1
0
mirror of https://github.com/Mailu/Mailu.git synced 2025-06-23 00:28:06 +02:00
Commit Graph

3738 Commits

Author SHA1 Message Date
2a894cb15d Process nextgens review remarks 2022-11-10 20:03:26 +01:00
92f270c94e Update the webmail images:
Roundcube
  - Switch to base image (alpine)
  - Switch to php-fpm
SnappyMail
  - Switch to base image
  - Upgrade php7 to php8.
2022-11-10 15:51:22 +00:00
745c211c4a Merge #2523
2523: fix JS error r=mergify[bot] a=nextgens

## What type of PR?

bug-fix

## What does this PR do?

It fixes a bug whereby one may have to click twice on the submit button depending on timing.

e.trigger() will error out on most browsers.

Co-authored-by: Florent Daigniere <nextgens@freenetproject.org>
2022-11-09 15:34:37 +00:00
0839490beb Merge #2479
2479: Rework the anti-spoofing rule r=mergify[bot] a=nextgens

## What type of PR?

Feature

## What does this PR do?

We shouldn't assume that Mailu is the only MTA allowed to send emails on behalf of the domains it hosts.
We should also ensure that it's non-trivial for email-spoofing of hosted domains to happen

Previously we were preventing any spoofing of the envelope from; Now we are preventing spoofing of both the envelope from and the header from unless some form of authentication passes (is a RELAYHOST, SPF, DKIM, ARC)

### Related issue(s)
- close #2475

## Prerequisites
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.

- [x] In case of feature or enhancement: documentation updated accordingly
- [x] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/workflow.html#changelog) entry file.


Co-authored-by: Florent Daigniere <nextgens@freenetproject.org>
2022-11-09 15:16:36 +00:00
c91c9df134 fix error 2022-11-09 11:52:53 +01:00
cf6da1492e Merge #2157
2157: configure datatables via html5 data attributes r=mergify[bot] a=ghostwheel42

## What type of PR?

bug-fix

## What does this PR do?

allows to sort most columns as a human would expect

### Related issue(s)
- closes #2154 

## Prerequisites
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.

- [ ] In case of feature or enhancement: documentation updated accordingly
- [ ] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/workflow.html#changelog) entry file.


Co-authored-by: Alexander Graf <ghostwheel42@users.noreply.github.com>
2022-11-08 16:10:49 +00:00
e0d2432c6b Rename data-ordered to data-sort 2022-11-08 16:22:24 +01:00
2a4402cdc2 Fix datatable for list fo sign-up domains 2022-11-08 13:27:57 +01:00
af6cf5fd1d Fix language selector without session 2022-11-08 13:27:57 +01:00
2778641e78 Fix screen reader title of language selector 2022-11-08 13:27:56 +01:00
4776094ea7 Configure datatables on missing tables, add sign in button to sso page. 2022-11-08 13:27:56 +01:00
6218b36372 configure datatables via html5 data attributes 2022-11-08 13:27:56 +01:00
896e7fb54b Merge #2500
2500: Password policy enforcement r=mergify[bot] a=nextgens

## What type of PR?

Feature

## What does this PR do?

It enforces that all new passwords set by users are at least 8 characters in length and checks all users' passwords at login time against HIBP.

The HIBP part requires javascript and Mailu to be accessed over HTTPS to work but degrades gracefully (no message will be shown if the requirements are not met).

It was a conscious choice to implement it at this level: administrators can set weaker passwords using non-HTTP based interfaces.

### Related issue(s)
- close #2208
- close #287

## Prerequisites
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.

- [ ] In case of feature or enhancement: documentation updated accordingly
- [x] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/workflow.html#changelog) entry file.

Co-authored-by: Florent Daigniere <nextgens@freenetproject.org>
Co-authored-by: Alexander Graf <ghostwheel42@users.noreply.github.com>
2022-11-08 07:55:25 +00:00
4b179d9008 Merge branch 'master' into hibp 2022-11-07 23:05:51 +01:00
4563038b32 Merge #2518
2518: Add dev runner for admin container r=mergify[bot] a=ghostwheel42

## What type of PR?

development feature

## What does this PR do?

This adds a shell script (run_dev.sh) to run a live development environment in a container.


Co-authored-by: Alexander Graf <ghostwheel42@users.noreply.github.com>
2022-11-07 15:50:10 +00:00
36019a8ce9 Don't show Dockerfile before building 2022-11-07 16:48:58 +01:00
dd3cd1263e Add development documentation again 2022-11-07 16:47:13 +01:00
91e12d510d Use default password used everywhere else 2022-11-07 16:35:01 +01:00
defd533319 Don't duplicate hidden fields 2022-11-07 16:16:09 +01:00
db87a0f3a1 Move temporary db into container and show docker run command 2022-11-04 23:51:32 +01:00
f7caaddbec Speed up asset building when developing 2022-11-04 23:39:39 +01:00
71263f1a8c Add more env variables and restyle code 2022-11-04 23:21:11 +01:00
fd8570ec34 Remove unused QUOTA_STORAGE_URL 2022-11-04 22:20:08 +01:00
bbeb211d72 Listen to localhost by default 2022-11-04 21:41:31 +01:00
1d90dc3ea3 Allow running without redis 2022-11-04 18:54:59 +01:00
c507b765be Improve dev runner 2022-11-04 18:29:45 +01:00
8732b70b30 Add shell script to run admin dev environment 2022-11-04 18:08:23 +01:00
ea636a1835 Fix hibp test 2022-11-04 15:13:56 +01:00
ac93e6a9be Merge #2517
2517: Use the new notation: arm64/v8 instead of arm64 r=mergify[bot] a=nextgens

## What type of PR?

bug-fix

## What does this PR do?

With a modern version of docker compose, on arm64 you get:
```
docker-compose pull 
[+] Running 0/8
 ⠼ admin Pulling                                                                                                                                                                        1.4s
 ⠿ smtp Error                                                                                                                                                                           1.4s
 ⠿ imap Error                                                                                                                                                                           1.4s
 ⠿ webmail Error                                                                                                                                                                        1.4s
 ⠿ antispam Error                                                                                                                                                                       1.4s
 ⠼ redis Pulling                                                                                                                                                                        1.4s
 ⠼ front Pulling                                                                                                                                                                        1.4s
 ⠿ resolver Error                                                                                                                                                                       1.4s
no matching manifest for linux/arm64/v8 in the manifest list entries
```

This may fix it.

It's discussed at https://stackoverflow.com/questions/70819028/relation-between-linux-arm64-and-linux-arm64-v8-are-these-aliases-for-each-othe

Co-authored-by: Florent Daigniere <nextgens@freenetproject.org>
Co-authored-by: Dimitri Huisman <diman@huisman.xyz>
2022-11-04 13:22:34 +00:00
2a3266b6b8 Forgot to update both deploy jobs 2022-11-04 14:13:06 +01:00
b2e47642f7 Tag the images with latest tag as well. 2022-11-04 13:49:05 +01:00
311f41c331 Add missing hidden fields 2022-11-04 13:35:38 +01:00
27a5f9db65 Reformatting 2022-11-04 13:35:13 +01:00
3e9def6cd9 Use the new notation: arm64/v8 instead of arm64 2022-11-04 10:46:45 +01:00
54e9858633 this 2022-11-03 18:42:19 +01:00
14f802fb4a untested but that should work 2022-11-03 18:38:55 +01:00
e0ff135a00 Merge #2498
2498: Implement ITERATE in podop r=mergify[bot] a=nextgens

## What type of PR?

Feature

## What does this PR do?

This makes ``doveadm -A`` work.

The easiest way to try it out is:
```
doveadm dict iter proxy:/tmp/podop.socket:auth shared/userdb

or 

doveadm user '*'
```

The protocol is described at https://doc.dovecot.org/developer_manual/design/dict_protocol/
The current version of dovecot is not using flags... so there's little gain in implementing them.

### Related issue(s)
- close #2499

## Prerequisites
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.

- [ ] In case of feature or enhancement: documentation updated accordingly
- [x] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/workflow.html#changelog) entry file.


Co-authored-by: Florent Daigniere <nextgens@freenetproject.org>
Co-authored-by: Alexander Graf <ghostwheel42@users.noreply.github.com>
2022-11-03 16:54:24 +00:00
c57706ad27 Duh 2022-11-03 17:50:39 +01:00
46773f639b Return 404 is user-id cannot be parsed 2022-11-03 17:45:21 +01:00
595b32cf97 Fix quota return value 2022-11-03 17:37:21 +01:00
bec0b1c3b2 Fix variable name 2022-11-03 17:26:27 +01:00
001acd60ac doh2 2022-11-03 16:44:18 +01:00
dec5309ef9 Fix typo 2022-11-03 16:39:29 +01:00
6b7026ef69 Here too 2022-11-03 16:28:07 +01:00
24b2c7c04a doh 2022-11-03 16:25:10 +01:00
66250e396c refactor 2022-11-03 16:19:44 +01:00
5b2b379c91 Merge #2513
2513: fix(auto-reply): include start and end dates in the auto-reply period r=mergify[bot] a=bb-wkr

## What type of PR?
bug-fix

## What does this PR do?
Include start and end dates in the auto-reply period

### Related issue(s)
closes #2512

## Prerequisites
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry is not applicable, you can check it or remove it from the list.

- [X] In case of feature or enhancement: documentation updated accordingly
- [X] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/workflow.html#changelog) entry file.


Co-authored-by: wkr <wkr@bitsbeats.com>
2022-11-03 07:53:24 +00:00
wkr
d920b3d037 fix(auto-reply): include start and end dates in the auto-reply period; issue #2512 2022-11-02 17:48:22 +01:00
323f0a4e70 Merge #2509
2509: Login docker.io to prevent rate limiting for pulling images r=mergify[bot] a=Diman0

## What type of PR?

feat/fix

## What does this PR do?
Added login to docker.io for CI/CD workflow. When logged in, we have a higher limit for pulling images. The arm workers were rate limited.


Co-authored-by: Dimitri Huisman <diman@huisman.xyz>
2022-11-01 15:37:50 +00:00
db7ce8c83e Login docker.io to prevent rate limiting for pulling images 2022-11-01 15:18:03 +00:00