FreddleSpl0it and GitHub
02552ffefd
Merge pull request #7427 from mailcow/staging
...
Update 2026-07b
2026-07b
2026-08-18 09:29:10 +02:00
FreddleSpl0it and GitHub
6644699e65
Merge pull request #7426 from mailcow/fix/web-hardening
...
[Web] Minor hardening across web UI and nginx
2026-08-18 09:10:09 +02:00
FreddleSpl0it
91d3b7246a
[Web] Minor hardening across web UI and nginx
2026-08-18 09:08:17 +02:00
FreddleSpl0it and GitHub
b362c7105d
Merge pull request #7425 from mailcow/feat/redis-7.4.10
...
[Redis] Update to 7.4.10
2026-08-18 08:14:21 +02:00
FreddleSpl0it
555e7ed706
[Redis] Update to 7.4.10
2026-08-18 08:12:32 +02:00
FreddleSpl0it and GitHub
59e2a9ac77
Merge pull request #7423 from mailcow/fix/7418
...
[Dovecot] Remove legacy DeltaChat auto-filing sieve rule
2026-08-17 08:41:18 +02:00
FreddleSpl0it
feed5ad183
[Dovecot] Remove legacy DeltaChat auto-filing sieve rule
2026-08-17 08:35:53 +02:00
FreddleSpl0it and GitHub
f1f7a9800b
Merge pull request #7422 from mailcow/feat/sogo-5.12.10
...
[SOGo] Update to 5.12.10
2026-08-17 08:24:10 +02:00
FreddleSpl0it
8c85044781
[SOGo] Update to 5.12.10
2026-08-17 08:20:45 +02:00
FreddleSpl0it and GitHub
8fb32e4b59
Merge pull request #7415 from mailcow/feat/clamd-1.4.6
...
[Clamd] Update to 1.4.6
2026-08-13 13:59:13 +02:00
FreddleSpl0it
b5fa926bc0
[Clamd] Update to 1.4.6
2026-08-13 13:56:49 +02:00
FreddleSpl0it and GitHub
06424670fa
Merge pull request #7393 from mailcow/staging
...
update README.md sponsors
2026-08-05 09:00:52 +02:00
d1a2f4e168
Translations update from Weblate ( #7400 )
...
* [Web] Updated lang.si-si.json
Co-authored-by: Matjaž Tekavec <matjaz@moj-svet.si >
Co-authored-by: milkmaker <milkmaker@mailcow.de >
* [Web] Updated lang.pt-br.json
Co-authored-by: André Glazastov <andre@glazastov.com >
---------
Co-authored-by: Matjaž Tekavec <matjaz@moj-svet.si >
Co-authored-by: André Glazastov <andre@glazastov.com >
2026-08-04 18:37:38 +02:00
milkmaker and GitHub
f7a536d634
update postscreen_access.cidr ( #7394 )
2026-08-04 18:35:48 +02:00
Maximal Benedikt and GitHub
8b456a33e7
Merge pull request #7392 from mailcow/update-sponsoring
...
update README.md sponsors
2026-07-30 14:21:39 +02:00
MaximalBenedikt
54da526d41
update README.md sponsors
2026-07-30 14:11:32 +02:00
FreddleSpl0it and GitHub
489db90512
Merge pull request #7391 from mailcow/staging
...
Update 2026-07a
2026-07a
2026-07-30 11:17:15 +02:00
FreddleSpl0it and GitHub
50be483c39
Merge pull request #7390 from mailcow/fix/6859
...
[ACME] Skip mta-sts certificate request when MTA-STS is not active for a domain
2026-07-30 10:44:24 +02:00
FreddleSpl0it
d64c923aca
[ACME] Skip mta-sts certificate request when MTA-STS is not active for a domain
2026-07-30 10:33:55 +02:00
FreddleSpl0it and GitHub
2d5f166ba8
Merge pull request #7389 from mailcow/fix/default-mbox-template
...
[Web] Create default mailbox template with eas and dav access
2026-07-30 09:23:24 +02:00
FreddleSpl0it and GitHub
94b5a623ab
Merge pull request #7388 from mailcow/fix/7329
...
[Web] Move mailcow update check to server side
2026-07-30 09:13:19 +02:00
FreddleSpl0it and GitHub
e406ecd461
Merge pull request #7387 from mailcow/fix/mfk25
...
Hardening mailcow
2026-07-30 09:07:10 +02:00
FreddleSpl0it and GitHub
68a95c3af3
Merge pull request #7386 from mailcow/feat/rspamd-4.1.4
...
[Rspamd] update to 4.1.4
2026-07-30 08:59:04 +02:00
FreddleSpl0it
bd037d5644
[Nginx] Set image tag to 1.30.4-1
2026-07-30 08:51:21 +02:00
FreddleSpl0it
7036dbf4f8
[Rspamd] update to 4.1.4
2026-07-30 08:50:18 +02:00
FreddleSpl0it and GitHub
2f10a4633f
Merge pull request #7385 from mailcow/fix/cors
...
[Web] harden CORS origin matching and add Vary: Origin
2026-07-30 08:41:01 +02:00
FreddleSpl0it
36c70db86c
[Web] harden CORS origin matching and add Vary: Origin
2026-07-30 08:37:18 +02:00
FreddleSpl0it and GitHub
f4961c4023
Merge pull request #7333 from fallmo/fix/cors-settings-validation
...
fix: cors allowed origins settings validation
2026-07-28 15:35:29 +02:00
FreddleSpl0it and GitHub
38de21592c
Merge pull request #7358 from SYNLINQ/staging
...
Fix nginx CVE-2026-42533
2026-07-28 14:40:30 +02:00
FreddleSpl0it
f44bd2f36a
[Web] document sender_acl in get/mailbox API examples
2026-07-28 14:19:45 +02:00
FreddleSpl0it and GitHub
95a77f2dcb
Merge pull request #7348 from smpaz7467/fix/api-get-mailbox-sender-acl
...
[Web] return sender_acl in get/mailbox API
2026-07-28 14:12:57 +02:00
FreddleSpl0it and GitHub
e856510fb2
Merge pull request #7345 from smpaz7467/fix/time-limited-alias-api
...
[Web] fix add/time_limited_alias silently discarding requests and validity
2026-07-28 13:49:37 +02:00
FreddleSpl0it and GitHub
d51d06d716
Merge pull request #7343 from smpaz7467/fix/nginx-ipv6-default-server
...
[Nginx] only bind IPv6 default_server when ENABLE_IPV6 is set
2026-07-28 13:35:17 +02:00
FreddleSpl0it
54170d075a
[Web] Move mailcow update check to server side
2026-07-28 13:32:18 +02:00
renovate[bot] and GitHub
b4bb1a625b
Update actions/stale action to v11 ( #7375 )
2026-07-28 11:07:20 +02:00
FreddleSpl0it and GitHub
2e5a29bf69
Merge pull request #7367 from oidipos/fix/quarantine-subject
...
fix: restore subject display in quarantine overview
2026-07-28 10:54:23 +02:00
FreddleSpl0it
e245ac04d9
[Web] enforce tenant boundary for SOGo SSO
2026-07-28 09:21:29 +02:00
oidipos
c877fdf0a5
fix: remove MIME decoding of JSON encoded subject
...
Since moving to rspamd's multipart metadata_exporter,
`subject` is a JSON encoded UTF-8 string and must not be MIME decoded.
2026-07-24 21:03:00 +02:00
FreddleSpl0it
fea38c8e1b
[Web] escape mailbox name
2026-07-24 11:16:39 +02:00
FreddleSpl0it
cc9af65852
[Web] remove domain admin sso token after use
2026-07-24 10:26:23 +02:00
FreddleSpl0it
92cc8bec90
[Web] Use parameterized LIKE for sogo_acl deletion
2026-07-23 15:29:41 +02:00
FreddleSpl0it
145745329e
[Web] add dot stuffing for quarantine raw release
2026-07-23 15:01:44 +02:00
FreddleSpl0it
8e72d22c56
[Web] Escape rspamd_history and rllog
2026-07-23 11:17:55 +02:00
FreddleSpl0it
ddd76d99cd
[Web] Add sogo_auth_internal nginx marker for sogo-auth.php
2026-07-23 10:10:29 +02:00
SYNLINQ and GitHub
8c9524a2fe
Update docker-compose.yml
...
reference patched nginx image
2026-07-20 21:32:57 +02:00
SYNLINQ and GitHub
2ebd32d2ee
Update Dockerfile
...
bump nginx version to 1.30.4
2026-07-20 21:31:57 +02:00
FreddleSpl0it and GitHub
641ed63782
Merge pull request #7353 from mailcow/staging
...
update README.md sponsors
2026-07-15 08:31:16 +02:00
FreddleSpl0it
4b62af9d02
update README.md sponsors
2026-07-15 08:29:46 +02:00
Stephen Ritz and Claude Opus 4.8
14772c3a20
[Web] return sender_acl in get/mailbox API
...
sender_acl can be set through edit/mailbox but was never returned by
get/mailbox, so an API client could not read back what it had written,
and get/mailbox/all / get/mailbox/{mailbox} both omitted it.
Add the mailbox's internal send-as ACL (the sender_acl table rows with
external = 0) to mailbox_details as sender_acl, an array of send_as
values, mirroring the field edit/mailbox accepts. It is added in the same
block as the other detailed fields, so the lightweight get/mailbox/reduced
endpoint is unaffected.
Fixes #7011
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-07-14 16:36:40 -07:00
Stephen Ritz and Claude Opus 4.8
c17cc8a792
[Web] fix add/time_limited_alias silently discarding requests and validity
...
Three defects in add/time_limited_alias:
The description was read as $_data['description'] without a guard. When a
client omits it, null is bound to spamalias.description, which is TEXT NOT
NULL, so the insert raises a PDOException. The global exception handler is
terminal, so process_add_return() never echoes anything and the caller sees
HTTP 200 with an empty body while no alias was created. Default it to an
empty string instead.
The validity guard used a single condition whose else branch also caught the
success case, so every valid validity was overwritten with the 8760 hour
default and the parameter did nothing. Only invalid values were rejected.
Nest the range check so a valid value survives.
The OpenAPI spec documented only username and domain, while the code also
reads description, validity and permanent. Spec driven clients therefore
could not construct a working request. Document all three.
spamalias.description is the only NOT NULL description column in the schema,
which is why the same unguarded read in add/domain and add/resource does not
fail, both of those columns are nullable.
This does not change the generic exception handling. A database error is
still swallowed into an empty HTTP 200, and the message the handler builds
carries the raw PDOException, so surfacing it to API clients would need
sanitising first. That is left for a separate change.
Refs #7287
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-07-14 15:23:31 -07:00