The screen for inbuxa:ProtocolPolicy, the server-wide switch that closes
IMAP, POP3 and ManageSieve (legacy-protocols spec). Reached as
CustomComponent/LegacyProtocols, which the server's schema places under
Settings › Security; a server without that link never shows it.
- The selector lists every mail protocol, with what the switch does to
each and on which ports. SMTP and JMAP are shown locked, from the
server's lockedProtocols rather than a list carried here, so unlocking
later needs no admin release (LP-21).
- The statement is shown in full before the switch moves and while it is
off, with the listeners that close by name and port, and the note that
firewall rules and port-forwards are the operator's to reconcile
(LP-16, LP-20).
- Turning it off takes the typed phrase "turn off legacy mail", matched
exactly. Turning it back on is one click (LP-17).
- Listeners that could not be reopened stay listed, with a Try again
(LP-5).
- A banner on the Security settings and the dashboard while it is off
(LP-18). It stays silent on a server without the switch.
Visible to whoever may see listeners, changeable by whoever may update
them, matching the permissions the server checks.
Not here yet: the impact panel (LP-15), which needs the server to record
last use per protocol, and the tenant switch (LP-9 to LP-14).
Publishing the source is what asks for it: a modified version has to carry
prominent notices saying it was modified, with a date. These files already
added a Coffey Labs copyright line beside upstream's, which implies as much
without saying it; now they say it.
38 files, found by diffing against the merge base with upstream rather than
by guessing. Upstream's own notices are untouched. The build is unchanged.
- Cards and charts link to the page they're about: pending messages to the
queue, bans to blocked IPs, report warnings to the reports, and so on,
shown only to viewers who may open that page.
- A one-line status under the greeting: what needs a look (failed tasks,
messages retrying, recipients given up on) or, when nothing does, what's
there. Each phrase is a link.
- Counts from the server's own objects stand in for live metrics it can't
report, and a live number with no source reads as unknown, not zero.
- Who uses the space: a treemap of people sized by storage, colored by how
near their quota they are, each tile opening the account.
- Where mail is waiting: queued recipients by destination, split into
waiting, retrying and given up, each row opening the filtered queue.
- The weekly rhythm: messages by hour and weekday, shown once metric
history exists.
- Dashboard tabs are titled by their label.
It greets the account by its full name where it has one, and otherwise by
the name it signs in with. The line beneath says who is signed in. The account
is looked up by its local part and matched on the whole address, so a
same-named account on another domain can't answer. The username is kept from
the JMAP session and cleared on sign-out.
- The INBUXA palette on warm surfaces, softer cards, buttons and inputs, and
self-hosted Inter and Space Grotesk.
- Each section's icon sits on a colored tile, colored by what the section is
about.
- The sidebar gets a guide line for sub-pages and a labeled Management /
Settings / Account switch, and folds to a rail of tiles (remembered).
- Every page has a header with its section's tile.
- Fields and pages with no label of their own are spelled out in words
(defaultCertificateId becomes Default certificate ID).
- The dashboard greets you, and its stat cards wear colored tiles.
- Unavailable live numbers are a calm note, not an error.
- The cat appears in empty lists and while loading.
- Chart colors work again: they were hex values wrapped in hsl().