Merge pull request 'Don't let a group's members share its mailboxes on' (#146) from fix/group-mailbox-no-onward-share into main
ci / github (push) Skipped
ci / fork-checks (push) Successful in 15s
github/ci (branch) GitHub Actions
ci / build (push) Successful in 48m50s

This commit was merged in pull request #146.
This commit is contained in:
jcoffey-dev committed 2026-10-05 21:26:52 +00:00
commit 5f6548bfdd
5 files changed
+76 -4

No files matched your search

+8
View File
@@ -2,6 +2,8 @@
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
*
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
*
* Modified by Coffey Labs in 2026 for INBUXA.
*/
use common::{Server, auth::AccessToken, sharing::EffectiveAcl};
@@ -14,6 +16,7 @@ use jmap_tools::{Map, Value};
use std::future::Future;
use store::ahash::AHashSet;
use types::{acl::Acl, collection::Collection, keyword::Keyword, special_use::SpecialUse};
use utils::map::bitmap::Bitmap;
use crate::{api::acl::JmapRights, changes::state::JmapCacheState};
@@ -138,6 +141,11 @@ impl MailboxGet for Server {
JmapRights::rights::<Mailbox>(
cached_mailbox.acls.as_slice().effective_acl(access_token),
)
} else if access_token.is_group_member_only(account_id) {
// inbuxa: MA-D0: everything but sharing it on.
let mut acl = Bitmap::<Acl>::all();
acl.remove(Acl::Share);
JmapRights::rights::<Mailbox>(acl)
} else {
JmapRights::all_rights::<Mailbox>()
}
+9
View File
@@ -613,6 +613,15 @@ impl MailboxSet for Server {
// Refresh ACLs
let current = update.map(|(_, current)| current);
if has_acl_changes {
// inbuxa: MA-D0: a group's members don't share its mailboxes on.
if ctx.access_token.is_group_member_only(ctx.account_id) {
return Ok(Err(SetError::forbidden()
.with_property(MailboxProperty::ShareWith)
.with_description(
"This mailbox belongs to a group. Only an administrator can change who has it.",
)));
}
if !changes.acls.is_empty()
&& let Err(err) = self.acl_validate(ctx.account_id, &changes.acls).await
{