Lock accounts: keep receiving mail, no sign-in, hand to delegates
ci / fork-checks (pull_request) Successful in 1m4s
ci / build (pull_request) Successful in 8m47s

A locked account can't sign in (it fails as a wrong password does), its
sessions end on every node, refresh tokens stop working, and its Sieve
scripts forward and reply to nothing. Mail keeps arriving.

Delegates get real ACL grants on the account's mailboxes, calendars,
address books and files at read, organize or full, with the rights they
replaced restored on unlock. Folders made later are granted after the
create and in a daily sweep. Organize delegates can't destroy; send-as
needs organize or full. The JMAP session marks delegated accounts in
urn:inbuxa:jmap.

New inbuxa:AccountLock object with get/set, permissions 665-668, and a
Compliance > Locked Accounts entry in the schema. Lock, unlock and
delegate changes need a reason and are audited; delegate access and
writes are audited too (audit-hold-lock spec AL-1 to AL-12).
This commit is contained in:
2026-09-27 14:46:06 -07:00
parent ebf2fe11d9
commit 447229f871
46 changed files with 2573 additions and 29 deletions
+89 -7
View File
@@ -143,15 +143,27 @@ impl RequestHandler for Server {
| RequestMethod::Changes(_)
| RequestMethod::QueryChanges(_)
);
if matches!(
let is_write = matches!(
call.method,
RequestMethod::Set(_)
| RequestMethod::Copy(_)
| RequestMethod::ImportEmail(_)
| RequestMethod::UploadBlob(_)
) {
);
if is_write {
has_written = true;
}
// inbuxa: AL-7: what a delegate makes in a locked account
// may need the lock's grants
let makes_containers = is_write
&& matches!(
call.name.obj,
MethodObject::Mailbox
| MethodObject::Calendar
| MethodObject::AddressBook
| MethodObject::FileNode
);
let call_name = call.name.as_str().into_owned();
let presented = match &call.method {
RequestMethod::Changes(changes) => match &changes.since_state {
jmap_proto::types::state::State::Exact(change_id) => {
@@ -189,7 +201,28 @@ impl RequestHandler for Server {
};
let (result, reached) = result;
for account_id in reached {
self.audit_foreign_access(access_token, account_id, false).await;
// inbuxa: AL-9: a delegate's access, and what it
// changes, are recorded; anyone else here impersonated
if let Some(delegation) = access_token.delegation(account_id) {
let access = delegation.access.as_str();
self.audit_delegate(
access_token,
account_id,
access,
is_write.then_some(call_name.as_str()),
result.as_ref().err(),
)
.await;
if makes_containers
&& result.is_ok()
&& let Err(err) =
email::inbuxa_lock::reconcile(self, account_id).await
{
trc::error!(err.details("Failed to grant a lock's delegates on new folders"));
}
} else {
self.audit_foreign_access(access_token, account_id, false).await;
}
}
match result
{
@@ -237,6 +270,9 @@ impl RequestHandler for Server {
SetResponseMethod::AuditVerification(set_response) => {
set_response.update_created_ids(&mut response);
}
SetResponseMethod::AccountLock(set_response) => {
set_response.update_created_ids(&mut response);
}
SetResponseMethod::Explanation(set_response) => {
set_response.update_created_ids(&mut response);
}
@@ -354,13 +390,15 @@ impl RequestHandler for Server {
}
GetRequestMethod::Identity(mut req) => {
resolve_account_id(&mut req.account_id, method_name.obj, access_token)?;
access_token.assert_is_member(req.account_id)?;
// inbuxa: AL-8: a delegate may send as a locked account
access_token.assert_can_send(req.account_id)?;
self.identity_get(*req).await?.into()
}
GetRequestMethod::EmailSubmission(mut req) => {
resolve_account_id(&mut req.account_id, method_name.obj, access_token)?;
access_token.assert_is_member(req.account_id)?;
// inbuxa: AL-8: a delegate may send as a locked account
access_token.assert_can_send(req.account_id)?;
self.email_submission_get(*req).await?.into()
}
@@ -401,6 +439,13 @@ impl RequestHandler for Server {
.await?
.into()
}
// inbuxa: account lock with delegation (AL-1)
GetRequestMethod::AccountLock(mut req) => {
resolve_account_id(&mut req.account_id, method_name.obj, access_token)?;
crate::inbuxa::account_lock::get(self, access_token, *req)
.await?
.into()
}
// inbuxa: the audit log (AU-9)
GetRequestMethod::AuditEvent(mut req) => {
resolve_account_id(&mut req.account_id, method_name.obj, access_token)?;
@@ -526,7 +571,8 @@ impl RequestHandler for Server {
}
QueryRequestMethod::EmailSubmission(mut req) => {
resolve_account_id(&mut req.account_id, method_name.obj, access_token)?;
access_token.assert_is_member(req.account_id)?;
// inbuxa: AL-8: a delegate may send as a locked account
access_token.assert_can_send(req.account_id)?;
self.email_submission_query(*req).await?.into()
}
@@ -631,7 +677,8 @@ impl RequestHandler for Server {
}
SetRequestMethod::EmailSubmission(mut req) => {
resolve_account_id(&mut req.account_id, method_name.obj, access_token)?;
access_token.assert_is_member(req.account_id)?;
// inbuxa: AL-8: a delegate may send as a locked account
access_token.assert_can_send(req.account_id)?;
self.email_submission_set(*req, &session.instance, next_call)
.await?
@@ -665,6 +712,7 @@ impl RequestHandler for Server {
session,
&method_name.obj.to_string(),
None,
None,
*req,
|req| Box::pin(crate::inbuxa::fastmail::set(self, access_token, req)),
)
@@ -681,6 +729,7 @@ impl RequestHandler for Server {
session,
&method_name.obj.to_string(),
None,
None,
*req,
|req| Box::pin(crate::inbuxa::deleted_account::set(self, access_token, req)),
)
@@ -697,6 +746,7 @@ impl RequestHandler for Server {
session,
&method_name.obj.to_string(),
None,
None,
*req,
|req| Box::pin(crate::inbuxa::ai_limits::set(self, access_token, req)),
)
@@ -712,12 +762,41 @@ impl RequestHandler for Server {
session,
&method_name.obj.to_string(),
None,
None,
*req,
|req| Box::pin(crate::inbuxa::audit_log::settings_set(self, access_token, req)),
)
.await?
.into()
}
// inbuxa: account lock with delegation, recorded with its
// reason (AL-1, AU-12)
SetRequestMethod::AccountLock(mut req) => {
resolve_account_id(&mut req.account_id, method_name.obj, access_token)?;
let reason = req.arguments.reason.clone().or_else(|| {
req.create.as_ref().and_then(|create| {
create.values().find_map(|value| {
serde_json::to_value(value)
.ok()?
.get("reason")?
.as_str()
.map(str::to_string)
})
})
});
crate::inbuxa::audit::recorded(
self,
access_token,
session,
&method_name.obj.to_string(),
None,
reason,
*req,
|req| Box::pin(crate::inbuxa::account_lock::set(self, access_token, req)),
)
.await?
.into()
}
SetRequestMethod::AuditExport(mut req) => {
resolve_account_id(&mut req.account_id, method_name.obj, access_token)?;
crate::inbuxa::audit_log::export_set(self, access_token, session, *req)
@@ -747,6 +826,7 @@ impl RequestHandler for Server {
session,
&method_name.obj.to_string(),
None,
None,
*req,
|req| Box::pin(crate::inbuxa::protocol_policy::set(self, access_token, req)),
)
@@ -763,6 +843,7 @@ impl RequestHandler for Server {
session,
&method_name.obj.to_string(),
None,
None,
*req,
|req| Box::pin(crate::inbuxa::tenant_protocol_policy::set(self, access_token, req)),
)
@@ -840,6 +921,7 @@ impl RequestHandler for Server {
session,
&method_name.obj.to_string(),
Some(object_type),
None,
*req,
|req| Box::pin(self.registry_set(object_type, req, access_token, session)),
)