Compare commits

...
10 Commits
Author SHA1 Message Date
Joshua Tauberer df7f245e0e v77
Version 77 (September 26, 2026)
-------------------------------

* Roundcube updated to version 1.6.19, fixing numerous security issues.
* Nextcloud updated to version 27.1.11, and install failure fixed.
2026-09-26 15:55:03 -04:00
Joshua Tauberer d317da15e1 Update Roundcube to 1.6.19 2026-09-26 15:53:04 -04:00
Joshua Tauberer 60b7ca2b74 Revert "Add python3-gnupg package which seems required by duplicity now"
This reverts commit 39b1d3ce24.
2026-09-26 15:51:23 -04:00
Yoann Gauthier-ColinandClaude Opus 4.8 fbb137dd96 Upgrade Nextcloud to 27.1.11 (#2591)
Bump Nextcloud core to 27.1.11 (latest 27.x, the highest release still
supported on PHP 8.0) and the bundled apps to their highest NC 27
compatible versions: contacts 5.5.4, calendar 4.7.20, user_external 3.4.0.
Add the 25 -> 26 step to the upgrade chain so existing installs migrate
25 -> 26 -> 27 in one run.

Closes #2399.

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-01 10:20:40 -04:00
Alex Trepca c62cc9fc5e Fix contacts/calendar download as source archive (#2588)
The setup script is using GitHub's auto-generated source archive URL
(archive/refs/tags/) to download the Nextcloud contacts and calendar apps.

Source archives exclude `vendor/` composer dependencies and compiled frontend
assets since they're gitignored, causing app:enable to fail with: `Could not
download app contacts`.

Switch to the release tarball URL (releases/download/) which includes all
pre-built assets.
2026-09-01 10:03:05 -04:00
KiekerJan fc8d4318ee [security] Update roundcube to 1.6.17 (#2586) 2026-09-01 10:02:33 -04:00
Joshua Tauberer 39b1d3ce24 Add python3-gnupg package which seems required by duplicity now
https://discourse.mailinabox.email/t/duplicity-oops-they-did-it-again/16051/35
2026-08-21 10:00:59 -04:00
Joshua Tauberer 1de9a93140 v76 2026-05-23 22:01:12 -04:00
Joshua Tauberer e64f88bb64 Set Nextcloud appstoreenabled setting to false
Updated php-fpm settings broke Nextcloud. See:

https://discourse.mailinabox.email/t/problems-with-z-push-and-nextcloud-likely-after-package-updates-today/16460/21
2026-05-23 21:48:53 -04:00
Nils Norman Haukås 86d78e946a Bugfix management interface HTML (#2574)
* bugfix: don't display management interface internals on frontpage
* nitpick: remove trailing whitespace

fixes #2572
2026-05-23 10:22:53 -04:00
5 changed files with 66 additions and 51 deletions
+12
View File
@@ -1,6 +1,18 @@
CHANGELOG CHANGELOG
========= =========
Version 77 (September 26, 2026)
-------------------------------
* Roundcube updated to version 1.6.19, fixing numerous security issues.
* Nextcloud updated to version 27.1.11, and install failure fixed.
Version 76 (May 24, 2026)
-------------------------
* Fixed Nextcloud broken after PHP update by updating Nextcloud settings.
* Fixed invalid HTML in the control panel broken by the last version.
Version 75 (April 20, 2026) Version 75 (April 20, 2026)
--------------------------- ---------------------------
+34 -36
View File
@@ -45,44 +45,42 @@
</div> </div>
</div> </div>
</div> </div>
<div class="form-group"> <div class="form-group">
<fieldset> <fieldset>
<legend> <legend>
<label for="addaliasSenders" class="col-sm-1 control-label">Permitted Senders</label> <label for="addaliasSenders" class="col-sm-1 control-label">Permitted Senders</label>
</legend> </legend>
<div class="col-sm-10"> <div class="col-sm-10">
<div class="radio"> <div class="radio">
<label for="addaliasForwardsToNotAdvanced"> <label for="addaliasForwardsToNotAdvanced">
<input id="addaliasForwardsToNotAdvanced" <input id="addaliasForwardsToNotAdvanced"
name="addaliasForwardsToDivToggle" name="addaliasForwardsToDivToggle"
type="radio" type="radio"
checked checked
onclick="$('#addaliasForwardsToDiv').toggle(false)"> onclick="$('#addaliasForwardsToDiv').toggle(false)">
Any mail user listed in the Forwards To box can send mail claiming to be from Any mail user listed in the Forwards To box can send mail claiming to be from
<span class="regularalias">the alias address</span> <span class="regularalias">the alias address</span>
<span class="catchall domainalias">any address on the alias domain</span>. <span class="catchall domainalias">any address on the alias domain</span>.
</label> </label>
</div> </div>
<div class="radio"> <div class="radio">
<label for="addaliasForwardsToAdvanced"> <label for="addaliasForwardsToAdvanced">
<input id="addaliasForwardsToAdvanced" <input id="addaliasForwardsToAdvanced"
name="addaliasForwardsToDivToggle" name="addaliasForwardsToDivToggle"
type="radio" type="radio"
onclick="$('#addaliasForwardsToDiv').toggle(true)"> onclick="$('#addaliasForwardsToDiv').toggle(true)">
I&rsquo;ll enter the mail users that can send mail claiming to be from I&rsquo;ll enter the mail users that can send mail claiming to be from
<span class="regularalias">the alias address</span> <span class="regularalias">the alias address</span>
<span class="catchall domainalias">any address on the alias domain</span>. <span class="catchall domainalias">any address on the alias domain</span>.
</label> </label>
</div>
</div> </div>
</div> </fieldset>
</fieldset> </div>
</div> <div id="addaliasForwardsToDiv" style="margin-top: .5em; margin-left: 1.4em; display: none;">
<div id="addaliasForwardsToDiv" style="margin-top: .5em; margin-left: 1.4em; display: none;"> <textarea class="form-control" rows="3" id="addaliasSenders" placeholder="one user per line or separated by commas"></textarea>
<textarea class="form-control" rows="3" id="addaliasSenders" placeholder="one user per line or separated by commas"></textarea>
</div>
</div>
</div> </div>
<div class="form-group"> <div class="form-group">
<div class="col-sm-offset-1 col-sm-11"> <div class="col-sm-offset-1 col-sm-11">
@@ -96,7 +94,7 @@
<table id="alias_table" class="table" style="width: auto"> <table id="alias_table" class="table" style="width: auto">
<thead> <thead>
<tr> <tr>
<th scope="col" aria-label="Actions"></th> <th scope="col" aria-label="Actions"></th>
<th scope="col"> Alias<br></th> <th scope="col"> Alias<br></th>
<th scope="col"> Forwards To</th> <th scope="col"> Forwards To</th>
<th scope="col"> Permitted Senders</th> <th scope="col"> Permitted Senders</th>
+1 -1
View File
@@ -23,7 +23,7 @@ if [ -z "$TAG" ]; then
if [ "$UBUNTU_VERSION" == "Ubuntu 22.04 LTS" ]; then if [ "$UBUNTU_VERSION" == "Ubuntu 22.04 LTS" ]; then
# This machine is running Ubuntu 22.04, which is supported by # This machine is running Ubuntu 22.04, which is supported by
# Mail-in-a-Box versions 60 and later. # Mail-in-a-Box versions 60 and later.
TAG=v75 TAG=v77
elif [ "$UBUNTU_VERSION" == "Ubuntu 18.04 LTS" ]; then elif [ "$UBUNTU_VERSION" == "Ubuntu 18.04 LTS" ]; then
# This machine is running Ubuntu 18.04, which is supported by # This machine is running Ubuntu 18.04, which is supported by
# Mail-in-a-Box versions 0.40 through 5x. # Mail-in-a-Box versions 0.40 through 5x.
+17 -12
View File
@@ -21,8 +21,8 @@ echo "Installing Nextcloud (contacts/calendar)..."
# we automatically install intermediate versions as needed. # we automatically install intermediate versions as needed.
# * The hash is the SHA1 hash of the ZIP package, which you can find by just running this script and # * The hash is the SHA1 hash of the ZIP package, which you can find by just running this script and
# copying it from the error message when it doesn't match what is below. # copying it from the error message when it doesn't match what is below.
nextcloud_ver=26.0.13 nextcloud_ver=27.1.11
nextcloud_hash=d5c10b650e5396d5045131c6d22c02a90572527c nextcloud_hash=9f30c01a021c2e5a9e7baff119955afb3c552ebc
# Nextcloud apps # Nextcloud apps
# -------------- # --------------
@@ -32,20 +32,20 @@ nextcloud_hash=d5c10b650e5396d5045131c6d22c02a90572527c
# https://github.com/nextcloud/user_external/tags # https://github.com/nextcloud/user_external/tags
# #
# * For these three packages, contact, calendar and user_external, the hash is the SHA1 hash of # * For these three packages, contact, calendar and user_external, the hash is the SHA1 hash of
# the ZIP package, which you can find by just running this script and copying it from # the release tarball (from the releases/download URL, not the source archive), which you can
# the error message when it doesn't match what is below: # find by running: curl -sL <url> | sha1sum
# Always ensure the versions are supported, see https://apps.nextcloud.com/apps/contacts # Always ensure the versions are supported, see https://apps.nextcloud.com/apps/contacts
contacts_ver=5.5.3 contacts_ver=5.5.4
contacts_hash=799550f38e46764d90fa32ca1a6535dccd8316e5 contacts_hash=c4e3f2183a0088b829f8aa1b3af1f87c9a4c46a2
# Always ensure the versions are supported, see https://apps.nextcloud.com/apps/calendar # Always ensure the versions are supported, see https://apps.nextcloud.com/apps/calendar
calendar_ver=4.7.6 calendar_ver=4.7.20
calendar_hash=a995bca4effeecb2cab25f3bbeac9bfe05fee766 calendar_hash=12d876904e227156e39ca4335b18481b42a6d00f
# Always ensure the versions are supported, see https://apps.nextcloud.com/apps/user_external # Always ensure the versions are supported, see https://apps.nextcloud.com/apps/user_external
user_external_ver=3.3.0 user_external_ver=3.4.0
user_external_hash=280d24eb2a6cb56b4590af8847f925c28d8d853e user_external_hash=7f9d8f4dd6adb85a0e3d7622d85eeb7bfe53f3b4
# Developer advice (test plan) # Developer advice (test plan)
# ---------------------------- # ----------------------------
@@ -105,11 +105,11 @@ InstallNextcloud() {
# their github repositories. # their github repositories.
mkdir -p /usr/local/lib/owncloud/apps mkdir -p /usr/local/lib/owncloud/apps
wget_verify "https://github.com/nextcloud-releases/contacts/archive/refs/tags/v$version_contacts.tar.gz" "$hash_contacts" /tmp/contacts.tgz wget_verify "https://github.com/nextcloud-releases/contacts/releases/download/v$version_contacts/contacts-v$version_contacts.tar.gz" "$hash_contacts" /tmp/contacts.tgz
tar xf /tmp/contacts.tgz -C /usr/local/lib/owncloud/apps/ tar xf /tmp/contacts.tgz -C /usr/local/lib/owncloud/apps/
rm /tmp/contacts.tgz rm /tmp/contacts.tgz
wget_verify "https://github.com/nextcloud-releases/calendar/archive/refs/tags/v$version_calendar.tar.gz" "$hash_calendar" /tmp/calendar.tgz wget_verify "https://github.com/nextcloud-releases/calendar/releases/download/v$version_calendar/calendar-v$version_calendar.tar.gz" "$hash_calendar" /tmp/calendar.tgz
tar xf /tmp/calendar.tgz -C /usr/local/lib/owncloud/apps/ tar xf /tmp/calendar.tgz -C /usr/local/lib/owncloud/apps/
rm /tmp/calendar.tgz rm /tmp/calendar.tgz
@@ -239,6 +239,10 @@ if [ ! -d /usr/local/lib/owncloud/ ] || [[ ! ${CURRENT_NEXTCLOUD_VER} =~ ^$nextc
InstallNextcloud 25.0.7 a5a565c916355005c7b408dd41a1e53505e1a080 5.3.0 4b0a6666374e3b55cfd2ae9b72e1d458b87d4c8c 4.4.2 21a42e15806adc9b2618760ef94f1797ef399e2f 3.2.0 a494073dcdecbbbc79a9c77f72524ac9994d2eec InstallNextcloud 25.0.7 a5a565c916355005c7b408dd41a1e53505e1a080 5.3.0 4b0a6666374e3b55cfd2ae9b72e1d458b87d4c8c 4.4.2 21a42e15806adc9b2618760ef94f1797ef399e2f 3.2.0 a494073dcdecbbbc79a9c77f72524ac9994d2eec
CURRENT_NEXTCLOUD_VER="25.0.7" CURRENT_NEXTCLOUD_VER="25.0.7"
fi fi
if [[ ${CURRENT_NEXTCLOUD_VER} =~ ^25 ]]; then
InstallNextcloud 26.0.13 d5c10b650e5396d5045131c6d22c02a90572527c 5.5.3 b234ab410480a4106176a28f39c9b27f471d0473 4.7.6 cf8e68e7d945ee71933f5bb71a969faf152da55c 3.3.0 280d24eb2a6cb56b4590af8847f925c28d8d853e
CURRENT_NEXTCLOUD_VER="26.0.13"
fi
fi fi
InstallNextcloud $nextcloud_ver $nextcloud_hash $contacts_ver $contacts_hash $calendar_ver $calendar_hash $user_external_ver $user_external_hash InstallNextcloud $nextcloud_ver $nextcloud_hash $contacts_ver $contacts_hash $calendar_ver $calendar_hash $user_external_ver $user_external_hash
@@ -324,6 +328,7 @@ php"$PHP_VER" <<EOF > "$CONFIG_TEMP" && mv "$CONFIG_TEMP" "$STORAGE_ROOT/ownclou
include("$STORAGE_ROOT/owncloud/config.php"); include("$STORAGE_ROOT/owncloud/config.php");
\$CONFIG['config_is_read_only'] = false; \$CONFIG['config_is_read_only'] = false;
\$CONFIG['appstoreenabled'] = false; # https://discourse.mailinabox.email/t/problems-with-z-push-and-nextcloud-likely-after-package-updates-today/16460/21
\$CONFIG['trusted_domains'] = array('$PRIMARY_HOSTNAME'); \$CONFIG['trusted_domains'] = array('$PRIMARY_HOSTNAME');
+2 -2
View File
@@ -36,8 +36,8 @@ apt_install \
# https://github.com/mstilkerich/rcmcarddav/releases # https://github.com/mstilkerich/rcmcarddav/releases
# The easiest way to get the package hashes is to run this script and get the hash from # The easiest way to get the package hashes is to run this script and get the hash from
# the error message. # the error message.
VERSION=1.6.15 VERSION=1.6.19
HASH=1228dce33d7dd4085529d0ccc920deb603cd4e04 HASH=d30d11f91857b1962879e06a19ef217dceeb506c
PERSISTENT_LOGIN_VERSION=bde7b6840c7d91de627ea14e81cf4133cbb3c07a # version 5.3 PERSISTENT_LOGIN_VERSION=bde7b6840c7d91de627ea14e81cf4133cbb3c07a # version 5.3
HTML5_NOTIFIER_VERSION=68d9ca194212e15b3c7225eb6085dbcf02fd13d7 # version 0.6.4+ HTML5_NOTIFIER_VERSION=68d9ca194212e15b3c7225eb6085dbcf02fd13d7 # version 0.6.4+
CARDDAV_VERSION=4.4.3 CARDDAV_VERSION=4.4.3