Compare commits
41
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
b62713bb8d | ||
|
|
ef56eb33ed | ||
|
|
b64f6690f6 | ||
|
|
bf7c84bc15 | ||
|
|
b07e69b5ed | ||
|
|
ce8284df6c | ||
|
|
966241070e | ||
|
|
b25258330c | ||
|
|
db4135e481 | ||
|
|
72f8ddd5e7 | ||
|
|
88e756bc3a | ||
|
|
f77d171063 | ||
|
|
79db6c537b | ||
|
|
1a23243cc1 | ||
|
|
ca4bf75c1b | ||
|
|
8a596c44ac | ||
|
|
c50d5eb109 | ||
|
|
098abb102a | ||
|
|
c1702a00bb | ||
|
|
a24ed3b60a | ||
|
|
f791c78d17 | ||
|
|
461f5fab3c | ||
|
|
4f25927d18 | ||
|
|
fb785b8635 | ||
|
|
50a03df30b | ||
|
|
9976d52e29 | ||
|
|
58d2804278 | ||
|
|
5f6548bfdd | ||
|
|
daa484efbc | ||
|
|
1aedc77791 | ||
|
|
a19d9eec89 | ||
|
|
5c1c4c6248 | ||
|
|
2d8728793c | ||
|
|
9429f1de00 | ||
|
|
76c170db9d | ||
|
|
d7bebd454d | ||
|
|
282ad5fc13 | ||
|
|
133d41df36 | ||
|
|
c4a6e4d117 | ||
|
|
f59a9de4dc | ||
|
|
083f22d6fb |
No files matched your search
@@ -5,11 +5,6 @@
|
||||
|
||||
version: 2
|
||||
updates:
|
||||
- package-ecosystem: "cargo" # See documentation for possible values
|
||||
directory: "/" # Location of package manifests
|
||||
schedule:
|
||||
interval: "weekly"
|
||||
|
||||
# Enable version updates for GitHub Actions
|
||||
- package-ecosystem: "github-actions"
|
||||
# Workflow files stored in the default location of `.github/workflows`
|
||||
|
||||
@@ -12,7 +12,7 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Close issues from non-allowed authors
|
||||
uses: actions/github-script@v7
|
||||
uses: actions/github-script@v9
|
||||
with:
|
||||
script: |
|
||||
// Users allowed to open issues directly. All other authors will have
|
||||
|
||||
@@ -18,7 +18,7 @@ jobs:
|
||||
sparse-checkout-cone-mode: false
|
||||
|
||||
- name: Close PRs from non-allowed authors
|
||||
uses: actions/github-script@v7
|
||||
uses: actions/github-script@v9
|
||||
with:
|
||||
script: |
|
||||
const fs = require('fs');
|
||||
|
||||
@@ -12,7 +12,7 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Post support portal redirect
|
||||
uses: actions/github-script@v7
|
||||
uses: actions/github-script@v9
|
||||
with:
|
||||
script: |
|
||||
const discussion = context.payload.discussion;
|
||||
|
||||
@@ -73,6 +73,6 @@ jobs:
|
||||
# Upload the results to GitHub's code scanning dashboard (optional).
|
||||
# Commenting out will disable upload of results to your repo's Code Scanning dashboard
|
||||
- name: "Upload to code-scanning"
|
||||
uses: github/codeql-action/[email protected]7.4
|
||||
uses: github/codeql-action/[email protected]8.2
|
||||
with:
|
||||
sarif_file: results.sarif
|
||||
@@ -36,6 +36,6 @@ jobs:
|
||||
severity: 'CRITICAL,HIGH'
|
||||
|
||||
- name: Upload Trivy scan results to GitHub Security tab
|
||||
uses: github/codeql-action/[email protected]7.4
|
||||
uses: github/codeql-action/[email protected]8.2
|
||||
with:
|
||||
sarif_file: 'trivy-results.sarif'
|
||||
@@ -2,6 +2,33 @@
|
||||
|
||||
All notable changes to this project will be documented in this file. This project adheres to [Semantic Versioning](http://semver.org/).
|
||||
|
||||
## [0.16.25] - 2026-10-05
|
||||
|
||||
If you are upgrading from v0.16.x, replace the binary (or run `docker pull`). If you are upgrading from v0.15.x and below, please read the [upgrading documentation](https://github.com/stalwartlabs/stalwart/blob/main/UPGRADING/v0_16.md) for more information on how to upgrade from previous versions.
|
||||
|
||||
## Added
|
||||
|
||||
## Changed
|
||||
|
||||
## Fixed
|
||||
- JMAP: Creating a `MaskedEmail` with `emailDomain` fails with `forbidden` for every domain when the account has addresses on more than one domain.
|
||||
- Autodiscover: Requests for a response schema other than Outlook's, such as ActiveSync (`mobilesync`), are answered with the Outlook settings instead of error 601.
|
||||
- IMAP:
|
||||
- `LOGIN` and `AUTHENTICATE` with a wrong, expired or unknown app password or API key are answered with an untagged `NO`, so clients keep waiting for the command to complete until the connection times out.
|
||||
- The failed login that exceeds the maximum number of authentication failures is answered with an untagged `NO` before the connection is closed.
|
||||
- DKIM:
|
||||
- A rotation moves the active key to retiring even when its successor fails to publish or propagate, so outgoing mail is sent unsigned until a retry publishes the new key. The DNS write failure is also not logged and the task reports success.
|
||||
- Keys created while DNS management was manual, or before DKIM was added to the published records, are never rotated after DNS management becomes automatic. Domains already affected start rotating once a `DkimManagement` task is created for them.
|
||||
- After switching DNS management from automatic to manual, a due rotation activates a new key that was never published in DNS, so signatures fail verification, and retiring the old key is retried forever.
|
||||
- Spam filter:
|
||||
- Messages with no text line long enough for a Pyzor digest are checked with the digest of empty input and tagged `PYZOR`.
|
||||
- DNSBL answers with several return codes, such as a Spamhaus ZEN listing in both SBL and PBL, are scored for only the first code returned.
|
||||
- DNSBL lookups that return "not listed" are cached for 24 hours regardless of the zone's negative TTL.
|
||||
- Removing a duplicate training sample of a message reclassified on the same day clears the blob link of the sample that is kept.
|
||||
- MTA: Queue quotas with an empty `match` expression are never enforced, including the global queue quota created on first start.
|
||||
- RocksDB: The info log (`LOG`, `LOG.old.*`) grows without limit because log rotation and retention are left at RocksDB defaults.
|
||||
- WebUI: A blob store read error at startup, such as an S3 authentication failure, stops the web interface from being downloaded.
|
||||
|
||||
## [0.16.24] - 2026-09-27
|
||||
|
||||
If you are upgrading from v0.16.x, replace the binary (or run `docker pull`). If you are upgrading from v0.15.x and below, please read the [upgrading documentation](https://github.com/stalwartlabs/stalwart/blob/main/UPGRADING/v0_16.md) for more information on how to upgrade from previous versions.
|
||||
|
||||
+1
-1
@@ -60,7 +60,7 @@ representative at an online or offline event.
|
||||
|
||||
Instances of abusive, harassing, or otherwise unacceptable behavior may be
|
||||
reported to the community leaders responsible for enforcement at
|
||||
**johnellisATlinuxDOTcom**.
|
||||
**communityATcoffeylabsDOTorg**.
|
||||
All complaints will be reviewed and investigated promptly and fairly.
|
||||
|
||||
All community leaders are obligated to respect the privacy and security of the
|
||||
|
||||
+1
-1
@@ -54,7 +54,7 @@ Coffey Labs" line in place. New files carry:
|
||||
|
||||
```
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
Generated
+81
-69
@@ -277,9 +277,9 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "async-compression"
|
||||
version = "0.4.48"
|
||||
version = "0.4.50"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "fb61aea1a7def73ee7c350a184f0e70b32c182344e2e75bf70c9b621b83417fd"
|
||||
checksum = "ee19bd99b43e3691acbad4e840420a4881cea6c0b66a208125a824f8fd53f5a1"
|
||||
dependencies = [
|
||||
"compression-codecs",
|
||||
"compression-core",
|
||||
@@ -1292,7 +1292,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "common"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"aes-gcm-siv",
|
||||
"ahash",
|
||||
@@ -1392,9 +1392,9 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "compression-codecs"
|
||||
version = "0.4.43"
|
||||
version = "0.4.45"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "bef16c47ba2797aa6a909cc37d39911f3a6743811fe7408ac0b0cc0276b656e9"
|
||||
checksum = "98fc98460ba0ad5317075d3632b8dfc45d0be8c4a49347c2a38272019717614a"
|
||||
dependencies = [
|
||||
"compression-core",
|
||||
"flate2",
|
||||
@@ -1477,7 +1477,7 @@ checksum = "3d52eff69cd5e647efe296129160853a42795992097e8af39800e1060caeea9b"
|
||||
|
||||
[[package]]
|
||||
name = "coordinator"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"async-nats",
|
||||
"futures",
|
||||
@@ -1889,7 +1889,7 @@ checksum = "4583a4551df46e2792f82ceeac45e850d2e2d5debba0b91f102385cda5b11f06"
|
||||
|
||||
[[package]]
|
||||
name = "dav"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"calcard",
|
||||
"chrono",
|
||||
@@ -1912,7 +1912,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "dav-proto"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"calcard",
|
||||
"chrono",
|
||||
@@ -2125,7 +2125,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "directory"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"ahash",
|
||||
"argon2 0.6.0",
|
||||
@@ -2366,7 +2366,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "email"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"aes 0.9.3",
|
||||
"aes-gcm 0.11.1",
|
||||
@@ -2406,6 +2406,16 @@ dependencies = [
|
||||
"log",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "encodify"
|
||||
version = "1.0.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "798c447647dd23f673748f2b868ef309a01dd86aaae999182559d36f06ac82f0"
|
||||
dependencies = [
|
||||
"memchr",
|
||||
"simdutf8",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "encoding_rs"
|
||||
version = "0.8.42"
|
||||
@@ -2474,7 +2484,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "event_macro"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"quote",
|
||||
"syn 3.0.6",
|
||||
@@ -3002,7 +3012,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "groupware"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"ahash",
|
||||
"calcard",
|
||||
@@ -3289,7 +3299,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "http"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"async-stream",
|
||||
"base64 0.23.1",
|
||||
@@ -3385,7 +3395,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "http_proto"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"common",
|
||||
"compact_str",
|
||||
@@ -3872,7 +3882,7 @@ checksum = "65b27460c2c92b037f3f94c538ed9a3342f3fdf923606781629ccb35f82d042a"
|
||||
|
||||
[[package]]
|
||||
name = "imap"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"ahash",
|
||||
"common",
|
||||
@@ -3897,7 +3907,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "imap_proto"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"ahash",
|
||||
"base64 0.23.1",
|
||||
@@ -3912,7 +3922,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "inbuxa"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"common",
|
||||
"coordinator",
|
||||
@@ -3920,7 +3930,7 @@ dependencies = [
|
||||
"directory",
|
||||
"email",
|
||||
"groupware",
|
||||
"http 0.16.24",
|
||||
"http 0.16.25",
|
||||
"http_proto",
|
||||
"imap",
|
||||
"jmap",
|
||||
@@ -4209,7 +4219,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "jmap"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"async-stream",
|
||||
"base64 0.23.1",
|
||||
@@ -4258,14 +4268,14 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "jmap-client"
|
||||
version = "0.4.2"
|
||||
version = "0.4.3"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "4deab22e057d24e32122f0fc6e2d667a124fdd6a0d8ef3ed4f8a89923c11084f"
|
||||
checksum = "f5b5bc66252cc8e779ef1238f40ab93971d54ad00b5d7afb5c1d447a9647ed62"
|
||||
dependencies = [
|
||||
"ahash",
|
||||
"async-stream",
|
||||
"base64 0.22.1",
|
||||
"chrono",
|
||||
"encodify",
|
||||
"futures-util",
|
||||
"maybe-async",
|
||||
"parking_lot",
|
||||
@@ -4292,7 +4302,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "jmap_proto"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"ahash",
|
||||
"calcard",
|
||||
@@ -4502,9 +4512,9 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "lazy_static"
|
||||
version = "1.5.0"
|
||||
version = "1.5.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "bbd2bcb4c963f2ddae06a2efc7e9f3591312473c50c6685e1f298068316e66fe"
|
||||
checksum = "20870f649af7073d53e38067b2a84312175d56ea15217e1b15bc83506ec50afb"
|
||||
dependencies = [
|
||||
"spin 0.9.9",
|
||||
]
|
||||
@@ -4798,7 +4808,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "managesieve"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"common",
|
||||
"compact_str",
|
||||
@@ -4933,7 +4943,7 @@ checksum = "c797b9d6bb23aab2fc369c65f871be49214f5c759af65bde26ffaaa2b646b492"
|
||||
|
||||
[[package]]
|
||||
name = "migration"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"common",
|
||||
"email",
|
||||
@@ -5183,7 +5193,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "nlp"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"ahash",
|
||||
"hashify",
|
||||
@@ -5503,8 +5513,8 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "opentelemetry"
|
||||
version = "0.32.0"
|
||||
source = "git+https://github.com/stalwartlabs/opentelemetry-rust#80a14a3b6846f62f85506d68d2600c948fccc9d2"
|
||||
version = "0.33.0"
|
||||
source = "git+https://github.com/stalwartlabs/opentelemetry-rust#ae66e97b140f70e477ab710686aafce665cc2f8b"
|
||||
dependencies = [
|
||||
"futures-core",
|
||||
"futures-sink",
|
||||
@@ -5516,8 +5526,8 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "opentelemetry-http"
|
||||
version = "0.32.0"
|
||||
source = "git+https://github.com/stalwartlabs/opentelemetry-rust#80a14a3b6846f62f85506d68d2600c948fccc9d2"
|
||||
version = "0.33.0"
|
||||
source = "git+https://github.com/stalwartlabs/opentelemetry-rust#ae66e97b140f70e477ab710686aafce665cc2f8b"
|
||||
dependencies = [
|
||||
"async-trait",
|
||||
"bytes",
|
||||
@@ -5528,8 +5538,8 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "opentelemetry-otlp"
|
||||
version = "0.32.0"
|
||||
source = "git+https://github.com/stalwartlabs/opentelemetry-rust#80a14a3b6846f62f85506d68d2600c948fccc9d2"
|
||||
version = "0.33.0"
|
||||
source = "git+https://github.com/stalwartlabs/opentelemetry-rust#ae66e97b140f70e477ab710686aafce665cc2f8b"
|
||||
dependencies = [
|
||||
"http 1.5.0",
|
||||
"httpdate",
|
||||
@@ -5547,8 +5557,8 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "opentelemetry-proto"
|
||||
version = "0.32.0"
|
||||
source = "git+https://github.com/stalwartlabs/opentelemetry-rust#80a14a3b6846f62f85506d68d2600c948fccc9d2"
|
||||
version = "0.33.0"
|
||||
source = "git+https://github.com/stalwartlabs/opentelemetry-rust#ae66e97b140f70e477ab710686aafce665cc2f8b"
|
||||
dependencies = [
|
||||
"opentelemetry",
|
||||
"opentelemetry_sdk",
|
||||
@@ -5559,13 +5569,13 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "opentelemetry-semantic-conventions"
|
||||
version = "0.32.1"
|
||||
source = "git+https://github.com/stalwartlabs/opentelemetry-rust#80a14a3b6846f62f85506d68d2600c948fccc9d2"
|
||||
version = "0.33.0"
|
||||
source = "git+https://github.com/stalwartlabs/opentelemetry-rust#ae66e97b140f70e477ab710686aafce665cc2f8b"
|
||||
|
||||
[[package]]
|
||||
name = "opentelemetry_sdk"
|
||||
version = "0.32.1"
|
||||
source = "git+https://github.com/stalwartlabs/opentelemetry-rust#80a14a3b6846f62f85506d68d2600c948fccc9d2"
|
||||
version = "0.33.0"
|
||||
source = "git+https://github.com/stalwartlabs/opentelemetry-rust#ae66e97b140f70e477ab710686aafce665cc2f8b"
|
||||
dependencies = [
|
||||
"futures-channel",
|
||||
"futures-executor",
|
||||
@@ -6015,7 +6025,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "pop3"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"common",
|
||||
"directory",
|
||||
@@ -6385,9 +6395,9 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "quinn-proto"
|
||||
version = "0.11.18"
|
||||
version = "0.11.19"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "a9746dbde176634f4f2f1faf2404e30a31b2bc1e9cafb5329c95d8177a18c9fc"
|
||||
checksum = "0e750cca55fe4f0439a15d0bb529da9651e79993e8e72c61a899a36d462befbe"
|
||||
dependencies = [
|
||||
"aws-lc-rs",
|
||||
"bytes",
|
||||
@@ -6410,9 +6420,9 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "quinn-udp"
|
||||
version = "0.5.15"
|
||||
version = "0.5.16"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "35a133f956daabe89a61a685c2649f13d82d5aa4bd5d12d1277e1072a21c0694"
|
||||
checksum = "af66907df18639dcf4db56ca65490cabc4b27a97dbadd96f2926cca73298f016"
|
||||
dependencies = [
|
||||
"cfg_aliases",
|
||||
"libc",
|
||||
@@ -6835,7 +6845,7 @@ checksum = "d6f6ff9a378485b298a5286656da665ba74413d36db0979633275d2e708145d4"
|
||||
|
||||
[[package]]
|
||||
name = "registry"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"ahash",
|
||||
"hashify",
|
||||
@@ -7392,7 +7402,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "scim"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"ahash",
|
||||
"base64 0.23.1",
|
||||
@@ -7418,7 +7428,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "scim-proto"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"hashify",
|
||||
"serde",
|
||||
@@ -7672,9 +7682,9 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "serde_with"
|
||||
version = "3.23.0"
|
||||
version = "3.24.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "935177bb8c0cd8ca1a4e6d1a2ac8988bea69cab4f9d3a31311e012ad27868ea4"
|
||||
checksum = "df9adc193c780ef8f159aee8b61e2d5801aaa555e6eb0947fe45530ec506296f"
|
||||
dependencies = [
|
||||
"base64 0.23.1",
|
||||
"bs58",
|
||||
@@ -7693,9 +7703,9 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "serde_with_macros"
|
||||
version = "3.23.0"
|
||||
version = "3.24.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "1d607aa01a3cb0ad757d6fd216136910db3c97b102fe686585689615a02dbcdc"
|
||||
checksum = "3e17bbc68e28663bbbb90df47e058aa7eda4fb445b89fe70457bb94fbccf6e49"
|
||||
dependencies = [
|
||||
"darling 0.24.1",
|
||||
"proc-macro2",
|
||||
@@ -7753,7 +7763,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "services"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"aes-gcm 0.11.1",
|
||||
"aho-corasick",
|
||||
@@ -7762,11 +7772,13 @@ dependencies = [
|
||||
"common",
|
||||
"dns-update",
|
||||
"email",
|
||||
"futures",
|
||||
"groupware",
|
||||
"hkdf 0.13.0",
|
||||
"inbuxa-features",
|
||||
"jmap-tools",
|
||||
"jmap_proto",
|
||||
"mail-auth",
|
||||
"mail-builder 1.0.0",
|
||||
"mail-parser",
|
||||
"memory-stats",
|
||||
@@ -8066,7 +8078,7 @@ checksum = "f9395f0f0eee849a9b707b2f06bb92a6a422090e2123bb2ef8e87a0e61892a8e"
|
||||
|
||||
[[package]]
|
||||
name = "smtp"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"ahash",
|
||||
"base64 0.23.1",
|
||||
@@ -8105,9 +8117,9 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "smtp-proto"
|
||||
version = "0.2.4"
|
||||
version = "0.2.5"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "707104487221ff447b5b796b5049e5c09cf52ff9fc1c8abba4695b89ac4b0f37"
|
||||
checksum = "142a5a642c6bd7ffd7e1b525ad6a6e9921ccef992dba4663974f8519209a00c1"
|
||||
dependencies = [
|
||||
"memchr",
|
||||
"rkyv",
|
||||
@@ -8157,7 +8169,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "spam-filter"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"common",
|
||||
"compact_str",
|
||||
@@ -8277,7 +8289,7 @@ checksum = "a2eb9349b6444b326872e140eb1cf5e7c522154d69e7a0ffb0fb81c06b37543f"
|
||||
|
||||
[[package]]
|
||||
name = "store"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"ahash",
|
||||
"arc-swap",
|
||||
@@ -8537,7 +8549,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "tests"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"ahash",
|
||||
"aws-lc-rs",
|
||||
@@ -8559,7 +8571,7 @@ dependencies = [
|
||||
"form_urlencoded",
|
||||
"futures",
|
||||
"groupware",
|
||||
"http 0.16.24",
|
||||
"http 0.16.25",
|
||||
"http_proto",
|
||||
"hyper",
|
||||
"hyper-util",
|
||||
@@ -8816,9 +8828,9 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "tokio-rustls"
|
||||
version = "0.26.5"
|
||||
version = "0.26.6"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "b0c85f2c3ef0b1cd58b36682f4b17aaa995f0e5db534d85692b4903abce21f67"
|
||||
checksum = "c9cc2678c2cdd569ef8215e2afd7954ada2ae20b4fdd2c5fe6139a3b02d105db"
|
||||
dependencies = [
|
||||
"rustls",
|
||||
"tokio",
|
||||
@@ -9152,7 +9164,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "trc"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"ahash",
|
||||
"base64 0.23.1",
|
||||
@@ -9261,7 +9273,7 @@ checksum = "b6f5e870be6c3b371b77fe0ee0bafb859fa4964b4404c27de1d380043c4dda20"
|
||||
|
||||
[[package]]
|
||||
name = "types"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"blake3",
|
||||
"compact_str",
|
||||
@@ -9430,7 +9442,7 @@ checksum = "b6c140620e7ffbb22c2dee59cafe6084a59b5ffc27a8859a5f0d494b5d52b6be"
|
||||
|
||||
[[package]]
|
||||
name = "utils"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
dependencies = [
|
||||
"ahash",
|
||||
"arcstr",
|
||||
@@ -10115,9 +10127,9 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "xxhash-rust"
|
||||
version = "0.8.18"
|
||||
version = "0.8.19"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "aee1b19627c7c60102ab80d3a9cbe18de90bfe03bfa6c3715447681f0e8c8af6"
|
||||
checksum = "550a2b930b62486a393c52d5c3b84bff264b28aa437ed64694d31e93b1757af7"
|
||||
|
||||
[[package]]
|
||||
name = "yasna"
|
||||
@@ -10142,9 +10154,9 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "yoke-derive"
|
||||
version = "0.8.3"
|
||||
version = "0.8.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "33811428bee40dbceb6d545e95754741d17a6aef9a4849f0fd62e2ba4f412a78"
|
||||
checksum = "ec8ebde2db3681e8c9980cc27822030e68752690ddfa9473e739aeb4dbde6d71"
|
||||
dependencies = [
|
||||
"proc-macro2",
|
||||
"quote",
|
||||
|
||||
+1
-1
@@ -4,7 +4,7 @@
|
||||
# *****************
|
||||
# Base image for planner & builder
|
||||
# *****************
|
||||
FROM --platform=$BUILDPLATFORM rust:slim-trixie AS base
|
||||
FROM --platform=$BUILDPLATFORM rust:1.98.1-slim-trixie AS base
|
||||
|
||||
ENV DEBIAN_FRONTEND="noninteractive" \
|
||||
BINSTALL_DISABLE_TELEMETRY=true \
|
||||
|
||||
+2
-2
@@ -17,7 +17,7 @@ visible to everyone, including whoever would use it, before there is a fix.
|
||||
|
||||
Report it privately by email to:
|
||||
|
||||
**johnellisATlinuxDOTcom**
|
||||
**securityATcoffeylabsDOTorg**
|
||||
|
||||
Include as much as you can of:
|
||||
|
||||
@@ -36,7 +36,7 @@ to Stalwart Labs with credit to you, and you'll be told that has happened.
|
||||
This repository is the mail server. The web front ends have their own:
|
||||
|
||||
- [inbuxa-admin](https://git.coffeylabs.org/inbuxa/inbuxa-admin)
|
||||
- [ihasmail-inbuxa](https://git.coffeylabs.org/inbuxa/ihasmail-inbuxa)
|
||||
- [inbuxa-webmail](https://git.coffeylabs.org/inbuxa/inbuxa-webmail)
|
||||
|
||||
Upstream's own security documents are kept in `.github-upstream/` for
|
||||
reference. They describe Stalwart Labs' process, not this project's.
|
||||
@@ -1,6 +1,6 @@
|
||||
[package]
|
||||
name = "common"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
edition = "2024"
|
||||
build = "build.rs"
|
||||
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
@@ -445,6 +445,63 @@ impl Server {
|
||||
}
|
||||
}
|
||||
|
||||
/// MA-D0a: a message sent from an address that isn't the sender's own:
|
||||
/// a group's or a shared mailbox's. The message itself only says
|
||||
/// `From:` that address, so the audit log is where the person who sent
|
||||
/// it is named. A locked account's delegate's send is AL-9's record, not
|
||||
/// this one.
|
||||
pub async fn audit_send_as(
|
||||
&self,
|
||||
token: &AccessToken,
|
||||
submission_account_id: u32,
|
||||
submission_id: u32,
|
||||
address: &str,
|
||||
) {
|
||||
let Ok(Some(as_account_id)) = self.account_id_from_email(address, true).await else {
|
||||
return;
|
||||
};
|
||||
if as_account_id == token.account_id()
|
||||
|| token
|
||||
.delegation(as_account_id)
|
||||
.is_some_and(|delegation| delegation.kind.is_lock())
|
||||
{
|
||||
return;
|
||||
}
|
||||
let actor = self.audit_actor(token).await;
|
||||
let tenant_id = self
|
||||
.account(as_account_id)
|
||||
.await
|
||||
.ok()
|
||||
.and_then(|account| account.id_tenant);
|
||||
let details = if submission_account_id == as_account_id {
|
||||
format!("Sent as {address}")
|
||||
} else {
|
||||
format!(
|
||||
"Sent as {address}, from {}",
|
||||
self.audit_account_name(submission_account_id).await
|
||||
)
|
||||
};
|
||||
self.audit_note(Record {
|
||||
at: ms(),
|
||||
actor,
|
||||
via: token.origin().cloned(),
|
||||
remote_ip: None,
|
||||
action: Action::Create,
|
||||
target: Target {
|
||||
kind: "EmailSubmission".into(),
|
||||
id: Some(Id::from(submission_id).to_string()),
|
||||
name: Some(address.to_string()),
|
||||
account_id: Some(as_account_id),
|
||||
tenant_id,
|
||||
},
|
||||
changes: vec![],
|
||||
details: Some(details),
|
||||
reason: None,
|
||||
outcome: Outcome::success(),
|
||||
})
|
||||
.await;
|
||||
}
|
||||
|
||||
/// AU-7: removes entries past the retention period.
|
||||
pub async fn audit_purge(&self) -> trc::Result<usize> {
|
||||
let settings = log::settings(self.store()).await?;
|
||||
|
||||
@@ -36,6 +36,32 @@ use utils::map::bitmap::{Bitmap, BitmapItem};
|
||||
use xxhash_rust::xxh3;
|
||||
|
||||
impl Server {
|
||||
/// inbuxa: MA-C: whether people in `owner`'s tenant may share their mail
|
||||
/// (the server's switch, narrowed by the tenant's).
|
||||
pub async fn mail_sharing_allowed(&self, owner: u32) -> trc::Result<bool> {
|
||||
let tenant_id = self.account(owner).await.ok().and_then(|account| account.id_tenant);
|
||||
Ok(
|
||||
inbuxa_features::security::sharing_policy::effective_for(self.store(), tenant_id)
|
||||
.await
|
||||
.caused_by(trc::location!())?
|
||||
.mail_sharing,
|
||||
)
|
||||
}
|
||||
|
||||
/// inbuxa: MA-C: whether `owner`'s mail shares give access now. A locked
|
||||
/// account's or shared mailbox's grants are an administrator's and always
|
||||
/// do; anyone else's only while their tenant allows mail sharing.
|
||||
pub async fn mail_shares_honored(&self, owner: u32) -> trc::Result<bool> {
|
||||
if inbuxa_features::lock::get(self.store(), owner)
|
||||
.await
|
||||
.caused_by(trc::location!())?
|
||||
.is_some()
|
||||
{
|
||||
return Ok(true);
|
||||
}
|
||||
self.mail_sharing_allowed(owner).await
|
||||
}
|
||||
|
||||
async fn build_access_token(
|
||||
&self,
|
||||
account: Account,
|
||||
@@ -46,19 +72,22 @@ impl Server {
|
||||
// inbuxa: AL-2, AL-5: whether this account is locked, and which
|
||||
// locked accounts are handed to it. The token is their cache: every
|
||||
// change to a lock invalidates the tokens it touches.
|
||||
let locked = inbuxa_features::lock::get(self.store(), account_id)
|
||||
let lock_kind = inbuxa_features::lock::get(self.store(), account_id)
|
||||
.await
|
||||
.caused_by(trc::location!())?
|
||||
.is_some();
|
||||
.map(|lock| lock.kind);
|
||||
let locked = lock_kind.is_some();
|
||||
let shared_mailbox = lock_kind == Some(inbuxa_features::lock::Kind::SharedMailbox);
|
||||
let now_secs = now();
|
||||
let delegations: Box<[super::Delegation]> =
|
||||
inbuxa_features::lock::delegated_to(self.store(), account_id)
|
||||
.await
|
||||
.caused_by(trc::location!())?
|
||||
.into_iter()
|
||||
.filter(|(_, delegate)| delegate.is_current(now_secs))
|
||||
.map(|(locked_id, delegate)| super::Delegation {
|
||||
.filter(|(_, delegate, _)| delegate.is_current(now_secs))
|
||||
.map(|(locked_id, delegate, kind)| super::Delegation {
|
||||
account_id: locked_id,
|
||||
kind,
|
||||
access: delegate.access,
|
||||
send_as: delegate.send_as,
|
||||
until: delegate.until,
|
||||
@@ -97,6 +126,9 @@ impl Server {
|
||||
.map(|m| m.id() as u32)
|
||||
.collect::<TinyVec<[u32; 3]>>();
|
||||
let mut access_to: Vec<AccessTo> = Vec::new();
|
||||
// inbuxa: MA-C: whether an owner's mail shares are honored,
|
||||
// looked up once per owner
|
||||
let mut mail_shares_honored: Vec<(u32, bool)> = Vec::new();
|
||||
for grant_account_id in [account_id].into_iter().chain(member_of.iter().copied()) {
|
||||
for acl_item in self
|
||||
.store()
|
||||
@@ -117,6 +149,27 @@ impl Server {
|
||||
.caused_by(trc::location!()));
|
||||
}
|
||||
|
||||
// inbuxa: MA-C: a mail share from an account whose
|
||||
// tenant (or server) has mail sharing off gives
|
||||
// nothing while it is off. It stays stored, so it
|
||||
// comes back when sharing does. A lock's and a
|
||||
// shared mailbox's grants are an administrator's,
|
||||
// and always count.
|
||||
if collection == Collection::Mailbox {
|
||||
let owner = acl_item.to_account_id;
|
||||
let honored = match mail_shares_honored.iter().find(|(id, _)| *id == owner) {
|
||||
Some((_, honored)) => *honored,
|
||||
None => {
|
||||
let honored = self.mail_shares_honored(owner).await?;
|
||||
mail_shares_honored.push((owner, honored));
|
||||
honored
|
||||
}
|
||||
};
|
||||
if !honored {
|
||||
continue;
|
||||
}
|
||||
}
|
||||
|
||||
let mut collections: Bitmap<Collection> = Bitmap::new();
|
||||
if acl.contains(Acl::Read) {
|
||||
collections.insert(collection);
|
||||
@@ -247,6 +300,7 @@ impl Server {
|
||||
.map(ConcurrencyLimiter::new),
|
||||
obj_size: 0,
|
||||
locked,
|
||||
shared_mailbox,
|
||||
delegations: delegations.clone(),
|
||||
revision,
|
||||
revision_account,
|
||||
@@ -300,6 +354,7 @@ impl Server {
|
||||
.map(ConcurrencyLimiter::new),
|
||||
obj_size: 0,
|
||||
locked,
|
||||
shared_mailbox,
|
||||
delegations: delegations.clone(),
|
||||
revision,
|
||||
revision_account,
|
||||
@@ -553,6 +608,16 @@ impl AccessToken {
|
||||
|| self.inner.access_to.iter().any(|a| a.account_id == account_id)
|
||||
}
|
||||
|
||||
/// inbuxa: MA-D0: in the account only because it is a group this token
|
||||
/// belongs to. Such a member has the group's mailbox but may not share it
|
||||
/// on: who is in a group is an administrator's decision, and a share
|
||||
/// would let anyone in.
|
||||
pub fn is_group_member_only(&self, account_id: u32) -> bool {
|
||||
self.inner.account_id != account_id
|
||||
&& self.inner.member_of.contains(&account_id)
|
||||
&& !self.has_permission(Permission::Impersonate)
|
||||
}
|
||||
|
||||
pub fn is_account_id(&self, account_id: u32) -> bool {
|
||||
self.inner.account_id == account_id
|
||||
}
|
||||
@@ -648,6 +713,7 @@ impl AccessToken {
|
||||
credential_version: old_inner.credential_version,
|
||||
obj_size: old_inner.obj_size,
|
||||
locked: old_inner.locked,
|
||||
shared_mailbox: old_inner.shared_mailbox,
|
||||
delegations: old_inner.delegations.clone(),
|
||||
};
|
||||
|
||||
@@ -838,6 +904,18 @@ impl AccessToken {
|
||||
self.inner.locked
|
||||
}
|
||||
|
||||
/// inbuxa: MA-S: the account is a shared mailbox (a lock of that kind).
|
||||
pub fn is_shared_mailbox(&self) -> bool {
|
||||
self.inner.shared_mailbox
|
||||
}
|
||||
|
||||
/// inbuxa: MA-S: this account's delegation into `account_id` is to a
|
||||
/// shared mailbox, not a locked account.
|
||||
pub fn delegated_shared_mailbox(&self, account_id: u32) -> bool {
|
||||
self.delegation(account_id)
|
||||
.is_some_and(|d| d.kind == inbuxa_features::lock::Kind::SharedMailbox)
|
||||
}
|
||||
|
||||
/// inbuxa: AL-5: this account's delegation into a locked account, if it
|
||||
/// has one that hasn't ended.
|
||||
/// inbuxa: AL-6, AL-7: a delegate at organize or full, who may add to
|
||||
@@ -918,6 +996,7 @@ impl AccessToken {
|
||||
credential_version: Default::default(),
|
||||
obj_size: Default::default(),
|
||||
locked: false,
|
||||
shared_mailbox: false,
|
||||
delegations: Default::default(),
|
||||
}),
|
||||
}
|
||||
@@ -978,6 +1057,7 @@ impl AccessTokenInner {
|
||||
credential_version: Default::default(),
|
||||
obj_size: Default::default(),
|
||||
locked: false,
|
||||
shared_mailbox: false,
|
||||
delegations: Default::default(),
|
||||
}
|
||||
}
|
||||
|
||||
@@ -152,6 +152,8 @@ pub struct AccessTokenInner {
|
||||
pub(crate) obj_size: u64,
|
||||
// inbuxa: AL-2: the account is locked; it may not authenticate
|
||||
pub(crate) locked: bool,
|
||||
// inbuxa: MA-S: the lock is a shared mailbox
|
||||
pub(crate) shared_mailbox: bool,
|
||||
// inbuxa: AL-5: locked accounts handed to this one
|
||||
pub(crate) delegations: Box<[Delegation]>,
|
||||
}
|
||||
@@ -165,6 +167,8 @@ pub struct Delegation {
|
||||
pub send_as: bool,
|
||||
/// Seconds since the epoch.
|
||||
pub until: Option<u64>,
|
||||
/// MA-S: a locked account, or a shared mailbox.
|
||||
pub kind: inbuxa_features::lock::Kind,
|
||||
}
|
||||
|
||||
#[derive(Debug, Default, Hash, Clone)]
|
||||
|
||||
@@ -111,6 +111,9 @@ impl Server {
|
||||
Permission::SysLegalHoldCreate,
|
||||
Permission::SysLegalHoldUpdate,
|
||||
Permission::SysLegalHoldExport,
|
||||
// inbuxa: DL-20: the lists and the check are the server's
|
||||
Permission::SysDeliverabilityUpdate,
|
||||
Permission::SysDeliverabilityCheck,
|
||||
] {
|
||||
permissions.disabled.set(permission as usize);
|
||||
}
|
||||
@@ -304,6 +307,16 @@ impl Default for DefaultPermissions {
|
||||
default.superuser.push(permission);
|
||||
default.tenant.push(permission);
|
||||
}
|
||||
// inbuxa: deliverability spec, DL-20: a tenant administrator
|
||||
// reads its own domains' findings; the lists and the check
|
||||
// itself are the server's
|
||||
Permission::SysDeliverabilityGet => {
|
||||
default.superuser.push(permission);
|
||||
default.tenant.push(permission);
|
||||
}
|
||||
Permission::SysDeliverabilityUpdate | Permission::SysDeliverabilityCheck => {
|
||||
default.superuser.push(permission);
|
||||
}
|
||||
// inbuxa: DLP and mail flow rules, and held mail, are the
|
||||
// server's: never a tenant's (dlp-and-mail-flow-rules spec,
|
||||
// settled answer 3)
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -88,6 +88,8 @@ pub enum BroadcastEvent {
|
||||
QueueRefresh,
|
||||
// inbuxa: AL-3: end an account's open sessions on every node
|
||||
EndSessions(u32),
|
||||
// inbuxa: deliverability spec, DL-15: every node checks itself now
|
||||
DeliverabilityCheck,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Copy)]
|
||||
|
||||
@@ -225,7 +225,7 @@ pub struct Caches {
|
||||
pub dns_ipv6: CacheWithTtl<Box<str>, RecordSet<Ipv6Addr>>,
|
||||
pub dns_tlsa: CacheWithTtl<Box<str>, Arc<Tlsa>>,
|
||||
pub dns_mta_sts: CacheWithTtl<Box<str>, Arc<Policy>>,
|
||||
pub dns_rbl: CacheWithTtl<Box<str>, Option<Arc<IpResolver>>>,
|
||||
pub dns_rbl: CacheWithTtl<Box<str>, Option<Arc<[IpResolver]>>>,
|
||||
|
||||
pub negative_cache_ttl: Duration,
|
||||
}
|
||||
|
||||
@@ -227,10 +227,22 @@ impl WebApplicationManager {
|
||||
let cached = if force_refresh {
|
||||
None
|
||||
} else {
|
||||
server
|
||||
match server
|
||||
.blob_store()
|
||||
.get_blob(self.blob_key.as_slice(), 0..usize::MAX)
|
||||
.await?
|
||||
.await
|
||||
{
|
||||
Ok(cached) => cached,
|
||||
Err(err) => {
|
||||
trc::event!(
|
||||
Resource(trc::ResourceEvent::Error),
|
||||
Reason = err,
|
||||
Url = self.url.clone(),
|
||||
Details = "Failed to read cached application bundle, downloading it again"
|
||||
);
|
||||
None
|
||||
}
|
||||
}
|
||||
};
|
||||
let is_cached = cached.is_some();
|
||||
let bundle = match cached {
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
@@ -14,7 +14,7 @@
|
||||
//! application names another;
|
||||
//! - INBUXA Admin hosted elsewhere, as `inbuxa-admin`, when `INBUXA_ADMIN_URL`
|
||||
//! is set;
|
||||
//! - ihasmail-inbuxa, as the confidential client `ihasmail-inbuxa`, when
|
||||
//! - inbuxa-webmail, as the confidential client `ihasmail-inbuxa`, when
|
||||
//! `INBUXA_WEBMAIL_URL` and `INBUXA_WEBMAIL_CLIENT_SECRET` are set.
|
||||
//!
|
||||
//! inbuxa: the environment variables stand in for `x:FrontEnds` (C-4) until
|
||||
@@ -22,7 +22,7 @@
|
||||
//! it instead.
|
||||
//!
|
||||
//! A missing client is created. An existing one gains any redirect URI it
|
||||
//! lacks and, for ihasmail-inbuxa, the configured secret; nothing an operator
|
||||
//! lacks and, for inbuxa-webmail, the configured secret; nothing an operator
|
||||
//! added is removed.
|
||||
|
||||
use directory::core::secret::{hash_secret, verify_secret_hash};
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
@@ -31,8 +31,9 @@ use types::id::Id;
|
||||
/// Granted to the default administrator roles: "Explain this"
|
||||
/// (ai-explain spec, EX-4: superuser by default), the audit log, account
|
||||
/// locks and legal holds (audit-hold-lock spec, AU-9, AL-12, LH-13), and
|
||||
/// the data inventory (personal-data catalog spec), and accepting security
|
||||
/// to-do items (security to-do list spec).
|
||||
/// the data inventory (personal-data catalog spec), accepting security
|
||||
/// to-do items (security to-do list spec), and the deliverability check
|
||||
/// (deliverability spec).
|
||||
const ADMIN_GRANTS: &[Permission] = &[
|
||||
Permission::SysAiExplain,
|
||||
Permission::SysAuditGet,
|
||||
@@ -56,6 +57,9 @@ const ADMIN_GRANTS: &[Permission] = &[
|
||||
Permission::SysJournalGet,
|
||||
Permission::SysJournalUpdate,
|
||||
Permission::SysSecurityAccept,
|
||||
Permission::SysDeliverabilityGet,
|
||||
Permission::SysDeliverabilityUpdate,
|
||||
Permission::SysDeliverabilityCheck,
|
||||
];
|
||||
|
||||
/// Granted to the server-level Compliance Officer role once it exists:
|
||||
@@ -73,7 +77,8 @@ const OFFICER_GRANTS: &[Permission] = &[
|
||||
|
||||
/// Granted to the default tenant administrator roles: reading and exporting
|
||||
/// the tenant's audit log (AU-9), locking and delegating its accounts
|
||||
/// (AL-12), and the tenant's slice of the data inventory.
|
||||
/// (AL-12), the tenant's slice of the data inventory, and its own domains'
|
||||
/// deliverability findings (DL-20).
|
||||
const TENANT_GRANTS: &[Permission] = &[
|
||||
Permission::SysAuditGet,
|
||||
Permission::SysAuditExport,
|
||||
@@ -82,6 +87,7 @@ const TENANT_GRANTS: &[Permission] = &[
|
||||
Permission::SysAccountLockUpdate,
|
||||
Permission::SysAccountLockDestroy,
|
||||
Permission::SysComplianceGet,
|
||||
Permission::SysDeliverabilityGet,
|
||||
];
|
||||
|
||||
#[derive(Clone, Copy, PartialEq, Eq)]
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <hello@stalw.art>
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||
*
|
||||
|
||||
@@ -11,7 +11,7 @@ use quick_xml::Reader;
|
||||
use quick_xml::XmlVersion;
|
||||
use quick_xml::events::Event;
|
||||
use registry::schema::{enums::ServiceProtocol, structs::Service};
|
||||
use std::fmt::Write;
|
||||
use std::{borrow::Cow, fmt::Write};
|
||||
use utils::map::vec_map::VecMap;
|
||||
|
||||
impl Server {
|
||||
@@ -20,32 +20,78 @@ impl Server {
|
||||
body: Option<Vec<u8>>,
|
||||
) -> trc::Result<Resource<Vec<u8>>> {
|
||||
// Obtain parameters
|
||||
let emailaddress = parse_autodiscover_request(body.as_deref().unwrap_or_default())
|
||||
.map_err(|err| {
|
||||
let request =
|
||||
parse_autodiscover_request(body.as_deref().unwrap_or_default()).map_err(|err| {
|
||||
trc::ResourceEvent::BadParameters
|
||||
.into_err()
|
||||
.details("Failed to parse autodiscover request")
|
||||
.ctx(trc::Key::Reason, err)
|
||||
})?;
|
||||
// inbuxa: legacy-protocols LP-7, LP-14a
|
||||
let legacy_off = match emailaddress.rsplit_once('@') {
|
||||
let legacy_off = match request.email.rsplit_once('@') {
|
||||
Some((_, domain)) => self.legacy_off_for(domain).await?,
|
||||
None => self.legacy_off_for("").await?,
|
||||
};
|
||||
|
||||
Ok(Resource::new(
|
||||
"application/xml; charset=utf-8",
|
||||
build_autodiscover_response(
|
||||
&emailaddress,
|
||||
let response = match request.response_schema {
|
||||
ResponseSchema::Outlook => build_autodiscover_response(
|
||||
&request.email,
|
||||
&self.core.network.server_name,
|
||||
&self.core.network.info.services,
|
||||
|protocol| legacy_off.service(protocol),
|
||||
)
|
||||
.into_bytes(),
|
||||
))
|
||||
ResponseSchema::Unsupported => PROVIDER_NOT_AVAILABLE_RESPONSE.as_bytes().to_vec(),
|
||||
};
|
||||
|
||||
Ok(Resource::new("application/xml; charset=utf-8", response))
|
||||
}
|
||||
}
|
||||
|
||||
const OUTLOOK_RESPONSE_SCHEMA: &str =
|
||||
"http://schemas.microsoft.com/exchange/autodiscover/outlook/responseschema/2006a";
|
||||
|
||||
const PROVIDER_NOT_AVAILABLE_RESPONSE: &str = concat!(
|
||||
"<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n",
|
||||
"<Autodiscover xmlns=\"http://schemas.microsoft.com/exchange/autodiscover/responseschema/2006\">\n",
|
||||
"\t<Response>\n",
|
||||
"\t\t<Error>\n",
|
||||
"\t\t\t<ErrorCode>601</ErrorCode>\n",
|
||||
"\t\t\t<Message>Provider is not available</Message>\n",
|
||||
"\t\t\t<DebugData />\n",
|
||||
"\t\t</Error>\n",
|
||||
"\t</Response>\n",
|
||||
"</Autodiscover>\n",
|
||||
);
|
||||
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
enum ResponseSchema {
|
||||
Outlook,
|
||||
Unsupported,
|
||||
}
|
||||
|
||||
impl ResponseSchema {
|
||||
fn parse(value: &str) -> Self {
|
||||
if value.trim().eq_ignore_ascii_case(OUTLOOK_RESPONSE_SCHEMA) {
|
||||
ResponseSchema::Outlook
|
||||
} else {
|
||||
ResponseSchema::Unsupported
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#[derive(Debug, PartialEq, Eq)]
|
||||
struct AutodiscoverRequest {
|
||||
email: String,
|
||||
response_schema: ResponseSchema,
|
||||
}
|
||||
|
||||
#[derive(Clone, Copy)]
|
||||
enum RequestField {
|
||||
EmailAddress,
|
||||
ResponseSchema,
|
||||
}
|
||||
|
||||
fn build_autodiscover_response(
|
||||
emailaddress: &str,
|
||||
default_host: &str,
|
||||
@@ -124,7 +170,7 @@ fn build_autodiscover_response(
|
||||
config
|
||||
}
|
||||
|
||||
fn parse_autodiscover_request(bytes: &[u8]) -> Result<String, String> {
|
||||
fn parse_autodiscover_request(bytes: &[u8]) -> Result<AutodiscoverRequest, String> {
|
||||
if bytes.is_empty() {
|
||||
return Err("Empty request body".to_string());
|
||||
}
|
||||
@@ -132,8 +178,9 @@ fn parse_autodiscover_request(bytes: &[u8]) -> Result<String, String> {
|
||||
let mut reader = Reader::from_reader(bytes);
|
||||
reader.config_mut().trim_text(true);
|
||||
let mut buf = Vec::with_capacity(128);
|
||||
let mut value_buf = Vec::with_capacity(128);
|
||||
|
||||
'outer: for tag_name in ["Autodiscover", "Request", "EMailAddress"] {
|
||||
'outer: for tag_name in ["Autodiscover", "Request"] {
|
||||
loop {
|
||||
match reader.read_event_into(&mut buf) {
|
||||
Ok(Event::Start(e)) => {
|
||||
@@ -143,30 +190,6 @@ fn parse_autodiscover_request(bytes: &[u8]) -> Result<String, String> {
|
||||
.eq_ignore_ascii_case(found_tag_name.as_ref())
|
||||
{
|
||||
continue 'outer;
|
||||
} else if tag_name == "EMailAddress" {
|
||||
// Skip unsupported tags under Request, such as AcceptableResponseSchema
|
||||
let mut tag_count = 0;
|
||||
loop {
|
||||
match reader.read_event_into(&mut buf) {
|
||||
Ok(Event::End(_)) => {
|
||||
if tag_count == 0 {
|
||||
break;
|
||||
} else {
|
||||
tag_count -= 1;
|
||||
}
|
||||
}
|
||||
Ok(Event::Start(_)) => {
|
||||
tag_count += 1;
|
||||
}
|
||||
Ok(Event::Eof) => {
|
||||
return Err(format!(
|
||||
"Expected value, found unexpected EOF at position {}.",
|
||||
reader.buffer_position()
|
||||
));
|
||||
}
|
||||
_ => (),
|
||||
}
|
||||
}
|
||||
} else {
|
||||
return Err(format!(
|
||||
"Expected tag {}, found unexpected tag {} at position {}.",
|
||||
@@ -195,36 +218,170 @@ fn parse_autodiscover_request(bytes: &[u8]) -> Result<String, String> {
|
||||
}
|
||||
}
|
||||
|
||||
if let Ok(Event::Text(text)) = reader.read_event_into(&mut buf)
|
||||
&& let Ok(text) = text.xml_content(XmlVersion::Implicit1_0)
|
||||
&& text.contains('@')
|
||||
{
|
||||
return Ok(text.trim().to_lowercase());
|
||||
let mut email = None;
|
||||
let mut response_schema = ResponseSchema::Outlook;
|
||||
|
||||
loop {
|
||||
match reader.read_event_into(&mut buf) {
|
||||
Ok(Event::Start(e)) => {
|
||||
let local_name = e.local_name();
|
||||
let field = hashify::tiny_map_ignore_case!(local_name.as_ref(),
|
||||
b"EMailAddress" => RequestField::EmailAddress,
|
||||
b"AcceptableResponseSchema" => RequestField::ResponseSchema,
|
||||
);
|
||||
|
||||
let value = match reader.read_event_into(&mut value_buf) {
|
||||
Ok(Event::End(_)) => None,
|
||||
Ok(event) => {
|
||||
let value = match event {
|
||||
Event::Text(text) => text
|
||||
.xml_content(XmlVersion::Implicit1_0)
|
||||
.ok()
|
||||
.map(Cow::into_owned),
|
||||
_ => None,
|
||||
};
|
||||
reader
|
||||
.read_to_end_into(e.name(), &mut value_buf)
|
||||
.map_err(|err| {
|
||||
format!("Error at position {}: {:?}", reader.buffer_position(), err)
|
||||
})?;
|
||||
value
|
||||
}
|
||||
Err(err) => {
|
||||
return Err(format!(
|
||||
"Error at position {}: {:?}",
|
||||
reader.buffer_position(),
|
||||
err
|
||||
));
|
||||
}
|
||||
};
|
||||
|
||||
match (field, value) {
|
||||
(Some(RequestField::EmailAddress), Some(value)) => {
|
||||
email = Some(value);
|
||||
}
|
||||
(Some(RequestField::ResponseSchema), Some(value)) => {
|
||||
response_schema = ResponseSchema::parse(&value);
|
||||
}
|
||||
_ => (),
|
||||
}
|
||||
}
|
||||
Ok(Event::End(_) | Event::Eof) => break,
|
||||
Ok(_) => (),
|
||||
Err(e) => {
|
||||
return Err(format!(
|
||||
"Error at position {}: {:?}",
|
||||
reader.buffer_position(),
|
||||
e
|
||||
));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Err(format!(
|
||||
"Expected email address, found unexpected value at position {}.",
|
||||
reader.buffer_position()
|
||||
))
|
||||
match email {
|
||||
Some(email) if email.contains('@') => Ok(AutodiscoverRequest {
|
||||
email: email.trim().to_lowercase(),
|
||||
response_schema,
|
||||
}),
|
||||
_ => Err(format!(
|
||||
"Expected email address, found unexpected value at position {}.",
|
||||
reader.buffer_position()
|
||||
)),
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::{AutodiscoverRequest, ResponseSchema, parse_autodiscover_request};
|
||||
|
||||
#[test]
|
||||
fn parse_autodiscover() {
|
||||
let r = r#"<?xml version="1.0" encoding="utf-8"?>
|
||||
const OUTLOOK: &str =
|
||||
"http://schemas.microsoft.com/exchange/autodiscover/outlook/responseschema/2006a";
|
||||
const MOBILESYNC: &str =
|
||||
"http://schemas.microsoft.com/exchange/autodiscover/mobilesync/responseschema/2006";
|
||||
|
||||
for (request, expected) in [
|
||||
(
|
||||
format!(
|
||||
r#"<?xml version="1.0" encoding="utf-8"?>
|
||||
<Autodiscover xmlns="http://schemas.microsoft.com/exchange/autodiscover/outlook/requestschema/2006">
|
||||
<Request>
|
||||
<EMailAddress>email@example.com</EMailAddress>
|
||||
<AcceptableResponseSchema>http://schemas.microsoft.com/exchange/autodiscover/outlook/responseschema/2006a</AcceptableResponseSchema>
|
||||
<EMailAddress>Email@Example.com</EMailAddress>
|
||||
<AcceptableResponseSchema>{OUTLOOK}</AcceptableResponseSchema>
|
||||
</Request>
|
||||
</Autodiscover>"#;
|
||||
</Autodiscover>"#
|
||||
),
|
||||
ResponseSchema::Outlook,
|
||||
),
|
||||
(
|
||||
format!(
|
||||
r#"<Autodiscover xmlns="http://schemas.microsoft.com/exchange/autodiscover/outlook/requestschema/2006">
|
||||
<Request>
|
||||
<AcceptableResponseSchema>{OUTLOOK}</AcceptableResponseSchema>
|
||||
<EMailAddress>email@example.com</EMailAddress>
|
||||
</Request>
|
||||
</Autodiscover>"#
|
||||
),
|
||||
ResponseSchema::Outlook,
|
||||
),
|
||||
(
|
||||
r#"<Autodiscover>
|
||||
<Request>
|
||||
<EMailAddress>email@example.com</EMailAddress>
|
||||
</Request>
|
||||
</Autodiscover>"#
|
||||
.to_string(),
|
||||
ResponseSchema::Outlook,
|
||||
),
|
||||
(
|
||||
format!(
|
||||
r#"<?xml version="1.0" encoding="utf-8"?>
|
||||
<Autodiscover xmlns="http://schemas.microsoft.com/exchange/autodiscover/mobilesync/requestschema/2006">
|
||||
<Request>
|
||||
<EMailAddress>email@example.com</EMailAddress>
|
||||
<AcceptableResponseSchema>{MOBILESYNC}</AcceptableResponseSchema>
|
||||
</Request>
|
||||
</Autodiscover>"#
|
||||
),
|
||||
ResponseSchema::Unsupported,
|
||||
),
|
||||
(
|
||||
format!(
|
||||
r#"<Autodiscover>
|
||||
<Request>
|
||||
<LegacyDN>/o=Example/ou=Users/cn=email</LegacyDN>
|
||||
<Unknown><Nested>value</Nested><Empty/></Unknown>
|
||||
<AcceptableResponseSchema>{MOBILESYNC}</AcceptableResponseSchema>
|
||||
<EMailAddress>email@example.com</EMailAddress>
|
||||
</Request>
|
||||
</Autodiscover>"#
|
||||
),
|
||||
ResponseSchema::Unsupported,
|
||||
),
|
||||
] {
|
||||
assert_eq!(
|
||||
parse_autodiscover_request(request.as_bytes()).expect("valid request"),
|
||||
AutodiscoverRequest {
|
||||
email: "[email protected]".to_string(),
|
||||
response_schema: expected,
|
||||
},
|
||||
"{request}"
|
||||
);
|
||||
}
|
||||
|
||||
assert_eq!(
|
||||
super::parse_autodiscover_request(r.as_bytes()).unwrap(),
|
||||
"[email protected]"
|
||||
);
|
||||
for request in [
|
||||
"",
|
||||
"<Autodiscover><Request></Request></Autodiscover>",
|
||||
"<Autodiscover><Request><EMailAddress>no-domain</EMailAddress></Request></Autodiscover>",
|
||||
"<Autodiscover><Request><EMailAddress>[email protected]</Request></Autodiscover>",
|
||||
"<Request><EMailAddress>[email protected]</EMailAddress></Request>",
|
||||
] {
|
||||
assert!(
|
||||
parse_autodiscover_request(request.as_bytes()).is_err(),
|
||||
"{request}"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
[package]
|
||||
name = "coordinator"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
edition = "2024"
|
||||
|
||||
[dependencies]
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
[package]
|
||||
name = "dav-proto"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
edition = "2024"
|
||||
|
||||
[dependencies]
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
[package]
|
||||
name = "dav"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
edition = "2024"
|
||||
|
||||
[dependencies]
|
||||
|
||||
@@ -133,6 +133,10 @@ impl DavAclHandler for Server {
|
||||
{
|
||||
return Err(DavError::Code(StatusCode::FORBIDDEN));
|
||||
}
|
||||
// inbuxa: MA-D0: a group's members don't share what it owns on.
|
||||
if access_token.is_group_member_only(account_id) {
|
||||
return Err(DavError::Code(StatusCode::FORBIDDEN));
|
||||
}
|
||||
|
||||
// Validate ACEs
|
||||
let grants = self
|
||||
@@ -565,7 +569,13 @@ impl Privileges for AccessToken {
|
||||
grants: &ArchivedVec<ArchivedAclGrant>,
|
||||
is_calendar: bool,
|
||||
) -> Vec<Privilege> {
|
||||
if self.is_member(account_id) {
|
||||
if self.is_group_member_only(account_id) {
|
||||
// inbuxa: MA-D0: everything but sharing it on.
|
||||
Privilege::all(is_calendar)
|
||||
.into_iter()
|
||||
.filter(|privilege| !matches!(privilege, Privilege::All | Privilege::WriteAcl))
|
||||
.collect()
|
||||
} else if self.is_member(account_id) {
|
||||
Privilege::all(is_calendar)
|
||||
} else {
|
||||
current_user_privilege_set(grants.effective_acl(self))
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
[package]
|
||||
name = "directory"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
edition = "2024"
|
||||
|
||||
[dependencies]
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
[package]
|
||||
name = "email"
|
||||
version = "0.16.24"
|
||||
version = "0.16.25"
|
||||
edition = "2024"
|
||||
|
||||
[dependencies]
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -20,7 +20,7 @@ use groupware::{
|
||||
scheduling::{ItipError, ItipMessages},
|
||||
};
|
||||
use mail_parser::{
|
||||
DateTime, Header, HeaderName, HeaderValue, Message, MessageParser, MimeHeaders, PartType,
|
||||
Header, HeaderName, HeaderValue, Message, MessageParser, MimeHeaders, PartType,
|
||||
parsers::fields::thread::thread_name,
|
||||
};
|
||||
use registry::{
|
||||
@@ -924,11 +924,7 @@ impl EmailIngest for Server {
|
||||
span_id: u64,
|
||||
) {
|
||||
if let Some(config) = &self.core.spam.classifier {
|
||||
let mut dt = DateTime::from_timestamp(now() as i64);
|
||||
dt.hour = 0;
|
||||
dt.minute = 0;
|
||||
dt.second = 0;
|
||||
let until = dt.to_timestamp() as u64 + config.hold_samples_for;
|
||||
let until = now() + config.hold_samples_for;
|
||||
|
||||
let sample = SpamTrainingSample {
|
||||
account_id: Some(Id::from(account_id)),
|
||||
|
||||
@@ -290,7 +290,11 @@ impl SieveScriptIngest for Server {
|
||||
// inbuxa: AL-4: a locked account answers no sender, so a
|
||||
// rejection is kept instead; sieve has already cleared
|
||||
// the implicit keep, so it is filed here
|
||||
Event::Reject { .. } if access_token.is_locked() => {
|
||||
// A shared mailbox (MA-S) is a role address and answers
|
||||
// as one: its Sieve script runs as written
|
||||
Event::Reject { .. }
|
||||
if access_token.is_locked() && !access_token.is_shared_mailbox() =>
|
||||
{
|
||||
if let Some(message) = messages.get_mut(0)
|
||||
&& !message.file_into.contains(&INBOX_ID)
|
||||
{
|
||||
@@ -403,7 +407,11 @@ impl SieveScriptIngest for Server {
|
||||
// inbuxa: AL-4: a locked account sends nothing on its
|
||||
// own: no redirect, vacation reply or notification. An
|
||||
// unsent redirect leaves the message to be kept.
|
||||
Event::SendMessage { .. } if access_token.is_locked() => {
|
||||
// A shared mailbox's acknowledgements and redirects go
|
||||
// out (MA-S).
|
||||
Event::SendMessage { .. }
|
||||
if access_token.is_locked() && !access_token.is_shared_mailbox() =>
|
||||
{
|
||||
trc::event!(
|
||||
Sieve(SieveEvent::ActionReject),
|
||||
Details = "Account is locked: nothing is sent",
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -0,0 +1,282 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
//! The blocklists a node asks about itself (deliverability spec, DL-6), and
|
||||
//! how to read each one's answer.
|
||||
//!
|
||||
//! A list answers with an address in 127.0.0.0/8. Each list says which of
|
||||
//! those mean "listed" and which mean "I won't answer you": Spamhaus, for
|
||||
//! one, answers `127.255.255.254` to a query that came through a public
|
||||
//! resolver. A refusal is never read as a listing (DL-4).
|
||||
|
||||
use std::net::{IpAddr, Ipv4Addr};
|
||||
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub enum Scope {
|
||||
/// Looked up by the reversed address: `2.0.0.127.zen.spamhaus.org`.
|
||||
Ip,
|
||||
/// Looked up by name: `example.org.dbl.spamhaus.org`.
|
||||
Domain,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Copy)]
|
||||
pub struct BlockList {
|
||||
/// What the page and the settings call it.
|
||||
pub name: &'static str,
|
||||
pub zone: &'static str,
|
||||
pub scope: Scope,
|
||||
/// Where an administrator looks the address up and asks for removal.
|
||||
pub lookup: &'static str,
|
||||
/// Something the page says beside the list.
|
||||
pub note: Option<&'static str>,
|
||||
read: fn(Ipv4Addr) -> Answer,
|
||||
}
|
||||
|
||||
/// What a list's answer means.
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub enum Answer {
|
||||
Listed(&'static str),
|
||||
/// The list won't answer this resolver, or not now.
|
||||
Refused(&'static str),
|
||||
/// A code the list doesn't define: neither listed nor clean.
|
||||
Unknown,
|
||||
}
|
||||
|
||||
impl BlockList {
|
||||
pub fn read(&self, answer: Ipv4Addr) -> Answer {
|
||||
(self.read)(answer)
|
||||
}
|
||||
|
||||
/// The name to look up for `subject`, or None when the subject doesn't
|
||||
/// suit the list (a domain on an IP list, or an IPv6 address: none of
|
||||
/// these lists publish IPv6 zones worth asking).
|
||||
pub fn query(&self, subject: &Subject<'_>) -> Option<String> {
|
||||
match (self.scope, subject) {
|
||||
(Scope::Ip, Subject::Ip(IpAddr::V4(ip))) => {
|
||||
let [a, b, c, d] = ip.octets();
|
||||
Some(format!("{d}.{c}.{b}.{a}.{}.", self.zone))
|
||||
}
|
||||
(Scope::Domain, Subject::Domain(domain)) => {
|
||||
Some(format!("{}.{}.", domain.trim_end_matches('.'), self.zone))
|
||||
}
|
||||
_ => None,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
pub enum Subject<'x> {
|
||||
Ip(IpAddr),
|
||||
Domain(&'x str),
|
||||
}
|
||||
|
||||
/// Spamhaus' error codes, the same on every Spamhaus zone.
|
||||
fn spamhaus_refusal(ip: Ipv4Addr) -> Option<Answer> {
|
||||
match ip.octets() {
|
||||
[127, 255, 255, 252] => Some(Answer::Refused("The query was malformed")),
|
||||
[127, 255, 255, 254] => Some(Answer::Refused(
|
||||
"Spamhaus doesn't answer public resolvers; use the server's own",
|
||||
)),
|
||||
[127, 255, 255, 255] => Some(Answer::Refused("Too many queries from this resolver")),
|
||||
_ => None,
|
||||
}
|
||||
}
|
||||
|
||||
fn zen(ip: Ipv4Addr) -> Answer {
|
||||
if let Some(refused) = spamhaus_refusal(ip) {
|
||||
return refused;
|
||||
}
|
||||
match ip.octets() {
|
||||
[127, 0, 0, 2] => Answer::Listed("SBL: a known spam source"),
|
||||
[127, 0, 0, 3] => Answer::Listed("CSS: sent spam recently"),
|
||||
[127, 0, 0, 4..=7] => Answer::Listed("XBL: a compromised or infected host"),
|
||||
[127, 0, 0, 9] => Answer::Listed("DROP: a hijacked or criminal network"),
|
||||
[127, 0, 0, 10 | 11] => {
|
||||
Answer::Listed("PBL: an address that isn't meant to send mail directly")
|
||||
}
|
||||
_ => Answer::Unknown,
|
||||
}
|
||||
}
|
||||
|
||||
fn dbl(ip: Ipv4Addr) -> Answer {
|
||||
if let Some(refused) = spamhaus_refusal(ip) {
|
||||
return refused;
|
||||
}
|
||||
match ip.octets() {
|
||||
[127, 0, 1, 2] => Answer::Listed("A spam domain"),
|
||||
[127, 0, 1, 4] => Answer::Listed("A phishing domain"),
|
||||
[127, 0, 1, 5] => Answer::Listed("A malware domain"),
|
||||
[127, 0, 1, 6] => Answer::Listed("A botnet controller"),
|
||||
[127, 0, 1, 102..=106] => Answer::Listed("A legitimate domain being abused"),
|
||||
[127, 0, 1, 255] => Answer::Refused("The query was malformed"),
|
||||
_ => Answer::Unknown,
|
||||
}
|
||||
}
|
||||
|
||||
/// Most lists answer 127.0.0.2 for "listed" and define nothing else.
|
||||
fn just_two(ip: Ipv4Addr) -> Answer {
|
||||
match ip.octets() {
|
||||
[127, 0, 0, 2] => Answer::Listed("Listed"),
|
||||
_ => Answer::Unknown,
|
||||
}
|
||||
}
|
||||
|
||||
fn surbl(ip: Ipv4Addr) -> Answer {
|
||||
match ip.octets() {
|
||||
[127, 0, 0, 1] => Answer::Refused("SURBL doesn't answer this resolver"),
|
||||
[127, 0, 0, bits] if bits & (8 | 16 | 64 | 128) != 0 => {
|
||||
Answer::Listed("Seen in phishing, malware, abuse or cracked sites")
|
||||
}
|
||||
_ => Answer::Unknown,
|
||||
}
|
||||
}
|
||||
|
||||
fn uribl(ip: Ipv4Addr) -> Answer {
|
||||
match ip.octets() {
|
||||
[127, 0, 0, 1] => Answer::Refused("URIBL doesn't answer public resolvers"),
|
||||
[127, 0, 0, bits] if bits & (2 | 8) != 0 => Answer::Listed("Seen in spam"),
|
||||
[127, 0, 0, bits] if bits & 4 != 0 => {
|
||||
Answer::Listed("Grey: seen in bulk mail some people don't want")
|
||||
}
|
||||
_ => Answer::Unknown,
|
||||
}
|
||||
}
|
||||
|
||||
pub const LISTS: &[BlockList] = &[
|
||||
BlockList {
|
||||
name: "Spamhaus ZEN",
|
||||
zone: "zen.spamhaus.org",
|
||||
scope: Scope::Ip,
|
||||
lookup: "https://check.spamhaus.org/",
|
||||
note: None,
|
||||
read: zen,
|
||||
},
|
||||
BlockList {
|
||||
name: "SpamCop",
|
||||
zone: "bl.spamcop.net",
|
||||
scope: Scope::Ip,
|
||||
lookup: "https://www.spamcop.net/bl.shtml",
|
||||
note: None,
|
||||
read: just_two,
|
||||
},
|
||||
BlockList {
|
||||
name: "Barracuda",
|
||||
zone: "b.barracudacentral.org",
|
||||
scope: Scope::Ip,
|
||||
lookup: "https://www.barracudacentral.org/lookups",
|
||||
note: Some(
|
||||
"Barracuda answers only resolvers whose address is registered with it (free, at barracudacentral.org/rbl). Until then its lookups can't be checked.",
|
||||
),
|
||||
read: just_two,
|
||||
},
|
||||
BlockList {
|
||||
name: "UCEPROTECT level 1",
|
||||
zone: "dnsbl-1.uceprotect.net",
|
||||
scope: Scope::Ip,
|
||||
lookup: "https://www.uceprotect.net/en/rblcheck.php",
|
||||
note: None,
|
||||
read: just_two,
|
||||
},
|
||||
BlockList {
|
||||
name: "Mailspike",
|
||||
zone: "bl.mailspike.net",
|
||||
scope: Scope::Ip,
|
||||
lookup: "https://mailspike.org/iplookup.html",
|
||||
note: None,
|
||||
read: just_two,
|
||||
},
|
||||
BlockList {
|
||||
name: "PSBL",
|
||||
zone: "psbl.surriel.com",
|
||||
scope: Scope::Ip,
|
||||
lookup: "https://psbl.org/",
|
||||
note: None,
|
||||
read: just_two,
|
||||
},
|
||||
BlockList {
|
||||
name: "Spamhaus DBL",
|
||||
zone: "dbl.spamhaus.org",
|
||||
scope: Scope::Domain,
|
||||
lookup: "https://check.spamhaus.org/",
|
||||
note: None,
|
||||
read: dbl,
|
||||
},
|
||||
BlockList {
|
||||
name: "SURBL",
|
||||
zone: "multi.surbl.org",
|
||||
scope: Scope::Domain,
|
||||
lookup: "https://surbl.org/surbl-analysis",
|
||||
note: None,
|
||||
read: surbl,
|
||||
},
|
||||
BlockList {
|
||||
name: "URIBL",
|
||||
zone: "multi.uribl.com",
|
||||
scope: Scope::Domain,
|
||||
lookup: "https://admin.uribl.com/",
|
||||
note: None,
|
||||
read: uribl,
|
||||
},
|
||||
];
|
||||
|
||||
pub fn by_name(name: &str) -> Option<&'static BlockList> {
|
||||
LISTS.iter().find(|list| list.name == name)
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
fn ip(s: &str) -> Ipv4Addr {
|
||||
s.parse().unwrap()
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn a_refusal_is_not_a_listing() {
|
||||
let zen = by_name("Spamhaus ZEN").unwrap();
|
||||
assert!(matches!(
|
||||
zen.read(ip("127.255.255.254")),
|
||||
Answer::Refused(_)
|
||||
));
|
||||
assert!(matches!(zen.read(ip("127.0.0.2")), Answer::Listed(_)));
|
||||
assert!(matches!(zen.read(ip("127.0.0.10")), Answer::Listed(_)));
|
||||
assert_eq!(zen.read(ip("127.0.0.200")), Answer::Unknown);
|
||||
|
||||
let uribl = by_name("URIBL").unwrap();
|
||||
assert!(matches!(uribl.read(ip("127.0.0.1")), Answer::Refused(_)));
|
||||
assert!(matches!(uribl.read(ip("127.0.0.2")), Answer::Listed(_)));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn queries_are_built_per_scope() {
|
||||
let zen = by_name("Spamhaus ZEN").unwrap();
|
||||
let dbl = by_name("Spamhaus DBL").unwrap();
|
||||
let v4 = Subject::Ip("192.0.2.10".parse().unwrap());
|
||||
let v6 = Subject::Ip("2001:db8::1".parse().unwrap());
|
||||
let domain = Subject::Domain("example.org");
|
||||
assert_eq!(
|
||||
zen.query(&v4).as_deref(),
|
||||
Some("10.2.0.192.zen.spamhaus.org.")
|
||||
);
|
||||
assert_eq!(zen.query(&v6), None);
|
||||
assert_eq!(zen.query(&domain), None);
|
||||
assert_eq!(
|
||||
dbl.query(&domain).as_deref(),
|
||||
Some("example.org.dbl.spamhaus.org.")
|
||||
);
|
||||
assert_eq!(dbl.query(&v4), None);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn names_are_unique() {
|
||||
for (i, a) in LISTS.iter().enumerate() {
|
||||
assert!(
|
||||
LISTS[i + 1..].iter().all(|b| b.name != a.name),
|
||||
"{}",
|
||||
a.name
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,410 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
//! The deliverability check (deliverability spec): what other mail servers
|
||||
//! see when this one sends. Not a rebuild of anything upstream ships.
|
||||
//!
|
||||
//! Every node that sends mail checks itself, because only it knows which
|
||||
//! address it leaves from, and keeps one report. The report holds facts: an
|
||||
//! address's reverse DNS, what each blocklist answered, what SPF said for
|
||||
//! each address, whether a DKIM key in DNS matches the one signing. The
|
||||
//! console grades them, so its wording can change without a server release.
|
||||
//!
|
||||
//! Kept in the fork's subspace (`store::SUBSPACE_INBUXA`). Every key starts
|
||||
//! with `D`, then one byte for the kind:
|
||||
//!
|
||||
//! - `r` + node id (u64): that node's last report, as JSON.
|
||||
//! - `s`: the settings, as JSON.
|
||||
//!
|
||||
//! Numbers are big-endian.
|
||||
|
||||
pub mod lists;
|
||||
|
||||
use serde::{Deserialize as SerdeDeserialize, Serialize as SerdeSerialize};
|
||||
use store::{
|
||||
Deserialize, IterateParams, SUBSPACE_INBUXA, Serialize, Store, ValueKey,
|
||||
write::{AnyClass, BatchBuilder, ValueClass},
|
||||
};
|
||||
use trc::AddContext;
|
||||
|
||||
const FEATURE: u8 = b'D';
|
||||
const KIND_REPORT: u8 = b'r';
|
||||
const KIND_SETTINGS: u8 = b's';
|
||||
|
||||
/// DL-15: **Check now** runs a node again only this long after its last run.
|
||||
pub const MIN_INTERVAL_SECS: u64 = 600;
|
||||
|
||||
#[derive(Debug, Clone, Default, PartialEq, SerdeSerialize, SerdeDeserialize)]
|
||||
#[serde(rename_all = "camelCase", default)]
|
||||
pub struct Report {
|
||||
/// The node's cluster id, as metric samples carry it.
|
||||
pub node_id: u64,
|
||||
pub hostname: String,
|
||||
/// Seconds since the epoch.
|
||||
pub checked_at: u64,
|
||||
pub addresses: Vec<Address>,
|
||||
pub domains: Vec<DomainReport>,
|
||||
pub certificates: Vec<Certificate>,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Default, PartialEq, SerdeSerialize, SerdeDeserialize)]
|
||||
#[serde(rename_all = "camelCase", default)]
|
||||
pub struct Address {
|
||||
pub ip: String,
|
||||
/// DL-2: how the node came by the address.
|
||||
pub source: AddressSource,
|
||||
/// The connection strategy that sends from it.
|
||||
pub strategy: String,
|
||||
/// The name the node greets with from this address.
|
||||
pub ehlo: String,
|
||||
/// The PTR names, empty when there's none.
|
||||
pub ptr: Vec<String>,
|
||||
/// Some PTR name resolves back to the address.
|
||||
pub forward_confirmed: bool,
|
||||
/// The forward-confirmed name is the EHLO name.
|
||||
pub ehlo_matches: bool,
|
||||
/// Set when the reverse lookup itself failed, rather than found nothing.
|
||||
pub ptr_error: Option<String>,
|
||||
pub listings: Vec<Listing>,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Copy, Default, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
|
||||
#[serde(rename_all = "camelCase")]
|
||||
pub enum AddressSource {
|
||||
/// Set in the connection strategy's source addresses.
|
||||
#[default]
|
||||
Configured,
|
||||
/// What the EHLO name resolves to.
|
||||
Ehlo,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Default, PartialEq, SerdeSerialize, SerdeDeserialize)]
|
||||
#[serde(rename_all = "camelCase", default)]
|
||||
pub struct Listing {
|
||||
/// The list's name, as in [`lists::LISTS`].
|
||||
pub list: String,
|
||||
pub state: ListingState,
|
||||
/// The address the list answered, when it answered one.
|
||||
pub code: Option<String>,
|
||||
/// What the list says the answer means.
|
||||
pub meaning: Option<String>,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Copy, Default, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
|
||||
#[serde(rename_all = "camelCase")]
|
||||
pub enum ListingState {
|
||||
#[default]
|
||||
Clean,
|
||||
Listed,
|
||||
/// The list wouldn't answer, or the lookup failed: neither listed nor clean.
|
||||
Refused,
|
||||
Error,
|
||||
/// Switched off in the settings, so not asked.
|
||||
Off,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Default, PartialEq, SerdeSerialize, SerdeDeserialize)]
|
||||
#[serde(rename_all = "camelCase", default)]
|
||||
pub struct DomainReport {
|
||||
pub domain: String,
|
||||
/// DL-20: a tenant administrator sees only their tenant's domains.
|
||||
pub tenant_id: Option<u32>,
|
||||
/// DL-7: what SPF says for each of the node's addresses.
|
||||
pub spf: Vec<SpfResult>,
|
||||
/// DL-8: each DKIM key the domain signs with.
|
||||
pub dkim: Vec<DkimKey>,
|
||||
/// DL-9: the DMARC record, if there's one.
|
||||
pub dmarc: Option<Dmarc>,
|
||||
/// DL-10.
|
||||
pub mta_sts: MtaSts,
|
||||
/// DL-11: there's a `_smtp._tls` record.
|
||||
pub tls_rpt: bool,
|
||||
/// DL-12.
|
||||
pub listings: Vec<Listing>,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Default, PartialEq, SerdeSerialize, SerdeDeserialize)]
|
||||
#[serde(rename_all = "camelCase", default)]
|
||||
pub struct SpfResult {
|
||||
pub ip: String,
|
||||
/// `pass`, `fail`, `softFail`, `neutral`, `none`, `tempError` or `permError`.
|
||||
pub result: String,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Default, PartialEq, SerdeSerialize, SerdeDeserialize)]
|
||||
#[serde(rename_all = "camelCase", default)]
|
||||
pub struct DkimKey {
|
||||
pub selector: String,
|
||||
pub state: DkimState,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Copy, Default, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
|
||||
#[serde(rename_all = "camelCase")]
|
||||
pub enum DkimState {
|
||||
#[default]
|
||||
Matches,
|
||||
/// Nothing published at `<selector>._domainkey.<domain>`.
|
||||
Missing,
|
||||
/// Published, but a different key.
|
||||
Different,
|
||||
/// The lookup failed.
|
||||
Error,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Default, PartialEq, SerdeSerialize, SerdeDeserialize)]
|
||||
#[serde(rename_all = "camelCase", default)]
|
||||
pub struct Dmarc {
|
||||
/// `none`, `quarantine` or `reject`.
|
||||
pub policy: String,
|
||||
/// DKIM alignment: `relaxed` or `strict`.
|
||||
pub adkim: String,
|
||||
/// SPF alignment: `relaxed` or `strict`.
|
||||
pub aspf: String,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Default, PartialEq, SerdeSerialize, SerdeDeserialize)]
|
||||
#[serde(rename_all = "camelCase", default)]
|
||||
pub struct MtaSts {
|
||||
/// The `_mta-sts` record's id; None when there's no record.
|
||||
pub record_id: Option<String>,
|
||||
/// The policy was fetched and parsed. False with a record means the
|
||||
/// fetch or the parse failed, and `error` says why.
|
||||
pub fetched: bool,
|
||||
pub error: Option<String>,
|
||||
/// `enforce`, `testing` or `none`.
|
||||
pub mode: Option<String>,
|
||||
pub max_age: Option<u64>,
|
||||
/// The domain's MX names no `mx:` line matches.
|
||||
pub mx_not_covered: Vec<String>,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Default, PartialEq, SerdeSerialize, SerdeDeserialize)]
|
||||
#[serde(rename_all = "camelCase", default)]
|
||||
pub struct Certificate {
|
||||
/// The EHLO name, or an MX name that points at this node.
|
||||
pub name: String,
|
||||
/// The node holds a certificate for the name.
|
||||
pub covered: bool,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Default, PartialEq, SerdeSerialize, SerdeDeserialize)]
|
||||
#[serde(rename_all = "camelCase", default)]
|
||||
pub struct Settings {
|
||||
/// DL-6: lists not to ask, by name.
|
||||
pub disabled_lists: Vec<String>,
|
||||
}
|
||||
|
||||
impl Settings {
|
||||
pub fn is_off(&self, list: &str) -> bool {
|
||||
self.disabled_lists.iter().any(|name| name == list)
|
||||
}
|
||||
|
||||
/// Only the built-in lists' names, once each.
|
||||
pub fn validate(&self) -> Result<(), String> {
|
||||
for (i, name) in self.disabled_lists.iter().enumerate() {
|
||||
if lists::by_name(name).is_none() {
|
||||
return Err(format!("There's no list called {name:?}."));
|
||||
}
|
||||
if self.disabled_lists[..i].contains(name) {
|
||||
return Err(format!("{name:?} is named twice."));
|
||||
}
|
||||
}
|
||||
Ok(())
|
||||
}
|
||||
}
|
||||
|
||||
impl Report {
|
||||
/// DL-20: what a tenant administrator may see: their tenant's domains
|
||||
/// and nothing about the node's addresses or certificates.
|
||||
pub fn for_tenant(&self, tenant_id: u32) -> Report {
|
||||
Report {
|
||||
node_id: self.node_id,
|
||||
hostname: self.hostname.clone(),
|
||||
checked_at: self.checked_at,
|
||||
addresses: Vec::new(),
|
||||
domains: self
|
||||
.domains
|
||||
.iter()
|
||||
.filter(|d| d.tenant_id == Some(tenant_id))
|
||||
.cloned()
|
||||
.collect(),
|
||||
certificates: Vec::new(),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// --- Storage --------------------------------------------------------------
|
||||
|
||||
struct Json<T>(T);
|
||||
|
||||
impl<T: SerdeSerialize> Serialize for Json<T> {
|
||||
fn serialize(&self) -> trc::Result<Vec<u8>> {
|
||||
serde_json::to_vec(&self.0).map_err(|err| {
|
||||
trc::StoreEvent::UnexpectedError
|
||||
.into_err()
|
||||
.details("Failed to serialize deliverability data")
|
||||
.reason(err)
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
impl<T: for<'de> SerdeDeserialize<'de> + Send + Sync> Deserialize for Json<T> {
|
||||
fn deserialize(bytes: &[u8]) -> trc::Result<Self> {
|
||||
serde_json::from_slice(bytes).map(Json).map_err(|err| {
|
||||
trc::StoreEvent::DataCorruption
|
||||
.into_err()
|
||||
.details("Invalid deliverability data")
|
||||
.reason(err)
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
fn class(kind: u8, node_id: Option<u64>) -> ValueClass {
|
||||
let mut key = Vec::with_capacity(10);
|
||||
key.push(FEATURE);
|
||||
key.push(kind);
|
||||
if let Some(node_id) = node_id {
|
||||
key.extend_from_slice(&node_id.to_be_bytes());
|
||||
}
|
||||
ValueClass::Any(AnyClass {
|
||||
subspace: SUBSPACE_INBUXA,
|
||||
key,
|
||||
})
|
||||
}
|
||||
|
||||
pub async fn report(data: &Store, node_id: u64) -> trc::Result<Option<Report>> {
|
||||
Ok(data
|
||||
.get_value::<Json<Report>>(ValueKey::from(class(KIND_REPORT, Some(node_id))))
|
||||
.await
|
||||
.caused_by(trc::location!())?
|
||||
.map(|Json(report)| report))
|
||||
}
|
||||
|
||||
/// Every node's report, by node id.
|
||||
pub async fn reports(data: &Store) -> trc::Result<Vec<Report>> {
|
||||
let mut out = Vec::new();
|
||||
data.iterate(
|
||||
IterateParams::new(
|
||||
ValueKey::from(class(KIND_REPORT, Some(0))),
|
||||
ValueKey::from(class(KIND_REPORT, Some(u64::MAX))),
|
||||
),
|
||||
|_, value| {
|
||||
if let Ok(Json(report)) = Json::<Report>::deserialize(value) {
|
||||
out.push(report);
|
||||
}
|
||||
Ok(true)
|
||||
},
|
||||
)
|
||||
.await
|
||||
.caused_by(trc::location!())?;
|
||||
out.sort_by_key(|r| r.node_id);
|
||||
Ok(out)
|
||||
}
|
||||
|
||||
/// Replaces the node's report.
|
||||
pub async fn put_report(data: &Store, report: &Report) -> trc::Result<()> {
|
||||
let mut batch = BatchBuilder::new();
|
||||
batch.set(
|
||||
class(KIND_REPORT, Some(report.node_id)),
|
||||
Json(report).serialize()?,
|
||||
);
|
||||
data.write(batch.build_all())
|
||||
.await
|
||||
.caused_by(trc::location!())?;
|
||||
Ok(())
|
||||
}
|
||||
|
||||
pub async fn settings(data: &Store) -> trc::Result<Settings> {
|
||||
Ok(data
|
||||
.get_value::<Json<Settings>>(ValueKey::from(class(KIND_SETTINGS, None)))
|
||||
.await
|
||||
.caused_by(trc::location!())?
|
||||
.map(|Json(settings)| settings)
|
||||
.unwrap_or_default())
|
||||
}
|
||||
|
||||
pub async fn put_settings(data: &Store, settings: &Settings) -> trc::Result<()> {
|
||||
let mut batch = BatchBuilder::new();
|
||||
batch.set(class(KIND_SETTINGS, None), Json(settings).serialize()?);
|
||||
data.write(batch.build_all())
|
||||
.await
|
||||
.caused_by(trc::location!())?;
|
||||
Ok(())
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn settings_name_only_built_in_lists_once() {
|
||||
let ok = Settings {
|
||||
disabled_lists: vec!["Barracuda".into(), "URIBL".into()],
|
||||
};
|
||||
assert!(ok.validate().is_ok());
|
||||
assert!(ok.is_off("Barracuda"));
|
||||
assert!(!ok.is_off("SpamCop"));
|
||||
let unknown = Settings {
|
||||
disabled_lists: vec!["My list".into()],
|
||||
};
|
||||
assert!(unknown.validate().is_err());
|
||||
let twice = Settings {
|
||||
disabled_lists: vec!["URIBL".into(), "URIBL".into()],
|
||||
};
|
||||
assert!(twice.validate().is_err());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn a_tenant_sees_only_its_domains() {
|
||||
let report = Report {
|
||||
node_id: 2,
|
||||
hostname: "mx2.example.org".into(),
|
||||
checked_at: 1,
|
||||
addresses: vec![Address {
|
||||
ip: "192.0.2.10".into(),
|
||||
..Default::default()
|
||||
}],
|
||||
domains: vec![
|
||||
DomainReport {
|
||||
domain: "a.example".into(),
|
||||
tenant_id: Some(7),
|
||||
..Default::default()
|
||||
},
|
||||
DomainReport {
|
||||
domain: "b.example".into(),
|
||||
tenant_id: Some(8),
|
||||
..Default::default()
|
||||
},
|
||||
DomainReport {
|
||||
domain: "server.example".into(),
|
||||
tenant_id: None,
|
||||
..Default::default()
|
||||
},
|
||||
],
|
||||
certificates: vec![Certificate {
|
||||
name: "mx2.example.org".into(),
|
||||
covered: true,
|
||||
}],
|
||||
};
|
||||
let seen = report.for_tenant(7);
|
||||
assert!(seen.addresses.is_empty());
|
||||
assert!(seen.certificates.is_empty());
|
||||
assert_eq!(
|
||||
seen.domains
|
||||
.iter()
|
||||
.map(|d| d.domain.as_str())
|
||||
.collect::<Vec<_>>(),
|
||||
["a.example"]
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn a_report_reads_back_with_missing_fields() {
|
||||
let report: Report = serde_json::from_str(r#"{"nodeId": 3}"#).unwrap();
|
||||
assert_eq!(report.node_id, 3);
|
||||
assert!(report.domains.is_empty());
|
||||
}
|
||||
}
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
@@ -21,6 +21,7 @@
|
||||
pub mod ai;
|
||||
pub mod audit;
|
||||
pub mod branding;
|
||||
pub mod deliverability; // inbuxa: the deliverability check (not a rebuild)
|
||||
pub mod hold;
|
||||
pub mod journal;
|
||||
pub mod lock;
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
@@ -66,6 +66,53 @@ const KIND_DELEGATE: u8 = b'd';
|
||||
/// Most delegates one lock may have (AL-5).
|
||||
pub const MAX_DELEGATES: usize = 10;
|
||||
|
||||
/// Most people one shared mailbox may have (MA-S): a help desk is bigger
|
||||
/// than the handful a departed colleague's mail is handed to.
|
||||
pub const MAX_SHARED_MAILBOX_DELEGATES: usize = 100;
|
||||
|
||||
/// What a lock is for (multi-account spec, MA-S).
|
||||
///
|
||||
/// Both kinds keep receiving mail, can't be signed in to, and are opened by
|
||||
/// delegates through real grants. A shared mailbox is a role address such
|
||||
/// as support@: it needs no reason, holds more people, runs its own Sieve
|
||||
/// replies (an automatic acknowledgement), records only what is sent as it,
|
||||
/// and may only send as its own addresses.
|
||||
#[derive(Debug, Clone, Copy, Default, PartialEq, Eq, Hash, SerdeSerialize, SerdeDeserialize)]
|
||||
#[serde(rename_all = "camelCase")]
|
||||
pub enum Kind {
|
||||
#[default]
|
||||
Lock,
|
||||
SharedMailbox,
|
||||
}
|
||||
|
||||
impl Kind {
|
||||
pub fn as_str(&self) -> &'static str {
|
||||
match self {
|
||||
Kind::Lock => "lock",
|
||||
Kind::SharedMailbox => "sharedMailbox",
|
||||
}
|
||||
}
|
||||
|
||||
pub fn parse(value: &str) -> Option<Self> {
|
||||
match value {
|
||||
"lock" => Some(Kind::Lock),
|
||||
"sharedMailbox" => Some(Kind::SharedMailbox),
|
||||
_ => None,
|
||||
}
|
||||
}
|
||||
|
||||
pub fn is_lock(&self) -> bool {
|
||||
matches!(self, Kind::Lock)
|
||||
}
|
||||
|
||||
pub fn max_delegates(&self) -> usize {
|
||||
match self {
|
||||
Kind::Lock => MAX_DELEGATES,
|
||||
Kind::SharedMailbox => MAX_SHARED_MAILBOX_DELEGATES,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// What a delegate may do in the locked account (AL-6).
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, SerdeSerialize, SerdeDeserialize)]
|
||||
#[serde(rename_all = "camelCase")]
|
||||
@@ -189,6 +236,9 @@ pub struct Replaced {
|
||||
#[serde(rename_all = "camelCase")]
|
||||
pub struct Lock {
|
||||
pub account_id: u32,
|
||||
/// Absent on locks written before shared mailboxes existed: a lock.
|
||||
#[serde(default, skip_serializing_if = "Kind::is_lock")]
|
||||
pub kind: Kind,
|
||||
pub reason: String,
|
||||
/// Seconds since the epoch.
|
||||
pub locked_at: u64,
|
||||
@@ -401,8 +451,9 @@ pub async fn all(data: &Store) -> trc::Result<Vec<Lock>> {
|
||||
Ok(locks)
|
||||
}
|
||||
|
||||
/// The accounts delegated to `delegate`, with its delegation in each.
|
||||
pub async fn delegated_to(data: &Store, delegate: u32) -> trc::Result<Vec<(u32, Delegate)>> {
|
||||
/// The accounts delegated to `delegate`, with its delegation in each and
|
||||
/// the kind of lock it is in.
|
||||
pub async fn delegated_to(data: &Store, delegate: u32) -> trc::Result<Vec<(u32, Delegate, Kind)>> {
|
||||
let mut locked = Vec::new();
|
||||
data.iterate(
|
||||
IterateParams::new(
|
||||
@@ -425,7 +476,7 @@ pub async fn delegated_to(data: &Store, delegate: u32) -> trc::Result<Vec<(u32,
|
||||
if let Some(lock) = get(data, account_id).await?
|
||||
&& let Some(delegation) = lock.delegate(delegate)
|
||||
{
|
||||
delegations.push((account_id, delegation.clone()));
|
||||
delegations.push((account_id, delegation.clone(), lock.kind));
|
||||
}
|
||||
}
|
||||
Ok(delegations)
|
||||
@@ -472,6 +523,22 @@ pub async fn remove(data: &Store, lock: &Lock) -> trc::Result<()> {
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn kind_reads_back_and_defaults_to_lock() {
|
||||
// MA-S: a lock stored before shared mailboxes existed has no kind
|
||||
let stored = r#"{"accountId":1,"reason":"r","lockedAt":0,"lockedBy":"admin","delegates":[]}"#;
|
||||
let lock: Lock = serde_json::from_str(stored).unwrap();
|
||||
assert_eq!(lock.kind, Kind::Lock);
|
||||
assert!(!serde_json::to_string(&lock).unwrap().contains("kind"), "a lock is written as before");
|
||||
|
||||
let shared = Lock { kind: Kind::SharedMailbox, ..lock };
|
||||
let written = serde_json::to_string(&shared).unwrap();
|
||||
assert!(written.contains(r#""kind":"sharedMailbox""#), "{written}");
|
||||
assert_eq!(serde_json::from_str::<Lock>(&written).unwrap().kind, Kind::SharedMailbox);
|
||||
assert_eq!(Kind::parse("sharedMailbox"), Some(Kind::SharedMailbox));
|
||||
assert_eq!(Kind::SharedMailbox.max_delegates(), MAX_SHARED_MAILBOX_DELEGATES);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn keys_read_back() {
|
||||
let ValueClass::Any(any) = class(KIND_DELEGATE, &[7, 9]) else {
|
||||
@@ -509,6 +576,7 @@ mod tests {
|
||||
fn lock_with(delegates: Vec<Delegate>, replaced: Vec<Replaced>) -> Lock {
|
||||
Lock {
|
||||
account_id: 1,
|
||||
kind: Kind::Lock,
|
||||
reason: "r".into(),
|
||||
locked_at: 0,
|
||||
locked_by: "admin".into(),
|
||||
@@ -623,6 +691,7 @@ mod tests {
|
||||
fn expired_delegations_grant_nothing() {
|
||||
let lock = Lock {
|
||||
account_id: 1,
|
||||
kind: Kind::Lock,
|
||||
reason: "Left the company".into(),
|
||||
locked_at: 100,
|
||||
locked_by: "admin".into(),
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
Loaded 100 of 374 files, more files were not shown because too many files have changed in this diff.
Show more
Reference in new issue
Block a user