feat(dovecot): shared mailboxes — info@ reads all accounts (#79)
Dovecot ACL + shared namespace (shared/%%u/), acl_shared_dict in mail-state, idempotent user-patches.sh grants info@ read-only (lookup read) on every mailbox of ano@, andriy.oblivantsev@, postmaster@ and pre-subscribes the shared folders so Roundcube's subscribed folder list shows them. Delivery and passwords untouched; other accounts see no shared folders.
This commit is contained in:
Executable
+33
@@ -0,0 +1,33 @@
|
||||
#!/bin/bash
|
||||
# Dovecot shared mailboxes (issue #79): info@produktor.io gets read-only (lr)
|
||||
# access to the mailboxes of ano@, andriy.oblivantsev@, postmaster@produktor.io.
|
||||
# DMS runs this only on the FIRST start of each container instance (plain
|
||||
# `docker compose restart` skips the setup step by design — /CONTAINER_START
|
||||
# marker), so it must stay idempotent. ACLs, the shared dict and subscriptions
|
||||
# persist in mail-state / maildirs across restarts.
|
||||
set -euo pipefail
|
||||
|
||||
# 1. acl_shared_dict directory: must exist and be writable by the mail user.
|
||||
SHARED_DB_DIR=/var/lib/dovecot/db
|
||||
mkdir -p "${SHARED_DB_DIR}"
|
||||
chown docker:docker "${SHARED_DB_DIR}"
|
||||
chmod 0770 "${SHARED_DB_DIR}"
|
||||
|
||||
# 2. Grant info@ read-only rights on every current mailbox of the shared owners.
|
||||
# doveadm acl set is the only way Dovecot records the share in acl_shared_dict
|
||||
# (manual dovecot-acl files do NOT populate the dictionary — Dovecot docs).
|
||||
# NOTE: this Dovecot build accepts full right NAMES ("lookup read"), single
|
||||
# letters ("lr") are rejected with "Invalid right".
|
||||
READER='info@produktor.io'
|
||||
for owner in ano@produktor.io andriy.oblivantsev@produktor.io postmaster@produktor.io; do
|
||||
# The shared mailbox "shared/<owner>" maps to the owner's INBOX (Dovecot
|
||||
# shared-storage semantics) — subscribe it explicitly so Roundcube's
|
||||
# subscribed folder list shows it.
|
||||
doveadm mailbox subscribe -u "${READER}" "shared/${owner}"
|
||||
for mb in $(doveadm mailbox list -u "${owner}"); do
|
||||
doveadm acl set -u "${owner}" "${mb}" "user=${READER}" lookup read
|
||||
if [ "${mb}" != "INBOX" ]; then
|
||||
doveadm mailbox subscribe -u "${READER}" "shared/${owner}/${mb}"
|
||||
fi
|
||||
done
|
||||
done
|
||||
Reference in New Issue
Block a user