New installs start with the hashed-address blocklist off, and DNSBL zones read right
Personal-data catalog spec, default D5 (settled 2026-09-28; built after the v0.16.24 import's spam-rules loader landed). msbl.org's EBL is sent a SHA-1 of every email address it's asked about. A new install's first boot now leaves a note, and the rules update, once the bundled rules are in, switches STWT_MSBL_EBL_EMAIL off and forgets the note, so it happens once; the loader keeps that switch through later updates. An existing server has no note and keeps every blocklist as it is. Also fixes the data inventory's DNSBL endpoints: a zone is an expression (`ip_reverse + '.zen.spamhaus.org'`, conditional branches, `hash(email, 'sha1') + '.ebl.msbl.org'`), and the zone names are now the quoted literals that start with a dot, from every branch, rather than the expression's text. Tested: unit test for the zone rule; the compliance system test (no note, no change; the inventory lists ebl.msbl.org, not a hash; with the note the blocklist goes off; the note works once); the system suite; fork checks.
This commit is contained in:
@@ -407,7 +407,11 @@ retention is (not a field on `x:TracerLog`, which is also stored inside
|
||||
`x:Bootstrap` with fields after it, so a new field would change that
|
||||
object's stored format); new installs 30 days, existing servers keep every
|
||||
file as today. D5 is built after the v0.16.24 import lands, on its reworked
|
||||
spam-rules loader, which keeps each blocklist's on/off state.
|
||||
spam-rules loader, which keeps each blocklist's on/off state. D5 built after the import: a new install's first boot leaves a note
|
||||
(`S` `n`), and the rules update, once the bundled rules are in, switches
|
||||
`STWT_MSBL_EBL_EMAIL` off and forgets the note; the loader keeps that
|
||||
switch through later updates. An existing server has no note and keeps
|
||||
every blocklist as it is.
|
||||
|
||||
| # | Change | Trade-off |
|
||||
|---|---|---|
|
||||
|
||||
Reference in New Issue
Block a user