inbuxa:LegalHold get/set places a hold on accounts, groups, domains, tenants or the whole server, with an optional date range. A hold's range and scope can only widen, a released hold is read-only, and none is ever deleted. Placing, changing and releasing each need a reason and are audited (LH-1, LH-3, LH-10, AU-12). Permissions 669-672 (see, place, widen or release, export held data) go to server administrators only; the tenant ceiling always strips them, as it does Impersonate (LH-13). Schema: Compliance > Legal Holds. What a hold keeps comes next, through the undelete hooks. Also moves the lock expiry helpers below the lock module's imports.
30 lines
900 B
Rust
30 lines
900 B
Rust
/*
|
|
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
|
*
|
|
* SPDX-License-Identifier: AGPL-3.0-only
|
|
*/
|
|
|
|
//! INBUXA's rebuilt features.
|
|
//!
|
|
//! Upstream ships these only in its Enterprise Edition. INBUXA rebuilds each
|
|
//! one clean-room from a written spec under `docs/spec/features/`, one module
|
|
//! per feature, and ships it to everybody (docs/spec/SPEC.md §2.3, §3).
|
|
//!
|
|
//! Upstream files change only by small hooks that call in here, each marked
|
|
//! with an `inbuxa:` comment naming the requirement it serves. That keeps
|
|
//! every upstream merge's conflicts few and predictable.
|
|
//!
|
|
//! This crate sits below `common`, so hooks anywhere in the server can call
|
|
//! it. It works on registry objects and the store directly, never on
|
|
//! `common::Server`.
|
|
|
|
pub mod ai;
|
|
pub mod audit;
|
|
pub mod branding;
|
|
pub mod hold;
|
|
pub mod lock;
|
|
pub mod masked_email;
|
|
pub mod security;
|
|
pub mod tenancy;
|
|
pub mod undelete;
|