Commit graph

3 commits

Author SHA1 Message Date
Stefan
99882bb80a Restrict readerEmail to allowlisted domains
Prevents the form being abused as an open email relay to arbitrary
addresses (which is the realistic abuse vector — disk fill, server
compromise, and device exploitation are all bounded already).

Default allowlist: kindle.com, pbsync.com. Suffix matching so
subdomains (e.g. free.kindle.com) are also accepted.

Configurable via ALLOWED_READER_DOMAINS env var so the list can be
extended without code changes.
2026-05-21 23:54:55 +03:00
Stefan
39292bfee9 Add file upload (POST /send-file) and drag-and-drop UI
Adds a second flow alongside the URL-to-EPUB pipeline:

- New POST /send-file endpoint accepts multipart/form-data with a `file`
  and `readerEmail`, attaches the file to an email, and ships it to the
  reader as-is. No conversion — the device decides what it accepts
  (EPUB, PDF, MOBI, FB2, ...).
- 25 MB cap enforced both client-side and server-side (multer).
- Shares the same 20/hour rate limit as /send-article (now sendLimiter).
- UI: dropzone with drag/drop + click-to-pick + visible filename feedback.
- Shared e-reader email input across both flows.
- Codeberg source link added to the footer.
- Version bumped 0.1.0 → 0.2.0.
2026-05-21 23:43:17 +03:00
Stefan
66bb1f497b Rewrite the send-to-kindle app to work for at least pocketbook as well 2026-05-21 23:08:55 +03:00