Give IMAP, POP3 and ManageSieve a switch each #79

Merged
jcoffey-dev merged 1 commits from feature/per-protocol-switches into main 2026-09-28 06:32:41 +00:00
Owner

legacy-protocols spec, "Revisit: one switch per protocol" (settled 2026-09-28).

  • imap, pop3, manageSieve on inbuxa:ProtocolPolicy and inbuxa:TenantProtocolPolicy; legacyProtocols stays as the kill-all (sets all three; reads disabled only when all three are off). Old stored policies read as all three at their one value.
  • Submission AUTH is refused only with all three off, as before; one protocol off never stops sending. Decision in the build — please confirm.
  • Server-wide: closes listeners of what's off, reopens saved listeners of what's back on, in one change. Sign-in, autoconfig, autodiscover, PACC (16 prepared variants) and suggested DNS follow each protocol.
  • Tenants: same three; turning one on while the server has it off is refused, naming it.
  • Session: legacyAllowed on urn:inbuxa:jmap.

Tested: unit tests (features, common, jmap); tests/e2e/legacy_protocols.py against a running server, 100 checks including new per-protocol and per-tenant ones.

Console: inbuxa-admin feature/per-protocol-switches. Webmail: ihasmail-inbuxa feature/per-protocol-legacy-note.

legacy-protocols spec, "Revisit: one switch per protocol" (settled 2026-09-28). - `imap`, `pop3`, `manageSieve` on `inbuxa:ProtocolPolicy` and `inbuxa:TenantProtocolPolicy`; `legacyProtocols` stays as the kill-all (sets all three; reads `disabled` only when all three are off). Old stored policies read as all three at their one value. - Submission AUTH is refused only with all three off, as before; one protocol off never stops sending. **Decision in the build — please confirm.** - Server-wide: closes listeners of what's off, reopens saved listeners of what's back on, in one change. Sign-in, autoconfig, autodiscover, PACC (16 prepared variants) and suggested DNS follow each protocol. - Tenants: same three; turning one on while the server has it off is refused, naming it. - Session: `legacyAllowed` on `urn:inbuxa:jmap`. Tested: unit tests (features, common, jmap); `tests/e2e/legacy_protocols.py` against a running server, 100 checks including new per-protocol and per-tenant ones. Console: inbuxa-admin `feature/per-protocol-switches`. Webmail: ihasmail-inbuxa `feature/per-protocol-legacy-note`.
jcoffey-dev added 1 commit 2026-09-28 06:24:47 +00:00
Give IMAP, POP3 and ManageSieve a switch each
ci / fork-checks (pull_request) Successful in 43s
ci / build (pull_request) Successful in 7m40s
8e9cedbe97
The legacy-protocols switch was all or nothing. An operator can now stop
POP3 and keep IMAP: each of IMAP, POP3 and ManageSieve has its own
switch, server-wide on inbuxa:ProtocolPolicy and per tenant on
inbuxa:TenantProtocolPolicy (properties imap, pop3, manageSieve).

legacyProtocols stays as the kill-all: setting it sets all three, and it
reads "disabled" exactly when all three are off. A policy stored before
this has only legacyProtocols and reads as all three at that value, so
existing servers and tenants carry over unchanged. In one /set, a
protocol named beside legacyProtocols overrides it.

SMTP submission keeps no switch of its own: sign-in over it is refused
only when all three are off, as the single switch did (LP-6), so
turning one protocol off never stops a mail app sending. For a tenant,
the server's switches and the tenant's count together.

Server-wide, a change closes the listeners of whatever is now off and
puts back the saved listeners of whatever is on again, both in one
change if asked; listeners of a protocol still off stay saved. Sign-in,
autoconfig, autodiscover, PACC (now prepared once per combination) and
the suggested DNS records all follow each protocol separately. A tenant
may turn a protocol on only while the server has it on (LP-9), and the
refusal names which. The JMAP session adds legacyAllowed, the protocols
still allowed for the account; legacyProtocols there keeps its meaning
for older webmail builds. Events name the switches ("pop3 disabled"),
and audit before/after reads every switch even from an older policy.

Tested: unit tests for the switches, the old-policy reading, the
server/tenant combination, the tenant refusal and listener refusal; and
tests/e2e/legacy_protocols.py against a running server, all 100 checks,
including new ones: POP3 alone off closes only its port and refuses
only its sign-in while IMAP and sending go on; only POP3 stops being
advertised; one change closes IMAP and reopens POP3; a tenant turns
POP3 off for itself, and can't turn IMAP on while the server has it off.
jcoffey-dev merged commit f5888d79b0 into main 2026-09-28 06:32:41 +00:00
jcoffey-dev deleted branch feature/per-protocol-switches 2026-09-28 06:32:42 +00:00
jcoffey-dev referenced this issue from a commit 2026-09-28 07:15:36 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: inbuxa/inbuxa-server#79