mailcow/data
DerLinkman ee15721550
feat: implement passwordless autodiscover endpoint
- Remove HTTP Basic Authentication requirement from autodiscover.php
- Extract email address from XML request body instead of AUTH headers
- Validate mailbox existence and active status before returning config
- Improve security by eliminating password transmission
- Add comprehensive error handling for invalid/inactive mailboxes
- Follow industry standards (Microsoft, Google, Apple)
- Maintain backward compatibility with existing email clients
- Keep full logging functionality in Redis AUTODISCOVER_LOG

This change enhances security while improving user experience and
follows modern email client configuration best practices.
2025-12-17 13:39:05 +01:00
..
assets Merge pull request #6223 from mailcow/ffdhe2048 2025-02-12 10:48:22 +01:00
conf rspamd: upgrade to 3.14.1, trixie rebuild + bcc forwarded hosts fix (#6958) 2025-12-11 09:45:56 +01:00
Dockerfiles Add MTA-STS support for alias domains (#6972) 2025-12-15 16:29:21 +01:00
hooks [SOGo] Added hooks support for SOGo image (#4181) 2021-07-28 21:41:44 +02:00
web feat: implement passwordless autodiscover endpoint 2025-12-17 13:39:05 +01:00