Show HN: IMAP API – Self-hosted access to IMAP over REST
imapapi.com
imapapi.com
https://jmap.io/software.html has a list of some known implementations.
The downside of the JMAP model for a proxy to IMAP is that you do need to have a bit of state in your proxy server. jmap-perl uses a sqlite3 database per user for storing that state.
Structurally, it's a non-blocking server in front of a forking server - the non-blocking handles connections and event streaming, and opens multiple backend forking servers per user, one for reads, one for writes, and one for background syncing/import.
I'm looking forward to getting JMAP Calendars and JMAP Contacts done, at which point is becomes a much more compelling replacement for multiple protocols.
https://datatracker.ietf.org/group/jmap/meetings/
https://www.ietf.org/mailman/listinfo/jmap
One could potentially write JMAP as a proxy to an existing IMAP server (just like your 'imap-api') therefore the current lack of JMAP servers doesn’t really matter.
Of course, until other email servers add support for jmap, the protocol has a bit of a bootstrapping problem. Getting support from gmail + microsoft exchange would be a huge win for jmap, and in the long run email as a whole.
> Licensed for evaluation use only
Is clear enough in legal terms for what can or cannot be done ? I assume it means it's free to use to test it and see how it works, but not for anything else ? Does that cover the code too ?
How is this different to the wilduck webmail api?
Would it be hard to abstract away the wildduck storage code to use a datastore other than mongodb?
WildDuck is pretty much coupled with MongoDB. IMAP is not very easily abstractable and keeping the result scalable at the same time. Largest WildDuck cluster in production manages 20TB (~20k accounts) of email by now with no special config or modifications - making it scalable was the main goal from the start and supporting arbitrary storage would not have helped.
Fine for playing around with on your computer but not integrating with anything productive.
This is not legal advice though. Always consult a lawyer if you have legal questions.
IMAP is on its own insecure because it is a plain protocol, but it can be used in conjunction with TLS to add secure transport. Exactly the same can be said for many other mail protocols such as POP3.
https://www.zdnet.com/article/google-were-banning-these-inse...
So in general it comes down to configuration. IMAP per se is not insecure. How you use it though, might be.