1089 次程式碼提交 (c4ca1cffafe29cedaec72ba918b068a7c83234dd)

作者 SHA1 備註 日期
Alexander Graf a5eeab37e1
Add default for column allow_spoofing 3 年前
Florent Daigniere 3721a6aa02 Merge branch 'master' of https://github.com/Mailu/Mailu into HEAD 3 年前
bors[bot] 2104c04e3b
Merge #2544
2544: Fix #2242: Make quotas adjustable in 50MiB increments r=mergify[bot] a=nextgens

## What type of PR?

enhancement

## What does this PR do?

Make quotas adjustable in 50MiB increments

### Related issue(s)
- closes #2242

## Prerequisites
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.

- [ ] In case of feature or enhancement: documentation updated accordingly
- [x] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/workflow.html#changelog) entry file.


Co-authored-by: Florent Daigniere <nextgens@freenetproject.org>
3 年前
Florent Daigniere 19bd9362d3 As suggested by ghost 3 年前
Florent Daigniere 12117cef37 Reduce the scope of the try: except 3 年前
Florent Daigniere 546884d10c ghost's requested changes 3 年前
Florent Daigniere c1144612be
fix sorting 3 年前
Florent Daigniere 4d8bd210c5
Update run_dev.sh 3 年前
Florent Daigniere ee512112fb
fix flask db history 3 年前
bors[bot] 9c6e9b05db
Merge #2543
2543: Fix #2231: make public announcements work r=nextgens a=nextgens

## What type of PR?

bug-fix

## What does this PR do?

Ensure public announcements bypass filters.

They can still time-out... but this is already a big improvement that we should be able to backport.

### Related issue(s)
- closes #2231

## Prerequisites
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.

- [ ] In case of feature or enhancement: documentation updated accordingly
- [x] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/workflow.html#changelog) entry file.


Co-authored-by: Florent Daigniere <nextgens@freenetproject.org>
3 年前
Florent Daigniere f994c8687e doh 3 年前
Florent Daigniere 44c47586ea Fix potential permission problems 3 年前
Florent Daigniere d3d7916b58 Merge remote-tracking branch 'upstream/master' into upgrade-alpine 3 年前
Florent Daigniere 45b01db9de Fix the language switcher 3 年前
Florent Daigniere 3fc0a0e7fa Merge branch 'master' of https://github.com/Mailu/Mailu into fetchmail-improvements 3 年前
Florent Daigniere 4da2db1b0b add comment as requested 3 年前
Florent Daigniere c79e8d3852 Fix display bug 3 年前
bors[bot] 553b02fb3d
Merge #2529
2529: Improve fetchmail r=mergify[bot] a=nextgens

## What type of PR?

enhancement

## What does this PR do?

Improve fetchmail:
- allow delivery via LMTP (faster, bypassing the filters)
- allow several folders to be retrieved
- run fetchmail as non-root
- tweak the compose file to ensure we have all the dependencies

### Related issue(s)
- closes #1231 
- closes #2246 
- closes #711

## Prerequisites
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.

- [ ] In case of feature or enhancement: documentation updated accordingly
- [x] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/workflow.html#changelog) entry file.

Co-authored-by: Florent Daigniere <nextgens@freenetproject.org>
Co-authored-by: Florent Daigniere <nextgens@users.noreply.github.com>
3 年前
Florent Daigniere dcf11aea48 Don't force a password reset 3 年前
Florent Daigniere f802601a08
Update f4f0f89e0047_.py 3 年前
Florent Daigniere d5ac9199a0
Update 7ac252f2bbbf_.py 3 年前
Florent Daigniere 7822b41048 same for domains 3 年前
Florent Daigniere ef9cc3c866 Show spoofing on /admin/user/list too 3 年前
Florent Daigniere 38507b2e1b Close #2372: Implement a GUI for WILDCARD_SENDERS 3 年前
Florent Daigniere 6a22c82c02 Fix run_dev 3 年前
Florent Daigniere cf7404e26c Fix #2242: Make quotas adjustable in 50MiB increments 3 年前
Florent Daigniere b20bf996ec Fix #2231: make public announcements work 3 年前
Florent Daigniere e2d4e3eb2e Implement header authentication via external proxy 3 年前
Florent Daigniere bdc085048d Restore the Dockerfile like it was 3 年前
Florent Daigniere 699be6f9fa Drop privs when running admin too 3 年前
bors[bot] f43c8c652e
Merge #2483 #2535
2483: Introduce FETCHMAIL_ENABLED r=mergify[bot] a=DjVinnii

## What type of PR?

Enhancement

## What does this PR do?
Add `FETCHMAIL_ENABLED` to enable/disable the Fetchmail functionality in the Admin UI.

### Related issue(s)
- closes #2127

## Prerequisites
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.

- [x] In case of feature or enhancement: documentation updated accordingly
- [x] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/workflow.html#changelog) entry file.


2535: fix the linux/arm/v7 build r=mergify[bot] a=nextgens

## What type of PR?

bug-fix

## What does this PR do?

The arm builder is running aarch64 ... and there is no package for arm/v7


Co-authored-by: Vincent Kling <v.kling@vinniict.nl>
Co-authored-by: Dimitri Huisman <diman@huisman.xyz>
Co-authored-by: Florent Daigniere <nextgens@freenetproject.org>
3 年前
Dimitri Huisman 8afb544a10
Default FETCHMAIL_ENABLED to False 3 年前
bors[bot] 40bdf7a6d9
Merge #2530
2530: disable SESSION_COOKIE_SECURE when TLS_FLAVOR=notls r=mergify[bot] a=nextgens

## What type of PR?

bug-fix

## What does this PR do?

People are unlikely to proxy everything

### Related issue(s)
- closes #2527

Co-authored-by: Florent Daigniere <nextgens@freenetproject.org>
3 年前
Florent Daigniere b9e5560fb6 Better way to express the same thing
Thanks @ghostwheel42
3 年前
Florent Daigniere 66de1dcec8 Change the logic
The idea here is that if you have set SESSION_COOKIE_SECURE we should
honor that... and if you haven't we should try to do the right thing.
3 年前
Florent Daigniere 76f8517e00 This is still required (as TLS_FLAVOR isn't set) 3 年前
Florent Daigniere b9564c0bc9 This shouldn't have been commited 3 年前
Florent Daigniere 19af2944d7 Refactor as requested 3 年前
Alexander Graf 6b470ac403
Allow proper JS debugging, speed-up assets dev-build, disable redirect-debug by default. 3 年前
Florent Daigniere 7aad1158fb @ghostwheel42 will fix it in another PR 3 年前
Florent Daigniere a566cb07d6 fix 3 年前
Florent Daigniere 08b3a2814b Merge branch 'master' of https://github.com/Mailu/Mailu into notls 3 年前
Florent Daigniere 6474108056 Use a join() instead 3 年前
Florent Daigniere c0c91691fd Fix the issue on /admin/fetch/edit 3 年前
Alexander Graf b0b64a8e63
Use FLASK_DEBUG, fix assets, show startup errors. 3 年前
Florent Daigniere 505bb79a78 Don't set the secure Cookie flag if TLS_FLAVOR=notls 3 年前
Florent Daigniere 08a9ab9a56 Improve fetchmail 3 年前
bors[bot] 8a90f83bd0
Merge #2514
2514: Update deps r=mergify[bot] a=ghostwheel42

## What type of PR?

update python dependencies

## What does this PR do?

Update python deps in base image


Co-authored-by: Alexander Graf <ghostwheel42@users.noreply.github.com>
3 年前
bors[bot] 745c211c4a
Merge #2523
2523: fix JS error r=mergify[bot] a=nextgens

## What type of PR?

bug-fix

## What does this PR do?

It fixes a bug whereby one may have to click twice on the submit button depending on timing.

e.trigger() will error out on most browsers.

Co-authored-by: Florent Daigniere <nextgens@freenetproject.org>
3 年前
bors[bot] 0839490beb
Merge #2479
2479: Rework the anti-spoofing rule r=mergify[bot] a=nextgens

## What type of PR?

Feature

## What does this PR do?

We shouldn't assume that Mailu is the only MTA allowed to send emails on behalf of the domains it hosts.
We should also ensure that it's non-trivial for email-spoofing of hosted domains to happen

Previously we were preventing any spoofing of the envelope from; Now we are preventing spoofing of both the envelope from and the header from unless some form of authentication passes (is a RELAYHOST, SPF, DKIM, ARC)

### Related issue(s)
- close #2475

## Prerequisites
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.

- [x] In case of feature or enhancement: documentation updated accordingly
- [x] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/workflow.html#changelog) entry file.


Co-authored-by: Florent Daigniere <nextgens@freenetproject.org>
3 年前
Florent Daigniere c91c9df134 fix error 3 年前
Alexander Graf e0d2432c6b
Rename data-ordered to data-sort 3 年前
Alexander Graf 2a4402cdc2
Fix datatable for list fo sign-up domains 3 年前
Alexander Graf af6cf5fd1d
Fix language selector without session 3 年前
Alexander Graf 2778641e78
Fix screen reader title of language selector 3 年前
Alexander Graf 4776094ea7
Configure datatables on missing tables, add sign in button to sso page. 3 年前
Alexander Graf 6218b36372
configure datatables via html5 data attributes 3 年前
Alexander Graf a74396a9ef
Fix wtforms usage 3 年前
Alexander Graf 4b179d9008
Merge branch 'master' into hibp 3 年前
Alexander Graf 36019a8ce9
Don't show Dockerfile before building 3 年前
Alexander Graf 91e12d510d
Use default password used everywhere else 3 年前
Alexander Graf defd533319
Don't duplicate hidden fields 3 年前
Alexander Graf db87a0f3a1
Move temporary db into container and show docker run command 3 年前
Alexander Graf f7caaddbec
Speed up asset building when developing 3 年前
Alexander Graf 71263f1a8c
Add more env variables and restyle code 3 年前
Alexander Graf fd8570ec34
Remove unused QUOTA_STORAGE_URL 3 年前
Alexander Graf bbeb211d72
Listen to localhost by default 3 年前
Alexander Graf 1d90dc3ea3
Allow running without redis 3 年前
Alexander Graf c507b765be
Improve dev runner 3 年前
Alexander Graf 8732b70b30
Add shell script to run admin dev environment 3 年前
Alexander Graf ea636a1835
Fix hibp test 3 年前
Alexander Graf 311f41c331
Add missing hidden fields 3 年前
Alexander Graf 27a5f9db65
Reformatting 3 年前
Vincent Kling 83fdc07a6f Default FETCHMAIL_ENABLED to True 3 年前
Florent Daigniere 54e9858633 this 3 年前
Florent Daigniere 14f802fb4a untested but that should work 3 年前
bors[bot] e0ff135a00
Merge #2498
2498: Implement ITERATE in podop r=mergify[bot] a=nextgens

## What type of PR?

Feature

## What does this PR do?

This makes ``doveadm -A`` work.

The easiest way to try it out is:
```
doveadm dict iter proxy:/tmp/podop.socket:auth shared/userdb

or 

doveadm user '*'
```

The protocol is described at https://doc.dovecot.org/developer_manual/design/dict_protocol/
The current version of dovecot is not using flags... so there's little gain in implementing them.

### Related issue(s)
- close #2499

## Prerequisites
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.

- [ ] In case of feature or enhancement: documentation updated accordingly
- [x] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/workflow.html#changelog) entry file.


Co-authored-by: Florent Daigniere <nextgens@freenetproject.org>
Co-authored-by: Alexander Graf <ghostwheel42@users.noreply.github.com>
3 年前
Alexander Graf c57706ad27
Duh 3 年前
Alexander Graf 46773f639b
Return 404 is user-id cannot be parsed 3 年前
Alexander Graf 595b32cf97
Fix quota return value 3 年前
Alexander Graf bec0b1c3b2
Fix variable name 3 年前
Florent Daigniere 001acd60ac doh2 3 年前
Alexander Graf dec5309ef9
Fix typo 3 年前
Florent Daigniere 6b7026ef69 Here too 3 年前
Florent Daigniere 24b2c7c04a doh 3 年前
Florent Daigniere 66250e396c refactor 3 年前
wkr d920b3d037 fix(auto-reply): include start and end dates in the auto-reply period; issue #2512 3 年前
Alexander Graf 91f86a4c2a
Resolve using socrate function 3 年前
Florent Daigniere 9cb8df57c6 enforce at least 8 chars 3 年前
Florent Daigniere afbaabd8cd v1 3 年前
Florent Daigniere c1f571a4c3 Speed things up.
If we want to go further than this we should change podop's incr(), pass
the flags and make admin process the results.
3 年前
Florent Daigniere cf34be967c Implement ITERATE 3 年前
bors[bot] 12480ccbff
Merge #2328
2328: Feature: Configurable default spam threshold used for new users r=mergify[bot] a=enginefeeder101

## What type of PR?

Feature

## What does this PR do?

This PR adds functionality to set a custom default spam threshold
for new users. The environment variable ``DEFAULT_SPAM_THRESHOLD`` is
used for this purpose. When not set, it defaults back to 80%, as the
default value was before.

If ``DEFAULT_SPAM_THRESHOLD`` is set to a value that Python cannot
parse as an integer, a ValueError is thrown. There is no error handling
for that case built-in. Should that be done?

## Prerequisites
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.

- [x] In case of feature or enhancement: documentation updated accordingly
- [x] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/workflow.html#changelog) entry file.


Co-authored-by: enginefeeder101 <enginefeeder101@users.noreply.github.com>
Co-authored-by: Dimitri Huisman <diman@huisman.xyz>
3 年前
Dimitri Huisman 06b784da57
Shorten default function by using lambda 3 年前
bors[bot] 9975a793fe
Merge #2458
2458: Fix: Don't update updated_at on quota_bytes_used change r=mergify[bot] a=DjVinnii

## What type of PR?

bug-fix

## What does this PR do?

This PR makes sure that the `updated_at` field is not updated when `quota_bytes_used` is updated. All other updates to the `User` model still updates the `updated_at` field. 

This is done by explicitly using an method in the `Base` class triggering [`flag_modified`][url-flag-modified].

### Related issue(s)
- closes #1363

## Prerequisites
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.

- [ ] In case of feature or enhancement: documentation updated accordingly
- [x] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/workflow.html#changelog) entry file.

<!-- LINKS-->
[url-flag-modified]: https://docs.sqlalchemy.org/en/14/orm/session_api.html#sqlalchemy.orm.attributes.flag_modified


Co-authored-by: Vincent Kling <v.kling@vinniict.nl>
3 年前
bors[bot] 5703e97c73
Merge #2460
2460: Switch to a base image containing base tools and the podop and socrate libs r=mergify[bot] a=ghostwheel42

## What type of PR?

enhancement of build process

## What does this PR do?

Changes build.hcl to build core images using a base image.
Also adds a "assets" base image for the admin container.


Co-authored-by: Alexander Graf <ghostwheel42@users.noreply.github.com>
Co-authored-by: Pierre Jaury <pierre@jaury.eu>
Co-authored-by: kaiyou <pierre@jaury.eu>
Co-authored-by: Dimitri Huisman <52963853+Diman0@users.noreply.github.com>
3 年前
Vincent Kling 6363acf30a Add dont_change_updated_at to fetch_done 3 年前
Vincent Kling 6b785abb01 Rename flag_updated_at_as_modified to dont_change_updated_at 3 年前
Florent Daigniere 84a722eabc Optimize the query 3 年前
Vincent Kling 8a60b658b4 Implement FETCHMAIL_ENABLED 3 年前