From cca49de92c8b8b727cb3c787f1388a2029555677 Mon Sep 17 00:00:00 2001 From: John Coffey Date: Mon, 28 Sep 2026 10:54:17 -0700 Subject: [PATCH 1/2] Compliance menu: Overview and Data Inventory first MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Personal-data catalog spec, ยง8: the Compliance section in the console reads Overview, Data Inventory, Legal Holds, Audit Log, Locked Accounts. The two new entries are hand-built console pages (CustomComponent/ComplianceOverview, CustomComponent/DataInventory), shown to people with sysComplianceGet. A console from before these pages shows the links and answers "Unknown component", so the console that has them should be deployed with the server release that carries this. Schema edited as the fork's earlier Compliance entries were, hash updated. --- resources/schema/schema.json.gz | Bin 151484 -> 151510 bytes resources/schema/schema.json.sha256 | 2 +- 2 files changed, 1 insertion(+), 1 deletion(-) diff --git a/resources/schema/schema.json.gz b/resources/schema/schema.json.gz index 09338c90bd2559c0d8fcd8cc08c549ca026eebec..41d5a713d3b2228c4fcd3a91360d93a89caa77f4 100644 GIT binary patch delta 1764 zcmVcDThwX~x*qBB}$>;Cq-7;?z>4zDB5^SRS{q2RC%Y#D-He>NDDX>Vtx zP`-)CM$TSGZW`qbq)VK&t!>EAfYUha$0qAa1m{uqiG96sRX$itYYTkkqd8LDL*Ps+ zqtX*s=j=`Q%;lj%oS22<0Azyv$HO8$3zq4%78ZrYS1-3`>c z5xWP_0pFnW+mabBCuK7m0+M*;Z-qu#eA*T7Nx|*IpiiXtB4hdQe{~h)>p+?HPQ9$~ zpb2n=kuoAYlNSc8xTK8$oR<@&;$<<;OGzC;QF|dC!}OsJ9BQR9f`?E<0>O1Ssrqg4 z3RP&Y#?J9*#|c4g;MIDz^?E3=xzUW_-O@3}-RO4XaGKFS_Mipx2eKb^v3jbM3CaoIk3sdBLW4W=|eIdjtQl|%kB z@A=7bKXnoHM!sD1w9p<=9DSa&-8TX!(Oud=3v{sK%Txc{J6&wEm=Zv!pP>YxylS(^ zv$QfAizuixO@rwnrQ`GxCs{~WO#afIzPq>%L!7SF13-Lje|@-n7nYyu7pD11ZhC%^ zoZVhuhCxt=7tq2TgAMK7NI7m7yFfjhOz);)`4b(qg0Dx=B9z+X(3LlcV>`9;-brWd zDAe~8_iGA5GXz#jbcs⋘bR!$TZT1GOQI_aZQ{;C9cRAVIf=XnGb1@o+Y5M?Ubcy~_ zvSz(5eNWU+0rGgyIEIkf4eSQ#E*0esYDhf_^W^k=L}QCw(>wrkahZfObD`e5X1fCg@R2ySG7E#5E;A0mzPWe zDjM#e4T}r)Yi!r4wP4n#1=dgEujUBs&_sN@m)lGN9|~}LHEisZe%cK0mjq1$B7cg* z`UY2LS4$viZ`8u=t48d)xH+D!Qx!H>t9#&rFN>%^F+4mS6ltS9bNI47u2gbp`Bp&* zOp}2{wT#dW%gdTXTx9R+tYy|b#FlI(mw#r%D1Bpi$P|U9@;4I}eoY{6l4B%WAsA%P zAc2}5E|K(|X%(Xh^Dd*KcTVrXLVqkP$M5{%E_$)oF*cg<^#LLsFdBU%org5OMNvKS z(u#!A{`!*(Ps8{+j8veAlEIpk;l-PT4Rj-E%GiJ0ZUZEaAq+PWuxgI2s*x}g5f*w3 z?4yeD%w1*A`r0#VQ;&V-zQu2AXe!?I;(>Or6J_r?(mpc&bi*1|)gxO`b$@^Id($UWaxXi8Pz7X(T~n*P%ICTa0t#oLtM-dhFulm(ZCD zRv2n1neM<;NUBRs2lL$ye1GdpaHt@713!!T2A+&vTI>G~wjlD!TD!93@|8E4Vjf;xU6Tb3iW%z?&!VBeFr2)+TSM^gM|E;qcmlMHjJF#&2!rv)(vyLn?C+wx zU81=frYRy2ZqC^m7v5DB6D`|8RmdqW0;&O`xY%x>_nrJ!+FXbG?PoF9yNzwBi6pn_ zHjuSV<)(TOJ#W~-Fnc`%P40};c7{Rwn94DLh6%8PXpG(C4jycC&@^|?%vX9N4Af*f z%(}<3%mgA}FjJ#ZS?l(k79mcmzrxv7=9l7~RMCAay)|ZM;0xAf~SMK13 GbPfOjIdqBu delta 1702 zcmV;X23h&mp9#F534nwFv;t#De`Cv1x6Io_dL;%5AlO7^yt#)}zktW*isjh2Lq^FL zs0vgHCj6R7@+P@ZrU_LRJg>HKuiQi}MXcU4U|eS4&B@?nZyQBcd3Lrl z$I>mruzIP!($z(AT~+vu1%oo}O_&tQHxV?**+$6ym>k@?#97i6YHagQv#U}yH^x)2_{f&BI+V?^pF{L?ddA@KP#mdeb#)f3L70dPO1DzzpY_)+-MjjpPXIJCsGFg>b%2cfk*zOh39Z zn3_HW*67()^1tKbx98+@)21BhZlF1hSeQY*dV_vtOJ=y7l+A32_2HGj70O!iX;-`_ z1y|-lRY$KJ#`52*0m#>ZGVA?iS>fT3?Fu7hM0h53@vOL{jR2gNe-ouWWiif6NgY8^ z+YBDVbWaYP7v(vhhfqWU!F4#PRc-NhQYeN-_ab1S0P$krL3pLMg06R zhP3E*<8YeMKlY#n^9QokbFq51q2PgIwTh+?hV0o4NdH`P3^A8T^~uD*kega&ZsuVJ z>bM5wYuP?|sdBLWe+{OTD>-wB?)5JI{ZhC%^oZVhuhCxt07Eo{n$MLth+{jo^WOhu>?qXt6ZdNhLNf$bO7u2P$duzOnaDKKhB9Il zTX9XCt|G3;7`z}`?U@g0ke(%=4DFbi0U!h+xDQuGmWldE&cY0Q<9R_N@E{ndQpQnw zZJRzFb4Z#=fAjd^KIRZ}7IX+gcgaC12042ev;=ymAxe68=Ckba8OH zfwwV&dTg!S4C86GaX@J^)R)Eu5@bOgubDxi`K0As%8#GAQ7_IZ!=vTBI>K0l*$q)? z&UW{)(!7Q-I`^|HlJ}-`rAM0TEHB!q+oj8%(d`(LToRl^L2FlSI9W^&pVYics?j|J z81TR|pz=!3-YXfT!)}&TX5WTT+=)Nb8(r3GjpMyl9y9V0y!qC9m_CwWjNH+t6`}tkhXm9v;9w^p6ZZB zN<~>sJhz}cpb#0mAeXXC0xAWrb`4_&m*GqT69VYCm-b8o9|}lzHEisZe%g$jmmf_6 zA|DEI`UY2LS4$viZ`8u=t48d)xH+D!Qx%a`t9#&HE|*|U0u_J${^o7`qFP4ihUH~V zBJPNHb=ER#9%4&2lgmG|VF0`_JYz!X&O;jCqNpBuX+=V5fBngYr(xU( zMk-JQpkS@F@Zx_>!UnpLv=Zz;Znpsv#}I~_2v{}8R@F$DiHNv72KG^fPv)+&XMOFN zwW-HGbKl}O<1-cSdhtM$(up#q9BCgJ+PPuvmFkhLsJcIS@)<+R`!x^XFyXyeP}1@oGFStb6L7(~<_?>XE)Rd3{;`Fw$uFTZ7pySUP%_wATL}Y(eB}uy$q1N3_Po<)B{ePK9xdAEk(I*;n)wD80}85wUka1aLLjio08J=xzyce_M$HB3`PAl#g@ zGcG(?DkfUCgQ{pwTyRkXL~*g*K<_*Gt+crg_uFHxcN^PM6G?8b$Fs}?f=e({ wrjU_GLAC diff --git a/resources/schema/schema.json.sha256 b/resources/schema/schema.json.sha256 index c7b2069..d392df4 100644 --- a/resources/schema/schema.json.sha256 +++ b/resources/schema/schema.json.sha256 @@ -1 +1 @@ -8Wyl9buv_eSbbGGhV-UZcjGHG_H77eorpuoI2u6wgnY \ No newline at end of file +wDJZ1KdKs21tjHD-UBI9R_XwPEET7Iul8XEXbPlgBPE \ No newline at end of file From 728586998b9f70b183791d18db05d274710bf0bf Mon Sep 17 00:00:00 2001 From: John Coffey Date: Mon, 28 Sep 2026 11:03:55 -0700 Subject: [PATCH 2/2] Catalog: what the Overview showed wrong Seen in the console's first Overview. x:DmarcTroubleshoot and x:SpamClassify are one-off actions whose results come back in the response, not kept: object-life, not unbounded. Tasks go when done (only a failed one's status may stay, still unconfirmed): object-life. x:Log reads the log files, so it follows inbuxa:LogSettings.keepForDays. x:TracerLog, x:WebHook and the OpenTelemetry tracers are configuration: their credential fields stay classified, but they are no longer listed in the inventory, where they counted as always sent off the server even with none configured; the log-file, webhooks and otel-tracer sources carry what they send. --- resources/privacy/catalog.toml | 37 +++++++++++++--------------------- 1 file changed, 14 insertions(+), 23 deletions(-) diff --git a/resources/privacy/catalog.toml b/resources/privacy/catalog.toml index 366965d..80705aa 100644 --- a/resources/privacy/catalog.toml +++ b/resources/privacy/catalog.toml @@ -847,7 +847,7 @@ default = "none" whose = ["correspondent"] where = ["memory"] scope = "server" -retention = "unbounded" +retention = "object-life" [object."x:DmarcTroubleshoot".properties] ehloDomain = ["network"] ipRevPtr = ["network"] @@ -1266,7 +1266,7 @@ default = "none" whose = ["correspondent", "holder", "administrator"] where = ["log-file"] scope = "server" -retention = "unbounded" +retention = { setting = "inbuxa:LogSettings.keepForDays" } [object."x:Log".properties] details = ["network", "identifier", "metadata"] timestamp = ["metadata"] @@ -1689,7 +1689,7 @@ default = "none" whose = ["correspondent"] where = ["memory"] scope = "server" -retention = "unbounded" +retention = "object-life" [object."x:SpamClassify".properties] authenticatedAs = ["identifier"] ehloDomain = ["network"] @@ -1810,7 +1810,7 @@ default = "none" whose = ["holder", "correspondent"] where = ["data-store"] scope = "tenant" -retention = "unbounded" +retention = "object-life" [object."x:TaskCalendarItipContents".properties] from = ["identifier"] iCalendarData = ["content"] @@ -1825,7 +1825,7 @@ default = "none" whose = ["holder"] where = ["data-store"] scope = "tenant" -retention = "unbounded" +retention = "object-life" [object."x:TaskDestroyAccount".properties] accountName = ["identifier"] @@ -1852,7 +1852,7 @@ default = "none" whose = ["holder"] where = ["data-store"] scope = "tenant" -retention = "unbounded" +retention = "object-life" [object."x:TaskMergeThreads".properties] messageIds = ["metadata"] threadName = ["content"] @@ -1886,7 +1886,7 @@ default = "none" whose = ["holder"] where = ["data-store"] scope = "tenant" -retention = "unbounded" +retention = "object-life" [object."x:TaskStatusRetry".properties] failureReason = ["content"] @@ -2040,30 +2040,23 @@ default = "none" [object."x:TracerLog"] default = "none" -whose = ["correspondent", "holder", "administrator"] -where = ["log-file"] -scope = "server" -retention = "unbounded" + [object."x:TracerLog".properties] path = ["metadata"] [object."x:TracerOtelGrpc"] +# Configuration: the "webhooks" and "otel-tracer" sources carry what it sends default = "none" -whose = ["correspondent", "holder", "administrator"] -where = ["external"] -scope = "server" -retention = "receiver" + [object."x:TracerOtelGrpc".properties] endpoint = ["network"] httpAuth = ["credential"] httpHeaders = ["credential"] [object."x:TracerOtelHttp"] +# Configuration: the "webhooks" and "otel-tracer" sources carry what it sends default = "none" -whose = ["correspondent", "holder", "administrator"] -where = ["external"] -scope = "server" -retention = "receiver" + [object."x:TracerOtelHttp".properties] endpoint = ["network"] httpAuth = ["credential"] @@ -2095,11 +2088,9 @@ usedDiskQuota = ["metadata"] default = "none" [object."x:WebHook"] +# Configuration: the "webhooks" and "otel-tracer" sources carry what it sends default = "none" -whose = ["correspondent", "holder", "administrator"] -where = ["external"] -scope = "server" -retention = "receiver" + [object."x:WebHook".properties] httpAuth = ["credential"] httpHeaders = ["credential"]