Files
inbuxa-server/crates/features/src/lib.rs
T
jcoffey-dev 441ad0b18e
ci / fork-checks (pull_request) Successful in 41s
ci / build (pull_request) Successful in 8m2s
Journaling: capture at the queue, the built-in journal, retention
Phase 2 of the journaling spec.

- A copy of each message is taken in MessageWrapper::queue, after DLP and
  transport rules, for every enabled journal that takes it (direction and
  scope: everyone, or accounts, groups, domains, tenants). If the copy
  can't be taken the message isn't queued (temporary failure).
- The journal report: the envelope one field a line (sender, To, Cc, Bcc
  from the envelope, list members from their ORCPT, direction, held for
  review), then the queued message byte for byte as message/rfc822.
- The built-in journal under J in the inbuxa subspace: one chain per node
  whose links name each entry by SHA-256, so entries can expire out of
  chain order; purge leaves a marker, and verify catches an entry changed
  or removed early and a report that doesn't match.
- Retention per journal (30 to 3650 days); an entry keeps what it was
  written with. The daily maintenance purges what's due, keeping entries
  whose people a legal hold covers (deleted accounts a hold keeps too),
  and records the counts in the audit log.
- inbuxa:Journal get/set, audited by the request layer. Permissions
  680-683: administrators see and change journals; the Compliance Officer
  sees, searches and exports. Whoever changes journals may grant search and
  export without holding them, so officers can still be appointed.
- Catalog entries (inbuxa:Journal, source "journal"); spec as-built notes.

tests/src/system/journal.rs: validation, internal mail with a Bcc,
outgoing into two journals, incoming over LMTP, the report and its
original, tamper and early removal caught, hold-aware purge, retention
changes leave entries alone, disabled and removed journals take nothing.
2026-09-28 20:46:04 -07:00

33 lines
952 B
Rust

/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! INBUXA's rebuilt features.
//!
//! Upstream ships these only in its Enterprise Edition. INBUXA rebuilds each
//! one clean-room from a written spec under `docs/spec/features/`, one module
//! per feature, and ships it to everybody (docs/spec/SPEC.md §2.3, §3).
//!
//! Upstream files change only by small hooks that call in here, each marked
//! with an `inbuxa:` comment naming the requirement it serves. That keeps
//! every upstream merge's conflicts few and predictable.
//!
//! This crate sits below `common`, so hooks anywhere in the server can call
//! it. It works on registry objects and the store directly, never on
//! `common::Server`.
pub mod ai;
pub mod audit;
pub mod branding;
pub mod hold;
pub mod journal;
pub mod lock;
pub mod mailflow;
pub mod masked_email;
pub mod privacy;
pub mod security;
pub mod tenancy;
pub mod undelete;