Files
inbuxa-webmail/web/src/lib/delegation.ts
T
jcoffey-dev c66a8aadd7
ci / version (pull_request) Skipped
ci / github (pull_request) Skipped
ci / node (pull_request) Successful in 1m29s
ci / publish (pull_request) Skipped
ci / announce (pull_request) Skipped
ci / docker-build (pull_request) Successful in 36s
github/ci (branch) GitHub Actions
Show an assigned shared mailbox as shared, not as a locked account
The server now marks a shared mailbox (support@, legal@) as a
delegation of kind "sharedMailbox" (multi-account spec, MA-S). Without
this, the webmail would show one exactly as it shows a locked account:
a red bar, a padlock in the tab and on the brand, and its calendars and
files in place of the reader's own.

Now such a mailbox is listed with the other shared mailboxes under
"Mail to show", opens with the shared bar, which also gives the
person's access level and whether they can send as it, and changes
mail only. Its access level still applies exactly as a lock's does:
read changes nothing, organize never deletes, no sending without
send-as. Found without asking Mailbox/get, since the server's mark says
it is mail.

A server that sends no kind is treated as before: every delegation is a
lock. No new strings. typecheck and vitest (174 files, 1534 tests)
pass.
2026-10-05 15:15:57 -07:00

75 lines
2.7 KiB
TypeScript

/**
* Locked accounts handed to the reader (inbuxa audit-hold-lock spec, AL-7).
*
* The server marks one in the account's `urn:inbuxa:jmap` capability, as
* `delegation: {locked, access, sendAs, until}`. Only that mark makes an
* account switchable: a server advertises every capability on any shared
* account, so "it has mail" proves nothing about what was handed over.
*/
import type { Id, JmapSession } from "@/jmap/types";
export type DelegationAccess = "read" | "organize" | "full";
export interface Delegation {
locked: boolean;
/**
* A locked account, or a shared mailbox such as support@ (MA-S). Both are
* reached as a delegate at an access level; only how they are shown
* differs. Absent from older servers, where it is always a lock.
*/
kind: "lock" | "sharedMailbox";
access: DelegationAccess;
sendAs: boolean;
/** UTC date the delegation ends, if it does. */
until: string | null;
}
export interface DelegatedAccount {
id: Id;
name: string;
delegation: Delegation;
}
const INBUXA = "urn:inbuxa:jmap";
type SessionLike = Pick<JmapSession, "accounts">;
export function delegationOf(session: SessionLike | null, accountId: Id | null): Delegation | null {
if (!session || !accountId) return null;
const account = session.accounts[accountId];
if (!account || account.isPersonal) return null;
const raw = (account.accountCapabilities?.[INBUXA] as { delegation?: Partial<Delegation> } | undefined)?.delegation;
if (!raw || raw.locked !== true) return null;
const access: DelegationAccess = raw.access === "organize" || raw.access === "full" ? raw.access : "read";
return {
locked: true,
kind: raw.kind === "sharedMailbox" ? "sharedMailbox" : "lock",
access,
sendAs: raw.sendAs === true && access !== "read",
until: typeof raw.until === "string" ? raw.until : null,
};
}
/** Every locked account handed to the reader, by name. Shared mailboxes are listed by lib/sharedMail. */
export function delegatedAccounts(session: SessionLike | null): DelegatedAccount[] {
if (!session) return [];
return Object.entries(session.accounts)
.map(([id, account]) => {
const delegation = delegationOf(session, id);
return delegation?.kind === "lock" ? { id, name: account.name, delegation } : null;
})
.filter((a): a is DelegatedAccount => a !== null)
.sort((a, b) => a.name.localeCompare(b.name));
}
/** Whether the reader may change anything in the account (AL-6). */
export function mayWrite(delegation: Delegation | null): boolean {
return !delegation || delegation.access !== "read";
}
/** Whether the reader may delete in the account (AL-6). */
export function mayDestroy(delegation: Delegation | null): boolean {
return !delegation || delegation.access === "full";
}