A new method, inbuxa:Explanation/set, asks the node's local model for a short plain-words reading of one thing an administrator is looking at: a failed recipient in the queue, a Classify verdict, a log line or trace event, or one setting with its saved value. The server builds the prompt itself from stored data and the registry schema, never from text the console sends, and grounds SMTP replies in RFC 3463 and RFC 5321. What the model is never shown: secrets (including ones nested inside a setting, like an AI model's HTTP auth), raw protocol events, and the contents of any other event. A tag name that doesn't have a tag's shape is refused before a model is asked. Calls share the AI gate with spam classification, but mail always keeps its slot, and Explain has its own hourly count per account and its own on/off switch in inbuxa:AiLimits. The permission is sysAiExplain, superuser only; tenant administrators can't use it. The session carries an aiExplain flag so a console knows when to offer the button. An install whose roles were stored before the permission existed gets it added once, at start-up, to the roles that are administrators' alone, not the User role their defaults share with every account. An operator who removes it later isn't overruled. Tests: unit tests in inbuxa-features and jmap, and ai_explain_tests (run with --ignored) covering the acceptance tests and the upgrade.
88 lines
2.7 KiB
Rust
88 lines
2.7 KiB
Rust
/*
|
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
|
*
|
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
|
*
|
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
|
*/
|
|
|
|
use crate::USER_AGENT;
|
|
use hyper::HeaderMap;
|
|
use mail_auth::flate2;
|
|
use std::{
|
|
io::{BufReader, Read},
|
|
time::Duration,
|
|
};
|
|
use utils::HttpLimitResponse;
|
|
|
|
pub mod application;
|
|
pub mod backup;
|
|
pub mod boot;
|
|
pub mod console;
|
|
pub mod defaults;
|
|
pub mod first_party;
|
|
pub mod granted_permissions; // inbuxa: permissions added after roles were stored
|
|
pub mod restore;
|
|
pub mod spam_rules; // inbuxa: rules bundled with the server
|
|
|
|
pub const SPAM_TRAINER_KEY: &[u8] = "INBUXA_SPAM_TRAIN_DATA.lz4".as_bytes();
|
|
pub const SPAM_CLASSIFIER_KEY: &[u8] = "INBUXA_SPAM_CLASSIFIER_MODEL.lz4".as_bytes();
|
|
|
|
pub async fn fetch_resource(
|
|
url: &str,
|
|
headers: Option<HeaderMap>,
|
|
timeout: Duration,
|
|
max_size: usize,
|
|
) -> Result<Vec<u8>, String> {
|
|
if let Some(path) = url.strip_prefix("file://") {
|
|
tokio::fs::read(path)
|
|
.await
|
|
.map_err(|err| format!("Failed to read {path}: {err}"))
|
|
} else {
|
|
let response = utils::http::http_client_builder(is_localhost_url(url))
|
|
.timeout(timeout)
|
|
.user_agent(USER_AGENT)
|
|
.build()
|
|
.unwrap_or_default()
|
|
.get(url)
|
|
.headers(headers.unwrap_or_default())
|
|
.send()
|
|
.await
|
|
.map_err(|err| format!("Failed to fetch {url}: {err}"))?;
|
|
|
|
if response.status().is_success() {
|
|
response
|
|
.bytes_with_limit(max_size)
|
|
.await
|
|
.map_err(|err| format!("Failed to fetch {url}: {err}"))
|
|
.and_then(|bytes| bytes.ok_or_else(|| format!("Resource too large: {url}")))
|
|
} else {
|
|
let code = response.status().canonical_reason().unwrap_or_default();
|
|
let reason = response.text().await.unwrap_or_default();
|
|
|
|
Err(format!(
|
|
"Failed to fetch {url}: Code: {code}, Details: {reason}",
|
|
))
|
|
}
|
|
}
|
|
.and_then(|bytes| {
|
|
if url.ends_with(".gz") || url.ends_with(".gzip") {
|
|
BufReader::new(flate2::read::GzDecoder::new(&bytes[..]))
|
|
.bytes()
|
|
.collect::<Result<Vec<u8>, _>>()
|
|
.map_err(|err| format!("Failed to decompress {url}: {err}"))
|
|
} else {
|
|
Ok(bytes)
|
|
}
|
|
})
|
|
}
|
|
|
|
pub fn is_localhost_url(url: &str) -> bool {
|
|
url.split_once("://")
|
|
.map(|(_, url)| url.split_once('/').map_or(url, |(host, _)| host))
|
|
.is_some_and(|host| {
|
|
let host = host.rsplit_once(':').map_or(host, |(host, _)| host);
|
|
host == "localhost" || host == "127.0.0.1" || host == "[::1]"
|
|
})
|
|
}
|