feat(dovecot): shared mailboxes — info@ reads all accounts (#79)

Dovecot ACL + shared namespace (shared/%%u/), acl_shared_dict in mail-state,
idempotent user-patches.sh grants info@ read-only (lookup read) on every
mailbox of ano@, andriy.oblivantsev@, postmaster@ and pre-subscribes the
shared folders so Roundcube's subscribed folder list shows them. Delivery and
passwords untouched; other accounts see no shared folders.
This commit is contained in:
2026-09-01 16:02:52 +01:00
parent c9bc594031
commit 2bb6ed310e
3 changed files with 113 additions and 2 deletions
+40
View File
@@ -0,0 +1,40 @@
# Dovecot hardening (E2 D3).
auth_failure_delay = 2s
mail_max_userip_connections = 10
# --- Dovecot shared mailboxes (issue #79): info@ reads all mailboxes. ---
# Canonical Dovecot 2.3 shared-mailbox scheme: acl plugin + shared namespace +
# acl_shared_dict. The imap plugin list is explicit: inside a `protocol imap {}`
# filter $mail_plugins expands to the filter-level value from DMS's 20-imap.conf
# (which shadows the global), so a `$mail_plugins acl` line would silently drop
# `acl`. Keep DMS's imap_quota to not regress quota IMAP commands.
mail_plugins = " quota acl"
protocol imap {
mail_plugins = " quota acl imap_quota"
}
# Dovecot merges namespace blocks with the same identity (type+prefix); this
# makes the default (maildir) "." separator explicit "/" so it matches the
# shared namespace below ("All list=yes namespaces must use the same separator").
namespace inbox {
separator = /
}
namespace {
type = shared
separator = /
prefix = shared/%%u/
location = maildir:/var/mail/%%d/%%n:INDEXPVT=~/shared/%%u
# subscriptions=yes: Roundcube's folder list is subscribed-based (LIST-EXTENDED
# SUBSCRIBED / LSUB); without per-user subscriptions shared folders would be
# invisible in the web UI. user-patches.sh pre-subscribes them for info@.
subscriptions = yes
list = children
}
plugin {
acl = vfile
# Required for the shared namespace LIST to work: tracks "who shared to whom".
# /var/lib/dovecot is a symlink to /var/mail-state/lib-dovecot (persistent).
acl_shared_dict = file:/var/lib/dovecot/db/shared-mailboxes.db
}
+33
View File
@@ -0,0 +1,33 @@
#!/bin/bash
# Dovecot shared mailboxes (issue #79): info@produktor.io gets read-only (lr)
# access to the mailboxes of ano@, andriy.oblivantsev@, postmaster@produktor.io.
# DMS runs this only on the FIRST start of each container instance (plain
# `docker compose restart` skips the setup step by design — /CONTAINER_START
# marker), so it must stay idempotent. ACLs, the shared dict and subscriptions
# persist in mail-state / maildirs across restarts.
set -euo pipefail
# 1. acl_shared_dict directory: must exist and be writable by the mail user.
SHARED_DB_DIR=/var/lib/dovecot/db
mkdir -p "${SHARED_DB_DIR}"
chown docker:docker "${SHARED_DB_DIR}"
chmod 0770 "${SHARED_DB_DIR}"
# 2. Grant info@ read-only rights on every current mailbox of the shared owners.
# doveadm acl set is the only way Dovecot records the share in acl_shared_dict
# (manual dovecot-acl files do NOT populate the dictionary — Dovecot docs).
# NOTE: this Dovecot build accepts full right NAMES ("lookup read"), single
# letters ("lr") are rejected with "Invalid right".
READER='info@produktor.io'
for owner in ano@produktor.io andriy.oblivantsev@produktor.io postmaster@produktor.io; do
# The shared mailbox "shared/<owner>" maps to the owner's INBOX (Dovecot
# shared-storage semantics) — subscribe it explicitly so Roundcube's
# subscribed folder list shows it.
doveadm mailbox subscribe -u "${READER}" "shared/${owner}"
for mb in $(doveadm mailbox list -u "${owner}"); do
doveadm acl set -u "${owner}" "${mb}" "user=${READER}" lookup read
if [ "${mb}" != "INBOX" ]; then
doveadm mailbox subscribe -u "${READER}" "shared/${owner}/${mb}"
fi
done
done