Audit mail sent from an address that isn't the sender's own
ci / github (pull_request) Skipped
ci / fork-checks (pull_request) Successful in 48s
ci / build (pull_request) Successful in 8m50s
github/ci (branch) GitHub Actions

A group's members can send as the group, and the message says only
From: the group, so nothing recorded which person sent it. Every
submission whose envelope sender belongs to another account now writes
an audit record: the person as actor, an EmailSubmission target named
by the address and owned by that account, and "Sent as <address>",
with ", from <account>" when it went out through the sender's own
account rather than the group's.

A delegate's send is left to AL-9's record, and a send from the
sender's own address writes nothing. No Sender: header is added: the
audit log is where the real sender is named. email_submission_set now
takes the access token, from its one caller.

The audit suite has a group member send once as the group (one
record, with the address, account and details) and once as themselves
(none) (specs/multi-account.md, MA-D0a, G2).
This commit is contained in:
jcoffey-dev committed 2026-10-05 14:07:25 -07:00
1 parent d7bebd454d
commit 76c170db9d
4 files changed
+165 -1

No files matched your search

+12
View File
@@ -8,6 +8,7 @@
use common::{
Server,
auth::AccessToken,
config::smtp::queue::QueueName,
network::{ServerInstance, stream::NullIo},
storage::index::ObjectIndexBuilder,
@@ -49,6 +50,7 @@ pub trait EmailSubmissionSet: Sync + Send {
fn email_submission_set<'x>(
&self,
request: SetRequest<'x, email_submission::EmailSubmission>,
access_token: &AccessToken,
instance: &Arc<ServerInstance>,
next_call: &mut Option<Call<RequestMethod<'x>>>,
) -> impl Future<Output = trc::Result<SetResponse<email_submission::EmailSubmission>>> + Send;
@@ -68,6 +70,7 @@ impl EmailSubmissionSet for Server {
async fn email_submission_set<'x>(
&self,
mut request: SetRequest<'x, email_submission::EmailSubmission>,
access_token: &AccessToken,
instance: &Arc<ServerInstance>,
next_call: &mut Option<Call<RequestMethod<'x>>>,
) -> trc::Result<SetResponse<email_submission::EmailSubmission>> {
@@ -110,6 +113,15 @@ impl EmailSubmissionSet for Server {
.assign_document_ids(account_id, Collection::EmailSubmission, 1)
.await
.caused_by(trc::location!())?;
// inbuxa: MA-D0a: who sent it, when it went out as someone else
self.audit_send_as(
access_token,
account_id,
document_id,
&submission.envelope.mail_from.email,
)
.await;
batch
.with_account_id(account_id)
.with_collection(Collection::EmailSubmission)