• v1.1.0 603e1e344b

    v1.1.0
    Release / build (amd64, freebsd) (push) Successful in 56s
    Release / build (amd64, linux) (push) Successful in 58s
    Release / build (arm64, freebsd) (push) Successful in 58s
    Release / build (arm64, linux) (push) Successful in 58s
    Release / build (loong64, linux) (push) Successful in 1m3s
    Release / build (riscv64, freebsd) (push) Successful in 1m1s
    Release / build (riscv64, linux) (push) Successful in 1m1s
    Release / release (push) Successful in 20s
    Stable

    petrbalvin released this 2026-07-26 19:48:22 +00:00 | 0 commits to main since this release

    Added

    • RISC-V and LoongArch builds — CI now produces binaries for linux/riscv64,
      linux/loong64, and freebsd/riscv64 in addition to the existing four
      targets.
    • 80 % coverage gatejust test and CI enforce ≥ 80 % test coverage on
      internal/ and pkg/ packages.
    • Handler and email test suites — 22 handler tests covering CORS, rate
      limiting, validation, honeypot, and send/store paths via mock interfaces.
      12 email composition tests covering all four form types.

    Changed

    • Module migrated to sourcedock.dev — all imports and documentation now
      reference sourcedock.dev/petrbalvin/nuntius.
    • CI migrated from Forgejo to Gitea — workflows now live in
      .gitea/workflows/, run on the fedora runner, and use the standard
      actions/* short form.
    • Dependency bumpinterpres updated to v1.1.1.
    • IPv6-first — the server now binds [::]:port for explicit dual-stack.
    • Installer rewritten in Pythoninstall.py replaces install.sh.
    • nginx → Caddy — all documentation and the installer now use Caddy as the
      recommended reverse proxy.

    Fixed

    • Rate limiter memory leak — a periodic cleanup goroutine removes expired
      IP entries from the token-bucket map.
    • Silent template errorscompose() now produces a fallback HTML message
      instead of silently discarding template execution errors.
    • Silent JSON encoding errors — all json.NewEncoder(w).Encode() calls now
      log errors instead of discarding them.
    • CI formatting gategofmt -l in the test workflow now actually fails
      when it finds unformatted files.
    • Missing just fmt recipe — added gofmt -w target.
    • Copyright headers — added to all Go and Python source files.
    • Smoke test restricted to native builds — cross-compiled binaries now
      skip the smoke test step since they cannot execute on the Linux amd64 CI
      runner.
    Downloads
  • v1.0.0 1b700f7975

    v1.0.0 Stable

    petrbalvin released this 2026-06-20 18:48:09 +00:00 | 16 commits to main since this release

    First stable release of nuntius: a small, opinionated, modular contact form
    backend written in Go. A single static binary, four form kinds out of the box,
    SMTP delivery, a JSONL newsletter log, strict TOML configuration, and env-var
    secrets. Its only dependency outside the standard library is the first-party
    interpres TOML parser.

    Added

    • Servercmd/server, the HTTP entry point. http.Server with explicit
      ReadHeaderTimeout (10 s), ReadTimeout (15 s), WriteTimeout (30 s), and
      IdleTimeout (60 s). Graceful shutdown on SIGINT / SIGTERM with a 15 s
      budget. Structured logging via log/slog (JSON handler, INFO level, stdout)
      with one log line per request. GET /health endpoint. --version flag.
    • Four form kindscontact, feedback, newsletter, and generic, each
      with its own endpoint, per-IP rate limit, CORS allowlist, and honeypot field.
      One POST + one OPTIONS handler per form on a fresh http.ServeMux.
    • SMTP delivery — stdlib net/smtp with PLAIN auth, multipart/alternative
      HTML + plain text bodies, one dedicated template per form type.
    • Newsletter JSONL log — append-only data_dir/newsletter-<name>.jsonl with
      crash-safe O_APPEND writes; Count and List skip malformed lines.
    • pkg/contactform — public Go package with Request / Response /
      FieldError / ErrorResponse types and a Validate function for all four
      form types.
    • Per-IP rate limiting — in-memory token bucket per form, configurable per
      hour.
    • Per-form honeypot — silent 200 on bot fill, no mail, no subscriber line.
    • Per-form CORS — allowlist enforced on preflight and actual requests, with
      echoed Access-Control-Allow-Origin + Vary: Origin.
    • TOML configuration — parsed by the first-party interpres library, with
      strict unknown-field rejection and per-type validation that fails loud on
      typos at startup.
    • Env-var secrets${VAR_NAME} / $VAR_NAME expansion before the config
      is parsed, so SMTP passwords never live in the file.
    • Auto-generated config — a three-form TOML template is written to
      /etc/nuntius/config.toml on first start.
    • systemd unit — installed inline from docs/deployment.md with
      Restart=on-failure and EnvironmentFile=.
    • Install scriptinstall.sh, idempotent, handles user creation, config
      generation, and secrets file mode 0600.
    • docs/architecture.md, configuration.md, api-reference.md,
      deployment.md, security.md, library-usage.md.
    Downloads