks/stalwart | Stalwart’s MTA hook | STALWART_HOOK_SECRET bearer |
/mail/discord/threads?discord_id= | Windmill f/mail, for the Discord bot | MAIL_DISCORD_SECRET bearer |
The Discord read
A Discord interaction cannot carry a Supabase JWT, so the Discord route reaches
Postgres as mail_discord, a login that can execute
mail_discord.thread_list and nothing else. It resolves the snowflake to a
user, returns thread headers with bodies stripped, and records every call in
mail.discord_reads. Discord ids are public, so that login’s password is the
boundary; only this service holds it.
Release
Bumping version here is the release: CI builds and publishes the image, then
repoints kube/mail/manifests/mail-deployment.yaml. See tools/version-sync.