Delegates reach the whole locked account #68

Merged
jcoffey-dev merged 2 commits from fix/delegate-whole-account into main 2026-09-28 01:22:48 +00:00
Owner

Found in prod testing: a delegate opening a locked account in the webmail got its mail, but its calendar, contacts and files didn't come through.

On the server side, the delegate's access token listed the locked account only for kinds of data it already held grants on. An account with no files (or no calendar) was therefore refused to the delegate outright with "You do not have access to account".

Now the token lists every current delegation's locked account for mail, calendars, contacts and files, so a kind with nothing in it reads as empty. Per-item access is unchanged: what a delegate sees or changes is still each container's ACL grant.

The webmail half (the calendar, contacts and files views following the account in view) is a separate PR in ihasmail-inbuxa.

Test: system::account_lock checks that FileNode/query, Calendar/get and AddressBook/get on the locked account answer the delegate, including for an owner with no files. It passes on RocksDB.

Found in prod testing: a delegate opening a locked account in the webmail got its mail, but its calendar, contacts and files didn't come through. On the server side, the delegate's access token listed the locked account only for kinds of data it already held grants on. An account with no files (or no calendar) was therefore refused to the delegate outright with "You do not have access to account". Now the token lists every current delegation's locked account for mail, calendars, contacts and files, so a kind with nothing in it reads as empty. Per-item access is unchanged: what a delegate sees or changes is still each container's ACL grant. The webmail half (the calendar, contacts and files views following the account in view) is a separate PR in ihasmail-inbuxa. Test: `system::account_lock` checks that FileNode/query, Calendar/get and AddressBook/get on the locked account answer the delegate, including for an owner with no files. It passes on RocksDB.
jcoffey-dev added 1 commit 2026-09-28 00:59:01 +00:00
Delegates reach the whole locked account
ci / build (pull_request) Canceled after 5m27s
ci / fork-checks (pull_request) Successful in 14s
d4d127fa7d
A delegate's token listed the locked account only for kinds of data it
held grants on, so one with no files (or no calendar) was refused to the
delegate outright: "You do not have access to account". The token now
lists the locked account for mail, calendars, contacts and files alike,
so an empty kind reads as empty. What the delegate may see or change is
still each container's grant (AL-7).
jcoffey-dev added 1 commit 2026-09-28 01:04:28 +00:00
Writing delegates may add at the top of a locked account's Files
ci / fork-checks (pull_request) Successful in 17s
ci / build (pull_request) Successful in 17m56s
9f6761c9dd
A shared account refuses top-level folders, so an organize or full
delegate couldn't add anything to a locked account with no folders. A
delegate who may write now can, as the owner could; the reconcile after
the create grants it the new folder. Read delegates still can't (AL-6,
AL-7).
jcoffey-dev merged commit f7a63b9ed0 into main 2026-09-28 01:22:48 +00:00
jcoffey-dev deleted branch fix/delegate-whole-account 2026-09-28 01:22:48 +00:00
jcoffey-dev referenced this issue from a commit 2026-09-28 01:27:36 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: inbuxa/inbuxa-server#68