Repository navigation
Kept forwards: a taken-over forward rule keeps forwarding the original (ADR 47), and verified destinations are managed from Mailda - #325
Merged
Conversation
…estination, one settled row per receipt Migration 0074 gives an address the forward destination it keeps and adds kept_forward_attempts, written in the receipt's own batch (only when the receipt row was inserted) and settled after forward() answers: handed_over, refused with Cloudflare's words, withheld for this Node's own X-Mailda-Forwarded-By marker, or left outcome_unknown. A redelivery is already_accepted and forwards nothing. The receipt for forward() is docs/receipts/email-worker-forward.md, from the 2 October drill on mailda.site. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…eople and doctor, ADR 47 A forward rule's take-over now names forward: keep or stop (E_ROUTING_FORWARD_NEEDS_CHOICE); keep records the rule's own destination on the address, refused when the account lists it unverified or not at all, dropped when the PUT is refused, cleared by a confirmed put-back, and removing the address is refused while it keeps one (E_ADDRESS_KEEPS_A_FORWARD). POST /api/provider/verified-destinations counts the account's whole list, re-checks each kept forward's destination and returns the addresses only when asked; POST /api/provider/destination-addresses registers one (Email Routing Addresses: Edit, named in every refusal; the audit entry names Cloudflare's id, never the address); GET /api/forwards lists kept forwards with their latest attempt. CLI (--forward, --forwards, --destinations [--addresses], --add-destination, the setup step's third choice), Setup and People, doctor's kept_forwards, SDK and Skill regenerated, MCP withheld. Blueprint ADR 47 amends §13, §14 and the journey. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…t remeasured, docs A put-back answering E_ROUTING_RULE_NOT_OURS_NOW now clears the address's kept forward, since that mail no longer reaches the Node; before, the address could be neither removed nor put back. doctor-check-cost.md records the one query kept_forwards adds (33 to 34 subrequests, measured). The forward receipt no longer points at a working file outside the repository, and application-shell.md describes the new Setup and People lines. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e destination count reads as a plural-free sentence The owner accepted 保留的转发 (kept forward), 等待验证 (waiting for verification) and 登记 (register) in the working session on 3 October 2026; they are glossary rows bound to their keys, recorded as round five. setup.verified.listed said "address(es)"; it now reads "Destination addresses in the account: 1 verified, 1 waiting for verification." Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Built on the live drill on mailda.site (2 Oct 2026, cleaned up):
message.forward()keeps the original sender, body and Message-ID, works after the message is stored, carries up to the 24.4 MB measured, and fails loudly in the Worker for an unverified destination without bouncing the sender. Receipt:docs/receipts/email-worker-forward.md.message.forward()for a forward a taken-over rule already had; §13/§14 amended.X-Mailda-Forwarded-Bycarries this Node's claim id.forward: keep|stop(contract, CLI--forward, the setup step's third choice, Setup screen); keep refused for an unverified destination; put-back clears it; removing an address that keeps a forward is refused.POST /api/provider/destination-addresses; Cloudflare mails the link),GET /api/forwards; CLI--destinations,--add-destination,--forwards. No address in audit or logs; nothing deletes a destination. MCP withheld.kept_forwardsflags unanswered and refused forwards.Token: the optional permission is now "Email Routing Addresses: Edit" (Read still lists). Not measured: non-refusal forward failures, larger forwards, a real end-to-end run on a Node. Not built: the "send a copy" fallback (PR 2).
Verified: full forced run (workerd 2,145, node 880, DOM 857), typecheck, lint, receipts/sdk/skill checks, dry-run deploy.
🤖 Generated with Claude Code