feat(dovecot): shared mailboxes — info@ reads all accounts (#79)
Dovecot ACL + shared namespace (shared/%%u/), acl_shared_dict in mail-state, idempotent user-patches.sh grants info@ read-only (lookup read) on every mailbox of ano@, andriy.oblivantsev@, postmaster@ and pre-subscribes the shared folders so Roundcube's subscribed folder list shows them. Delivery and passwords untouched; other accounts see no shared folders.
This commit is contained in:
@@ -0,0 +1,40 @@
|
||||
# Dovecot hardening (E2 D3).
|
||||
auth_failure_delay = 2s
|
||||
mail_max_userip_connections = 10
|
||||
|
||||
# --- Dovecot shared mailboxes (issue #79): info@ reads all mailboxes. ---
|
||||
# Canonical Dovecot 2.3 shared-mailbox scheme: acl plugin + shared namespace +
|
||||
# acl_shared_dict. The imap plugin list is explicit: inside a `protocol imap {}`
|
||||
# filter $mail_plugins expands to the filter-level value from DMS's 20-imap.conf
|
||||
# (which shadows the global), so a `$mail_plugins acl` line would silently drop
|
||||
# `acl`. Keep DMS's imap_quota to not regress quota IMAP commands.
|
||||
mail_plugins = " quota acl"
|
||||
protocol imap {
|
||||
mail_plugins = " quota acl imap_quota"
|
||||
}
|
||||
|
||||
# Dovecot merges namespace blocks with the same identity (type+prefix); this
|
||||
# makes the default (maildir) "." separator explicit "/" so it matches the
|
||||
# shared namespace below ("All list=yes namespaces must use the same separator").
|
||||
namespace inbox {
|
||||
separator = /
|
||||
}
|
||||
|
||||
namespace {
|
||||
type = shared
|
||||
separator = /
|
||||
prefix = shared/%%u/
|
||||
location = maildir:/var/mail/%%d/%%n:INDEXPVT=~/shared/%%u
|
||||
# subscriptions=yes: Roundcube's folder list is subscribed-based (LIST-EXTENDED
|
||||
# SUBSCRIBED / LSUB); without per-user subscriptions shared folders would be
|
||||
# invisible in the web UI. user-patches.sh pre-subscribes them for info@.
|
||||
subscriptions = yes
|
||||
list = children
|
||||
}
|
||||
|
||||
plugin {
|
||||
acl = vfile
|
||||
# Required for the shared namespace LIST to work: tracks "who shared to whom".
|
||||
# /var/lib/dovecot is a symlink to /var/mail-state/lib-dovecot (persistent).
|
||||
acl_shared_dict = file:/var/lib/dovecot/db/shared-mailboxes.db
|
||||
}
|
||||
Reference in New Issue
Block a user