Merge pull request 'Don't let a group's members share its mailboxes on' (#146) from fix/group-mailbox-no-onward-share into main
ci / github (push) Skipped
ci / fork-checks (push) Successful in 15s
github/ci (branch) GitHub Actions
ci / build (push) Successful in 48m50s

This commit was merged in pull request #146.
This commit is contained in:
jcoffey-dev committed 2026-10-05 21:26:52 +00:00
commit 5f6548bfdd
5 files changed
+76 -4

No files matched your search

+31
View File
@@ -2,6 +2,8 @@
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
*
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
*
* Modified by Coffey Labs in 2026 for INBUXA.
*/
use crate::utils::server::TestServer;
@@ -713,6 +715,35 @@ pub async fn test(test: &TestServer) {
.await,
);
// inbuxa: MA-D0: a member can't share the group's mailbox on, and isn't
// told it may. Who is in a group is an administrator's decision.
assert_forbidden(
john_client
.set_default_account_id(sales.id_string())
.mailbox_update_acl(&inbox_id, bill.id_string(), [ACL::ReadItems])
.await,
);
assert!(
!john_client
.set_default_account_id(sales.id_string())
.mailbox_get(&inbox_id, [mailbox::Property::MyRights].into())
.await
.unwrap()
.unwrap()
.my_rights()
.unwrap()
.acl_list()
.contains(&ACL::Administer)
);
bill_client.refresh_session().await.unwrap();
assert!(bill_client.session().account(sales.id_string()).is_none());
assert_forbidden(
bill_client
.set_default_account_id(sales.id_string())
.email_get(&email_id, [Property::Subject].into())
.await,
);
// Remove John from the sales group
admin
.registry_update_object(