Insular email distribution - mail server as Docker images https://mailu.io
  • Python 76.5%
  • HTML 11.1%
  • Shell 4.1%
  • Dockerfile 2.2%
  • JavaScript 2.1%
  • Other 3.9%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
bors-mailu[bot] e417c90134
Merge #4110
4110: Clear webmail session cookies on SSO login r=nextgens a=spomata

## What type of PR?

bug-fix

## What does this PR do?

After an SSO login as a different user, or after the Mailu session expired while the webmail cookie survived, the webmail keeps its old session. Its IMAP credential is a temp token bound to the replaced Mailu session (`flask.session.regenerate()`), so IMAP rejects it (`Folders error: AUTHENTICATIONFAILED`). Snappymail only goes back through `sso.php` when it has no session, so it never picks up the new user.

This PR expires the webmail cookies (`smsession`, `roundcube_sessauth`, `roundcube_sessid`) on every successful SSO login (form login and both proxy-auth paths), as `/sso/logout` already does. The cookie-clearing loop is moved into a helper shared with logout.

### Related issue(s)
- closes #4109

## Prerequisites
- [x] In case of feature or enhancement: documentation updated accordingly
- [x] Unless it's docs or a minor change: add changelog entry file.

## Testing

Tested on a 2024.06.60 deployment with Snappymail: switching A→B and B→A works with and without closing the browser in between; a normal single login and logout keep working.


Co-authored-by: spomata <49432438+spomata@users.noreply.github.com>
2026-09-30 11:26:57 +00:00
.github Merge branch 'master' into upgrade-deps2026 2026-09-24 14:59:46 +02:00
core Merge #4110 2026-09-30 11:26:57 +00:00
design s/docker\-compose\([^\.]\)/docker compose\1/g 2023-02-15 10:00:03 +01:00
docs Use exec form for the docs container 2026-09-25 10:49:56 +02:00
optional Major dep upgrade 2026-09-24 14:00:56 +02:00
scripts Fix purge_user.sh 2024-05-03 14:31:18 +02:00
setup Enable HTTP/3 and HTTP/2 backends 2026-09-25 10:36:45 +02:00
tests Merge #4099 #4101 2026-09-27 15:46:48 +00:00
towncrier Clear webmail session cookies on SSO login 2026-09-29 13:37:05 +02:00
webmails Merge #4103 2026-09-28 06:11:23 +00:00
.gitignore Major dep upgrade 2026-09-24 14:00:56 +02:00
.mergify.yml revert 2026-08-17 11:28:29 +02:00
AUTHORS.md Update AUTHORS.md. 2024-03-26 08:55:16 +01:00
bors.toml Switch to github actions for CI/CD 2021-06-26 08:25:15 +00:00
CHANGELOG.md Update release notes 2024-06-09 15:19:29 +00:00
CODE_OF_CONDUCT.md Add a code of conduct, fixes #319 2017-11-12 11:42:53 +01:00
CONTRIBUTING.md Fix a bunch of typos 2022-10-19 19:41:49 +02:00
ISSUE_TEMPLATE.md docs: remove references to defunct Matrix room 2026-04-21 10:42:52 +00:00
LICENSE.md Rename the freeposte/mailu directory and database 2016-10-29 13:42:39 +02:00
PULL_REQUEST_TEMPLATE.md fix spelling 2021-09-13 15:23:05 +02:00
pyproject.toml Fix the package setting 2019-09-17 21:13:35 +02:00
README.md docs: remove references to defunct Matrix room 2026-04-21 10:42:52 +00:00
RELEASE_TEMPLATE.md Update version to 2.+ in release template 2023-05-09 19:56:13 +02:00
SECURITY.md Create SECURITY.md 2022-08-24 08:51:47 +02:00

Mailu

Mailu is a simple yet full-featured mail server as a set of Docker images. It is free software (both as in free beer and as in free speech), open to suggestions and external contributions. The project aims at providing people with an easily setup, easily maintained and full-featured mail server while not shipping proprietary software nor unrelated features often found in popular groupware.

Most of the documentation is available on our Website. You can also try our demo server before setting up your own.

Features

Main features include:

  • Standard email server, IMAP and IMAP+, SMTP and Submission with auto-configuration profiles for clients
  • Advanced email features, aliases, domain aliases, custom routing, full-text search of email attachments
  • Web access, multiple Webmails and administration interface
  • User features, aliases, auto-reply, auto-forward, fetched accounts, managesieve
  • Admin features, global admins, announcements, per-domain delegation, quotas
  • Security, enforced TLS, DANE, MTA-STS, Letsencrypt!, outgoing DKIM, anti-virus scanner, Snuffleupagus, block malicious attachments
  • Antispam, auto-learn, greylisting, DMARC and SPF, anti-spoofing
  • Freedom, all FOSS components, no tracker included

Domains

Contributing

Mailu is free software, open to suggestions and contributions. All components are free software and compatible with the MIT license. All specific configuration files, Dockerfiles and code are placed under the MIT license.