Admin, plugins and themes
Setup wizard
Section titled “Setup wizard”A setup wizard runs on first launch and walks through JMAP servers, OAuth/OIDC, the session
secret, logging, branding (uploads included) and the admin password. It writes to the admin config
dir, so .env.local is left untouched. JSON config can read secrets from files
(passwordHashFile, sessionSecretFile, oauthClientSecretFile) for Docker/Kubernetes secret
mounts.
Admin dashboard
Section titled “Admin dashboard”The admin dashboard folds its policy sections into one tabbed page. It includes:
- Policy gates for the Unified Mailbox — turn All mail / Unread / Starred on or off org-wide, and gate the cross-account capability separately (off by default). A gated view still respects the user’s own toggle.
- Storage split —
ADMIN_CONFIG_DIRis operator-authored (can be mounted read-only once setup finishes) andADMIN_STATE_DIRholds the runtime audit log and login timestamps. - An admin toggle for search-engine indexing (
robots.txt/noindex).
Plugins and themes
Section titled “Plugins and themes”- A schema-driven plugin config UI with render and intercept hooks (
onAvatarResolve,onBeforeEmailSend), composer-sidebar and email-banner slots, calendar event slots, i18n APIs and an/api/translateproxy. Plugins hot-reload, load from a dev folder, bundlesrc/on demand through esbuild, and can requesthttp:fetchscoped byhttpOrigins. - Themes upload as ZIP bundles; an extension marketplace browses and installs plugins and themes from a configurable directory. Installing and uninstalling stay in the admin dashboard.
- Bundled plugins include Jitsi Meet for the calendar.
Operations
Section titled “Operations”- PWA: service worker, install prompt, web push for new inbox mail, a dynamic manifest and install screenshots configurable per domain.
- Update checks run on their own, log new releases server-side and raise a non-dismissible notice. Structured logging (text or JSON) with per-category levels; anonymous telemetry off unless enabled.