An administrator picks sections, a schedule (daily, weekly or monthly, at a time in a time zone) and recipients, who must be accounts on this server. Every node looks for due reports once a minute; a run is claimed with the task lock, keyed by report and due time, and recorded on the report, so it goes once. The report is built from what the server already keeps: mail flow, the queue, spoofing from received DMARC reports, TLS failures, deliverability findings and what changed since the last run, security counters, people near their quota, and expiring certificates. It is mailed as text and HTML with optional CSV attachments, DKIM-signed; a sender domain without a key fails the run with that reason instead of sending unsigned. The weekly digest is a built-in report on every server, on by default: every section, Mondays 07:00 UTC, to the system administrators. It can be changed or turned off, not deleted. A tenant administrator makes and sees only their own tenant's reports, which leave out server-wide sections. New: inbuxa:ScheduledReport and inbuxa:ScheduledReportSettings, the sysScheduledReportGet and sysScheduledReportUpdate permissions (granted once to existing administrator roles), privacy catalog entries, and a system test. Spec: inbuxa-drafts specs/scheduled-reports.md.
46 lines
1.4 KiB
Rust
46 lines
1.4 KiB
Rust
/*
|
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
|
*
|
|
* SPDX-License-Identifier: AGPL-3.0-only
|
|
*/
|
|
|
|
//! inbuxa: a server-built message, always DKIM-signed (scheduled-reports
|
|
//! spec, RP-14). Unlike `send_autogenerated`, a message that can't be signed
|
|
//! isn't sent, and the caller hears why.
|
|
|
|
use crate::queue::{
|
|
MessageSource,
|
|
spool::{QueueParams, SmtpSpool},
|
|
};
|
|
use common::Server;
|
|
|
|
/// Queues `raw` from `from` to `rcpts`, signed with `sign_domain`'s keys.
|
|
pub async fn send_signed(
|
|
server: &Server,
|
|
from: &str,
|
|
rcpts: &[String],
|
|
raw: &[u8],
|
|
sign_domain: &str,
|
|
) -> Result<(), String> {
|
|
let signers = match server.dkim_signers(sign_domain).await {
|
|
Ok(Some(signers)) => signers,
|
|
Ok(None) => return Err(format!("{sign_domain} has no DKIM key to sign with.")),
|
|
Err(err) => {
|
|
trc::error!(err.details("Failed to retrieve DKIM signers for a report"));
|
|
return Err(format!("The DKIM keys for {sign_domain} couldn't be read."));
|
|
}
|
|
};
|
|
let mut message = server.new_message(from, MessageSource::Autogenerated, 0);
|
|
for rcpt in rcpts {
|
|
message.add_expanded_recipient(rcpt, server).await;
|
|
}
|
|
if message
|
|
.queue(QueueParams::new(raw, 0, server).with_dkim_signers(Some(signers)))
|
|
.await
|
|
{
|
|
Ok(())
|
|
} else {
|
|
Err("The mail queue didn't accept the message.".into())
|
|
}
|
|
}
|