Skip to content

docs(dev): validate and rate-limit outgoing mail in email.rst - #15708

Open
whoalin1 wants to merge 1 commit into
nextcloud:masterfrom
whoalin1:docs-email-validate-rate-limit
Open

whoalin1 wants to merge 1 commit into
nextcloud:masterfrom
whoalin1:docs-email-validate-rate-limit

Conversation

@whoalin1

@whoalin1 whoalin1 commented Oct 6, 2026 •

Copy link
Copy Markdown

Summary

email.rst showed how to send mail but not how to avoid turning the instance into a spam relay.

  • Document validating recipients with IMailer::validateMailAddress() before send().
  • Point to #[UserRateLimit] / #[AnonRateLimit] or ILimiter (see security.rst programmatic rate limiting).
  • Warn that anonymous / public users must not freely make the instance send mail to a typed-in address.

Closes #15683

Test plan

  • Sphinx build of the developer manual succeeds for the email page
  • New Validate recipients and rate-limit sends section mentions validateMailAddress
  • Section references #[UserRateLimit] / #[AnonRateLimit] or ILimiter and links programmatic rate limiting
  • Warning covers anonymous / public users and typed-in addresses

AI disclosure

This PR was drafted with the help of AI coding assistants (Cursor agents / LLM-based tools), including the description. I am responsible for it and happy to rework anything that doesn't fit.

All commits carry an Assisted-by: Cursor:grok-4.7 trailer.

Assisted-by: Cursor:grok-4.7
Signed-off-by: whoalin1 <[email protected]>
@whoalin1
whoalin1 force-pushed the docs-email-validate-rate-limit branch from 13d9060 to d2611ec Compare October 9, 2026 14:12

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Developer manual: validate and rate-limit outgoing mail in email.rst

1 participant