Journaling: search, read and export over JMAP, and the chain check
Phase 4 of the journaling spec. - inbuxa:JournalEntry/query and /get (sysJournalSearch): filter by time, sender, recipient, either, direction, subject words, Message-ID and journal, newest first; the whole report only when asked for. - inbuxa:JournalExport/set (sysJournalExport): a reason is required; a ZIP of the matching reports with manifest.csv, exceptions.csv and manifest.sha256, up to 10,000 reports and 1 GB. - inbuxa:JournalVerification/set (sysJournalGet): chains and reports rechecked. - Every search, listing, read, export and check is written to the audit log before anything is returned, with existing actions only. - Catalog entries for the three objects; spec as-built notes. journal_tests: administrators can't search; a Compliance Officer searches, lists, reads a report, exports (reason required) and checks the chain; the officer can't change journals; each of those is in the audit log.
This commit is contained in:
1 parent
abd5811420
commit
daa486f7e7
17 files changed
+1725
-2
No files matched your search
@@ -118,6 +118,7 @@ impl JmapAuthorization for AccessToken {
|
||||
}
|
||||
// inbuxa: journaling (JR-18)
|
||||
GetRequestMethod::Journal(_) => Permission::SysJournalGet,
|
||||
GetRequestMethod::JournalEntry(_) => Permission::SysJournalSearch,
|
||||
GetRequestMethod::HoldExport(_) => Permission::SysLegalHoldExport,
|
||||
// inbuxa: accepted security items are read by whoever may
|
||||
// see the server's security settings
|
||||
@@ -301,6 +302,20 @@ impl JmapAuthorization for AccessToken {
|
||||
Permission::SysJournalUpdate,
|
||||
Permission::SysJournalUpdate,
|
||||
),
|
||||
SetRequestMethod::JournalExport(s) => validate_set(
|
||||
s,
|
||||
self,
|
||||
Permission::SysJournalExport,
|
||||
Permission::SysJournalExport,
|
||||
Permission::SysJournalExport,
|
||||
),
|
||||
SetRequestMethod::JournalVerification(s) => validate_set(
|
||||
s,
|
||||
self,
|
||||
Permission::SysJournalGet,
|
||||
Permission::SysJournalGet,
|
||||
Permission::SysJournalGet,
|
||||
),
|
||||
// inbuxa: accepting a security to-do item, or removing
|
||||
// an acceptance; nothing is ever edited
|
||||
SetRequestMethod::SecurityAcceptance(s) => {
|
||||
@@ -481,6 +496,9 @@ impl JmapAuthorization for AccessToken {
|
||||
| MethodObject::SecurityAcceptance
|
||||
| MethodObject::HeldMessage
|
||||
| MethodObject::Journal
|
||||
| MethodObject::JournalEntry
|
||||
| MethodObject::JournalExport
|
||||
| MethodObject::JournalVerification
|
||||
| MethodObject::ProtocolPolicy
|
||||
| MethodObject::TenantProtocolPolicy => Permission::JmapEmailChanges,
|
||||
// inbuxa: x:MaskedEmail/changes reads what /get reads
|
||||
@@ -539,6 +557,8 @@ impl JmapAuthorization for AccessToken {
|
||||
QueryRequestMethod::ShareNotification(_) => Permission::JmapShareNotificationQuery,
|
||||
// inbuxa: the audit log (AU-9)
|
||||
QueryRequestMethod::AuditEvent(_) => Permission::SysAuditGet,
|
||||
// inbuxa: journaling (JR-15)
|
||||
QueryRequestMethod::JournalEntry(_) => Permission::SysJournalSearch,
|
||||
QueryRequestMethod::Registry(_) => {
|
||||
let MethodObject::Registry(object_type) = object else {
|
||||
unreachable!()
|
||||
|
||||
Reference in new issue
Block a user