Phase 2 of the journaling spec. - A copy of each message is taken in MessageWrapper::queue, after DLP and transport rules, for every enabled journal that takes it (direction and scope: everyone, or accounts, groups, domains, tenants). If the copy can't be taken the message isn't queued (temporary failure). - The journal report: the envelope one field a line (sender, To, Cc, Bcc from the envelope, list members from their ORCPT, direction, held for review), then the queued message byte for byte as message/rfc822. - The built-in journal under J in the inbuxa subspace: one chain per node whose links name each entry by SHA-256, so entries can expire out of chain order; purge leaves a marker, and verify catches an entry changed or removed early and a report that doesn't match. - Retention per journal (30 to 3650 days); an entry keeps what it was written with. The daily maintenance purges what's due, keeping entries whose people a legal hold covers (deleted accounts a hold keeps too), and records the counts in the audit log. - inbuxa:Journal get/set, audited by the request layer. Permissions 680-683: administrators see and change journals; the Compliance Officer sees, searches and exports. Whoever changes journals may grant search and export without holding them, so officers can still be appointed. - Catalog entries (inbuxa:Journal, source "journal"); spec as-built notes. tests/src/system/journal.rs: validation, internal mail with a Bcc, outgoing into two journals, incoming over LMTP, the report and its original, tamper and early removal caught, hold-aware purge, retention changes leave entries alone, disabled and removed journals take nothing.
33 lines
952 B
Rust
33 lines
952 B
Rust
/*
|
|
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
|
*
|
|
* SPDX-License-Identifier: AGPL-3.0-only
|
|
*/
|
|
|
|
//! INBUXA's rebuilt features.
|
|
//!
|
|
//! Upstream ships these only in its Enterprise Edition. INBUXA rebuilds each
|
|
//! one clean-room from a written spec under `docs/spec/features/`, one module
|
|
//! per feature, and ships it to everybody (docs/spec/SPEC.md §2.3, §3).
|
|
//!
|
|
//! Upstream files change only by small hooks that call in here, each marked
|
|
//! with an `inbuxa:` comment naming the requirement it serves. That keeps
|
|
//! every upstream merge's conflicts few and predictable.
|
|
//!
|
|
//! This crate sits below `common`, so hooks anywhere in the server can call
|
|
//! it. It works on registry objects and the store directly, never on
|
|
//! `common::Server`.
|
|
|
|
pub mod ai;
|
|
pub mod audit;
|
|
pub mod branding;
|
|
pub mod hold;
|
|
pub mod journal;
|
|
pub mod lock;
|
|
pub mod mailflow;
|
|
pub mod masked_email;
|
|
pub mod privacy;
|
|
pub mod security;
|
|
pub mod tenancy;
|
|
pub mod undelete;
|