Shared mailboxes: a second kind of account lock #148

Merged
jcoffey-dev merged 1 commits from feat/shared-mailbox-lock-kind into main 2026-10-05 22:32:54 +00:00
Owner

A shared mailbox (support@, legal@) belongs to no one person: nobody
signs in to it, and the people assigned open it beside their own mail
at an access level an administrator chose. An account lock already is
most of that: it keeps receiving mail, refuses every sign-in, and its
delegates reach it through real grants on every container (so IMAP,
DAV and JMAP honor them), never including Share. So a shared mailbox is
a lock of a second kind (multi-account spec, MA-S; John, 2026-10-05).

Lock gains kind: "lock" (the default, so stored locks read as before)
or "sharedMailbox", set on create and fixed after. A shared mailbox:

  • needs no reason to make, change or end;
  • holds up to 100 people, where a lock holds 10;
  • runs its own Sieve replies and redirects, so an automatic
    acknowledgement goes out (a lock answers no one);
  • records only what is sent as it (audit_send_as, which now covers it),
    not AL-9's access and per-change records, which would bury the log
    for a busy desk;
  • sends only as itself (MA-S3): From and Reply-To must be its own
    addresses, so answers come back to the mailbox and not to whoever
    replied; anything else is forbiddenFrom.

The session marks it delegation: {locked: true, kind: "sharedMailbox"},
so a front end that knows no kind still treats it as a lock. The
console's layout gains Management › Directory › Shared Mailboxes
(CustomComponent/SharedMailboxes).

Tests: the account lock suite now goes on to a shared mailbox: made
without a reason with twelve people, sign-in refused, the session's
kind, its vacation reply delivered, an answer sent as it and recorded
as the agent with no per-change records, and a Reply-To naming the
agent refused; a lock unit test reads a stored lock without a kind.
account_lock_tests, jmap_tests, audit_log_tests and imap_tests pass
(RocksDB).

A shared mailbox (support@, legal@) belongs to no one person: nobody signs in to it, and the people assigned open it beside their own mail at an access level an administrator chose. An account lock already is most of that: it keeps receiving mail, refuses every sign-in, and its delegates reach it through real grants on every container (so IMAP, DAV and JMAP honor them), never including Share. So a shared mailbox is a lock of a second kind (multi-account spec, MA-S; John, 2026-10-05). Lock gains kind: "lock" (the default, so stored locks read as before) or "sharedMailbox", set on create and fixed after. A shared mailbox: - needs no reason to make, change or end; - holds up to 100 people, where a lock holds 10; - runs its own Sieve replies and redirects, so an automatic acknowledgement goes out (a lock answers no one); - records only what is sent as it (audit_send_as, which now covers it), not AL-9's access and per-change records, which would bury the log for a busy desk; - sends only as itself (MA-S3): From and Reply-To must be its own addresses, so answers come back to the mailbox and not to whoever replied; anything else is forbiddenFrom. The session marks it delegation: {locked: true, kind: "sharedMailbox"}, so a front end that knows no kind still treats it as a lock. The console's layout gains Management › Directory › Shared Mailboxes (CustomComponent/SharedMailboxes). Tests: the account lock suite now goes on to a shared mailbox: made without a reason with twelve people, sign-in refused, the session's kind, its vacation reply delivered, an answer sent as it and recorded as the agent with no per-change records, and a Reply-To naming the agent refused; a lock unit test reads a stored lock without a kind. account_lock_tests, jmap_tests, audit_log_tests and imap_tests pass (RocksDB).
jcoffey-dev added 1 commit 2026-10-05 22:28:07 +00:00
Shared mailboxes: a second kind of account lock
ci / github (pull_request) Skipped
ci / fork-checks (pull_request) Successful in 1m8s
ci / build (pull_request) Successful in 4m30s
github/ci (branch) GitHub Actions
9976d52e29
A shared mailbox (support@, legal@) belongs to no one person: nobody
signs in to it, and the people assigned open it beside their own mail
at an access level an administrator chose. An account lock already is
most of that: it keeps receiving mail, refuses every sign-in, and its
delegates reach it through real grants on every container (so IMAP,
DAV and JMAP honor them), never including Share. So a shared mailbox is
a lock of a second kind (multi-account spec, MA-S; John, 2026-10-05).

Lock gains kind: "lock" (the default, so stored locks read as before)
or "sharedMailbox", set on create and fixed after. A shared mailbox:

- needs no reason to make, change or end;
- holds up to 100 people, where a lock holds 10;
- runs its own Sieve replies and redirects, so an automatic
  acknowledgement goes out (a lock answers no one);
- records only what is sent as it (audit_send_as, which now covers it),
  not AL-9's access and per-change records, which would bury the log
  for a busy desk;
- sends only as itself (MA-S3): From and Reply-To must be its own
  addresses, so answers come back to the mailbox and not to whoever
  replied; anything else is forbiddenFrom.

The session marks it delegation: {locked: true, kind: "sharedMailbox"},
so a front end that knows no kind still treats it as a lock. The
console's layout gains Management › Directory › Shared Mailboxes
(CustomComponent/SharedMailboxes).

Tests: the account lock suite now goes on to a shared mailbox: made
without a reason with twelve people, sign-in refused, the session's
kind, its vacation reply delivered, an answer sent as it and recorded
as the agent with no per-change records, and a Reply-To naming the
agent refused; a lock unit test reads a stored lock without a kind.
account_lock_tests, jmap_tests, audit_log_tests and imap_tests pass
(RocksDB).
jcoffey-dev merged commit 50a03df30b into main 2026-10-05 22:32:54 +00:00
jcoffey-dev deleted branch feat/shared-mailbox-lock-kind 2026-10-05 22:32:54 +00:00
Sign in to join this conversation.