feat(mail-admin): unified inbox view of all mailboxes (#76)

This commit is contained in:
2026-09-01 15:21:24 +01:00
parent 403c79c3e4
commit 1f88063412
11 changed files with 1029 additions and 2 deletions
+31
View File
@@ -88,6 +88,37 @@ curl -u "$MAIL_ADMIN_USER:$MAIL_ADMIN_PASSWORD" https://mail.produktor.io/admin/
Credentials `MAIL_ADMIN_USER` / `MAIL_ADMIN_PASSWORD` are required in `.env`
(compose fails without them). The JSON API is at `/admin/api/accounts`.
## Web UI → Все письма
**https://mail.produktor.io/admin/messages** — unified inbox of **all**
mailboxes (info@, postmaster@, ano@, andriy.oblivantsev@, postman@) read
directly from the Maildir on disk: no IMAP, no user passwords. Each row shows
date, from, subject, size and links to the full message view (text/html
toggle + attachment list + headers). Messages are grouped by mailbox, sorted
newest first; the search box filters by subject/from client-side.
Read-only API (same Basic Auth):
| Endpoint | Description |
|----------|-------------|
| `GET /admin/api/messages` | Unified list, newest first. Filters: `?mailbox=` (full address or localpart), `?q=` (subject/from, case-insensitive), `?limit=` (default 100, max 500) |
| `GET /admin/api/messages/<mailbox>/<filename>` | Full message: decoded headers + unfolded `text/plain`/`text/html` bodies + `attachments` (filename/size/cid) |
```bash
curl -u "$MAIL_ADMIN_USER:$MAIL_ADMIN_PASSWORD" \
"https://mail.produktor.io/admin/api/messages?limit=5"
curl -u "$MAIL_ADMIN_USER:$MAIL_ADMIN_PASSWORD" \
"https://mail.produktor.io/admin/api/messages/ano@produktor.io/<filename>"
```
Layout assumption: `data/mail-data/<domain>/<localpart>/{cur,new}/` (docker
-mailserver default Maildir; message files in `cur/` + `new/`, `tmp/` is
transient and ignored). Mailbox and filename are validated strictly and
resolved against the real directory listing — path traversal and symlink
escape from `mail-data/` are impossible. MIME multipart bodies are unfolded
recursively with the Go stdlib (`net/mail`, `mime/multipart`,
`mime/quotedprintable`); nothing is ever written or deleted.
## Reverse proxy (NPM)
`mail.produktor.io` is a proxy host in Nginx Proxy Manager (`provider` container,