Page MenuHomePhorge
Feed All Stories

Today

machniak committed rS4ed2bddb86f2: Fix PHP warnings.
Thu, May 21, 2:24 PM
machniak committed rI0329a29f3f2a: Fix PHP warning.
Thu, May 21, 2:10 PM
machniak committed rRPK7faa4c6c9d2e: Fix PHP warning.
Thu, May 21, 2:05 PM
machniak requested review of D5899: Revoke user tokens on password change.
Thu, May 21, 1:25 PM
Spenneberg lowered the priority of T8385: kolab-saslauthd fails on Almalinux 9 with status=2/INVALIDARGUMENT from Needs Triage to Low.

On my system the problem has stopped. Actually I do not know since when. But for the last couple of weeks I did not have any crashes anymore. Currently I am running kolab-saslauthd-0.9.0.8-2.85.el9.kolab_16.noarch.
Therefore I change the priority to low.

Thu, May 21, 12:50 PM ยท Kolab 16
machniak closed D5896: Add "password change" event to the history.
Thu, May 21, 10:48 AM
machniak closed D5893: Move most delete jobs into the slow queue.
Thu, May 21, 10:48 AM
machniak closed D5894: Nicely handle warnings on get_dns_record().
Thu, May 21, 10:48 AM
machniak closed D5895: Nicely handle "duplicate entry" errors in greylisting.
Thu, May 21, 10:48 AM
machniak committed rKa6c70c524b5c: Move most delete jobs into the slow queue.
Thu, May 21, 10:47 AM
machniak committed rK5f6b79e01776: Add "password change" event to the history.
Thu, May 21, 10:47 AM
machniak committed rK47bb603339d3: Nicely handle warnings on get_dns_record().
Thu, May 21, 10:47 AM
machniak committed rKafd80adc1afb: Nicely handle "duplicate entry" errors in greylisting.
Thu, May 21, 10:47 AM
machniak updated the diff for D5892: PGP keys with proper email aliases support.
  • Use stable Crypt_GPG release
Thu, May 21, 10:23 AM

Yesterday

mollekopf committed R114:612660989bfd: Submit mail from sieve to port 10588.
Wed, May 20, 3:34 PM
mollekopf closed D5897: Respect the greylist setting when the network is not recognized.
Wed, May 20, 8:47 AM
mollekopf committed rKdc85f9961f88: Respect the greylist setting when the network is not recognized.
Wed, May 20, 8:47 AM
mollekopf closed D5898: Handle sieve redirects in policy controller.
Wed, May 20, 8:29 AM
mollekopf committed rK5939088de8bb: Handle sieve redirects in policy controller.
Wed, May 20, 8:29 AM
machniak accepted D5897: Respect the greylist setting when the network is not recognized.
Wed, May 20, 8:28 AM
mollekopf updated the diff for D5897: Respect the greylist setting when the network is not recognized.

Moved findConnectionsCollection after the netID check again

Wed, May 20, 8:11 AM
machniak requested changes to D5897: Respect the greylist setting when the network is not recognized.
Wed, May 20, 7:48 AM
machniak accepted D5898: Handle sieve redirects in policy controller.

An test for the new route in tests/Feature/Controller/PolicyTest.php would be nice.

Wed, May 20, 7:42 AM

Tue, May 19

mollekopf updated the diff for D5898: Handle sieve redirects in policy controller.

typo

Tue, May 19, 4:06 PM
mollekopf committed rK423f7b88bbc8: Handle smtp sender restrictions and dkim signatures for sieve.
Tue, May 19, 3:58 PM
mollekopf added a reviewer for D5898: Handle sieve redirects in policy controller: Restricted Project.
Tue, May 19, 3:45 PM
mollekopf requested review of D5898: Handle sieve redirects in policy controller.
Tue, May 19, 3:44 PM
mollekopf committed rK97510daab192: Configure SPAM subject tag.
Tue, May 19, 3:43 PM
mollekopf committed rKe894c406e4ad: kolab_policy_submission fix recipient_count handling.
Tue, May 19, 3:43 PM
mollekopf committed rKe5cbe659fcce: Fix reload of cyrus-imap master.
Tue, May 19, 3:43 PM
mollekopf committed rK71baf6d20586: Test out of office reply.
Tue, May 19, 3:43 PM
mollekopf committed rK04c0c5036c9c: mailtransporttest updates to search by another subject.
Tue, May 19, 3:43 PM
mollekopf committed rKa17c05c77980: Sieve testing.
Tue, May 19, 3:43 PM
mollekopf committed rKc2a6605e8cde: Configure an smtp_host for out of office replies and redirects.
Tue, May 19, 3:43 PM
mollekopf committed rK9dfae1c0da24: Enable vacation-seconds sieve plugin and set the minimum interval.
Tue, May 19, 3:43 PM
mollekopf added a reviewer for D5897: Respect the greylist setting when the network is not recognized: Restricted Project.

I ran into this in testing

Tue, May 19, 3:34 PM
mollekopf requested review of D5897: Respect the greylist setting when the network is not recognized.
Tue, May 19, 3:33 PM
mollekopf accepted D5895: Nicely handle "duplicate entry" errors in greylisting.
Tue, May 19, 3:15 PM
mollekopf accepted D5894: Nicely handle warnings on get_dns_record().
Tue, May 19, 3:13 PM
mollekopf accepted D5896: Add "password change" event to the history.
Tue, May 19, 3:11 PM
machniak requested review of D5896: Add "password change" event to the history.
Tue, May 19, 1:22 PM
machniak committed rKffe58a8f3ab8: CS fixes.
Tue, May 19, 12:45 PM
mollekopf closed D5884: Use a token with the 'config' scope for the user config request.
Tue, May 19, 8:17 AM
mollekopf closed D5888: Exchange the password for an otp token once 2fa has passed.
Tue, May 19, 8:17 AM
mollekopf committed rRPK5b8c505aade3: Use a token with the 'config' scope for the user config request.
Tue, May 19, 8:17 AM
mollekopf committed rRPK45726cbdd5f2: Exchange the password for an otp token once 2fa has passed.
Tue, May 19, 8:17 AM
mollekopf accepted D5893: Move most delete jobs into the slow queue.
Tue, May 19, 8:15 AM
mollekopf committed rKf8b52bf182a6: Test otp token.
Tue, May 19, 8:06 AM
mollekopf closed D5889: Validate the second factor if we received one.
Tue, May 19, 8:06 AM
mollekopf committed rKeb7b89c46695: Validate the second factor if we received one.
Tue, May 19, 8:06 AM
mollekopf closed D5883: Allow config api access without 2fa.
Tue, May 19, 8:06 AM
mollekopf closed D5887: Optional OTP token generation on logon.
Tue, May 19, 8:06 AM
mollekopf closed D5886: Prevent access over username & password when a second factor is configured.
Tue, May 19, 8:06 AM
mollekopf committed rK3c2cbb8f1245: Optional OTP token generation on logon (authored by machniak).
Tue, May 19, 8:06 AM
mollekopf committed rK58c12c8937f0: Allow config api access without 2fa.
Tue, May 19, 8:06 AM
mollekopf committed rK5a0a0fc71590: Prevent access over username & password when a second factor is configured.
Tue, May 19, 8:06 AM

Mon, May 18

machniak requested review of D5895: Nicely handle "duplicate entry" errors in greylisting.
Mon, May 18, 12:49 PM
machniak requested review of D5894: Nicely handle warnings on get_dns_record().
Mon, May 18, 12:03 PM

Fri, May 15

machniak committed rKb2a3938ad264: Fix test regression.
Fri, May 15, 2:43 PM
machniak committed rK9612658c1931: Fix test: Use always-existing shared folder.
Fri, May 15, 2:43 PM
machniak committed rKc0ea800f613f: Fix flaky test.
Fri, May 15, 2:43 PM
machniak requested review of D5893: Move most delete jobs into the slow queue.
Fri, May 15, 12:22 PM
machniak requested review of D5892: PGP keys with proper email aliases support.
Fri, May 15, 11:42 AM
machniak closed D5880: PGP key server (HKP v1).
Fri, May 15, 11:38 AM
machniak committed rK275b80e5f34e: PGP key server (HKP v1).
Fri, May 15, 11:38 AM
mollekopf committed R114:a083ab203c03: Monitor amavis for TROUBLE messages.
Fri, May 15, 9:06 AM
mollekopf committed R114:ab38f1fe5533: Configure roundcube MAX_FILESIZE.
Fri, May 15, 9:06 AM

Thu, May 14

mollekopf added inline comments to D5891: [WIP] SSO logout.
Thu, May 14, 9:11 AM
machniak added a comment to D5890: SSO Logout POC.

Roundcube 1.7 has it built-in https://github.com/roundcube/roundcubemail/blob/2e66510e2c4cf734a016befb02d96cef6bac12d4/program/include/rcmail_oauth.php#L1236. It also has support for "logout in cockpit should destroy OAuth tokens and client sessions" action (backchannel) https://github.com/roundcube/roundcubemail/blob/master/program/actions/login/oauth_backchannel.php.

Thu, May 14, 8:15 AM
machniak requested review of D5891: [WIP] SSO logout.
Thu, May 14, 8:13 AM

Wed, May 13

mollekopf planned changes to D5890: SSO Logout POC.
Wed, May 13, 8:02 PM
mollekopf added a reviewer for D5890: SSO Logout POC: Roundcube Kolab Plugins Developers.
Wed, May 13, 8:01 PM
mollekopf requested review of D5890: SSO Logout POC.
Wed, May 13, 8:01 PM
mollekopf accepted D5880: PGP key server (HKP v1).
Wed, May 13, 2:52 PM
mollekopf accepted D5887: Optional OTP token generation on logon.

I have a test available.

Wed, May 13, 2:51 PM
mollekopf added a reviewer for D5889: Validate the second factor if we received one: Restricted Project.
Wed, May 13, 2:25 PM
mollekopf requested review of D5889: Validate the second factor if we received one.
Wed, May 13, 2:25 PM
mollekopf added a reviewer for D5888: Exchange the password for an otp token once 2fa has passed: Roundcube Kolab Plugins Developers.
Wed, May 13, 2:24 PM
mollekopf updated the diff for D5888: Exchange the password for an otp token once 2fa has passed.

Use fast mode with otp mode and some cleanup

Wed, May 13, 2:17 PM
mollekopf requested review of D5888: Exchange the password for an otp token once 2fa has passed.
Wed, May 13, 2:04 PM
machniak requested review of D5887: Optional OTP token generation on logon.
Wed, May 13, 12:59 PM
mollekopf accepted D5885: Limit list of HTTP headers stored with signup codes.
Wed, May 13, 9:27 AM
machniak committed rKb768d6ef5508: Fix: count trashed signup codes.
Wed, May 13, 8:04 AM
machniak accepted D5886: Prevent access over username & password when a second factor is configured.
Wed, May 13, 5:37 AM

Tue, May 12

mollekopf added a comment to D5886: Prevent access over username & password when a second factor is configured.

This is what prevents external clients from bypassing 2fa now, without attempting to make 2fa work for username+password. We still allow "config" scope tokens to bypass 2fa, which is operationally easier than a separate shared secret.

Tue, May 12, 9:13 PM
mollekopf added a reviewer for D5886: Prevent access over username & password when a second factor is configured: Restricted Project.
Tue, May 12, 9:07 PM
mollekopf updated the diff for D5886: Prevent access over username & password when a second factor is configured.

Cleanup

Tue, May 12, 9:07 PM
mollekopf requested review of D5886: Prevent access over username & password when a second factor is configured.
Tue, May 12, 9:06 PM
machniak updated the diff for D5885: Limit list of HTTP headers stored with signup codes.
  • Use x-client-ip
Tue, May 12, 2:10 PM
machniak requested review of D5885: Limit list of HTTP headers stored with signup codes.
Tue, May 12, 12:24 PM
machniak added a comment to D5884: Use a token with the 'config' scope for the user config request.

Having a single secret token that identifies Roundcube client and allows for user impersonation on config/webmail request only would probably be better. It would allow to skip /api/auth/login and directly call /api/v4/config/webmail, e.g. with Bearer <email>:<secret>. It would also eliminate any token refresh issues, as it would not have to be refreshed.

Tue, May 12, 8:32 AM
machniak accepted D5883: Allow config api access without 2fa.
Tue, May 12, 7:51 AM
mollekopf added a reviewer for D5883: Allow config api access without 2fa: Restricted Project.
Tue, May 12, 6:40 AM
mollekopf added a reviewer for D5884: Use a token with the 'config' scope for the user config request: Roundcube Kolab Plugins Developers.
Tue, May 12, 6:39 AM
mollekopf updated the diff for D5884: Use a token with the 'config' scope for the user config request.

Fixup

Tue, May 12, 6:28 AM
mollekopf updated the diff for D5884: Use a token with the 'config' scope for the user config request.

Cleanup

Tue, May 12, 6:22 AM
mollekopf requested review of D5884: Use a token with the 'config' scope for the user config request.
Tue, May 12, 6:18 AM
mollekopf updated the diff for D5883: Allow config api access without 2fa.

Cleanup

Tue, May 12, 6:18 AM
mollekopf requested review of D5883: Allow config api access without 2fa.
Tue, May 12, 6:15 AM

Mon, May 11

machniak updated the diff for D5880: PGP key server (HKP v1).
  • Remove TODO line
Mon, May 11, 12:18 PM