Problem/Motivation

Operators currently have a settings page and one-address CLI history, but no protected administrative explanation or supported recovery action. Database edits are a poor operational interface.

Evidence and scope

Reviewed 1.0.0-alpha1, source commit 02fd9d36af5237e712cecb7155d79725f7824880. Location: src/Commands/PostmarkWebhookCommands.php:31.

Product opportunity grounded in the current form/command surface; not a claim that manual reactivation should always be allowed.

Proposed resolution

Provide a permission-controlled address lookup with effective decision, reason, expiry and redacted evidence timeline. Separate viewing from changing suppression. Permit only well-defined recovery actions with confirmation and audit records; complaint and opt-out protections must remain explicit.

Acceptance criteria

Test access, CSRF, output escaping, keyboard navigation and screen-reader labels. No recipient enumeration by anonymous users, no raw payload display, and no bulk unblock by default.

Comments

jmcerda created an issue. See original summary.

jmcerda’s picture

Assigned: Unassigned » jmcerda
Status: Active » Needs review

Implemented the exact-address inspector with separate view and hard-bounce-recovery permissions. The view omits raw payloads, provider descriptions and message identifiers. Recovery requires CSRF-protected confirmation, rechecks the selected evidence, and commits a source-specific release with an audit record. Complaints, opt-outs, manual suppressions and other sources remain protected.

All six compatibility jobs are green. Kernel and HTTP checks cover permission denial, output escaping, forged CSRF, stale confirmation, audit rollback and repeated form submissions. Live browser checks at 375 pixels verified labelled controls, keyboard lookup/evidence expansion, confirmation navigation/cancellation and no horizontal overflow. The implementation is awaiting integration.

  • jmcerda committed 188876de on 1.x
    Issue #3621130: Add protected inspection and audited hard-bounce...
jmcerda’s picture

Status: Needs review » Fixed

Integrated into the 1.x development branch and included in 1.0.0-alpha2. The release tag and branch are mirrored to Drupalcode. The six-job Drupal 10/11 and Mailer Plus integration matrix passes. See the release notes for database updates and retained-history limitations. This records module publication; site deployment is a separate operation.

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.