feat(workflows): add EMAIL_PROVIDER_SMTP_IGNORE_TLS - #8301
Merged
Conversation
Allow sending emails through SMTP servers that advertise STARTTLS but cannot complete a TLS handshake. The existing EMAIL_PROVIDER_SMTP_REJECT_UNAUTHORIZED only relaxes certificate validation, which does not help when TLS itself is not usable. The new variable maps to the nodemailer `ignoreTLS` option. It is opt-in and defaults to `0`, so existing deployments keep their current behaviour. nodemailer only honours the option when `secure` is false, so the `smtps` protocol is unaffected. Closes graphql-hive#1561
Closed
n1ru4l
approved these changes
Aug 3, 2026
n1ru4l
left a comment
Contributor
There was a problem hiding this comment.
Thank you for this contribution!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Background
Resolves #1561.
Sending emails fails when the SMTP server advertises
STARTTLSbut cannot actually complete a TLShandshake. The existing
EMAIL_PROVIDER_SMTP_REJECT_UNAUTHORIZEDvariable only relaxes certificatevalidation, which does not help when TLS itself is unusable — nodemailer still attempts the upgrade
and the connection fails.
Description
Affected package:
@hive/workflows(thesmtpemail provider).Adds a new optional environment variable
EMAIL_PROVIDER_SMTP_IGNORE_TLS, which maps to thenodemailer
ignoreTLStransport option.packages/services/workflows/src/environment.ts— added the variable toSMTPEmailModel(same'0' | '1'shape as the neighbouringEMAIL_PROVIDER_SMTP_REJECT_UNAUTHORIZED) and wired it intothe SMTP provider config.
packages/services/workflows/src/lib/emails/providers.ts— addedignoreTLStoSMTPEmailProviderConfigand passed it tonodemailer.createTransport.packages/services/workflows/README.md— documented the new variable, plusEMAIL_PROVIDER_SMTP_REJECT_UNAUTHORIZEDwhich was previously missing from the table.Notes on behaviour:
0. UnlikeREJECT_UNAUTHORIZED(which defaults toenabled via
!== '0'), this one is checked with=== '1', so deployments that do not set it keeptheir current behaviour and STARTTLS stays enabled.
ignoreTLSwhensecureisfalse, so settingEMAIL_PROVIDER_SMTP_PROTOCOL=smtpsis unaffected by this option.Checklist