/** * Shared HTML shell for transactional emails. Centralises the table- * based layout + the per-port branding override surface so templates * don't each inline a different copy of the boilerplate. * * Per-port branding (R2-H15): * - logoUrl — replaces the default Port Nimara logo image * - primaryColor — used for the page-title accent color * - emailHeaderHtml / emailFooterHtml — admin-authored HTML that * appears above / below the body content (e.g. legal footer, * custom marketing strip). When unset, the existing minimal * "Thank you, {{portName}} CRM" sign-off is rendered by callers. * * Senders resolve a `BrandingShell` via `resolveBrandingShell(portId)` * (or pass `null` for no override) and forward it to the template * function. Templates call `renderShell({ title, body, branding })`. */ const DEFAULT_LOGO_URL = 'https://s3.portnimara.com/images/Port%20Nimara%20New%20Logo-Circular%20Frame_250px.png'; const DEFAULT_BACKGROUND_URL = 'https://s3.portnimara.com/images/Overhead_1_blur.png'; const DEFAULT_PRIMARY_COLOR = '#0F4C81'; export interface BrandingShell { logoUrl: string | null; /** Phase 5: blurred page-background image rendered behind the white * card. Defaults to the Port Nimara overhead image. Ports with * their own marina photography override via system_settings. */ backgroundUrl: string | null; primaryColor: string | null; emailHeaderHtml: string | null; emailFooterHtml: string | null; } interface ShellOpts { title: string; body: string; branding?: BrandingShell | null; } export function renderShell({ title, body, branding }: ShellOpts): string { const logoUrl = branding?.logoUrl ?? DEFAULT_LOGO_URL; const backgroundUrl = branding?.backgroundUrl ?? DEFAULT_BACKGROUND_URL; const headerHtml = branding?.emailHeaderHtml ?? ''; const footerHtml = branding?.emailFooterHtml ?? ''; return ` ${title}
Port logo
${headerHtml ? `
${headerHtml}
` : ''} ${body} ${footerHtml ? `
${footerHtml}
` : ''}
`; } /** Surface the brand primary color to template bodies. */ export function brandingPrimaryColor(branding?: BrandingShell | null): string { return branding?.primaryColor ?? DEFAULT_PRIMARY_COLOR; } /** * URL-safe escaper for `href="..."` interpolations inside email * templates. The email-deliverability audit flagged that every template * inlined `${data.link}` directly into href + visible text without * escaping — a `"` (or worse, a `javascript:` scheme) would break out * of the attribute or trigger an XSS when the recipient opens the email * in a webmail client that runs scripts. * * Two-step defense: * 1. Scheme allow-list — only http(s), mailto, tel survive; everything * else (javascript:, data:, vbscript:, file:, …) is rewritten to * `about:blank`. * 2. HTML-attribute escape on `"`, `<`, `>`, `&`, `'`, backtick. */ export function safeUrl(url: string | null | undefined): string { if (!url) return 'about:blank'; const trimmed = String(url).trim(); // Block dangerous schemes. The allow-list is intentionally short. const lower = trimmed.toLowerCase(); const ok = lower.startsWith('http://') || lower.startsWith('https://') || lower.startsWith('mailto:') || lower.startsWith('tel:') || // Relative or root-relative paths are also acceptable — they // resolve against the host the email links to (rare in transactional // mail but used by tracking pixels and unsubscribe headers). lower.startsWith('/') || lower.startsWith('#'); if (!ok) return 'about:blank'; return trimmed .replace(/&/g, '&') .replace(/"/g, '"') .replace(/'/g, ''') .replace(//g, '>') .replace(/`/g, '`'); }