Don't let a group's members share its calendars, address books or files
github/ci (branch) GitHub Actions
ci / github (pull_request) Skipped
ci / fork-checks (pull_request) Successful in 14s
ci / build (pull_request) Canceled after 25m26s

#146 stopped a group's members sharing its mailboxes on. The same
shortcut lets them through everywhere else a group owns things: a
member counts as the account's owner, so Calendar/set, AddressBook/set
and FileNode/set skip the share check, and so does the WebDAV ACL
method. Who has what a group owns is decided by who is in the group.

For a member through a group only (is_group_member_only):

- Calendar/set, AddressBook/set and FileNode/set refuse a shareWith
  change as forbidden, on create and update; for files at the top of
  the account too, not only inside a folder;
- the DAV ACL method answers 403 on the group's calendars, address
  books and files;
- myRights reports mayShare false (JmapRights::owner_rights), and the
  DAV current-user-privilege-set leaves out all and write-acl.

Reading who something is shared with is unchanged, as in JMAP.

Tests: a new jmap::group_share module has a member create with a
share, create without one (and check myRights), share afterwards, and
an outsider reach each kind; the WebDAV ACL test has a member try the
ACL method on the group's folders; the IMAP ACL test now checks #146's
SETACL refusal, which had no test of its own. jmap_tests, webdav_tests
and imap_tests pass (RocksDB). specs/multi-account.md MA-D0.
This commit is contained in:
jcoffey-dev committed 2026-10-05 15:03:15 -07:00
1 parent 5f6548bfdd
commit 58d2804278
12 files changed
+267 -4

No files matched your search

+11
View File
@@ -2,6 +2,8 @@
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
*
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
*
* Modified by Coffey Labs in 2026 for INBUXA.
*/
use super::{AssertResult, ImapConnection, Type, append::assert_append_message};
@@ -69,6 +71,15 @@ pub async fn test(
.await;
imap_jane.assert_read(Type::Tagged, ResponseType::Ok).await;
// inbuxa: MA-D0: but she can't share the group's mailbox on
imap_jane
.send("SETACL \"Shared Folders/[email protected]/INBOX\" [email protected] lr")
.await;
imap_jane
.assert_read(Type::Tagged, ResponseType::No)
.await
.assert_contains("NOPERM");
// John should have no shared folders
imap_john.send("LIST \"\" \"*\"").await;
imap_john