From 8935b81f121f7fba131269d7d3d02e514a0fb25f Mon Sep 17 00:00:00 2001 From: Linus Rath <139418639+rathlinus@users.noreply.github.com> Date: Tue, 28 Apr 2026 17:34:06 +0200 Subject: [PATCH 01/68] chore: update version to 1.5.3 --- CHANGELOG.md | 19 +++++++++++++++++++ README.md | 4 +++- VERSION | 2 +- app/admin/telemetry/page.tsx | 2 +- app/api/auth/totp-token-exchange/route.ts | 2 +- lib/plugin-storage.ts | 2 +- lib/plugin-types.ts | 10 +++++----- lib/plugin-validator.ts | 8 ++++---- lib/telemetry/endpoint-guard.ts | 4 ++-- lib/telemetry/state.ts | 2 +- lib/theme-compiler.ts | 16 ++++++++-------- lib/theme-loader.ts | 4 ++-- package-lock.json | 4 ++-- package.json | 2 +- stores/theme-store.ts | 2 +- 15 files changed, 52 insertions(+), 31 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index e4373ed1..77ce99cd 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,24 @@ # Changelog +## 1.5.3 (2026-04-28) + +> **New:** Bulwark Webmail now sends an anonymous instance heartbeat once per day (version, platform, bucketed account counts, feature toggles — no message data, no PII). Disable any time from **Admin → Telemetry** or by setting `BULWARK_TELEMETRY=off`. See the [privacy notice](https://bulwarkmail.org/docs/legal/privacy/telemetry) for the full schema. + +### Features + +- **Telemetry**: Anonymous instance telemetry, on by default. Reports schema version, platform, bucketed account counts, and feature toggles only — disable from the admin UI, with `BULWARK_TELEMETRY=off`, or by clearing the endpoint +- **Telemetry**: Track unique logins (HMAC'd per instance, 90-day retention) so the heartbeat can report bucketed account totals without storing usernames +- **Plugins**: Theme API v2 with token compiler and skin slot +- **Plugins**: Extension preview page and detailed extension info API +- **Calendar**: Right-click context menu on empty calendar space +- **Docker**: Persistent named volume for telemetry data so the instance id and admin's consent choice survive container upgrades + +### Fixes + +- **Security**: Block telemetry endpoint from pointing at internal/loopback hosts (validation + DNS-rebind re-check at fetch time) +- **Security**: Harden plugin config, TOTP token exchange, and branding file serving +- **Mail**: Batch shortcuts now act on the multi-selection when one is present (#228) + ## 1.5.2 (2026-04-27) ### Features diff --git a/README.md b/README.md index 05c7f005..1d46afb6 100644 --- a/README.md +++ b/README.md @@ -12,7 +12,7 @@ A modern, self-hosted webmail client for [Stalwart Mail Server](https://stalw.ar [](LICENSE) [](https://discord.gg/tYCujymGrT) -[](CHANGELOG.md) +[](CHANGELOG.md) [](https://ghcr.io/bulwarkmail/webmail) @@ -53,6 +53,8 @@ A modern, self-hosted webmail client for [Stalwart Mail Server](https://stalw.ar +> **Anonymous telemetry is on by default** since 1.5.3. Each instance sends a daily heartbeat (version, platform, bucketed account counts, feature toggles — no message data, no PII). Disable from **Admin → Telemetry**, by setting `BULWARK_TELEMETRY=off`, or by clearing the endpoint. Full schema: [privacy notice](https://bulwarkmail.org/docs/legal/privacy/telemetry). + ## Overview Bulwark is a full webmail suite – not just an inbox. It bundles the four apps most self-hosters end up wanting on the same login: diff --git a/VERSION b/VERSION index 4cda8f19..8af85beb 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -1.5.2 +1.5.3 diff --git a/app/admin/telemetry/page.tsx b/app/admin/telemetry/page.tsx index 29ddd72c..ea60ab33 100644 --- a/app/admin/telemetry/page.tsx +++ b/app/admin/telemetry/page.tsx @@ -137,7 +137,7 @@ export default function AdminTelemetryPage() {