Repository navigation
Home
Functional:
- As a service provider, I want to be able to verify user email addresses so that I can prevent spam or other abuse.
- As a service provider, I want to be able to verify user email addresses so that I can provide a ticketing system or other outlet.
- As a service provider, I want to be able to provide a "hop" for ticketing outlets/similar so that the workflow is the same every time.
- As a service user, I want to be able to see confirmation that my hopped email or ticket was delivered so that I know it is not going to the void.
- As a service user, I want to be able to easily perform my email verification instead of having ambiguous prompts that are hard to read.
Non-functional:
- As a service provider, I want there to be an interface specifically for creating challenges and sending them as emails so that I can support any variety of these requests.
- As a service provider, I want to create an individual server connection to handle each request in order to prevent workers from having to compete for a use of the connection.
- As a service provider, I want to provide TLS for my mailserver to prevent abuse.
- As a service provider, I want to be able to configure CORS addresses to prevent misuse by attackers.
- As a service provider, I want to routinely remove outdated challenges in order to prevent clutter.
- As a service provider, I want to be able to configure timeout on the application's email features as this may differ between use cases.
- As a service provider, I want to be able to configure how long challenges are valid for.
- As a service provider, I want challenge-response items to be stored in memory to reduce unnecessary clutter in prod.
Constraints:
- Python programming language.
- FastAPI and Pydantic for user interface.
- smtplib with TLS for email.
Main Success:
- User interface is executed with a properly formatted email address.
- A 200/OK response is provided, as well as a unique challenge ID
Extension 1: Invalid email address
- User interface is executed with an improperly formatted email address.
- A 400 response is provided with a related message.
Extension 2: AuthMail was unable to send message (SMTPConnectError | TimeoutError | SMTPSenderRefused)
- User interface is executed with a properly formatted email address.
- A 503/Service Unavailable response is provided with a message describing the issue.
Extension 3: AuthMail was unable to deliver message (SMTPDataError | SMTPRecipientsRefused)
- User interface is executed with a properly formatted email address.
- A 400/Bad Request response is provided with a message describing the issue.
Main Success:
- User interface is executed with an existing challenge ID/email address pair and matching response
- A 200/OK response is provided
Extension 1: No such challenge
- User interface is executed with non-existent challenge ID/email address pair
- A 404/Not Found response is provided explaining that challenges expire after {} minutes
Extension 2: Invalid response
- User interface is executed an existing challenge ID/email address pair but without correct response
- A 400/Bad Request response is provided explaining that the challenge must be resubmitted

HTTP method: POST
Endpoint path: /authmail/1/challenge/
Content type: application/json
Authorization: None
Input data:
{
"email": "some@email.address"
}Output data:
{
"challenge_id": "00000000-0000-0000-0000-000000000000"
}HTTP Method: POST
Endpoint path: /authmail/1/response/
Content type: application/json
Authorization: None
Input data:
{
"challenge_id": "00000000-0000-0000-0000-000000000000",
"email": "some@email.address",
"response": "string response as sent to email address"
}Output data: null
HTTP Method: POST
Endpoint path: /authmail/1/msg/
Content type: application/json
Authorization: Pass the access_token returned from the PyAcct Create Session endpoint as the header token:
-H 'token: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx'Input data:
{
"sender" : "some@email.address",
"recipients" : [
"some@email.address",
"another@email.address",
"different@email.address"
],
"body" : "some_email_content"
}Output data: null
This service is going to depend directly on an instance of PyAcct to send an email. The authorization workflow, however, stands on its own.