#!/bin/bash # Dovecot shared mailboxes (issue #79): info@produktor.io gets read-only (lr) # access to the mailboxes of ano@, andriy.oblivantsev@, postmaster@produktor.io. # DMS runs this only on the FIRST start of each container instance (plain # `docker compose restart` skips the setup step by design — /CONTAINER_START # marker), so it must stay idempotent. ACLs, the shared dict and subscriptions # persist in mail-state / maildirs across restarts. set -euo pipefail # 1. acl_shared_dict directory: must exist and be writable by the mail user. SHARED_DB_DIR=/var/lib/dovecot/db mkdir -p "${SHARED_DB_DIR}" chown docker:docker "${SHARED_DB_DIR}" chmod 0770 "${SHARED_DB_DIR}" # 2. Grant info@ read-only rights on every current mailbox of the shared owners. # doveadm acl set is the only way Dovecot records the share in acl_shared_dict # (manual dovecot-acl files do NOT populate the dictionary — Dovecot docs). # NOTE: this Dovecot build accepts full right NAMES ("lookup read"), single # letters ("lr") are rejected with "Invalid right". READER='info@produktor.io' for owner in ano@produktor.io andriy.oblivantsev@produktor.io postmaster@produktor.io; do # The shared mailbox "shared/" maps to the owner's INBOX (Dovecot # shared-storage semantics) — subscribe it explicitly so Roundcube's # subscribed folder list shows it. doveadm mailbox subscribe -u "${READER}" "shared/${owner}" for mb in $(doveadm mailbox list -u "${owner}"); do doveadm acl set -u "${owner}" "${mb}" "user=${READER}" lookup read if [ "${mb}" != "INBOX" ]; then doveadm mailbox subscribe -u "${READER}" "shared/${owner}/${mb}" fi done done