Skip to content

Mail — Shared Inbox and Send API

services/mail is the single service that reads and sends herbmail.com mail. Every reader goes through it rather than to the mail schema directly.

Routes

RouteCallerAuth
/mail/inbox, /mail/threads, /mail/threads/{id}, /mail/messages/{id}, /mail/meweb, Rareicon, any signed-in clientthe user’s own Supabase JWT, passed through to Postgres
/mail/send, /mail/friendsthe samethe same
/hooks/stalwartStalwart’s MTA hookSTALWART_HOOK_SECRET bearer
/mail/discord/threads?discord_id=Windmill f/mail, for the Discord botMAIL_DISCORD_SECRET bearer

The Discord read

A Discord interaction cannot carry a Supabase JWT, so the Discord route reaches Postgres as mail_discord, a login that can execute mail_discord.thread_list and nothing else. It resolves the snowflake to a user, returns thread headers with bodies stripped, and records every call in mail.discord_reads. Discord ids are public, so that login’s password is the boundary; only this service holds it.

Release

Bumping version here is the release: CI builds and publishes the image, then repoints kube/mail/manifests/mail-deployment.yaml. See tools/version-sync.