feat(watcher): gate receipt watch with WATCHER_MAILBOXES

Limit Pub/Sub INBOX watch and receipt processing to an allowlisted mailbox set; leave the agent CLI usable for all connected accounts.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
2026-09-22 10:09:25 +07:00
co-authored by Cursor
parent bac8edfb6c
commit 770ed8121a
5 changed files with 115 additions and 3 deletions
+7 -1
View File
@@ -1,4 +1,4 @@
# Google OAuth Web client (gmail.readonly)
# Google OAuth Web client (gmail.modify)
GOOGLE_CLIENT_ID=
GOOGLE_CLIENT_SECRET=
@@ -14,8 +14,14 @@ SESSION_SECRET=change-me-to-a-long-random-string
PORT=3000
NODE_ENV=development
# Optional default mailbox when CLI omits --user (else users.is_default / sole account)
# GMAIL_DEFAULT_USER=you@gmail.com
# Watcher (apps/watcher) — Gmail Pub/Sub push
WATCHER_PORT=3001
# Only these mailboxes get INBOX watch + receipt parsing (comma-separated).
# Empty / unset = all connected accounts. CLI (npm run gmail) is unaffected.
WATCHER_MAILBOXES=eleven16th@gmail.com
# Full topic name, e.g. projects/my-gcp-project/topics/gmail-push
# A short name like gmail-push is expanded if GOOGLE_CLOUD_PROJECT is set.
GOOGLE_PUBSUB_TOPIC=