diff --git a/.github/FUNDING.yml b/.github/FUNDING.yml new file mode 100644 index 0000000..0c593be --- /dev/null +++ b/.github/FUNDING.yml @@ -0,0 +1,4 @@ +# Funding platforms shown behind the repository's Sponsor button. +# https://docs.github.com/repositories/managing-your-repositorys-settings-and-features/customizing-your-repository/displaying-a-sponsor-button-in-your-repository + +github: jcoffey-dev diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..7108006 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,31 @@ +version: 2 +updates: + # One npm entry at the root, where the single lockfile is. + # + # Minor and patch arrive as one pull request a week. Majors are left out of + # the group on purpose: they are migrations rather than bumps, and each one + # deserves its own pull request and its own CI run. + - package-ecosystem: npm + directory: "/" + schedule: + interval: weekly + day: tuesday + time: "09:00" + timezone: Etc/UTC + open-pull-requests-limit: 5 + groups: + minor-and-patch: + update-types: + - minor + - patch + - package-ecosystem: github-actions + directory: "/" + schedule: + interval: weekly + day: tuesday + time: "09:00" + timezone: Etc/UTC + groups: + actions: + patterns: + - "*" diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml new file mode 100644 index 0000000..29511f6 --- /dev/null +++ b/.github/workflows/ci.yml @@ -0,0 +1,31 @@ +name: CI +on: + push: + branches: [main] + pull_request: + workflow_dispatch: + +concurrency: + group: ci-${{ github.ref }} + cancel-in-progress: true + +jobs: + build: + runs-on: ubuntu-latest + steps: + # Pinned to full commit SHAs, with the release in the trailing comment. + # A tag is a mutable pointer, so trusting `@v7` is trusting every future + # version of that action. Dependabot updates both halves together on its + # weekly run -- do not "simplify" a pin back to a tag. + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + with: + node-version: 22 + cache: npm + # --ignore-scripts: a postinstall script in any transitive dependency + # would otherwise run with the runner's token in its environment. + - run: npm ci --ignore-scripts + - run: npm run typecheck + - run: npm run lint + - run: npm test + - run: npm run build diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md new file mode 100644 index 0000000..48d8417 --- /dev/null +++ b/CODE_OF_CONDUCT.md @@ -0,0 +1,128 @@ +# Contributor Covenant Code of Conduct + +## Our Pledge + +We as members, contributors, and leaders pledge to make participation in our +community a harassment-free experience for everyone, regardless of age, body +size, visible or invisible disability, ethnicity, sex characteristics, gender +identity and expression, level of experience, education, socio-economic status, +nationality, personal appearance, race, religion, or sexual identity +and orientation. + +We pledge to act and interact in ways that contribute to an open, welcoming, +diverse, inclusive, and healthy community. + +## Our Standards + +Examples of behavior that contributes to a positive environment for our +community include: + +* Demonstrating empathy and kindness toward other people +* Being respectful of differing opinions, viewpoints, and experiences +* Giving and gracefully accepting constructive feedback +* Accepting responsibility and apologizing to those affected by our mistakes, + and learning from the experience +* Focusing on what is best not just for us as individuals, but for the + overall community + +Examples of unacceptable behavior include: + +* The use of sexualized language or imagery, and sexual attention or + advances of any kind +* Trolling, insulting or derogatory comments, and personal or political attacks +* Public or private harassment +* Publishing others' private information, such as a physical or email + address, without their explicit permission +* Other conduct which could reasonably be considered inappropriate in a + professional setting + +## Enforcement Responsibilities + +Community leaders are responsible for clarifying and enforcing our standards of +acceptable behavior and will take appropriate and fair corrective action in +response to any behavior that they deem inappropriate, threatening, offensive, +or harmful. + +Community leaders have the right and responsibility to remove, edit, or reject +comments, commits, code, wiki edits, issues, and other contributions that are +not aligned to this Code of Conduct, and will communicate reasons for moderation +decisions when appropriate. + +## Scope + +This Code of Conduct applies within all community spaces, and also applies when +an individual is officially representing the community in public spaces. +Examples of representing our community include using an official e-mail address, +posting via an official social media account, or acting as an appointed +representative at an online or offline event. + +## Enforcement + +Instances of abusive, harassing, or otherwise unacceptable behavior may be +reported to the community leaders responsible for enforcement at +**johnellisATlinuxDOTcom**. +All complaints will be reviewed and investigated promptly and fairly. + +All community leaders are obligated to respect the privacy and security of the +reporter of any incident. + +## Enforcement Guidelines + +Community leaders will follow these Community Impact Guidelines in determining +the consequences for any action they deem in violation of this Code of Conduct: + +### 1. Correction + +**Community Impact**: Use of inappropriate language or other behavior deemed +unprofessional or unwelcome in the community. + +**Consequence**: A private, written warning from community leaders, providing +clarity around the nature of the violation and an explanation of why the +behavior was inappropriate. A public apology may be requested. + +### 2. Warning + +**Community Impact**: A violation through a single incident or series +of actions. + +**Consequence**: A warning with consequences for continued behavior. No +interaction with the people involved, including unsolicited interaction with +those enforcing the Code of Conduct, for a specified period of time. This +includes avoiding interactions in community spaces as well as external channels +like social media. Violating these terms may lead to a temporary or +permanent ban. + +### 3. Temporary Ban + +**Community Impact**: A serious violation of community standards, including +sustained inappropriate behavior. + +**Consequence**: A temporary ban from any sort of interaction or public +communication with the community for a specified period of time. No public or +private interaction with the people involved, including unsolicited interaction +with those enforcing the Code of Conduct, is allowed during this period. +Violating these terms may lead to a permanent ban. + +### 4. Permanent Ban + +**Community Impact**: Demonstrating a pattern of violation of community +standards, including sustained inappropriate behavior, harassment of an +individual, or aggression toward or disparagement of classes of individuals. + +**Consequence**: A permanent ban from any sort of public interaction within +the community. + +## Attribution + +This Code of Conduct is adapted from the [Contributor Covenant][homepage], +version 2.0, available at +https://www.contributor-covenant.org/version/2/0/code_of_conduct.html. + +Community Impact Guidelines were inspired by [Mozilla's code of conduct +enforcement ladder](https://github.com/mozilla/diversity). + +[homepage]: https://www.contributor-covenant.org + +For answers to common questions about this code of conduct, see the FAQ at +https://www.contributor-covenant.org/faq. Translations are available at +https://www.contributor-covenant.org/translations. diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md new file mode 100644 index 0000000..44afea0 --- /dev/null +++ b/CONTRIBUTING.md @@ -0,0 +1,29 @@ +# Contributing + +Patches, bug reports and questions are welcome. Open an issue first for +anything substantial; small fixes need no ceremony. + +## What this is + +A fork of Stalwart's web interface, taken under the AGPL-3.0-only half of its +dual licence, talking to INBUXA over JMAP and OAuth. Upstream's copyright +headers stay where they are, and a file this fork has changed says so beneath +them. New files carry Coffey Labs' own header and `AGPL-3.0-only`. + +Changes to files that came from upstream are kept small, so the next import +merges cleanly and a reader can tell fork from base. + +## Before you push + +``` +npm ci +npm run typecheck && npm run lint && npm test && npm run build +``` + +CI runs exactly that. Nothing here talks to a live server, so a failing test +is a real failure rather than a missing container. + +## Commit messages + +Say what changed and why, in prose. The why is the part that is hard to +recover later. No tool trailers. diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..9ce05db --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,37 @@ +# Security policy + +## Supported versions + +INBUXA Admin is developed on `main`, and security fixes are applied there and +in the latest release. Older tags are not backported. + +| Version | Supported | +| --- | --- | +| `main` and the latest release | :white_check_mark: | +| Older releases | :x: | + +## Reporting a vulnerability + +**Please don't open a public issue for a security problem.** An issue is +visible to everyone, including whoever would use it, before there is a fix. + +Report it privately by email to: + +**johnellisATlinuxDOTcom** + +Include as much as you can of: what it lets someone do, how to reproduce it, +the version or commit affected, and whether it needs an authenticated session +or a particular role. + +This is an administrative interface, so a few things are worth calling out as +in scope even though they are not bugs in the usual sense: anything that lets +a session act beyond the permissions its account holds, anything that leaks +another tenant's data, and anything that exposes a token or a secret to a +place it should not reach — the URL, the page, or storage that outlives the +session. + +You'll get an acknowledgement within a few days. A report that turns out to +affect the mail server rather than this interface will be moved to +[inbuxa-server](https://github.com/inbuxa/inbuxa-server), and one that affects +upstream Stalwart's web interface will be passed to Stalwart Labs with credit +to you.