Mail flow rules: carry out the transport actions #106

Merged
jcoffey-dev merged 1 commits from feature/mailflow-actions into main 2026-09-29 01:17:04 +00:00
Owner

Phase 2g of the DLP spec, stacked on #104 (its commit shows here until #104 lands).

Transport rules now act, on outgoing and incoming mail:

  • Message edits (features/mailflow/rewrite.rs): add/remove header, prefix/set subject (RFC 2047 when not ASCII), disclaimer top or bottom on the main text and HTML bodies only, re-encoded as UTF-8 quoted-printable, attachments untouched, not added twice.
  • Envelope: add recipient, redirect, route (a per-message queue ahead of the strategy).
  • Refuse: 550 5.7.1 with the rule's text.
  • The check now also runs for incoming mail (transport rules only; DLP stays outgoing).
  • Audit: refusals and routing changes are recorded; wording/header changes aren't (a banner rule would record every message). Spec §2.7 updated.

Tests: rewrite unit tests; mail_rules_tests end to end (disclaimer/header/prefix on a delivered message, redirect, refusal, incoming banner over LMTP, audit scope). smtp inbound and system_tests pass.

Phase 2g of the DLP spec, stacked on #104 (its commit shows here until #104 lands). Transport rules now act, on outgoing and incoming mail: - **Message edits** (`features/mailflow/rewrite.rs`): add/remove header, prefix/set subject (RFC 2047 when not ASCII), disclaimer top or bottom on the main text and HTML bodies only, re-encoded as UTF-8 quoted-printable, attachments untouched, not added twice. - **Envelope**: add recipient, redirect, route (a per-message queue ahead of the strategy). - **Refuse**: `550 5.7.1` with the rule's text. - The check now also runs for incoming mail (transport rules only; DLP stays outgoing). - Audit: refusals and routing changes are recorded; wording/header changes aren't (a banner rule would record every message). Spec §2.7 updated. Tests: rewrite unit tests; `mail_rules_tests` end to end (disclaimer/header/prefix on a delivered message, redirect, refusal, incoming banner over LMTP, audit scope). smtp inbound and system_tests pass.
jcoffey-dev added 2 commits 2026-09-29 01:11:40 +00:00
DLP at DATA: block, warn and override over SMTP and JMAP
ci / fork-checks (pull_request) Successful in 49s
ci / build (pull_request) Successful in 23m36s
e0060c9e6e
Phase 2f of the DLP and mail flow rules spec: the rules now run on mail
an authenticated sender submits, after the DATA system script and
before headers and DKIM signing (§2.1).

- smtp/inbound/mailflow.rs: builds what the rules look at from the
  message (subject, the text version of each body, one level of attached
  messages, attachment text via the extractor, 10 MB of text at most)
  and the envelope (sender's groups and tenant; each recipient local or
  not, and its groups). Skipped entirely when no enabled rule applies to
  outgoing mail. Rules that can't be loaded refuse with a 451: nothing
  unchecked leaves.
- Block: 550 5.7.1 with the rule's notice. Warn: 550 5.7.1 with the
  notice and how to override: "[override: reason]" at the start of the
  subject, taken out before the message goes on (settled answer 1).
  Until phase 3, a hold rule blocks rather than let mail through.
- JMAP: EmailSubmission takes inbuxa:dlpOverride {reason}; a refusal
  comes back as inbuxa:dlpWarning or inbuxa:dlpBlocked with each rule's
  name and notice (description too, for older clients).
- Audit: one record per DLP match, the sender as actor, action create,
  target a message: the recipient domains, each rule with its detectors'
  counts, the outcome, an override's reason. Never the matched text. No
  new audit action: an older node that meets one fails its daily
  clean-up, which would make rolling back unsafe (spec §2.7 updated).

Tests: mail_rules_tests gains the DLP flow over JMAP (no rules, warning
with rule and notice, local recipient not warned, override with a
reason, block that no reason passes, the subject tag stripped from the
delivered message, audit records with no card or key text). smtp
inbound tests pass; system_tests passed twice after one timeout in the
email delivery tests that didn't recur.
Mail flow rules: carry out the transport actions
ci / fork-checks (pull_request) Successful in 50s
ci / build (pull_request) Successful in 4m52s
7f22006e97
Phase 2g of the DLP and mail flow rules spec: transport rules now act,
on outgoing and incoming mail.

- features/mailflow/rewrite.rs: add or remove a header, prefix or set the
  subject (an RFC 2047 word when not ASCII), add a disclaimer. A
  disclaimer edits the message's main text and HTML bodies only, each
  decoded, changed and written back as UTF-8 quoted-printable with its
  other headers kept, top or bottom (after <body> or before </body> in
  HTML); attachments and attached messages are left alone, and a
  disclaimer already present isn't added again.
- smtp/inbound/mailflow.rs: the check runs for incoming mail too
  (transport rules only; DLP stays outgoing). After DLP passes, each
  matched transport rule's actions run in order: message edits,
  add-recipient and redirect (envelope changes DATA applies), route (a
  per-message queue ahead of the queue strategy), refuse (550 5.7.1
  with the rule's text). The override tag is stripped with the same
  subject writer, so a non-ASCII subject stays valid.
- Audit: refusals and changes to where mail goes are recorded (sender,
  or system:mail-flow for incoming mail); wording and header changes
  aren't, or a banner rule would record every message (spec §2.7).

Tests: rewrite unit tests (headers, encoded subjects, disclaimers on a
single part and on multipart/alternative with an attachment, once
only); mail_rules_tests gains the actions end to end: disclaimer,
header and subject prefix on a delivered message, a redirect, a
refusal, a banner on incoming LMTP mail that outgoing rules leave
alone, and which of those are audited.
jcoffey-dev merged commit dd73e0ad74 into main 2026-09-29 01:17:04 +00:00
jcoffey-dev deleted branch feature/mailflow-actions 2026-09-29 01:17:04 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: inbuxa/inbuxa-server#106