mirror of
https://github.com/mailcow/mailcow-dockerized.git
synced 2026-08-18 13:03:17 +00:00
Compare commits
6
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8bd9e12a73 | ||
|
|
6644699e65 | ||
|
|
91d3b7246a | ||
|
|
b362c7105d | ||
|
|
555e7ed706 | ||
|
|
59e2a9ac77 |
@@ -116,6 +116,7 @@ location ~ \.php$ {
|
|||||||
include /etc/nginx/fastcgi_params;
|
include /etc/nginx/fastcgi_params;
|
||||||
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
|
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
|
||||||
fastcgi_param PATH_INFO $fastcgi_path_info;
|
fastcgi_param PATH_INFO $fastcgi_path_info;
|
||||||
|
fastcgi_param HTTP_X_REAL_IP $remote_addr;
|
||||||
# trusted internal-auth marker; empty for external clients (see nginx.conf map)
|
# trusted internal-auth marker; empty for external clients (see nginx.conf map)
|
||||||
fastcgi_param SOGO_AUTH_INTERNAL $sogo_auth_internal;
|
fastcgi_param SOGO_AUTH_INTERNAL $sogo_auth_internal;
|
||||||
fastcgi_read_timeout 3600;
|
fastcgi_read_timeout 3600;
|
||||||
|
|||||||
@@ -380,13 +380,13 @@ if (isset($_SESSION['mailcow_cc_role']) && ($_SESSION['mailcow_cc_role'] == "adm
|
|||||||
else {
|
else {
|
||||||
$state = state_nomatch;
|
$state = state_nomatch;
|
||||||
}
|
}
|
||||||
$state .= '<br />' . $current[$data_field[$current['type']]];
|
$state .= '<br />' . htmlspecialchars($current[$data_field[$current['type']]]);
|
||||||
}
|
}
|
||||||
if ($current['type'] == 'TXT' &&
|
if ($current['type'] == 'TXT' &&
|
||||||
stripos($current['txt'], 'v=dmarc') === 0 &&
|
stripos($current['txt'], 'v=dmarc') === 0 &&
|
||||||
$record[2] == $dmarc_link) {
|
$record[2] == $dmarc_link) {
|
||||||
$current['txt'] = str_replace(' ', '', $current['txt']);
|
$current['txt'] = str_replace(' ', '', $current['txt']);
|
||||||
$state = $current[$data_field[$current['type']]] . state_optional;
|
$state = htmlspecialchars($current[$data_field[$current['type']]]) . state_optional;
|
||||||
}
|
}
|
||||||
elseif ($current['type'] == 'TXT' &&
|
elseif ($current['type'] == 'TXT' &&
|
||||||
stripos($current['txt'], 'v=spf') === 0 &&
|
stripos($current['txt'], 'v=spf') === 0 &&
|
||||||
@@ -396,7 +396,7 @@ if (isset($_SESSION['mailcow_cc_role']) && ($_SESSION['mailcow_cc_role'] == "adm
|
|||||||
if (in_array($ip, $rslt) && in_array(expand_ipv6($ip6), $rslt)) {
|
if (in_array($ip, $rslt) && in_array(expand_ipv6($ip6), $rslt)) {
|
||||||
$state = state_good;
|
$state = state_good;
|
||||||
}
|
}
|
||||||
$state .= '<br />' . $current[$data_field[$current['type']]] . state_optional;
|
$state .= '<br />' . htmlspecialchars($current[$data_field[$current['type']]]) . state_optional;
|
||||||
}
|
}
|
||||||
elseif ($current['type'] == 'TXT' &&
|
elseif ($current['type'] == 'TXT' &&
|
||||||
stripos($current['txt'], 'v=dkim') === 0 &&
|
stripos($current['txt'], 'v=dkim') === 0 &&
|
||||||
@@ -426,7 +426,7 @@ if (isset($_SESSION['mailcow_cc_role']) && ($_SESSION['mailcow_cc_role'] == "adm
|
|||||||
if ($state == state_nomatch) {
|
if ($state == state_nomatch) {
|
||||||
$state = array();
|
$state = array();
|
||||||
foreach ($currents as $current) {
|
foreach ($currents as $current) {
|
||||||
$state[] = $current[$data_field[$current['type']]];
|
$state[] = htmlspecialchars($current[$data_field[$current['type']]]);
|
||||||
}
|
}
|
||||||
$state = implode('<br />', $state);
|
$state = implode('<br />', $state);
|
||||||
}
|
}
|
||||||
@@ -436,7 +436,7 @@ if (isset($_SESSION['mailcow_cc_role']) && ($_SESSION['mailcow_cc_role'] == "adm
|
|||||||
<td>%s</td>
|
<td>%s</td>
|
||||||
<td class="dns-found">%s</td>
|
<td class="dns-found">%s</td>
|
||||||
<td class="dns-recommended">%s</td>
|
<td class="dns-recommended">%s</td>
|
||||||
</tr>', $record[0], $record[1], $record[2], $state);
|
</tr>', htmlspecialchars($record[0]), htmlspecialchars($record[1]), $record[2], $state);
|
||||||
$record[3] = explode('<br />', $state);
|
$record[3] = explode('<br />', $state);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -477,7 +477,7 @@ if (isset($_SESSION['mailcow_cc_role']) && ($_SESSION['mailcow_cc_role'] == "adm
|
|||||||
}
|
}
|
||||||
?>
|
?>
|
||||||
</table>
|
</table>
|
||||||
<a id='download-zonefile' class="btn btn-sm btn-secondary visible-xs-block visible-sm-inline visible-md-inline visible-lg-inline mb-4" style="margin-top:10px" data-zonefile="<?=base64_encode($dns_data);?>" download='<?=$_GET['domain'];?>.txt' type='text/csv'>Download</a>
|
<a id='download-zonefile' class="btn btn-sm btn-secondary visible-xs-block visible-sm-inline visible-md-inline visible-lg-inline mb-4" style="margin-top:10px" data-zonefile="<?=base64_encode($dns_data);?>" download='<?=htmlspecialchars($_GET['domain']);?>.txt' type='text/csv'>Download</a>
|
||||||
<script>
|
<script>
|
||||||
var zonefile_dl_link = document.getElementById('download-zonefile');
|
var zonefile_dl_link = document.getElementById('download-zonefile');
|
||||||
var zonefile = atob(zonefile_dl_link.getAttribute('data-zonefile'));
|
var zonefile = atob(zonefile_dl_link.getAttribute('data-zonefile'));
|
||||||
|
|||||||
@@ -591,7 +591,7 @@ function logger($_data = false) {
|
|||||||
$type = $return['type'];
|
$type = $return['type'];
|
||||||
$msg = null;
|
$msg = null;
|
||||||
if (isset($return['msg'])) {
|
if (isset($return['msg'])) {
|
||||||
$msg = json_encode($return['msg'], JSON_UNESCAPED_UNICODE);
|
$msg = json_encode($return['msg'], JSON_UNESCAPED_UNICODE | JSON_HEX_TAG | JSON_HEX_AMP | JSON_HEX_APOS | JSON_HEX_QUOT);
|
||||||
}
|
}
|
||||||
$call = null;
|
$call = null;
|
||||||
if (isset($return['log'])) {
|
if (isset($return['log'])) {
|
||||||
@@ -633,6 +633,18 @@ function logger($_data = false) {
|
|||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
function is_local_mailcow_domain($domain) {
|
||||||
|
// True if domain is a locally managed, active primary or alias domain
|
||||||
|
global $pdo;
|
||||||
|
$domain = idn_to_ascii($domain, 0, INTL_IDNA_VARIANT_UTS46);
|
||||||
|
if (empty($domain)) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
$stmt = $pdo->prepare("SELECT 1 FROM `domain` WHERE `domain` = :d AND `active` = 1
|
||||||
|
UNION SELECT 1 FROM `alias_domain` WHERE `alias_domain` = :d2 AND `active` = 1 LIMIT 1");
|
||||||
|
$stmt->execute(array(':d' => $domain, ':d2' => $domain));
|
||||||
|
return (bool)$stmt->fetchColumn();
|
||||||
|
}
|
||||||
function hasDomainAccess($username, $role, $domain) {
|
function hasDomainAccess($username, $role, $domain) {
|
||||||
global $pdo;
|
global $pdo;
|
||||||
if (empty($domain) || !is_valid_domain_name($domain)) {
|
if (empty($domain) || !is_valid_domain_name($domain)) {
|
||||||
|
|||||||
@@ -750,6 +750,18 @@ function mailbox($_action, $_type, $_data = null, $_extra = null) {
|
|||||||
$goto_domain = idn_to_ascii(substr(strstr($goto, '@'), 1), 0, INTL_IDNA_VARIANT_UTS46);
|
$goto_domain = idn_to_ascii(substr(strstr($goto, '@'), 1), 0, INTL_IDNA_VARIANT_UTS46);
|
||||||
$goto_local_part = strstr($goto, '@', true);
|
$goto_local_part = strstr($goto, '@', true);
|
||||||
$goto = $goto_local_part.'@'.$goto_domain;
|
$goto = $goto_local_part.'@'.$goto_domain;
|
||||||
|
// Deny external goto domains: global switch (all roles) overrides the per-DA ACL
|
||||||
|
if (($GLOBALS['ALIAS_DISABLE_EXTERNAL_DOMAINS'] === true ||
|
||||||
|
(isset($_SESSION['acl']['alias_external_goto']) && $_SESSION['acl']['alias_external_goto'] != "1")) &&
|
||||||
|
!is_local_mailcow_domain($goto_domain)) {
|
||||||
|
$_SESSION['return'][] = array(
|
||||||
|
'type' => 'danger',
|
||||||
|
'log' => array(__FUNCTION__, $_action, $_type, $_data_log, $_attr),
|
||||||
|
'msg' => array('external_goto_denied', htmlspecialchars($goto))
|
||||||
|
);
|
||||||
|
unset($gotos[$i]);
|
||||||
|
continue;
|
||||||
|
}
|
||||||
$stmt = $pdo->prepare("SELECT `username` FROM `mailbox`
|
$stmt = $pdo->prepare("SELECT `username` FROM `mailbox`
|
||||||
WHERE `kind` REGEXP 'location|thing|group'
|
WHERE `kind` REGEXP 'location|thing|group'
|
||||||
AND `username`= :goto");
|
AND `username`= :goto");
|
||||||
@@ -2715,6 +2727,19 @@ function mailbox($_action, $_type, $_data = null, $_extra = null) {
|
|||||||
unset($gotos[$i]);
|
unset($gotos[$i]);
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
// Deny external goto domains: global switch (all roles) overrides the per-DA ACL
|
||||||
|
$goto_domain = idn_to_ascii(substr(strstr($goto, '@'), 1), 0, INTL_IDNA_VARIANT_UTS46);
|
||||||
|
if (($GLOBALS['ALIAS_DISABLE_EXTERNAL_DOMAINS'] === true ||
|
||||||
|
(isset($_SESSION['acl']['alias_external_goto']) && $_SESSION['acl']['alias_external_goto'] != "1")) &&
|
||||||
|
!is_local_mailcow_domain($goto_domain)) {
|
||||||
|
$_SESSION['return'][] = array(
|
||||||
|
'type' => 'danger',
|
||||||
|
'log' => array(__FUNCTION__, $_action, $_type, $_data_log, $_attr),
|
||||||
|
'msg' => array('external_goto_denied', htmlspecialchars($goto))
|
||||||
|
);
|
||||||
|
unset($gotos[$i]);
|
||||||
|
continue;
|
||||||
|
}
|
||||||
if ($goto == $address) {
|
if ($goto == $address) {
|
||||||
$_SESSION['return'][] = array(
|
$_SESSION['return'][] = array(
|
||||||
'type' => 'danger',
|
'type' => 'danger',
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ function init_db_schema()
|
|||||||
try {
|
try {
|
||||||
global $pdo;
|
global $pdo;
|
||||||
|
|
||||||
$db_version = "19022026_1220";
|
$db_version = "18082026_1200";
|
||||||
|
|
||||||
$stmt = $pdo->query("SHOW TABLES LIKE 'versions'");
|
$stmt = $pdo->query("SHOW TABLES LIKE 'versions'");
|
||||||
$num_results = count($stmt->fetchAll(PDO::FETCH_ASSOC));
|
$num_results = count($stmt->fetchAll(PDO::FETCH_ASSOC));
|
||||||
@@ -719,7 +719,8 @@ function init_db_schema()
|
|||||||
"alias_domains" => "TINYINT(1) NOT NULL DEFAULT '0'",
|
"alias_domains" => "TINYINT(1) NOT NULL DEFAULT '0'",
|
||||||
"mailbox_relayhost" => "TINYINT(1) NOT NULL DEFAULT '1'",
|
"mailbox_relayhost" => "TINYINT(1) NOT NULL DEFAULT '1'",
|
||||||
"domain_relayhost" => "TINYINT(1) NOT NULL DEFAULT '1'",
|
"domain_relayhost" => "TINYINT(1) NOT NULL DEFAULT '1'",
|
||||||
"domain_desc" => "TINYINT(1) NOT NULL DEFAULT '0'"
|
"domain_desc" => "TINYINT(1) NOT NULL DEFAULT '0'",
|
||||||
|
"alias_external_goto" => "TINYINT(1) NOT NULL DEFAULT '1'"
|
||||||
),
|
),
|
||||||
"keys" => array(
|
"keys" => array(
|
||||||
"primary" => array(
|
"primary" => array(
|
||||||
|
|||||||
@@ -246,6 +246,10 @@ $PW_RESET_TOKEN_LIMIT = 3;
|
|||||||
// Maximum time in minutes a password reset token is valid
|
// Maximum time in minutes a password reset token is valid
|
||||||
$PW_RESET_TOKEN_LIFETIME = 15;
|
$PW_RESET_TOKEN_LIFETIME = 15;
|
||||||
|
|
||||||
|
// Globally forbid aliases with external (non-local) goto domains for ALL roles (incl. admins),
|
||||||
|
// overriding the per-domain-admin da_acl. false = defer to da_acl.
|
||||||
|
$ALIAS_DISABLE_EXTERNAL_DOMAINS = false;
|
||||||
|
|
||||||
// UV flag handling in FIDO2/WebAuthn - defaults to false to allow iOS logins
|
// UV flag handling in FIDO2/WebAuthn - defaults to false to allow iOS logins
|
||||||
// true = required
|
// true = required
|
||||||
// false = preferred
|
// false = preferred
|
||||||
|
|||||||
@@ -1169,6 +1169,7 @@ jQuery(function($){
|
|||||||
if (item === null) { return true; }
|
if (item === null) { return true; }
|
||||||
item.user = escapeHtml(item.user);
|
item.user = escapeHtml(item.user);
|
||||||
item.call = escapeHtml(item.call);
|
item.call = escapeHtml(item.call);
|
||||||
|
if (item.msg) item.msg = escapeHtml(item.msg);
|
||||||
item.task = '<code>' + item.task + '</code>';
|
item.task = '<code>' + item.task + '</code>';
|
||||||
item.type = '<span class="badge fs-6 bg-' + item.type + '">' + item.type + '</span>';
|
item.type = '<span class="badge fs-6 bg-' + item.type + '">' + item.type + '</span>';
|
||||||
});
|
});
|
||||||
@@ -1176,6 +1177,7 @@ jQuery(function($){
|
|||||||
$.each(data, function (i, item) {
|
$.each(data, function (i, item) {
|
||||||
if (item === null) { return true; }
|
if (item === null) { return true; }
|
||||||
item.username = escapeHtml(item.username);
|
item.username = escapeHtml(item.username);
|
||||||
|
item.real_rip = escapeHtml(item.real_rip);
|
||||||
item.service = '<div class="badge fs-6 bg-secondary">' + item.service.toUpperCase() + '</div>';
|
item.service = '<div class="badge fs-6 bg-secondary">' + item.service.toUpperCase() + '</div>';
|
||||||
});
|
});
|
||||||
} else if (table == 'general_syslog') {
|
} else if (table == 'general_syslog') {
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
{
|
{
|
||||||
"acl": {
|
"acl": {
|
||||||
"alias_domains": "Alias-Domains hinzufügen",
|
"alias_domains": "Alias-Domains hinzufügen",
|
||||||
|
"alias_external_goto": "Aliase mit externen Ziel-Domains erlauben",
|
||||||
"app_passwds": "App-Passwörter verwalten",
|
"app_passwds": "App-Passwörter verwalten",
|
||||||
"bcc_maps": "BCC-Maps",
|
"bcc_maps": "BCC-Maps",
|
||||||
"delimiter_action": "Delimiter-Aktionen (tags)",
|
"delimiter_action": "Delimiter-Aktionen (tags)",
|
||||||
@@ -443,6 +444,7 @@
|
|||||||
"domain_not_found": "Domain %s nicht gefunden",
|
"domain_not_found": "Domain %s nicht gefunden",
|
||||||
"domain_quota_m_in_use": "Domain-Speicherplatzlimit muss größer oder gleich %d MiB sein",
|
"domain_quota_m_in_use": "Domain-Speicherplatzlimit muss größer oder gleich %d MiB sein",
|
||||||
"extended_sender_acl_denied": "Keine Rechte zum Setzen von externen Absenderadressen",
|
"extended_sender_acl_denied": "Keine Rechte zum Setzen von externen Absenderadressen",
|
||||||
|
"external_goto_denied": "Externe Ziel-Adresse %s ist nicht erlaubt",
|
||||||
"extra_acl_invalid": "Externe Absenderadresse \"%s\" ist ungültig",
|
"extra_acl_invalid": "Externe Absenderadresse \"%s\" ist ungültig",
|
||||||
"extra_acl_invalid_domain": "Externe Absenderadresse \"%s\" verwendet eine ungültige Domain",
|
"extra_acl_invalid_domain": "Externe Absenderadresse \"%s\" verwendet eine ungültige Domain",
|
||||||
"fido2_verification_failed": "FIDO2-Verifizierung fehlgeschlagen: %s",
|
"fido2_verification_failed": "FIDO2-Verifizierung fehlgeschlagen: %s",
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
{
|
{
|
||||||
"acl": {
|
"acl": {
|
||||||
"alias_domains": "Add alias domains",
|
"alias_domains": "Add alias domains",
|
||||||
|
"alias_external_goto": "Allow aliases with external goto domains",
|
||||||
"app_passwds": "Manage app passwords",
|
"app_passwds": "Manage app passwords",
|
||||||
"bcc_maps": "BCC maps",
|
"bcc_maps": "BCC maps",
|
||||||
"delimiter_action": "Delimiter action",
|
"delimiter_action": "Delimiter action",
|
||||||
@@ -444,6 +445,7 @@
|
|||||||
"domain_not_found": "Domain %s not found",
|
"domain_not_found": "Domain %s not found",
|
||||||
"domain_quota_m_in_use": "Domain quota must be greater or equal to %s MiB",
|
"domain_quota_m_in_use": "Domain quota must be greater or equal to %s MiB",
|
||||||
"extended_sender_acl_denied": "missing ACL to set external sender addresses",
|
"extended_sender_acl_denied": "missing ACL to set external sender addresses",
|
||||||
|
"external_goto_denied": "External goto address %s is not allowed",
|
||||||
"extra_acl_invalid": "External sender address \"%s\" is invalid",
|
"extra_acl_invalid": "External sender address \"%s\" is invalid",
|
||||||
"extra_acl_invalid_domain": "External sender \"%s\" uses an invalid domain",
|
"extra_acl_invalid_domain": "External sender \"%s\" uses an invalid domain",
|
||||||
"fido2_verification_failed": "FIDO2 verification failed: %s",
|
"fido2_verification_failed": "FIDO2 verification failed: %s",
|
||||||
|
|||||||
@@ -4,6 +4,7 @@ require_once $_SERVER['DOCUMENT_ROOT'] . '/inc/prerequisites.inc.php';
|
|||||||
if (!isset($_SESSION['mailcow_cc_role'])) {
|
if (!isset($_SESSION['mailcow_cc_role'])) {
|
||||||
$_SESSION['oauth2_request'] = $_SERVER['REQUEST_URI'];
|
$_SESSION['oauth2_request'] = $_SERVER['REQUEST_URI'];
|
||||||
header('Location: /?oauth');
|
header('Location: /?oauth');
|
||||||
|
exit;
|
||||||
}
|
}
|
||||||
|
|
||||||
$request = OAuth2\Request::createFromGlobals();
|
$request = OAuth2\Request::createFromGlobals();
|
||||||
@@ -24,6 +25,11 @@ if (!isset($_POST['authorized'])) {
|
|||||||
exit;
|
exit;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (empty($_SESSION['mailcow_cc_username'])) {
|
||||||
|
header('Location: /?oauth');
|
||||||
|
exit;
|
||||||
|
}
|
||||||
|
|
||||||
// print the authorization code if the user has authorized your client
|
// print the authorization code if the user has authorized your client
|
||||||
$is_authorized = ($_POST['authorized'] == '1');
|
$is_authorized = ($_POST['authorized'] == '1');
|
||||||
$oauth2_server->handleAuthorizeRequest($request, $response, $is_authorized, $_SESSION['mailcow_cc_username']);
|
$oauth2_server->handleAuthorizeRequest($request, $response, $is_authorized, $_SESSION['mailcow_cc_username']);
|
||||||
|
|||||||
+1
-1
@@ -42,7 +42,7 @@ services:
|
|||||||
- mysql
|
- mysql
|
||||||
|
|
||||||
redis-mailcow:
|
redis-mailcow:
|
||||||
image: redis:7.4.6-alpine
|
image: redis:7.4.10-alpine
|
||||||
entrypoint: ["/bin/sh","/redis-conf.sh"]
|
entrypoint: ["/bin/sh","/redis-conf.sh"]
|
||||||
volumes:
|
volumes:
|
||||||
- redis-vol-1:/data/
|
- redis-vol-1:/data/
|
||||||
|
|||||||
Reference in New Issue
Block a user