Changelog
What changes
Every release with what is new and what was fixed. No sugar-coating — mistakes we are not proud of are listed here too.
1.0.4
Security release: The message list of a mailbox now checks that the mailbox belongs to the signed-in user — and mail sync with AnnexOffice gets leaner
Fixed and improved
- The message list of a mailbox via the programming interface (GET /api/v1/mailboxes/{id}/messages) did not check whether the mailbox belongs to the signed-in user. A signed-in user on the same server could therefore retrieve messages from other users' mailboxes if they knew the mailbox number. Since 1.0.4 the server answers "not found" for mailboxes that are not the user's. We recommend updating to 1.0.4
- Mail sync with AnnexOffice: The server delivers messages since the last sync (delta with checkpoint) instead of all of them every time, and deletions arrive completely, page by page. This takes effect with an AnnexOffice version that uses the sync (with AnnexCREATE 0.7.4) — older clients keep retrieving everything
1.0.3
Security release: Sign-in for the AnnexTalk app counts failed attempts, locks accounts, and honours blocked addresses — like sign-in in the browser
Fixed
- The AnnexTalk app's own sign-in path previously neither honoured blocked addresses nor counted failed attempts or locked accounts — unlike sign-in in the browser. The app now follows the same rules, and every failed attempt is recorded in the admin log
1.0.2
Correction release: Apple Contacts sets up with a bare address — and offers the account as the default for new contacts
Fixed
- Apple Contacts signed in in "Automatic" mode with only the local part of the address — the server rejected the login. It now adds the domain: set-up without a server name succeeds, and address books and the company directory arrive
- Apple did not offer the account as the default for new contacts — the account root returned an empty privilege list. New cards landed in the wrong account; the account is now offered, and creating on the server and deleting are proven
1.0.0
The scope is complete: from setup through migrating from Exchange to the workplace on Mac and Windows — plus reporting and blocking in AnnexTalk
New
- In AnnexTalk, a message can be reported: the report goes to the administration of your own server — it is recorded in the administration log and mailed to the admins of your domain, never to ma-kom. Block a sender and their messages no longer count
- Moving from Exchange on your own premises runs entirely on the server: straight over EWS, with no Mac in between — mail, events, contacts, tasks, notes and public folders come across, proven on a real mailbox
- The workplace in the web interface on Mac and Windows — set up from the blank machine to the first answered message
0.12.1
AnnexTalk now in the browser — read and answer channels and direct messages; plus two archive fixes, and the migration names every entry not transferred, the macOS installer checks the system version, and system status matches MX/SRV against the certificate
New
- The web interface has an AnnexTalk menu item: channels and direct messages can be read and answered there — limits: no unread counter, no threads, no reactions; "Refresh" fetches new messages
Fixed
- Archiving under a retention hold counted wrongly: `archive-run` reported, say, "24 archived" even though the hold had not moved a single message. The hold always held — nothing was lost; only the number was wrong. It now counts only what is actually in the archive
- The daily archival run would never finish when a message with an expired retention period could not be archived (for example in a folder without an owner) — it kept picking the message up again and looped forever. The run now stops and reports which messages were left behind
- The macOS installer did not check the minimum version: on a Mac with an older system, AnnexGroup crashed at launch with "dyld: Symbol not found" and "Abort trap" — with no hint that the system was the cause. `install-macos.sh` and the .pkg installer now refuse before installing anything: the script says AnnexGroup needs macOS 14 or newer and which macOS this Mac has; the .pkg installer shows the macOS notice that macOS 14 is required
- The system status reported the certificate as valid even when it did not cover the name that the administration’s DNS suggestions point MX and SRV at — by default `mail.<your-domain>`, configurable via `smtp_hostname`. A mail program following the SRV record then broke off when connecting. The system status now names what is missing
- A migration from Exchange ended with "completed_with_errors — 2 errors" without saying which — the names were only in the server log. The count was right; nothing disappeared silently. The migration log now names every entry it could not transfer, with the reason: folder, subject and message ID for messages, the title for events, contacts, tasks and notes
- The import page showed only the status for a finished job. A list now opens under each finished job, naming every skipped and failed entry with its reason — for example "Failed · Inbox / March invoice — message too large"
- An attachment that could not be read during a migration from Exchange used to cost the whole message; the message now arrives without it, and the attachment is listed with its subject and file name in the migration log. Empty attachments (such as `ATT00001.txt`) arrive as empty files
0.12.0
Windows time zones read correctly, AI agents without license pressure — and an uninstall that leaves nothing behind
New
- AI agents no longer count against the licensed user limit: one agent per paid user is possible, and going beyond that brings a notification — not a block
Fixed
- Appointments with Windows time zone names — the way the Windows calendar writes them — were two hours off: in calendar sync, in invitations by mail, and in migration via Microsoft Graph. The server now knows the mapping from Windows zones to IANA zones and reads all three places correctly
- A phone number edited in the browser never arrived in the client’s address book when the contact already had a stored card — the old number stayed. Edited numbers now replace the stored one, and new ones carry a type
- Uninstalling on macOS left the self-update helper loaded, pointing at a deleted program — it is now removed as well
- Appointments without attendees showed up in calendar programs as meeting requests with "Please respond" — the server wrote an organizer into every appointment. Now only appointments with attendees carry an organizer
- Attendees added in the web interface were missing in calendar sync: calendar programs received the appointment without them and showed a plain appointment instead of one with invitees. Sync now includes the attendees
- Calendar programs did not show the organizer of an appointment with attendees by name — it read "Unknown". The server sent no name for the organizer; it now carries the account’s name, and names containing a comma ("Sanwald, Pascal") arrive complete
- Concurrent sign-ins could lose entries in the administration log: measured with 40 concurrent entries, 2 arrived. All now arrive, and the audit chain stays closed
- The administration’s update page showed the notes of the last installed version for a new version, and reported "Never checked" while loading. Both are fixed as of the updates after 0.12.0 — anyone updating from 0.11.0 to 0.12.0 still sees the error during that update
0.11.0
Federation secure out of the box, five languages throughout, multiple calendars — and two security holes closed
New
- Federation between AnnexGroup servers is switched off by default from this version onwards; whoever uses it enables it in the configuration and stores each partner’s public key — without a key, the server accepts nothing any more
- The global address list is now also in the web interface — until 0.10.0 it was only visible through the address book of mail programs (CardDAV)
- The interface now speaks the user’s language consistently in all five languages — seven pages kept parts of their text hard-wired to English or German, the terms now follow those from Outlook, and the administration speaks German instead of Denglish
- An installation now opts out of search engines — a company server’s sign-in page does not belong in a search index
- Multiple calendars per user: create, rename, delete — in the web interface and via CalDAV; free/busy takes all of one’s own calendars into account, and the migration from Exchange creates additional calendars as calendars of their own instead of putting everything into one
- Search in one’s own address book now filters on the server — with 1 051 contacts, every search previously returned the whole address book (914 KB instead of a single match)
- Every user can decide for themselves who sees their availability — narrower or wider than the domain’s rule: no information, only free/busy, or with subject and location
- IMAP now supports UIDPLUS and MULTIAPPEND: mail programs such as mbsync uniquely assign uploaded messages, and several messages go in in one go or not at all
- Block lists now also take network ranges (IPv4 and IPv6) — with protection against locking yourself out
- The number of accounts and AnnexOffice workstations from the activation code is a hard limit; the administration shows who occupies a workstation and releases it with one click
- The appointment form does the planning: all invitees and rooms on one timeline, one click adopts the time, and a suggestion names the next slot everyone is free
- Employees see their day next to the inbox — today’s appointments and the tasks that are due
- Dates and times appear in the forms the way the interface language writes them — even when the browser has a different language
- The chain of evidence is checked daily in operation; a break appears in the system status — and the log of administrative actions is now chained too
- IMAP now supports NOTIFY: one channel for many folders — Evolution shows the inbox with the default setting
- The migration wizard accepts Exchange as a source via EWS, and public folders become shared rooms
- The company address book is now also an interface — clients get recipient suggestions from it when composing
Fixed
- The connection between two AnnexGroup servers now checks the other side’s certificate and requires a valid signature for every incoming message
- A race in the event stream could crash the server when a browser signed out at the exact moment a message was being distributed
- Anyone who clicked “Send” twice in the browser sent the mail twice — the lock against double sending never applied there
- A card on employees’ home page permanently showed “Loading …”
- The setup checklist ticked off the migration even when a migration had failed
- The API overview in the developer area named a path for the message list that does not exist
- An incoming HTML mail could execute script in the recipient’s session; HTML mail now appears in a sandboxed frame without scripts, and remote images and tracking pixels are not loaded
- Behind a reverse proxy, the sender address of a request could be forged, bypassing the sign-in lockout and the block list; the forwarding header now only counts from registered reverse proxies (trusted_proxies) — anyone running AnnexGroup behind nginx or similar enters its address
- The detail page of a mail shows the message instead of its raw build, and a reply quotes the text readably — with “Re:” in the subject when the interface is in English
- A moved message gets a new identifier in the target folder, after deletion the notifications to the mail program are correct, and QRESYNC reports deleted messages as the standard requires
- Subject and sender with umlauts appear readable — previously they stood in the inbox as “=?utf-8?q?…”, even in mails already sitting in the mailbox
- “Reply” in the web interface reaches senders who write with a name; subjects and names with umlauts go out encoded according to the standard
- The week view shows an appointment as one block spanning its duration, opens at 07:00 and shows the appointment colours; the folders of one’s own agents stand with their names on their own
- Write operations via CalDAV and CardDAV now need only half as many round trips to the database
- An account with the role “root” could be created via the API and then fell out of the count; rooms counted against the licence’s user number — both are now sealed
- IMAP now tolerates several mail programs on the same mailbox — measured with three simultaneous clients: 98 errors before, none after
- IMAP: COPY now creates either all messages or none — nothing left behind halfway
- Six findings from the Apple device pass are fixed: ORG with department stays in contacts, CalDAV and CardDAV store objects under the name the program chose, deleted contacts reach the devices, free/busy no longer counts the appointment being scheduled as a conflict — and saved appointments no longer carry a METHOD
0.10.0
Migration without a Mac, tenants, compliance — and an interface that fits together
New
- Migration from Exchange on premises runs on the server: directly via EWS, with no Mac in between — mail, appointments, contacts, tasks and notes all come along
- Create many mailboxes from a list instead of filling in fifty forms
- Multi-tenancy: the “domain admin” role manages its own domain — users, rooms, distribution groups, shares — and the boundary also applies to search, address book and free/busy
- Compliance: journaling, an archive mailbox as its own IMAP mailbox, litigation hold, domain-wide search with mbox export, and audit rules per tenant
- The system status checks the certificate against the discovery names and names the missing ones before setup fails on them
- Administration is ordered: four named areas instead of eleven identical buttons, and the wizards show which step you are on
- Free/busy in the web interface’s appointment form — “no information” is a state of its own and does not look like “free”
- In the web interface: several recipients, Cc and Bcc, and all times in the reader’s own time zone
Fixed
- An appointment moved back by the time zone difference on every save — the list, the calendar grid and the form each calculated in a different zone
- Message, contact, agent and space could not be opened: the message answered 404, the other three silently redirected back to their list
- The migration wizard did not submit the credentials that had been typed in and stored them in the browser instead
- A second click on “Send” sent the same mail a second time
- Filter rules did not store the selected action
- Load, disk usage and the server log were visible to every mailbox; the live stream was even available without signing in
- The calendar mixed German and English weekday and month names
- The bundled example configuration omitted `loc=UTC` in the database connection — on a machine not set to UTC, all times shifted
- The installation script now says when another mail server already holds port 25, instead of letting the service run into a restart loop without a word
0.9.0
Groupware complete — and the server updates itself
New
- Free/busy in the calendars: anyone scheduling a meeting sees who is available, without asking
- Rooms and equipment as calendar attendees — booked, declined, no hallway traffic
- Global address list in every standard client
- Distribution groups that resolve internally: write to one address, reach everyone
- Send as and send on behalf of — via shared access instead of shared passwords
- Out of office with a date range: from start to end, not just on and off
- Server-side rules (Sieve): set up in the client, applied at delivery
- Public folders with a three-level hierarchy
- Shared access for mailboxes, calendars and address books
- Self-update with rollback: the server fetches the release itself, tries it and switches — if anything fails, the previous one is at hand
Fixed
- Eight admin pages returned an empty page with HTTP 200 — the base-template call was missing from the templates
- macOS: the program and the installer meant different data directories — backup and restore wrongly reported "no data"
- The privileged helper for self-update listened one directory too high and missed the signal — the update sat silently at "staged"
- A successful self-initiated rollback reported an error where there was none
0.8.2
Calendar and contact clients can connect
Fixed
- CalDAV and CardDAV accept the same credentials as IMAP. Before this release only bearer tokens were accepted — Evolution, Thunderbird and the Apple clients offer no place to enter one, so no standard client could connect at all
- Account setup over the server address works: the service entry point now answers with the principal instead of refusing access
0.8.1
Multilingual throughout
New
- Documentation available in English as well as German
- Website in five languages (English, German, Spanish, French, Italian)
- Server interface, error messages and system mail follow the language of the recipient; language preference per user
- Licence bundle: AnnexOffice seats are included with a server licence
Fixed
- Five violations of the IMAP standard that made Thunderbird show received mail incorrectly
- macOS app: crash on start outside an app bundle, and TLS against a server with its own certificate
- A data race in the event stream that made the test suite abort
0.8.0
First public release
Included
- Mail server with SMTP, IMAP, queue and DKIM signing
- Calendar, contacts, tasks, notes, shared spaces, sharing
- AI agents as sub-accounts with autonomy levels and a review loop
- Web interface, installable as a web app, light and dark
- CalDAV and CardDAV for Apple devices
- Full-text search across all areas
- Administration with setup wizard, self-check, backup and restore
- Login-attempt protection, blocklists, security presets
- Rspamd and ClamAV integration
- Packages for macOS (Apple Silicon and Intel, notarized by Apple) and Linux (x86-64 and ARM64)
Known limitations
- No MAPI and no EWS as a server protocol — and no ActiveSync either. AnnexGroup builds on open protocols only; Exchange is a migration source for us, not a protocol to reimplement.
- Multi-tenancy was only prepared in the data model in 0.8.0 — since lifted: a dedicated tenant role (domain admin), in the web interface and through the API
- No wizard for automatically importing existing mailboxes
- Certificates via Let’s Encrypt only over the HTTP challenge — wildcard certificates need the DNS route and are not built in yet