Journaling: capture at the queue, the built-in journal, retention
Phase 2 of the journaling spec. - A copy of each message is taken in MessageWrapper::queue, after DLP and transport rules, for every enabled journal that takes it (direction and scope: everyone, or accounts, groups, domains, tenants). If the copy can't be taken the message isn't queued (temporary failure). - The journal report: the envelope one field a line (sender, To, Cc, Bcc from the envelope, list members from their ORCPT, direction, held for review), then the queued message byte for byte as message/rfc822. - The built-in journal under J in the inbuxa subspace: one chain per node whose links name each entry by SHA-256, so entries can expire out of chain order; purge leaves a marker, and verify catches an entry changed or removed early and a report that doesn't match. - Retention per journal (30 to 3650 days); an entry keeps what it was written with. The daily maintenance purges what's due, keeping entries whose people a legal hold covers (deleted accounts a hold keeps too), and records the counts in the audit log. - inbuxa:Journal get/set, audited by the request layer. Permissions 680-683: administrators see and change journals; the Compliance Officer sees, searches and exports. Whoever changes journals may grant search and export without holding them, so officers can still be appointed. - Catalog entries (inbuxa:Journal, source "journal"); spec as-built notes. tests/src/system/journal.rs: validation, internal mail with a Bcc, outgoing into two journals, incoming over LMTP, the report and its original, tamper and early removal caught, hold-aware purge, retention changes leave entries alone, disabled and removed journals take nothing.
This commit is contained in:
@@ -291,6 +291,12 @@ async fn store_maintenance(
|
||||
trc::error!(err.details("Failed to return unreviewed held mail"));
|
||||
}
|
||||
|
||||
// inbuxa: journaling, JR-13: entries past their retention go,
|
||||
// except those a legal hold keeps
|
||||
if let Err(err) = purge_journal(server).await {
|
||||
trc::error!(err.details("Failed to purge journal entries"));
|
||||
}
|
||||
|
||||
// inbuxa: AU-7: audit records past their retention go; a
|
||||
// failure leaves them for the next run
|
||||
if let Err(err) = server.audit_purge().await {
|
||||
@@ -409,6 +415,54 @@ async fn store_maintenance(
|
||||
Ok(TaskResult::Success(vec![]))
|
||||
}
|
||||
|
||||
/// inbuxa: journaling, JR-13: removes journal entries past their
|
||||
/// retention, keeping any whose sender or recipients a legal hold covers
|
||||
/// (deleted accounts a hold keeps included), and records how many went.
|
||||
async fn purge_journal(server: &Server) -> trc::Result<()> {
|
||||
use inbuxa_features::audit::{Action, Actor, Outcome, Record, Target};
|
||||
let mut held = server.held_accounts().await?;
|
||||
if !held.is_empty() {
|
||||
for (account_id, kept) in
|
||||
inbuxa_features::undelete::data::kept_accounts(server.store()).await?
|
||||
{
|
||||
if server.is_kept_held(account_id, &kept).await? {
|
||||
held.insert(account_id);
|
||||
}
|
||||
}
|
||||
}
|
||||
let at = store::write::now();
|
||||
let purged = inbuxa_features::journal::entries::purge(server.store(), at, |entry| {
|
||||
entry.accounts.iter().any(|account| held.contains(account))
|
||||
})
|
||||
.await?;
|
||||
if purged.removed > 0 || purged.kept_for_hold > 0 {
|
||||
server
|
||||
.audit_note(Record {
|
||||
at: at * 1000,
|
||||
actor: Actor::system("Journal"),
|
||||
via: None,
|
||||
remote_ip: None,
|
||||
action: Action::Destroy,
|
||||
target: Target {
|
||||
kind: "inbuxa:JournalEntry".into(),
|
||||
id: None,
|
||||
name: None,
|
||||
account_id: None,
|
||||
tenant_id: None,
|
||||
},
|
||||
changes: vec![],
|
||||
details: Some(format!(
|
||||
"{} past their retention removed; {} kept for a legal hold",
|
||||
purged.removed, purged.kept_for_hold
|
||||
)),
|
||||
reason: None,
|
||||
outcome: Outcome::success(),
|
||||
})
|
||||
.await;
|
||||
}
|
||||
Ok(())
|
||||
}
|
||||
|
||||
async fn account_maintenance(
|
||||
server: &Server,
|
||||
task: &TaskAccountMaintenance,
|
||||
|
||||
Reference in New Issue
Block a user