Commit Graph

80 Commits

Author SHA1 Message Date
Christian Krakau-Louis ee663afffb feat: add scoped read-only public API 2026-05-23 17:39:34 +02:00
Christian Krakau-Louis 2ff0c6d144 feat: add posture dashboard playbooks 2026-05-23 17:24:40 +02:00
Christian Krakau-Louis 6681aa4da0 feat: add BIMI posture readiness checks 2026-05-23 17:05:05 +02:00
Christian Krakau-Louis 00ea392bee feat: add TLS reporting posture summaries 2026-05-23 16:49:01 +02:00
Christian Krakau-Louis 57e164d282 feat: add mta-sts posture checks 2026-05-23 16:30:05 +02:00
Christian Krakau-Louis 8556ea30bf feat: add m365 safe backfill windows 2026-05-23 15:42:52 +02:00
Christian Krakau-Louis 10b0467424 feat: add m365 shared mailbox folder selection 2026-05-23 15:25:52 +02:00
Christian Krakau-Louis 5caefb06db feat: add Microsoft 365 Graph mail source 2026-05-23 15:06:28 +02:00
Christian Krakau-Louis 9d0b12efea feat: persist DMARC aggregate metadata 2026-05-23 14:17:09 +02:00
Christian Krakau-Louis e781b32a01 feat: add forensic sample analysis 2026-05-23 13:46:32 +02:00
Christian Krakau-Louis db49e7e481 feat: add forensic failure views 2026-05-23 13:32:46 +02:00
Christian Krakau-Louis 8bce8a8595 feat: add forensic redaction controls 2026-05-23 13:21:03 +02:00
Christian Krakau-Louis 817270b1fb fix: harden forensic report ingestion 2026-05-23 13:02:01 +02:00
Christian Krakau-Louis 1f954c9e08 feat: add forensic report parsing storage 2026-05-23 12:52:54 +02:00
Christian Krakau-Louis 65b154ae7f feat: add mailbox test diagnostics 2026-05-23 12:14:49 +02:00
Christian Krakau-Louis a6c795ee16 feat: add evidence-linked DNS health guidance 2026-05-23 12:01:45 +02:00
Christian Krakau-Louis beae6e7469 feat: add operations health and domain setup polish 2026-05-23 11:37:10 +02:00
Christian Krakau-Louis 521dbc92d0 feat: add Cloudflare DNS integration
Closes #31
2026-05-23 01:17:59 +02:00
Christian Krakau-Louis 947428afb6 harden notification settings 2026-05-23 00:56:49 +02:00
Christian Krakau-Louis 302159aeb6 feat: import selected fork operational fixes 2026-05-22 23:48:00 +02:00
Christian Krakau-Louis 77fd0f9552 feat: add cached DNS checks 2026-05-22 23:30:12 +02:00
Christian Krakau-Louis af66c93829 feat: add alert history 2026-05-22 23:18:32 +02:00
Christian Krakau-Louis f4ff1f151d feat: add scheduled summary notifications 2026-05-22 23:06:21 +02:00
Christian Krakau-Louis 05b687b525 feat: add notification alert rules 2026-05-22 22:55:49 +02:00
Christian Krakau-Louis dd4b90c9de feat: add apprise notification delivery 2026-05-22 22:44:08 +02:00
Christian Krakau-Louis 51f9f303ca Merge pull request #113 from christianlouis/copilot/fix-imap-client-folder-issue
Honor configured IMAP source folder
2026-05-22 22:19:01 +02:00
copilot-swe-agent[bot] f626675609 fix: honor configured IMAP source folder 2026-05-22 20:06:11 +00:00
Christian Krakau-Louis eeff24fa5c fix: redact secret diagnostics 2026-05-22 22:00:28 +02:00
Christian Krakau-Louis 364d517e07 feat: add source recommendations 2026-05-22 21:30:41 +02:00
Christian Krakau-Louis 34d8a655a2 feat: add domain report csv export 2026-05-22 21:21:39 +02:00
Christian Krakau-Louis ccc634a10b feat: add domain daily rollups 2026-05-22 21:12:43 +02:00
Christian Krakau-Louis 8485514445 feat: add dashboard trend charts 2026-05-22 20:52:47 +02:00
Christian Krakau-Louis 14f9f6defd feat: add source pass fail rollups 2026-05-22 20:41:34 +02:00
Christian Krakau-Louis c1b81d3e06 feat: add mail import detail events 2026-05-22 20:11:56 +02:00
Christian Krakau-Louis 1b7f00e7a0 feat: add per-source mail import trigger 2026-05-22 19:54:11 +02:00
Christian Krakau-Louis b9041012de feat: persist imported DMARC reports 2026-05-22 19:38:03 +02:00
Christian Krakau-Louis 4fc69602b3 feat: add mail source import history 2026-05-22 19:29:49 +02:00
Christian Krakau-Louis 181b43bff9 address copilot review followups (#96) 2026-05-18 19:17:36 +02:00
Christian Krakau-Louis b4191e956c address backend security and test suggestions 2026-05-18 16:44:06 +02:00
copilot-swe-agent[bot] 523b0529f4 fix: use Logto Account Center routes for password change and MFA management
Agent-Logs-Url: https://github.com/christianlouis/dmarq/sessions/d566f8d7-4560-4945-b9e5-388259f626a3

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-04-02 17:05:20 +00:00
Christian Krakau-Louis f8d4f936a7 Merge pull request #90 from christianlouis/copilot/fix-id-token-claims-extraction
fix: remove erroneous await from synchronous getIdTokenClaims() + add callback endpoint tests
2026-03-31 15:59:36 +02:00
copilot-swe-agent[bot] c81173e417 implement password reset on login screen and MFA management for users
Agent-Logs-Url: https://github.com/christianlouis/dmarq/sessions/0419399d-3a03-4f02-a3a8-fc75da7172bc

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-30 19:58:40 +00:00
copilot-swe-agent[bot] 9f1494a090 fix: remove erroneous await from getIdTokenClaims() call
Agent-Logs-Url: https://github.com/christianlouis/dmarq/sessions/2a043a05-25c6-4750-a9e8-da2b1651b55b

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-30 19:51:43 +00:00
copilot-swe-agent[bot] 04931172dd feat: add AUTH_DISABLED no-auth fallback mode
- config.py: AUTH_DISABLED: bool = False setting
- middleware/auth.py: bypass all checks when AUTH_DISABLED=True
- security.py: require_admin_auth returns synthetic context when disabled
- endpoints/auth.py: /me returns synthetic admin; /sign-out → / when disabled
- main.py: startup WARNING when disabled; pass auth_disabled to login.html
- templates/login.html: info banner with Go to dashboard link when disabled
- templates/setup.html: document AUTH_DISABLED option with security warning
- tests/test_auth.py: 4 new AUTH_DISABLED tests (445 total, all pass)

Agent-Logs-Url: https://github.com/christianlouis/dmarq/sessions/18f41bf2-0b68-4b7d-afb5-d2894c212a8f

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-30 11:38:52 +00:00
copilot-swe-agent[bot] 531dc968a8 feat: integrate Logto OIDC for user authentication
- Add Logto OIDC integration (app/core/logto.py): CookieStorage adapter,
  create/decode session token helpers, sync_logto_user upsert
- New auth endpoints (/api/v1/auth): sign-in, callback, sign-out, me
- AuthRedirectMiddleware: protects HTML pages, redirects to /setup when
  Logto is unconfigured, to /login otherwise
- Update require_admin_auth: accepts dmarq_session cookie JWT first,
  then API key, then Bearer JWT (fully backward compatible)
- Update User model: add logto_id, username, picture, created_at, updated_at;
  make hashed_password nullable for Logto-only users; is_superuser default=True
- New Alembic migration d4e5f6a7b8c9 for the above schema changes
- Add LOGTO_ENDPOINT / LOGTO_APP_ID / LOGTO_APP_SECRET / LOGTO_REDIRECT_URI
  settings with logto_configured property
- Create login.html (Sign in with Logto button) and setup.html (step-by-step
  configuration guide)
- Update base.html: user menu with avatar/name and sign-out via Alpine.js
  fetch to /api/v1/auth/me
- Update settings.html: remove localStorage adminApiKey; session cookie is
  sent automatically by browser; add 401 → /login redirect
- Update requirements.txt: replace fastapi-users additions with logto + aiohttp
- Add test_auth.py: 18 new tests covering session tokens, CookieStorage,
  sync_logto_user, /me, /sign-in (503), /sign-out cookie clearing
- Fix test_security_extra.py: pass Request mock to require_admin_auth;
  add new test_valid_session_cookie_returns_auth_context

Agent-Logs-Url: https://github.com/christianlouis/dmarq/sessions/b448f585-7646-40f8-ae2d-9986c361e3fd

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-30 10:09:50 +00:00
copilot-swe-agent[bot] 241713083b Add persistent settings system with database backend and comprehensive UI
- New Setting ORM model (key-value store with category, value_type, audit fields)
- Alembic migration to create the settings table
- Settings API endpoints: GET/PUT /api/v1/settings/{key}, GET /api/v1/settings (list+filter), POST /api/v1/settings/bulk
- Default seeding (17 sensible defaults across general/dmarc/dns/cloudflare/notifications categories)
- Secret redaction for cloudflare.api_token and notifications.smtp_password
- Updated settings.html: General, DMARC Policy Defaults, DNS Resolver, Cloudflare Integration, Email Notifications sections
- All forms wired to the API via Alpine.js with flash feedback
- 12 new tests for the settings model and endpoints

Agent-Logs-Url: https://github.com/christianlouis/dmarq/sessions/19dbc6cd-07cb-406e-b3b6-411f7721f737

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-30 07:58:51 +00:00
Christian Krakau-Louis 06a007d9db Merge pull request #76 from christianlouis/copilot/update-dkim-selectors
Fix DKIM selector extraction: surface all working selectors and auto-discovered report selectors
2026-03-30 01:57:12 +02:00
copilot-swe-agent[bot] 596a9b882e Fix DKIM selector extraction: show all working selectors and report-discovered selectors
- check_dkim now returns ALL matching selectors instead of stopping at first match
- DomainDNSResult.dkim_selectors is now a List[str] instead of a single Optional[str]
- DNSRecordResponse.dkimSelectors is now List[str]
- /selectors endpoint now also returns report_selectors (auto-discovered from DMARC reports)
- Frontend shows all live-check selectors and auto-discovered selectors as read-only
- Updated tests to match new data structures; added tests for multi-selector and report_selectors

Agent-Logs-Url: https://github.com/christianlouis/dmarq/sessions/87d8b8d9-23c3-4d3b-85a3-8e354e62c768

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-29 23:54:45 +00:00
copilot-swe-agent[bot] de225bc1cd Replace dummy/bogus reports data with real API data on /reports page
Agent-Logs-Url: https://github.com/christianlouis/dmarq/sessions/c6e36fd9-00c9-4000-985f-f7a42e2ba451

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-29 23:24:40 +00:00
copilot-swe-agent[bot] 58b5755f72 refactor: extract _spf_fix_hint and _safe_ptr_lookup helpers; fix spelling
Agent-Logs-Url: https://github.com/christianlouis/dmarq/sessions/9eaa7749-047c-46bd-8bc0-2851ea02ffe4

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-29 22:46:49 +00:00