1240 次代码提交 (0bfbb3bcd48325da8f07198700e42e6ebbfd4d86)

作者 SHA1 备注 提交日期
Erriez 4b0694705c Fix build dependencies pycares 4 年前
Dimitri Huisman 51d94b8d14 Fix issue 2102 4 年前
Will b2abbc8856 update Dockerfile to alpine 3.14.3 4 年前
Florent Daigniere bee6e980e3 doh 4 年前
Florent Daigniere 58d0faff7f ensure we clear the token on delete() 4 年前
Florent Daigniere 2b29cfb3f0 fix cleanup_sessions() 4 年前
Florent Daigniere f0247a2faf Use self where appropriate 4 年前
Florent Daigniere c161a2c987 syntax 4 年前
bors[bot] 18865bf03b
Merge #2094
2094: Sessions tweaks r=mergify[bot] a=nextgens

## What type of PR?

bug-fix

## What does this PR do?

- Make all sessions permanent, introduce SESSION_TIMEOUT and PERMANENT_SESSION_LIFETIME.
- Prevent the creation of a session before there is a login attempt
- Ensure that webmail tokens are in sync with sessions

### Related issue(s)
- close #2080 

## Prerequisites
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.

- [x] In case of feature or enhancement: documentation updated accordingly
- [x] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/workflow.html#changelog) entry file.


Co-authored-by: Florent Daigniere <nextgens@freenetproject.org>
Co-authored-by: Dimitri Huisman <diman@huisman.xyz>
4 年前
Dimitri Huisman d40be05117 Fix missing edit buttons in alias, relay and fetchmail lists in admin. 4 年前
Florent Daigniere a28c7f903e do it once 4 年前
Dimitri Huisman f88daa1e77 Add missing cast to int 4 年前
Florent Daigniere 5f313310d4 regenerate() shouldn't extend lifetime 4 年前
Florent Daigniere fe18cf9743 Fix 2080
Ensure that webmail tokens are in sync with sessions
4 年前
Florent Daigniere 02c93c44f2 Tweak sessions
simplify:
- make all sessions permanent by default
- update the TTL of sessions on access (save always)
- fix session-expiry, modulo 8byte precision
4 年前
Florent Daigniere ea96a68eb4 don't create a session if we don't have to 4 年前
bors[bot] 7c03878347
Merge #1441 #2090
1441: Rsyslog logging for postfix r=mergify[bot] a=micw


## What type of PR?

enhancement

## What does this PR do?
Changes postfix logging from stdout to rsyslog:
* stdout logging still enabled
* internal test request log messages are filtered out by rsyslog
* optional logging to file via POSTFIX_LOG_FILE env variable

## Prerequistes
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.

- [x] In case of feature or enhancement: documentation updated accordingly
- [x] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/guide.html#changelog) entry file.


2090: fix 2086 r=mergify[bot] a=nextgens

## What type of PR?

bug-fix

## What does this PR do?

Fix a bug I've introduced in ae8db08bd

### Related issue(s)
- close #2086

Co-authored-by: Michael Wyraz <michael@wyraz.de>
Co-authored-by: Dimitri Huisman <diman@huisman.xyz>
Co-authored-by: Dimitri Huisman <52963853+Diman0@users.noreply.github.com>
Co-authored-by: Florent Daigniere <nextgens@freenetproject.org>
4 年前
Florent Daigniere 346ace5fb3 Make webmail the default action 4 年前
bors[bot] 634318adba
Merge #2072
2072: use dovecot-fts-xapian from alpine package r=mergify[bot] a=willofr

## What type of PR?

enhancement

## What does this PR do?
use dovecot-fts-xapian from alpine packages repository (newer) instead of compiling an older version from source
see https://pkgs.alpinelinux.org/package/edge/community/x86/dovecot-fts-xapian

### Related issue(s)
No

## Prerequisites
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.

- [x] In case of feature or enhancement: documentation updated accordingly
- [x] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/workflow.html#changelog) entry file.


Co-authored-by: willofr <willofr@users.noreply.github.com>
4 年前
Florent Daigniere 09926702d6 fix 2086 4 年前
bors[bot] e7f77875e2
Merge #2084
2084: Fix #2078 (login to webmail did not work when WEB_WEBMAIL=/ was set) r=mergify[bot] a=Diman0

## What type of PR?

bug-fix

## What does this PR do?
It fixes #2078. Login from SSO page to webmail did not work if WEB_WEBMAIL=/ was set in mailu.env.

I tested that it works with
- WEB_WEBMAIL=/webmail
- WEB_WEBMAIL=/

### Related issue(s)
- closes #2078 

## Prerequisites
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.

- [x] n/a In case of feature or enhancement: documentation updated accordingly
- [x] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/workflow.html#changelog) entry file.


Co-authored-by: Dimitri Huisman <diman@huisman.xyz>
Co-authored-by: Florent Daigniere <nextgens@users.noreply.github.com>
4 年前
Florent Daigniere d7a8235b89
Simplify 4 年前
bors[bot] 08be233607
Merge #2058
2058: Implement versioning for CI/CD workflow. r=mergify[bot] a=Diman0

## What type of PR?

Feature!

## What does this PR do?
This PR introduces 3 things
- Add versioning (tagging) for branch x.y (1.8). E.g. 1.8.0, 1.8.1 etc.
  - docker repo will contain x.y (latest) and x.y.z (pinned version) images.
  - The X.Y.Z tag is incremented automatically. E.g. if 1.8.0 already exists, then the next merge on 1.8 will result in the new tag 1.8.1 being used.
- Make the version available in the image.
  -  For X.Y and X.Y.Z write the version (X.Y.Z) into /version on the image and add a label with version=X.Y.Z
	  -  This means that the latest X.Y image shows the pinned version (X.Y.Z e.g. 1.8.1) it was based on. Via the tag X.Y.Z you can see the commit hash that triggered the built.
  -  For master write the commit hash into /version on the image and add a label with version={commit hash}
-  Automatic releases. For x.y triggered builts (e.g. merge on 1.9) do a new github release for the pinned x.y.z (e.g. 1.9.2). 
  -  Release shows a static message (see RELEASE_TEMPLATE.md) that explains how to reach the newsfragments folder and change the branch to the tag (x.y.z) mentioned in the release. Now you can get the changelog by reading all newsfragment files in this folder.

This PR does not change anything to our workflow (what we (human persons) do). Our processes are still exactly the same. The above introduced logic is automatic. When we backport to X.Y all the magic for creating the pinned version X.Y.Z is handled by the CI/CD workflow.

### Related issue(s)
- closes #1182

## Prerequisites
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.

- [x] In case of feature or enhancement: documentation updated accordingly
- [x] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/workflow.html#changelog) entry file.

## Testing
Suggested testing steps. This should cover all situations including BORS. It does require that you use your own docker repo or temporarily create a new one.
Suggested testing steps.
1. Create new github repo.
2. Add the required docker secrets to the project (see beginning of CI.yml for the secret names), DOCKER_UN, DOCKER_PW, DOCKER_ORG, DOCKER_ORG_TESTS.
3. Clone the project.
4. Copy the contents of the PR to the cloned project.
5. Push to your new github repo.
6. Now master images are built. Check that images with tag master are pushed to your docker repo
7. Check with docker inspect nginx:master that it has the label version={commit hash}.
8. Run an image, run `docker-compose exec <name> cat /version`. Note that /version also contains the pinned version. For master the pinned version is the commit hash.
9. Create branch 1.8. 
10. Push branch 1.8 to repo.
11. Note that tags 1.8 and 1.8.0 are built and pushed to docker repo
12. Inspect label and /version. Note that 1.8 and 1.8.0 both show version 1.8.0.
13. Push another commit to branch 1.8.
14. Note that tags 1.8 and 1.8.1 are built and pushed to docker repo
15. Inspect label and /version. Note that 1.8 and 1.8.1 both show version 1.8.1.
16. Let's check BORS stuff.
17. Create branch testing.
18. Push the commit with the exact commit text (IMPORTANT!!): `Try #1234:`'.
19. Note that images are built and pushed for tag `pr-1234`.
20. Inspect label and /version. Note that the version is `pr-1234`.
20. Create branch staging.
21. Push the commit with commit text: `Merge #1234`.
22. Note that this image is not pushed to docker (as expected).

but you could also check the GH repo and docker repo I used:
https://github.com/Diman0/Mailu_Fork
https://hub.docker.com/r/diman/rainloop/tags

Co-authored-by: Dimitri Huisman <diman@huisman.xyz>
4 年前
bors[bot] d2a2a3a8bf
Merge #2076
2076: fix the default for DEFER_ON_TLS_ERROR r=mergify[bot] a=nextgens

## What type of PR?

bug-fix

## What does this PR do?

The default wasn't set anywhere

Co-authored-by: Florent Daigniere <nextgens@freenetproject.org>
4 年前
Dimitri Huisman fdb10cfb85 Start crond when POSTFIX_LOG_FILE is set 4 年前
Dimitri Huisman 5bedcc1cb1 Fix #2078 4 年前
Dimitri Huisman d76773b1df Also check the SMTP port for webmail/token 4 年前
Dimitri Huisman f26fa8da84 Fix Webmail token check. Fix Auth-Port for Webmail. #2079 4 年前
Florent Daigniere 593e3ac5a4 fix DEFER_ON_TLS_ERROR 4 年前
willofr 841b29e794
revert back to alpine 3.14.2 as requested 4 年前
willofr 73f5291cdb
Merge branch 'Mailu:master' into patch-1 4 年前
Dimitri Huisman 53975684b8 Using Syslog is the new standard. It is not optional anymore. 4 年前
willofr 84af3a3e50
use dovecot-fts-xapian from alpine package
I suggest using the dovecot-fts-xapian package from the alpine repository (newer) instead of compiling an older version from source:
see https://pkgs.alpinelinux.org/package/edge/community/x86/dovecot-fts-xapian
4 年前
Florent Daigniere 4fffdd95e9 Reduce logging level 4 年前
Dimitri Huisman d5896fb2c6 Add log rotation (if logging to file). Make rsyslog the default. 4 年前
Florent Daigniere 89a7a8ac13 Fix score of RCVD_NO_TLS_LAST 4 年前
Florent Daigniere 1925b2e0fb Upgrade rspamd 4 年前
Dimitri Huisman 567b5ef172
Merge branch 'master' into postfix-logging 4 年前
Dimitri Huisman 0de2ec77c6 Process code review remarks #1441 4 年前
Dimitri Huisman f7677543c6 Process code review remarks
- Moved run to bottom of Dockerfile to allow using unmodified / cached states.
- Simplified bash code in deploy.sh.
- Improved the large bash one-liner in CI.yml. It could not handle >9 for 1.x.
4 年前
Dimitri Huisman 56dd70cf4a Implement versioning for CI/CD workflow (see #1182). 4 年前
Alexander Graf aa1d605665
Merge remote-tracking branch 'upstream/master' into passlib 4 年前
Alexander Graf 84a5514a97
fixed auto reply form 4 年前
Alexander Graf cf7914d050
fixed field iteration 4 年前
Alexander Graf fd5bdc8650
added localized date output 4 年前
Alexander Graf 0315ed78d9
Merge remote-tracking branch 'upstream/master' into update_deps 4 年前
Till Skrodzki c48e00ee26 Do not call .split() on RELAYNETS if not specified 4 年前
bors[bot] 56cbc56df7
Merge #2044
2044: Vault/rspamd: don't return any key for relayed domains r=mergify[bot] a=nextgens

## What type of PR?

enhancement

## What does this PR 

Don't return any key for relayed domains. We may want to revisit this (ARC signing)... but in the meantime it saves from a scary message in rspamd.
    
```signing failure: cannot request data from the vault url: /internal/rspamd/vault/v1/dkim/ ...```


Co-authored-by: Florent Daigniere <nextgens@freenetproject.org>
4 年前
bors[bot] 78dd13a217
Merge #2042
2042: Add MESSAGE_RATELIMIT_EXEMPTION r=mergify[bot] a=nextgens

## What type of PR?

Enhancement

## What does this PR do?

Add a new knob called ```MESSAGE_RATELIMIT_EXEMPTION```.

### Related issue(s)
- #1774

## Prerequisites
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.

- [x] In case of feature or enhancement: documentation updated accordingly
- [ ] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/workflow.html#changelog) entry file.


Co-authored-by: Florent Daigniere <nextgens@freenetproject.org>
4 年前
Florent Daigniere 6bf1a178b9 Go with ghostwheel42's suggestion 4 年前
Florent Daigniere b68033eb43 only parse it once 4 年前
Alexander Graf 82e14f1292
Merge branch 'master' into update_deps 4 年前
bors[bot] f0188d9623
Merge #2034
2034: Add timezone to containers r=mergify[bot] a=DjVinnii

## What type of PR?

Enhancement

## What does this PR do?
This PR adds the tzdata package so that the environment variable `TZ` can be used to set the timezone of containers.

### Related issue(s)
- closes #1154 

## Prerequisites
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.

- [x] In case of feature or enhancement: documentation updated accordingly
- [x] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/workflow.html#changelog) entry file.


Co-authored-by: DjVinnii <vincentkling@msn.com>
4 年前
Florent Daigniere dc6e970a7f handle HTTP too 4 年前
Florent Daigniere bbef4bee27 Don't return any key for relayed domains
We may want to revisit this (ARC signing)... but in the meantime
it saves from a scary message in rspamd

signing failure: cannot request data from the vault url: /internal/rspamd/vault/v1/dkim/ ...
4 年前
Florent Daigniere 6c6b0b161c Set the right flags on the rate_limit cookie 4 年前
Florent Daigniere f9373eacab Merge remote-tracking branch 'upstream/master' into misc 4 年前
Florent Daigniere 5714b4f4b0 introduce MESSAGE_RATELIMIT_EXEMPTION 4 年前
DjVinnii 30d7e72765 Move TZ to Advanced settings 4 年前
DjVinnii 225160610b Set default TZ in Dockerfiles 4 年前
DjVinnii 81e33d3679 Add default TZ to config manager 4 年前
Alexander Graf 97e79a973f fix sso login button spacing again 4 年前
Alexander Graf 73ab4327c2 updated database libraries (sqlalchemy etc.)
this is working fine, but introduces a sqlalchemy warning
when using config-import:

  /app/mailu/schemas.py:822:
    SAWarning: Identity map already had an identity for (...),
    replacing it with newly flushed object.
    Are there load operations occurring inside of an event handler
    within the flush?
4 年前
Alexander Graf 4669374b9e use python wheels 4 年前
Alexander Graf 85d86d4156 some more libs updated 4 年前
Alexander Graf ffd99c3fa8 updated flask
ConfigManager should not replace app.config - this is causing trouble
with some other flask modules (swagger).
Updated ConfigManager to only modify app.config and not replace it.
4 年前
Alexander Graf 87884213c4 update misc helper libs 4 年前
Alexander Graf 56f65d724d update babel 4 年前
Alexander Graf 5238b00f0b update alembic 4 年前
Alexander Graf f613205fe1 update tenacity 4 年前
Alexander Graf 833ccb5544 reload page using GET when selecting language 4 年前
Alexander Graf 8b15820b01 fix sso login button spacing 4 年前
Alexander Graf 26fb108a3f updated Flask-Login 4 年前
Alexander Graf abc4112242 updated Werkzeug, Click and Flask-Migrate 4 年前
Alexander Graf f1d7bedd1b fix display of range inputs (again) 4 年前
Alexander Graf 13e6793c9f Merge remote-tracking branch 'upstream/master' into update_deps 4 年前
Alexander Graf aca1e13648 update socrate - will be removed later 4 年前
Alexander Graf 866741bcbe updated WTForms-Components deps 4 年前
Alexander Graf ef19869cde updated redis 4 年前
Alexander Graf d8efd3057c updated idna 4 年前
Alexander Graf 8ad8cde0e2 removed some obsolete requirements 4 年前
Alexander Graf 3ac1b3d86c update pyyaml and pygments 4 年前
Alexander Graf 40cdff4911 updated dnspython 4 年前
Alexander Graf dcbe55f062 updated crypto 4 年前
Alexander Graf 771b2d1112 duh 4 年前
Alexander Graf 23d0cd0466 update tabluate. fix audit.py and include in container 4 年前
Alexander Graf 8d90a74624 update werkzeug to 1.x 4 年前
bors[bot] 5e212ea46d
Merge #2036
2036: round display of range inputs to 2 decimals r=mergify[bot] a=ghostwheel42

## What type of PR?

small fix

## What does this PR do?

rounds display of range inputs to 2 decimals 

### Related issue(s)

- small fix to #1966

## Prerequisites
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.

- [X] In case of feature or enhancement: documentation updated accordingly
- [X] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/workflow.html#changelog) entry file.


Co-authored-by: Alexander Graf <ghostwheel42@users.noreply.github.com>
4 年前
Alexander Graf 80be3506da upgrade pip. completed reqs via pip freeze 4 年前
Alexander Graf 598b2df5a0 update wtforms 4 年前
Alexander Graf e8b5f1a185 round display of range inputs to 2 decimals 4 年前
DjVinnii 1d6809193b Add tzdata to core 4 年前
Florent Daigniere 74b31dc407 Ensure that RCVD_NO_TLS_LAST doesn't add spam points 4 年前
bors[bot] 11bbceb9cc
Merge #2032
2032: doh r=mergify[bot] a=nextgens

This should have been part of #2030

Co-authored-by: Florent Daigniere <nextgens@freenetproject.org>
4 年前
Florent Daigniere 8dad40f67c doh 4 年前
bors[bot] e52a3de1b0
Merge #2027 #2030
2027: Make logs more quiet r=mergify[bot] a=nextgens

## What type of PR?

enhancement

## What does this PR do?

It silences various useless log messages in front, specifically:
```
Oct 30 03:11:04 instance-20210109-1612 docker-front[1963]: 127.0.0.1 - - [30/Oct/2021:03:11:04 +0000] "GET /health HTTP/1.1" 301 162 "-" "curl/7.78.0"
Oct 30 03:11:04 instance-20210109-1612 docker-front[1963]: 127.0.0.1 - - [30/Oct/2021:03:11:04 +0000] "GET /health HTTP/2.0" 204 0 "-" "curl/7.78.0"
Oct 30 03:11:04 instance-20210109-1612 docker-front[1963]: 2021/10/30 03:11:04 [info] 476302#476302: *2622679 client 127.0.0.1 closed keepalive connection
Oct 30 03:13:02 instance-20210109-1612 docker-front[1963]: 127.0.0.1 - - [30/Oct/2021:03:13:02 +0000] "GET /auth/email HTTP/1.0" 200 0 "-" "-"
```

`@micw` has requested it for k8s

2030: Fix RELAYNETS r=mergify[bot] a=nextgens

## What type of PR?

bug-fix

## What does this PR do?

RELAYNETS should be comma separated like everything else; rspamd should also be aware of what is considered "trusted".

I am not sure whether ```local_networks``` is the right configuration option for it though

- close #360

Co-authored-by: Florent Daigniere <nextgens@freenetproject.org>
4 年前
Florent Daigniere 2170e07731 Tell rspamd about RELAYNETS 4 年前
Florent Daigniere 9d474f32a6 RELAYNETS is comma separated! 4 年前
Florent Daigniere f3c93212c6 The Rate-limiter should run after the deny 4 年前
Florent Daigniere 53a0363b9e Deal with the noisy keepalive messages
We don't particularly care about HTTP... and that's what's noisy.
4 年前