Add HTML template kind to Responses with a seeded system email-default
template, render-template.js using Mustache, and html body support in
send-email. Templates are editable but system pages cannot be deleted.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
Expose broader nodemailer transport options, require a separate from
address, and support optional cc/bcc plus reply-to and custom headers.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
Add a sandboxed send-email.js workflow script with SMTP settings
exposed via script config and password loaded from named secrets.
Allow nodemailer in the script sandbox require whitelist.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
Self-hosted automation targets often run on localhost or loopback
addresses, so keep blocking private/metadata hosts but stop blocking
localhost, 127.x.x.x, and .localhost names.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
Add $axios to the VM sandbox with a request interceptor that blocks
non-http(s) URLs and common SSRF targets (localhost, private IPs,
link-local, and cloud metadata hosts). require('axios') and import
axios resolve to the same screened instance so scripts cannot bypass
URL screening.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>