feat(dovecot): shared mailboxes — info@ reads all accounts (#79)

Dovecot ACL + shared namespace (shared/%%u/), acl_shared_dict in mail-state,
idempotent user-patches.sh grants info@ read-only (lookup read) on every
mailbox of ano@, andriy.oblivantsev@, postmaster@ and pre-subscribes the
shared folders so Roundcube's subscribed folder list shows them. Delivery and
passwords untouched; other accounts see no shared folders.
This commit is contained in:
2026-09-01 16:02:52 +01:00
parent c9bc594031
commit 2bb6ed310e
3 changed files with 113 additions and 2 deletions
+40 -2
View File
@@ -31,8 +31,12 @@ image) and is reachable at **https://mail.produktor.io** (alias
`172.17.0.1:19944`, Let's Encrypt).
Login: any mailbox address from the table above + its real password. The UI
shows one mailbox per login; to see all accounts, log in with each one. The
account list is the `postfix-accounts.cf` file (see Accounts).
shows one mailbox per login; the account list is the `postfix-accounts.cf`
file (see Accounts).
Since the shared-mailbox setup (below) `info@` additionally sees every other
mailbox under `Shared/` and can read them — one login covers the whole
account list.
Connection details used by the webmail (IMAP/SMTP):
@@ -57,6 +61,40 @@ The webmail stores its sqlite database (addressbook, settings) in
`data/roundcube/db/`. `ROUNDCUBEMAIL_DES_KEY` (session encryption) must be set
in `.env` — compose fails without it.
## Shared mailboxes (единый вход info@)
`info@produktor.io` can read all mailboxes (`ano@`, `andriy.oblivantsev@`,
`postmaster@`) as read-only shared folders — one login in Roundcube covers the
whole account list. Delivery is unchanged (no aliases, no redirects); other
accounts keep their own passwords and full rights.
How it works (Dovecot 2.3 ACL + shared namespace):
- `config/dovecot.cf` (→ `/etc/dovecot/local.conf`) enables the `acl` plugin,
adds a shared namespace `shared/%%u/` (`list=children`, read index per
reader via `INDEXPVT`), and points `acl_shared_dict` to
`/var/lib/dovecot/db/shared-mailboxes.db` (persistent via `mail-state`).
- `config/user-patches.sh` re-applies read-only (`lr`) ACLs from each shared
owner's mailboxes to `user=info@produktor.io` via `doveadm acl set` — the
only way Dovecot records the share in the shared dictionary — and
pre-subscribes the shared folders for `info@`. DMS runs it on the first
start of each container instance (plain `docker compose restart` skips the
setup step by design); ACLs, the shared dict and subscriptions persist in
`mail-state`/maildirs, so nothing is lost on restarts. Idempotent — safe to
run manually: `docker exec mailserver /bin/bash /tmp/docker-mailserver/user-patches.sh`.
Upgrade behavior (image `:latest`): the config survives container recreation
because both files live in the mounted `config/`. On image upgrade the
entrypoint re-applies `dovecot.cf` and runs `user-patches.sh` again on the new
container's first start, so ACLs and subscriptions are recreated. The only
state kept outside the repo is `shared-mailboxes.db` (inside
`data/mail-state/`); if it is lost, the next (re)creation rebuilds it via
`doveadm acl set`.
Limitation (Dovecot semantics): new mailboxes created by an owner *after* the
last start do not inherit the share (no ACL inheritance); they appear for
`info@` after the next container start.
## Reverse proxy (NPM)
`mail.produktor.io` is a proxy host in Nginx Proxy Manager (`provider` container,