Files
nuntius/CHANGELOG.md
T

2.9 KiB

Changelog

All notable changes to nuntius are documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

1.0.0 — 2026-06-20

First stable release of nuntius: a small, opinionated, modular contact form backend written in Go. A single static binary, four form kinds out of the box, SMTP delivery, a JSONL newsletter log, strict TOML configuration, and env-var secrets. Its only dependency outside the standard library is the first-party interpres

Added

  • Servercmd/server, the HTTP entry point. http.Server with explicit ReadHeaderTimeout (10 s), ReadTimeout (15 s), WriteTimeout (30 s), and IdleTimeout (60 s). Graceful shutdown on SIGINT / SIGTERM with a 15 s budget. Structured logging via log/slog (JSON handler, INFO level, stdout) with one log line per request. GET /health endpoint. --version flag.
  • Four form kindscontact, feedback, newsletter, and generic, each with its own endpoint, per-IP rate limit, CORS allowlist, and honeypot field. One POST + one OPTIONS handler per form on a fresh http.ServeMux.
  • SMTP delivery — stdlib net/smtp with PLAIN auth, multipart/alternative HTML + plain text bodies, one dedicated template per form type.
  • Newsletter JSONL log — append-only data_dir/newsletter-<name>.jsonl with crash-safe O_APPEND writes; Count and List skip malformed lines.
  • pkg/contactform — public Go package with Request / Response / FieldError / ErrorResponse types and a Validate function for all four form types.
  • Per-IP rate limiting — in-memory token bucket per form, configurable per hour.
  • Per-form honeypot — silent 200 on bot fill, no mail, no subscriber line.
  • Per-form CORS — allowlist enforced on preflight and actual requests, with echoed Access-Control-Allow-Origin + Vary: Origin.
  • TOML configuration — parsed by the first-party interpres library, with strict unknown-field rejection and per-type validation that fails loud on typos at startup.
  • Env-var secrets${VAR_NAME} / $VAR_NAME expansion before the config is parsed, so SMTP passwords never live in the file.
  • Auto-generated config — a three-form TOML template is written to /etc/nuntius/config.toml on first start.
  • systemd unit — installed inline from docs/deployment.md with Restart=on-failure and EnvironmentFile=.
  • Install scriptinstall.sh, idempotent, handles user creation, config generation, and secrets file mode 0600.
  • docs/architecture.md, configuration.md, api-reference.md, deployment.md, security.md, library-usage.md.