Block outgoing mail on non-production instances - #135
Merged
Merged
Conversation
Sanitization only ran on fresh bootstrap and restore, and bootstrap left Odoo's SMTP fallback open, so a testing lane with SMTP settings sent real mail on every deploy. Activate the neutralization dummy server and clear copied SMTP credentials on bootstrap, post-deploy maintenance, and restore (including --no-sanitize) for every non-production instance. Reuse an existing dummy server so repeated deploys do not add rows. Production is unchanged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The CM website testing lane sent real mail through the Cell Mechanic Google Workspace server during an ordinary deploy on 2026-09-29. Devkit already has Odoo-style mail neutralization (an active dummy
ir_mail_serverthat also blocks the SMTP fallback), but it only runs on sanitized restores. Fresh bootstrap deliberately leaves the fallback open, and post-deploy maintenance never neutralizes. Any non-production lane that receives SMTP settings from Launchplane can therefore email real people.Contact-form delivery for CM was verified once on 2026-09-24 (launchplane#2485), so testing no longer needs live mail. The owner approved turning mail off outside production.
What changed
block_outgoing_mail_outside_production()runs on bootstrap, on every post-deploy maintenance run, and on restore (right after the copy lands, and again after the Launchplane settings apply). It runs even with--no-sanitize, the same way credential neutralization already does.prod/production(an emptyPLATFORM_INSTANCEcounts as non-production), it deactivates real mail servers, clears their SMTP user and password, and activates the dummy server.This affects every tenant using devkit: OPW and CM testing/preview lanes, and local instances, will stop sending mail after their next deploy.
Verification
UNKNOWN(language_sdk_missing) in the fresh worktree, which is the known preparation debt in Make linked-worktree Python inspection preparation reproducible #111.Owner test notes
Nothing for the owner to test. After a testing deploy picks this up, contact-form submissions on testing will record the mail but not deliver it. Delivery checks happen on prod.
Refs #134