1
0
mirror of https://github.com/mailcow/mailcow-dockerized.git synced 2026-07-29 16:13:39 +00:00

5395 Commits

Author SHA1 Message Date
FreddleSpl0it f4961c4023 Merge pull request #7333 from fallmo/fix/cors-settings-validation
fix: cors allowed origins settings validation
2026-07-28 15:35:29 +02:00
FreddleSpl0it 38de21592c Merge pull request #7358 from SYNLINQ/staging
Fix nginx CVE-2026-42533
2026-07-28 14:40:30 +02:00
FreddleSpl0it f44bd2f36a [Web] document sender_acl in get/mailbox API examples 2026-07-28 14:19:45 +02:00
FreddleSpl0it 95a77f2dcb Merge pull request #7348 from smpaz7467/fix/api-get-mailbox-sender-acl
[Web] return sender_acl in get/mailbox API
2026-07-28 14:12:57 +02:00
FreddleSpl0it e856510fb2 Merge pull request #7345 from smpaz7467/fix/time-limited-alias-api
[Web] fix add/time_limited_alias silently discarding requests and validity
2026-07-28 13:49:37 +02:00
FreddleSpl0it d51d06d716 Merge pull request #7343 from smpaz7467/fix/nginx-ipv6-default-server
[Nginx] only bind IPv6 default_server when ENABLE_IPV6 is set
2026-07-28 13:35:17 +02:00
oidipos c877fdf0a5 fix: remove MIME decoding of JSON encoded subject
Since moving to rspamd's multipart metadata_exporter,
`subject` is a JSON encoded UTF-8 string and must not be MIME decoded.
2026-07-24 21:03:00 +02:00
SYNLINQ 2ebd32d2ee Update Dockerfile
bump nginx version to 1.30.4
2026-07-20 21:31:57 +02:00
Stephen Ritz 14772c3a20 [Web] return sender_acl in get/mailbox API
sender_acl can be set through edit/mailbox but was never returned by
get/mailbox, so an API client could not read back what it had written,
and get/mailbox/all / get/mailbox/{mailbox} both omitted it.

Add the mailbox's internal send-as ACL (the sender_acl table rows with
external = 0) to mailbox_details as sender_acl, an array of send_as
values, mirroring the field edit/mailbox accepts. It is added in the same
block as the other detailed fields, so the lightweight get/mailbox/reduced
endpoint is unaffected.

Fixes #7011

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-14 16:36:40 -07:00
Stephen Ritz c17cc8a792 [Web] fix add/time_limited_alias silently discarding requests and validity
Three defects in add/time_limited_alias:

The description was read as $_data['description'] without a guard. When a
client omits it, null is bound to spamalias.description, which is TEXT NOT
NULL, so the insert raises a PDOException. The global exception handler is
terminal, so process_add_return() never echoes anything and the caller sees
HTTP 200 with an empty body while no alias was created. Default it to an
empty string instead.

The validity guard used a single condition whose else branch also caught the
success case, so every valid validity was overwritten with the 8760 hour
default and the parameter did nothing. Only invalid values were rejected.
Nest the range check so a valid value survives.

The OpenAPI spec documented only username and domain, while the code also
reads description, validity and permanent. Spec driven clients therefore
could not construct a working request. Document all three.

spamalias.description is the only NOT NULL description column in the schema,
which is why the same unguarded read in add/domain and add/resource does not
fail, both of those columns are nullable.

This does not change the generic exception handling. A database error is
still swallowed into an empty HTTP 200, and the message the handler builds
carries the raw PDOException, so surfacing it to API clients would need
sanitising first. That is left for a separate change.

Refs #7287

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-14 15:23:31 -07:00
Stephen Ritz 7dab6c63d1 [Nginx] only bind IPv6 default_server when ENABLE_IPV6 is set
The HTTP-to-HTTPS redirect server block bound `listen [::]:{{ HTTP_PORT }}
default_server` unconditionally, while every other IPv6 listen directive in
this template is guarded by `{% if ENABLE_IPV6 %}`. On hosts where IPv6 is
disabled at the kernel level, nginx cannot bind `::` and fails to start.

This only triggers when HTTP_REDIRECT is enabled and ENABLE_IPV6 is false,
which is why it survives testing with ENABLE_IPV6=false alone.

Guard the directive like the other six IPv6 listeners in the template.

Refs #7296

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-14 14:54:28 -07:00
Mohamed Fall 6f7fee49cd fix: cors allowed origins settings validation 2026-07-13 15:29:48 +00:00
FreddleSpl0it c1d75cf808 Merge pull request #7312 from mailcow/renovate/composer-composer-2.x
Update dependency composer/composer to v2.10.2
2026-07-13 09:40:58 +02:00
FreddleSpl0it 473fe2885d Merge pull request #7326 from ralfbergs/fix/quarantine-text-refining
Refined wording for displaying of active settings on quarantine page.
2026-07-13 09:40:24 +02:00
FreddleSpl0it 31e1550668 [Postfix] change postscreen blacklist_action to denylist_action 2026-07-13 08:45:56 +02:00
Ralf Bergs e696ee2f6c Refined wording for displaying of active settings on quarantine page. 2026-07-12 17:22:15 +02:00
DerLinkman 3098caebbc migrate postfix to trixie 2026-07-10 18:29:45 +02:00
renovate[bot] 94e23a3cd3 Update dependency composer/composer to v2.10.2
Signed-off-by: milkmaker <milkmaker@mailcow.de>
2026-07-01 09:32:23 +00:00
milkmaker 1840074991 update postscreen_access.cidr (#7311) 2026-07-01 11:31:58 +02:00
FreddleSpl0it 1f8b4679cc [Nignx] Update to 1.30.3 2026-06-25 12:17:37 +02:00
milkmaker 9e723e942d Translations update from Weblate (#7302)
* [Web] Updated lang.fr-fr.json

Co-authored-by: Romain Ayme <ayme.romain@hotmail.fr>

* [Web] Updated lang.si-si.json

Co-authored-by: Matjaž Tekavec <matjaz@moj-svet.si>

---------

Co-authored-by: Romain Ayme <ayme.romain@hotmail.fr>
Co-authored-by: Matjaž Tekavec <matjaz@moj-svet.si>
2026-06-20 13:57:15 +02:00
FreddleSpl0it 83a045ed3e Merge pull request #7193 from mailcow/renovate/composer-composer-2.x
Update dependency composer/composer to v2.10.1
2026-06-11 10:07:19 +02:00
FreddleSpl0it 064817ac70 Merge pull request #7189 from mailcow/renovate/php-pecl-mail-mailparse-3.x
Update dependency php/pecl-mail-mailparse to v3.2.0
2026-06-11 10:06:49 +02:00
FreddleSpl0it 2bd7a24b8c Merge pull request #7212 from mailcow/mkuron-patch-mobileconfig
Escape generated password in mobileconfig
2026-06-11 10:05:17 +02:00
FreddleSpl0it ecc2462e4c Merge pull request #7267 from goodygh/7249-update-sogo
[SOGo] Update to 5.12.9
2026-06-11 10:04:30 +02:00
FreddleSpl0it 2d8db72d46 Merge pull request #7275 from Snafu/fix/admin-mailbox-tfa-missing
Fix force_tfa not available in mailbox template #7216
2026-06-11 10:03:39 +02:00
FreddleSpl0it 277a307fb9 [Web] Fix refresh SOGo view on mailbox deletion 2026-06-11 09:55:32 +02:00
FreddleSpl0it d455555621 Merge pull request #7277 from ibobgunardi/bobi/mailcow-7136-sogo-active-refresh
Refresh SOGo view after mailbox activation
2026-06-11 09:53:30 +02:00
FreddleSpl0it 24cc369d84 [Rspamd] Migrate metadata_exporter to multipart formatter 2026-06-11 09:34:27 +02:00
FreddleSpl0it 5f5367f2f9 Merge pull request #7172 from mailcow/dragoangel-patch-4
Update RSPAMD version to 4.1.0 in Dockerfile
2026-06-11 09:04:19 +02:00
milkmaker 03c31f825a update postscreen_access.cidr (#7269) 2026-06-09 12:20:53 +02:00
Dmytro Alieksieiev 15891960f7 Update RSPAMD version to 4.1.0 2026-06-09 01:19:06 +02:00
Bobby cce02e2b15 Refresh SOGo view after mailbox activation 2026-06-08 00:01:43 +07:00
Snafu 0fafda696b Fix force_tfa not available in mailbox template #7216 2026-06-07 17:03:52 +02:00
renovate[bot] 843db5854c Update dependency composer/composer to v2.10.1
Signed-off-by: milkmaker <milkmaker@mailcow.de>
2026-06-04 11:04:42 +00:00
goodygh 23e4e4f373 [SOGo] Update to 5.12.9 2026-05-29 01:39:38 +02:00
goodygh 175878f8f1 ui, fail2ban fix german ban_list_info translation (#7265) 2026-05-28 22:20:26 +02:00
milkmaker 3fcda21c4e [Web] Updated lang.vi-vn.json (#7263)
Co-authored-by: Phu D. Nguyen <sillycat@duck.com>
2026-05-27 17:46:42 +02:00
milkmaker eac1bf02fc [Web] Updated lang.lv-lv.json (#7262)
Co-authored-by: Edgars Andersons <Edgars+Mailcow+Weblate@gaitenis.id.lv>
2026-05-26 22:02:05 +02:00
FreddleSpl0it be37bc5a68 Merge pull request #7252 from SYNLINQ/staging
fix unbound CVE-2026-33278
2026-05-26 10:41:52 +02:00
FreddleSpl0it db4e3b4d54 [Nginx] Update to 1.30.2 2026-05-26 10:36:39 +02:00
Michael Kuron ffbc37a00c Escape generated password in mobileconfig
Escape ampersand, less than, greater than to avoid generating invalid XML.

Fixes #7171
2026-05-24 11:52:12 +02:00
SYNLINQ 7d17715e2e Update Dockerfile
install unbound package from alpine:edge
2026-05-22 16:26:47 +02:00
milkmaker 4f2348631a [Web] Updated lang.pl-pl.json (#7245)
Co-authored-by: Adrian-Kozien <adrian@kozien.net>
2026-05-21 17:16:34 +02:00
FreddleSpl0it 22ae1f5363 Merge pull request #7241 from mailcow/fix/quarantinetable
escape HTML in quarantine table
2026-05-20 18:02:19 +02:00
FreddleSpl0it cbd3d8b9bc escape HTML in quarantine table 2026-05-20 17:53:47 +02:00
FreddleSpl0it f553f38635 [Nginx] Update to 1.30.1 2026-05-20 17:24:41 +02:00
renovate[bot] 104af58628 Update dependency php/pecl-mail-mailparse to v3.2.0
Signed-off-by: milkmaker <milkmaker@mailcow.de>
2026-05-14 18:33:03 +00:00
Jahongir Qurbonov 4ddcee28e4 Add Uzbek language (#7224) 2026-05-13 16:42:38 +02:00
milkmaker b0d16bbcee [Web] Updated lang.pt-br.json (#7228)
Co-authored-by: Edson Wolf <edsonwolf@vivaldi.net>
2026-05-13 16:42:03 +02:00