mirror of
https://github.com/domainaware/parsedmarc.git
synced 2026-09-06 05:57:58 +00:00
* Make the output and mailbox integrations optional extras (#883) Breaking change for the next major release: pip install parsedmarc now installs the parsing core plus a working core CLI (file, IMAP, Maildir, and mbox input; CSV/JSON, Splunk HEC, webhook, and syslog output). Everything else moves behind an extra: elastic, opensearch, kafka, s3, gelf, loganalytics, msgraph, and gmail, joining the existing postgresql extra, with an umbrella [all] that deliberately excludes postgresql (psycopg's binary wheels do not exist on every platform, so parsedmarc[all] must never fail to install there). cli.py imports the six SDK-dependent output modules behind the #884 TYPE_CHECKING/try-except guard; a configured section whose extra is missing fails fast with a ConfigurationError naming the section and the exact pip install command — including the msgraph and gmail_api mailbox sections (detected via parsedmarc.mail's placeholder classes) and postgresql (checked before the constructor so the startup retry loop does not retry a missing dependency for a minute). The Azure/kiota Graph error types fall back to never-raised sentinel classes. The Docker image installs [all,postgresql], so container users see no change. CI lint installs [build,all,postgresql]; the unit-test job installs [build,all], deliberately without postgresql so test_postgres.py's absent-psycopg arm stays exercised. The never-imported dateparser dependency is dropped in favor of declaring python-dateutil, which utils.py actually imports; pytz moves to the build extra for the one test that uses it. Verified live: a no-extras wheel install imports, parses samples, and reports the install hint for each gated section; a [all] install restores every integration; the Docker image builds with every SDK importable. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Patch psycopg presence in the PostgreSQL CLI wiring tests CI's unit-test job deliberately installs [build,all] without the postgresql extra, so parsedmarc.cli.postgres.psycopg is None there and the new missing-extra presence check correctly made _main exit 1 before the wiring under test ran. The tests simulate the SDK being available (PostgreSQLClient is mocked at the SDK boundary), so the module-level psycopg handle is now patched present in setUp. Verified against a simulated psycopg-absent environment as well as the local full install. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Address Copilot review: narrow guards to ModuleNotFoundError, fix docs - The optional-integration and Graph error-type import guards now catch ModuleNotFoundError instead of ImportError, so only a genuinely absent package reads as a missing extra; a broken-but-present SDK fails loudly with its real error instead of masquerading as one. The test blocker raises ModuleNotFoundError accordingly — the exact exception a missing package produces. - _missing_extra_hint docstring no longer calls every gated integration an output module (it also serves the msgraph/gmail_api mailbox sections). - Fix the pre-existing passsword typo in usage.md's kafka section; the INI key the code reads is password (cli.py _parse_config). Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Quote extras specs in copy-paste install commands From Copilot's second review round: zsh treats an unquoted .[build,all] as a glob and fails with 'no matches found', so the commands shown in AGENTS.md, CONTRIBUTING.md, dashboards/README.md, and the bootstrap script's comment are now quoted. The CI workflows keep the unquoted form: they run under bash, which passes unmatched globs through literally. The suggestion to change the 'Choosing what to install' heading level was rejected — it is a subsection of 'Installing parsedmarc', matching the file's existing hierarchy. Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Fix upgrade command in the changelog * Documentation review: accuracy, spelling, grammar, and clarity pass A full prose review of docs/source, README, CONTRIBUTING, and the dashboards README, with every accuracy claim verified against the code before changing it. Highlights: - usage.md: documented six missing [general] options (the CSV/JSON filename options, prettify_json, normalize_timespan_threshold_hours), the required kafka smtp_tls_topic, [imap] timeout/max_retries, and the postgresql env-var prefix; corrected the maildir_path default (None, not INBOX — cli.py Namespace defaults), the mailbox check_timeout option name, the systemd restart interval (RestartSec is 5m), and merged the duplicate silent entry; quoted every copy-paste extras spec for zsh safety. - elasticsearch.md: fixed an invalid openssl command (rsa:4096 -nodes), the dashboards filename (opensearch_dashboards.ndjson, matching the file the link serves), and assorted grammar. - davmail.md: the service-enable command now enables davmail.service (was parsedmarc.service — a copy-paste error that left DavMail unenabled), plus a view typo and DavMail capitalization. - output.md: the example schema reference is RFC 7489 Appendix C (7480 is RDAP). kibana.md: SPF relies on the SMTP envelope, not session headers (RFC 7208). dmarc.md: DKM -> DKIM. - README: the intro now also names the OpenSearch/Grafana stack, matching the feature list. CONTRIBUTING: pre-PR checks now include ruff format --check and pyright, matching CI's lint job. - dashboards/README: the service table and seed description now include the PostgreSQL backend the compose stack runs. Sample data blocks, the CLI-help mirror block, and released CHANGELOG entries were deliberately left untouched. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Docstring review: accuracy, spelling, grammar, and clarity pass Every docstring in parsedmarc/, parsedmarc/mail/, the maps maintainer scripts, and the test suite reviewed with each claim verified against the code it documents. Text-only — no behavior changes. Highlights: - Copy-paste errors corrected: parsed_smtp_tls_reports_to_csv and splunk/loganalytics save functions described aggregate or failure reports they do not handle; LogAnalyticsException claimed to be an Elasticsearch error. - Docstring/behavior mismatches: parse_report_email's report_type enumeration omitted smtp_tls; parse_failure_report typed msg_date as str (it is datetime); strip_attachment_payloads claimed payloads are replaced with None (the key is deleted); kafkaclient's failure and SMTP TLS savers claimed per-record slicing while sending the whole list in one message (docstrings now describe reality — whether slicing was intended is flagged for follow-up); the postgres savers claimed to take parse_report_file's return value but receive the inner report dict; elastic/opensearch save functions' Raises listed only AlreadySaved. - None-as-semantic-state documented where missing (get_base_domain, get_ip_address_country), enumeration completeness fixed (get_ip_address_info's 9 result keys, maps script outputs, TSV columns), and the stale 44-industry-types count corrected to the 46 the authoritative README list defines. - Test docstrings aligned with what the tests actually assert, including two that overstated coverage of the elastic/opensearch address-list tests. - Two argparse help strings fixed: file_path now names SMTP TLS report files alongside aggregate and failure, mirrored into usage.md's CLI-help block; --offline's doubled spaces removed (rendered help unchanged). - elasticsearch.md's security claim corrected against Elastic's docs: security is enabled and auto-configured on first startup since 8.0 (not "8.7 secure mode"), so the settings are verified, not hand-written. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
190 lines
4.2 KiB
Markdown
190 lines
4.2 KiB
Markdown
# Accessing an inbox using OWA/EWS
|
|
|
|
:::{note}
|
|
Starting in 8.0.0, parsedmarc supports accessing Microsoft/Office 365
|
|
inboxes via the Microsoft Graph API, which is preferred over DavMail.
|
|
:::
|
|
|
|
Some organizations do not allow IMAP or the Microsoft Graph API,
|
|
and only support Exchange Web Services (EWS)/Outlook Web Access (OWA).
|
|
In that case, DavMail will need to be set up
|
|
as a local EWS/OWA IMAP gateway. It can even work where
|
|
[Modern Auth/multi-factor authentication] is required.
|
|
|
|
To do this, download the latest `davmail-version.zip` from
|
|
<https://sourceforge.net/projects/davmail/files/>
|
|
|
|
Extract the zip using the `unzip` command.
|
|
|
|
Install Java:
|
|
|
|
```bash
|
|
sudo apt-get install default-jre-headless
|
|
```
|
|
|
|
Configure DavMail by creating a `davmail.properties` file
|
|
|
|
```properties
|
|
# DavMail settings, see http://davmail.sourceforge.net/ for documentation
|
|
|
|
#############################################################
|
|
# Basic settings
|
|
|
|
# Server or workstation mode
|
|
davmail.server=true
|
|
|
|
# connection mode auto, EWS or WebDav
|
|
davmail.enableEws=auto
|
|
|
|
# base Exchange OWA or EWS url
|
|
davmail.url=https://outlook.office365.com/EWS/Exchange.asmx
|
|
|
|
# Listener ports
|
|
davmail.imapPort=1143
|
|
|
|
#############################################################
|
|
# Network settings
|
|
|
|
# Network proxy settings
|
|
davmail.enableProxy=false
|
|
davmail.useSystemProxies=false
|
|
davmail.proxyHost=
|
|
davmail.proxyPort=
|
|
davmail.proxyUser=
|
|
davmail.proxyPassword=
|
|
|
|
# proxy exclude list
|
|
davmail.noProxyFor=
|
|
|
|
# block remote connection to DavMail
|
|
davmail.allowRemote=false
|
|
|
|
# bind server sockets to the loopback address
|
|
davmail.bindAddress=127.0.0.1
|
|
|
|
# disable SSL for specified listeners
|
|
davmail.ssl.nosecureimap=true
|
|
|
|
# Send keepalive character during large folder and messages download
|
|
davmail.enableKeepalive=true
|
|
|
|
# Message count limit on folder retrieval
|
|
davmail.folderSizeLimit=0
|
|
|
|
#############################################################
|
|
# IMAP settings
|
|
|
|
# Delete messages immediately on IMAP STORE \Deleted flag
|
|
davmail.imapAutoExpunge=true
|
|
|
|
# Enable IDLE support, set polling delay in minutes
|
|
davmail.imapIdleDelay=1
|
|
|
|
# Always reply to IMAP RFC822.SIZE requests with Exchange approximate
|
|
# message size for performance reasons
|
|
davmail.imapAlwaysApproxMsgSize=true
|
|
|
|
# Client connection timeout in seconds - default 300, 0 to disable
|
|
davmail.clientSoTimeout=0
|
|
|
|
#############################################################
|
|
```
|
|
|
|
## Running DavMail as a systemd service
|
|
|
|
Use systemd to run `davmail` as a service.
|
|
|
|
Create a system user
|
|
|
|
```bash
|
|
sudo useradd davmail -r -s /bin/false
|
|
```
|
|
|
|
Protect the `davmail` configuration file from prying eyes
|
|
|
|
```bash
|
|
sudo chown root:davmail /opt/davmail/davmail.properties
|
|
sudo chmod u=rw,g=r,o= /opt/davmail/davmail.properties
|
|
```
|
|
|
|
Create the service configuration file
|
|
|
|
```bash
|
|
sudo nano /etc/systemd/system/davmail.service
|
|
```
|
|
|
|
```ini
|
|
[Unit]
|
|
Description=DavMail gateway service
|
|
Documentation=https://sourceforge.net/projects/davmail/
|
|
Wants=network-online.target
|
|
After=syslog.target network.target
|
|
|
|
[Service]
|
|
ExecStart=/opt/davmail/davmail /opt/davmail/davmail.properties
|
|
User=davmail
|
|
Group=davmail
|
|
Restart=always
|
|
RestartSec=5m
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|
|
```
|
|
|
|
Then, enable the service
|
|
|
|
```bash
|
|
sudo systemctl daemon-reload
|
|
sudo systemctl enable davmail.service
|
|
sudo service davmail restart
|
|
```
|
|
|
|
:::{note}
|
|
You must also run the above commands whenever you edit
|
|
`davmail.service`.
|
|
:::
|
|
|
|
:::{warning}
|
|
Always restart the service every time you upgrade to a new version of
|
|
`davmail`:
|
|
|
|
```bash
|
|
sudo service davmail restart
|
|
```
|
|
|
|
:::
|
|
|
|
To check the status of the service, run:
|
|
|
|
```bash
|
|
service davmail status
|
|
```
|
|
|
|
:::{note}
|
|
In the event of a crash, systemd will restart the service after 5
|
|
minutes, but the `service davmail status` command will only show the
|
|
logs for the current process. To view the logs for previous runs as
|
|
well as the current process (newest to oldest), run:
|
|
|
|
```bash
|
|
journalctl -u davmail.service -r
|
|
```
|
|
|
|
:::
|
|
|
|
## Configuring parsedmarc for DavMail
|
|
|
|
Because you are interacting with the DavMail server over the loopback
|
|
(i.e. `127.0.0.1`), add the following options to the `parsedmarc.ini`
|
|
config file:
|
|
|
|
```ini
|
|
[imap]
|
|
host=127.0.0.1
|
|
port=1143
|
|
ssl=False
|
|
watch=True
|
|
```
|
|
|
|
[modern auth/multi-factor authentication]: https://davmail.sourceforge.net/faq.html
|