mirror of
https://github.com/profullstack/agentbbs.git
synced 2026-08-13 22:37:28 +00:00
* feat(mail): give every verified member a free @bbs.profullstack.com mailbox Email was built but paid-only (Founding Lifetime gate) and never wired to a running backend. Make it a free benefit of membership and split the address domain from the mail-server host. - internal/mailu: Mailu admin-API client; EnsureUser idempotently provisions a mailbox via the loopback admin REST API (token = mailu.env API_TOKEN). - main.go: auto-provision <name>@<mailDomain> at join@ verification and on first Mail open; un-gate the Mail hub entry + mail@ (membership/email-verified, not Premium); address domain (AGENTBBS_MAIL_ADDR_DOMAIN, default the BBS host) is now distinct from the mail server host (AGENTBBS_MAIL_DOMAIN) and the webmail URL. Drop the forwardemail alias path (Mailu now owns delivery for everyone). - mailbox: gate on membership (a registered handle) instead of Paid; ErrNotPaid -> ErrNotMember. - join@ copy: list email under free membership; premium now pitches custom domains + Tor only. - setup.sh / docs/mail.md / deploy/mailu: address-domain vs server-host split, Mailu API token, MX for the address domain, local-relay SMTP for verify codes. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * chore(mailu): pin Docker network subnet to match SUBNET; ignore runtime state The base compose declares no network, so Docker assigns the default bridge an arbitrary subnet that won't match mailu.env SUBNET — breaking Mailu's internal service auth/relay. Add a docker-compose.override.yml.example that pins the default network to 192.168.203.0/24, and gitignore the live override + Mailu runtime state (mailu.env, certs/, data/). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * feat(mail): plaintext loopback IMAP so the gateway bypasses Mailu's front Mailu's front (nginx mail proxy) pre-authenticates against Mailu's user DB before proxying to Dovecot, which rejects the Dovecot master-user login <addr>*gateway. The gateway must reach Dovecot directly. The imap container has no TLS cert (only the front does), so the bypass is plaintext over loopback — the master password never leaves the host. - mailbox: IMAPConfig.Plaintext dials with DialInsecure (loopback only). - main.go: mailClientFor sets Plaintext from AGENTBBS_MAIL_IMAP_PLAINTEXT. - override.example: add the unbound resolver (admin needs DNSSEC), webmail image fix (2024.06 uses mailu/webmail), and publish Dovecot 143 on 127.0.0.1:14143. - docs/mail.md: document the front-bypass, the dovecot.conf master passdb (Mailu includes that exact filename), and the 644 master-users perms (640 = temp_fail). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * deploy(mailu): wire gateway IMAP to the loopback Dovecot path in setup.sh setup.sh §9e set AGENTBBS_MAIL_IMAP_ADDR to the front's :993, which the front's auth proxy rejects for the master-user login (and would clobber the working loopback wiring on every self-update). Point it at 127.0.0.1:14143 + AGENTBBS_MAIL_IMAP_PLAINTEXT=1 instead, matching the override + docs. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * feat(mail): give free members a webmail password at join@ The gateway opens mailboxes via the Dovecot master user (no member password), but webmail (Roundcube) needs the member to have a password. join@ now sets a fresh, readable webmail password via the Mailu API and shows it with the webmail URL + login, so free members can use webmail at mail.profullstack.com. - mailu: SetPassword (PATCH /user/<email> raw_password) + test. - main.go: setWebmailPassword + readablePassword; join@ displays url/login/password. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
56 lines
2.7 KiB
Text
56 lines
2.7 KiB
Text
# Mailu configuration — copy to deploy/mailu/mailu.env and fill the secrets.
|
|
# See docs/mail.md for the full setup (DNS, certs, gateway).
|
|
#
|
|
# Generate secrets with: openssl rand -hex 16
|
|
#
|
|
# NOTE: DOMAIN is the member ADDRESS domain (the @-part); HOSTNAMES is the mail
|
|
# SERVER host (TLS/HELO + webmail/admin/API). These deliberately differ:
|
|
# members get <name>@bbs.profullstack.com, served from mail.profullstack.com.
|
|
|
|
# --- General -----------------------------------------------------------------
|
|
SECRET_KEY=CHANGEME_16_HEX # openssl rand -hex 16
|
|
DOMAIN=bbs.profullstack.com # member addresses are <name>@bbs.profullstack.com
|
|
HOSTNAMES=mail.profullstack.com,smtp.profullstack.com
|
|
POSTMASTER=postmaster
|
|
# Apex profullstack.com is reserved for corporate mail and is NOT served here.
|
|
|
|
# Admin REST API: agentbbs auto-provisions member mailboxes through it. Mirror
|
|
# this value into the agentbbs service as AGENTBBS_MAIL_API_TOKEN.
|
|
API=true
|
|
API_TOKEN=CHANGEME_api_token # openssl rand -hex 24
|
|
|
|
# TLS_FLAVOR=mail: Mailu does NOT run its own ACME (Caddy owns :80/:443). We feed
|
|
# it certs copied from Caddy's mail.profullstack.com cert (deploy/mailu/refresh-certs.sh).
|
|
TLS_FLAVOR=mail
|
|
|
|
# --- Features ----------------------------------------------------------------
|
|
ADMIN=true # the admin UI (fronted at /admin via Caddy, internal only)
|
|
WEBMAIL=roundcube # the only member-facing surface (https://mail.profullstack.com)
|
|
WEBDAV=none
|
|
ANTIVIRUS=none # set to clamav on a 4GB+ host
|
|
ANTISPAM=true
|
|
|
|
# --- Networking --------------------------------------------------------------
|
|
# Mailu's front binds the mail ports on the host and HTTP on loopback only;
|
|
# Caddy reverse-proxies https://mail.profullstack.com to BIND_ADDRESS4:80.
|
|
BIND_ADDRESS4=127.0.0.1
|
|
SUBNET=192.168.203.0/24
|
|
MESSAGE_SIZE_LIMIT=52428800 # 50 MB
|
|
|
|
# --- Gateway (the BBS reads/sends on behalf of members) ----------------------
|
|
# A Dovecot master user lets the agentbbs gateway open any member's mailbox with
|
|
# one secret (login "<name>*<master>"). Created by deploy/mailu/provision-mailbox.sh.
|
|
# Mirror these into the agentbbs service env:
|
|
# AGENTBBS_MAIL_ADDR_DOMAIN=bbs.profullstack.com
|
|
# AGENTBBS_MAIL_DOMAIN=mail.profullstack.com
|
|
# AGENTBBS_MAIL_IMAP_ADDR=mail.profullstack.com:993
|
|
# AGENTBBS_MAIL_SMTP_ADDR=127.0.0.1:25
|
|
# AGENTBBS_MAIL_ADMIN_URL=http://127.0.0.1:8080
|
|
# AGENTBBS_MAIL_API_TOKEN=<the API_TOKEN above>
|
|
# AGENTBBS_MAIL_MASTER_USER=gateway
|
|
# AGENTBBS_MAIL_MASTER_PASS=<the master password you set>
|
|
|
|
# --- Admin bootstrap ---------------------------------------------------------
|
|
INITIAL_ADMIN_ACCOUNT=admin
|
|
INITIAL_ADMIN_DOMAIN=bbs.profullstack.com
|
|
INITIAL_ADMIN_PW=CHANGEME_admin_password
|