FreddleSpl0it
e856510fb2
Merge pull request #7345 from smpaz7467/fix/time-limited-alias-api
...
[Web] fix add/time_limited_alias silently discarding requests and validity
2026-07-28 13:49:37 +02:00
FreddleSpl0it
d51d06d716
Merge pull request #7343 from smpaz7467/fix/nginx-ipv6-default-server
...
[Nginx] only bind IPv6 default_server when ENABLE_IPV6 is set
2026-07-28 13:35:17 +02:00
renovate[bot]
b4bb1a625b
Update actions/stale action to v11 ( #7375 )
2026-07-28 11:07:20 +02:00
FreddleSpl0it
2e5a29bf69
Merge pull request #7367 from oidipos/fix/quarantine-subject
...
fix: restore subject display in quarantine overview
2026-07-28 10:54:23 +02:00
oidipos
c877fdf0a5
fix: remove MIME decoding of JSON encoded subject
...
Since moving to rspamd's multipart metadata_exporter,
`subject` is a JSON encoded UTF-8 string and must not be MIME decoded.
2026-07-24 21:03:00 +02:00
FreddleSpl0it
4b62af9d02
update README.md sponsors
2026-07-15 08:29:46 +02:00
Stephen Ritz
c17cc8a792
[Web] fix add/time_limited_alias silently discarding requests and validity
...
Three defects in add/time_limited_alias:
The description was read as $_data['description'] without a guard. When a
client omits it, null is bound to spamalias.description, which is TEXT NOT
NULL, so the insert raises a PDOException. The global exception handler is
terminal, so process_add_return() never echoes anything and the caller sees
HTTP 200 with an empty body while no alias was created. Default it to an
empty string instead.
The validity guard used a single condition whose else branch also caught the
success case, so every valid validity was overwritten with the 8760 hour
default and the parameter did nothing. Only invalid values were rejected.
Nest the range check so a valid value survives.
The OpenAPI spec documented only username and domain, while the code also
reads description, validity and permanent. Spec driven clients therefore
could not construct a working request. Document all three.
spamalias.description is the only NOT NULL description column in the schema,
which is why the same unguarded read in add/domain and add/resource does not
fail, both of those columns are nullable.
This does not change the generic exception handling. A database error is
still swallowed into an empty HTTP 200, and the message the handler builds
carries the raw PDOException, so surfacing it to API clients would need
sanitising first. That is left for a separate change.
Refs #7287
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-07-14 15:23:31 -07:00
Stephen Ritz
7dab6c63d1
[Nginx] only bind IPv6 default_server when ENABLE_IPV6 is set
...
The HTTP-to-HTTPS redirect server block bound `listen [::]:{{ HTTP_PORT }}
default_server` unconditionally, while every other IPv6 listen directive in
this template is guarded by `{% if ENABLE_IPV6 %}`. On hosts where IPv6 is
disabled at the kernel level, nginx cannot bind `::` and fails to start.
This only triggers when HTTP_REDIRECT is enabled and ENABLE_IPV6 is false,
which is why it survives testing with ENABLE_IPV6=false alone.
Guard the directive like the other six IPv6 listeners in the template.
Refs #7296
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-07-14 14:54:28 -07:00
FreddleSpl0it
c1d75cf808
Merge pull request #7312 from mailcow/renovate/composer-composer-2.x
...
Update dependency composer/composer to v2.10.2
2026-07-13 09:40:58 +02:00
FreddleSpl0it
473fe2885d
Merge pull request #7326 from ralfbergs/fix/quarantine-text-refining
...
Refined wording for displaying of active settings on quarantine page.
2026-07-13 09:40:24 +02:00
FreddleSpl0it
31e1550668
[Postfix] change postscreen blacklist_action to denylist_action
2026-07-13 08:45:56 +02:00
FreddleSpl0it
315f55bc65
Merge pull request #7323 from DerLinkman/feat/postfix-deb13
...
postfix: migrate from bookworm to trixie
2026-07-13 08:23:57 +02:00
Ralf Bergs
e696ee2f6c
Refined wording for displaying of active settings on quarantine page.
2026-07-12 17:22:15 +02:00
renovate[bot]
d65aa11870
Update devops-infra/action-pull-request action to v1.4.0 ( #7321 )
...
Signed-off-by: milkmaker <milkmaker@mailcow.de >
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-12 15:20:18 +02:00
renovate[bot]
f6630e5b43
Update actions/stale action to v10.4.0 ( #7322 )
...
Signed-off-by: milkmaker <milkmaker@mailcow.de >
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-12 15:19:49 +02:00
DerLinkman
98e26c5603
compose: upgrade Postfix
2026-07-10 18:41:58 +02:00
DerLinkman
3098caebbc
migrate postfix to trixie
2026-07-10 18:29:45 +02:00
renovate[bot]
94e23a3cd3
Update dependency composer/composer to v2.10.2
...
Signed-off-by: milkmaker <milkmaker@mailcow.de >
2026-07-01 09:32:23 +00:00
milkmaker
1840074991
update postscreen_access.cidr ( #7311 )
2026-07-01 11:31:58 +02:00
FreddleSpl0it
99768e16f5
Merge pull request #7305 from mailcow/feat/nginx-1.30.3
...
[Nignx] Update to 1.30.3
2026-06-25 12:20:25 +02:00
FreddleSpl0it
1f8b4679cc
[Nignx] Update to 1.30.3
2026-06-25 12:17:37 +02:00
milkmaker
9e723e942d
Translations update from Weblate ( #7302 )
...
* [Web] Updated lang.fr-fr.json
Co-authored-by: Romain Ayme <ayme.romain@hotmail.fr >
* [Web] Updated lang.si-si.json
Co-authored-by: Matjaž Tekavec <matjaz@moj-svet.si >
---------
Co-authored-by: Romain Ayme <ayme.romain@hotmail.fr >
Co-authored-by: Matjaž Tekavec <matjaz@moj-svet.si >
2026-06-20 13:57:15 +02:00
renovate[bot]
47e4552b44
Update actions/checkout action to v7 ( #7300 )
2026-06-19 08:34:02 +02:00
renovate[bot]
7e6c36dce1
Update alpine Docker tag to v3.24 ( #7280 )
2026-06-11 11:35:03 +02:00
FreddleSpl0it
fa154c71f3
[PHP] Rebuild Image
2026-06-11 10:29:01 +02:00
FreddleSpl0it
83a045ed3e
Merge pull request #7193 from mailcow/renovate/composer-composer-2.x
...
Update dependency composer/composer to v2.10.1
2026-06-11 10:07:19 +02:00
FreddleSpl0it
064817ac70
Merge pull request #7189 from mailcow/renovate/php-pecl-mail-mailparse-3.x
...
Update dependency php/pecl-mail-mailparse to v3.2.0
2026-06-11 10:06:49 +02:00
FreddleSpl0it
2bd7a24b8c
Merge pull request #7212 from mailcow/mkuron-patch-mobileconfig
...
Escape generated password in mobileconfig
2026-06-11 10:05:17 +02:00
FreddleSpl0it
ecc2462e4c
Merge pull request #7267 from goodygh/7249-update-sogo
...
[SOGo] Update to 5.12.9
2026-06-11 10:04:30 +02:00
FreddleSpl0it
2d8db72d46
Merge pull request #7275 from Snafu/fix/admin-mailbox-tfa-missing
...
Fix force_tfa not available in mailbox template #7216
2026-06-11 10:03:39 +02:00
FreddleSpl0it
277a307fb9
[Web] Fix refresh SOGo view on mailbox deletion
2026-06-11 09:55:32 +02:00
FreddleSpl0it
d455555621
Merge pull request #7277 from ibobgunardi/bobi/mailcow-7136-sogo-active-refresh
...
Refresh SOGo view after mailbox activation
2026-06-11 09:53:30 +02:00
FreddleSpl0it
9ea2ff1dff
Merge pull request #7283 from mailcow/feat/update-metadata-exporter
...
[Rspamd] Migrate metadata_exporter to multipart formatter
2026-06-11 09:40:34 +02:00
FreddleSpl0it
24cc369d84
[Rspamd] Migrate metadata_exporter to multipart formatter
2026-06-11 09:34:27 +02:00
FreddleSpl0it
5f5367f2f9
Merge pull request #7172 from mailcow/dragoangel-patch-4
...
Update RSPAMD version to 4.1.0 in Dockerfile
2026-06-11 09:04:19 +02:00
milkmaker
03c31f825a
update postscreen_access.cidr ( #7269 )
2026-06-09 12:20:53 +02:00
renovate[bot]
c0050e8836
Update devops-infra/action-pull-request action to v1.3.0 ( #7272 )
2026-06-09 12:19:09 +02:00
Dmytro Alieksieiev
15891960f7
Update RSPAMD version to 4.1.0
2026-06-09 01:19:06 +02:00
Bobby
cce02e2b15
Refresh SOGo view after mailbox activation
2026-06-08 00:01:43 +07:00
Snafu
0fafda696b
Fix force_tfa not available in mailbox template #7216
2026-06-07 17:03:52 +02:00
renovate[bot]
843db5854c
Update dependency composer/composer to v2.10.1
...
Signed-off-by: milkmaker <milkmaker@mailcow.de >
2026-06-04 11:04:42 +00:00
goodygh
23e4e4f373
[SOGo] Update to 5.12.9
2026-05-29 01:39:38 +02:00
goodygh
175878f8f1
ui, fail2ban fix german ban_list_info translation ( #7265 )
2026-05-28 22:20:26 +02:00
milkmaker
3fcda21c4e
[Web] Updated lang.vi-vn.json ( #7263 )
...
Co-authored-by: Phu D. Nguyen <sillycat@duck.com >
2026-05-27 17:46:42 +02:00
milkmaker
eac1bf02fc
[Web] Updated lang.lv-lv.json ( #7262 )
...
Co-authored-by: Edgars Andersons <Edgars+Mailcow+Weblate@gaitenis.id.lv >
2026-05-26 22:02:05 +02:00
renovate[bot]
a7f2b2145f
Update devops-infra/action-pull-request action to v1.2.1 ( #7258 )
...
Signed-off-by: milkmaker <milkmaker@mailcow.de >
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-05-26 22:00:43 +02:00
FreddleSpl0it
faac56a611
[Unbound] Change version tag
2026-05-26 10:43:25 +02:00
FreddleSpl0it
be37bc5a68
Merge pull request #7252 from SYNLINQ/staging
...
fix unbound CVE-2026-33278
2026-05-26 10:41:52 +02:00
FreddleSpl0it
b227c76156
Merge pull request #7259 from mailcow/feat/nginx-1.30.2
...
[Nginx] Update to 1.30.2
2026-05-26 10:37:57 +02:00
FreddleSpl0it
db4e3b4d54
[Nginx] Update to 1.30.2
2026-05-26 10:36:39 +02:00