Add Gmail+Email Worker hybrid mail path and private runtime config
Prefer Cloudflare Worker KV for verification codes with optional short IMAP fallback disabled for private deploy; track config.json/.env for private repo. Also add worker project, protocol mint backoff, and fail-fast Turnstile/mail timeouts from batch runs.
This commit is contained in:
1 parent
187792d6be
commit
55f56d27c9
19 files changed
+1225
-85
No files matched your search
@@ -0,0 +1,98 @@
|
||||
# Grok xAI 验证码 Email Worker
|
||||
|
||||
```
|
||||
xAI 发信
|
||||
→ Cloudflare Email Routing(catch-all)
|
||||
→ 本 Worker:提取验证码写入 KV
|
||||
→ (可选)forward 到 Gmail 作 IMAP 兜底
|
||||
→ 注册机 HTTP GET Worker /code?to=alias@domain&key=...
|
||||
```
|
||||
|
||||
## 1. 前置
|
||||
|
||||
- 域名 DNS 在 Cloudflare
|
||||
- 开通 **Email Routing**
|
||||
- 安装 Node:`npm i -g wrangler` 或用 `npx wrangler`
|
||||
|
||||
## 2. 创建 KV + 配置
|
||||
|
||||
```bash
|
||||
cd cf-email-worker
|
||||
npx wrangler login
|
||||
npx wrangler kv namespace create GROK_MAIL_CODES
|
||||
# 把返回的 id 填进 wrangler.toml 的 kv_namespaces.id
|
||||
```
|
||||
|
||||
编辑 `wrangler.toml`,或在 Dashboard → Workers → Settings → Variables 设置:
|
||||
|
||||
| 变量 | 含义 |
|
||||
|------|------|
|
||||
| `CODE_API_KEY` | 注册机查询密钥(必填) |
|
||||
| `GMAIL_FORWARD_TO` | 如 `you@gmail.com`,保留 IMAP 兜底 |
|
||||
| `CODE_TTL_SEC` | KV 过期秒数,默认 600 |
|
||||
|
||||
```bash
|
||||
npx wrangler secret put CODE_API_KEY
|
||||
# 可选:也可用 vars;secret 更安全
|
||||
```
|
||||
|
||||
## 3. 部署
|
||||
|
||||
```bash
|
||||
npx wrangler deploy
|
||||
# 记下 workers.dev 地址,例如:
|
||||
# https://grok-xai-mail-codes.<subdomain>.workers.dev
|
||||
```
|
||||
|
||||
## 4. Email Routing 绑定
|
||||
|
||||
Cloudflare Dashboard → **Email** → **Email Routing** → **Routing rules**:
|
||||
|
||||
1. 启用 Catch-all
|
||||
2. Action = **Send to a Worker** → 选择 `grok-xai-mail-codes`
|
||||
3. 域名 MX 按 Cloudflare 提示配置(若尚未)
|
||||
|
||||
> 若 catch-all 已转发到 Gmail,可改为:Worker 处理 + Worker 内 `GMAIL_FORWARD_TO` 再转到 Gmail。
|
||||
> 不要只转 Gmail 而不进 Worker,否则没有秒级路径。
|
||||
|
||||
## 5. 注册机配置
|
||||
|
||||
`config.json`:
|
||||
|
||||
```json
|
||||
{
|
||||
"email_provider": "gmail",
|
||||
"defaultDomains": "your-domain.com",
|
||||
"gmail_imap_user": "you@gmail.com",
|
||||
"gmail_imap_password": "app-password",
|
||||
"gmail_worker_enabled": true,
|
||||
"gmail_worker_url": "https://grok-xai-mail-codes.<subdomain>.workers.dev",
|
||||
"gmail_worker_api_key": "与 CODE_API_KEY 相同",
|
||||
"gmail_worker_timeout_sec": 25,
|
||||
"gmail_worker_poll_interval": 0.4,
|
||||
"gmail_imap_fallback": true
|
||||
}
|
||||
```
|
||||
|
||||
## 6. 自测
|
||||
|
||||
```bash
|
||||
# 健康检查
|
||||
curl -sS "https://YOUR_WORKER/health"
|
||||
|
||||
# 模拟入库
|
||||
curl -sS -X POST "https://YOUR_WORKER/ingest?key=YOUR_KEY" \
|
||||
-H 'content-type: application/json' \
|
||||
-d '{"to":"test@your-domain.com","code":"ABC-DEF","subject":"ABC-DEF xAI confirmation code"}'
|
||||
|
||||
# 取码(consume=1 用后即删)
|
||||
curl -sS "https://YOUR_WORKER/code?to=test@your-domain.com&key=YOUR_KEY"
|
||||
```
|
||||
|
||||
真实链路:给 `random@your-domain.com` 发一封带 `ABC-DEF xAI confirmation code` 主题的信,几秒内应能 GET 到。
|
||||
|
||||
## 7. 安全
|
||||
|
||||
- `CODE_API_KEY` 用足够长的随机串
|
||||
- 不要把 key 提交进 git(写 config.json / .env,二者已在 .gitignore)
|
||||
- KV 中验证码默认约 10 分钟过期,且 `/code` 默认 consume-once
|
||||
Reference in new issue
Block a user