diff --git a/docs/ConfigurationGuide.md b/docs/ConfigurationGuide.md index 424fa173..009dc5a9 100644 --- a/docs/ConfigurationGuide.md +++ b/docs/ConfigurationGuide.md @@ -272,10 +272,16 @@ DocuElevate can poll a WebDAV folder for new files. It reuses the existing WebDA In addition to system-level watch folders, each user can configure personal watch folder sources through the **Integrations** dashboard (`/integrations`). Documents ingested from per-user watch folder integrations are automatically attributed to the owning user's `owner_id`. Per-user watch folder integrations are stored in the `user_integrations` table with `integration_type='WATCH_FOLDER'` and `direction='SOURCE'`. The `config` JSON field stores: -- `folder_path` — absolute path to the directory to scan +- `source_type` — the type of source to scan (`local`, `s3`, `dropbox`, `google_drive`, `onedrive`, `nextcloud`, `webdav`; default: `local`) +- `folder_path` — path to the directory/folder to scan (used by local, Dropbox, OneDrive, Nextcloud, WebDAV) - `delete_after_process` — whether to remove source files after ingestion (default: `false`) -> **Security**: Path traversal protection is enforced on user-configured watch folder paths. Relative paths, `..` components, and symlink escapes are rejected to prevent access to files outside the intended directory. +Additional type-specific config fields: +- **S3**: `bucket`, `region`, `prefix`, `endpoint_url` +- **Google Drive**: `folder_id` +- **Nextcloud / WebDAV**: `url`, `folder_path` + +> **Security**: Path traversal protection is enforced on local watch folder paths. Relative paths, `..` components, and symlink escapes are rejected. Cloud source types use per-user encrypted credentials instead. - Individual scan failures are handled gracefully and recorded on the integration's `last_error` field without interrupting the scanning of other integrations. - The scan runs alongside the system-level watch folder polling cycle. @@ -302,7 +308,15 @@ DocuElevate can automatically pull document attachments from IMAP mailboxes — In addition to system-level mailboxes, each user can configure personal IMAP sources through the **Integrations** dashboard (`/integrations`). Documents ingested from per-user IMAP integrations are automatically attributed to the owning user's `owner_id`. -Per-user IMAP integrations are stored in the `user_integrations` table with `integration_type='IMAP'` and `direction='SOURCE'`. Credentials are encrypted at rest using Fernet encryption. +Per-user IMAP integrations are stored in the `user_integrations` table with `integration_type='IMAP'` and `direction='SOURCE'`. The `config` JSON field stores: +- `host` — IMAP server hostname (required) +- `port` — IMAP server port (default: `993`) +- `username` — IMAP login username (required) +- `use_ssl` — whether to use SSL/TLS (default: `true`) +- `delete_after_process` — whether to delete emails from the mailbox after processing (default: `false`) +- `gmail_apply_labels` — whether to apply Gmail-specific labels and stars to processed emails (default: `true`). When enabled, processed emails are starred and tagged with an "Ingested" label. Only applies to Gmail hosts. + +Credentials are encrypted at rest using Fernet encryption. - Individual connection failures are handled gracefully and recorded on the integration's `last_error` field without interrupting the polling of other integrations. - The polling loop runs every minute and processes all active IMAP sources (system-level and per-user) in sequence. diff --git a/docs/UserGuide.md b/docs/UserGuide.md index fbdf972f..9906a89c 100644 --- a/docs/UserGuide.md +++ b/docs/UserGuide.md @@ -157,13 +157,13 @@ The **Integrations** page (`/integrations`) provides a unified view of all your 2. Choose a **Direction** — Source (ingestion) or Destination (storage). 3. Choose an **Integration Type** (e.g. IMAP, S3, Dropbox, WebDAV). 4. Fill in the type-specific fields — the form adapts dynamically based on your choice: - - **IMAP** — host, port, username, password, SSL toggle + - **IMAP** — host, port, username, password, SSL toggle, delete after processing, Gmail labels & star toggle - **S3** — bucket, region, access key, secret key - **WebDAV / Nextcloud** — URL, folder, username, password - **FTP / SFTP** — host, port, remote path, username, password - **Dropbox / Google Drive / OneDrive** — folder path, with a link to the OAuth setup page - **Email Forward** — recipient email address - - **Watch Folder** — folder path + - **Watch Folder** — source type (Local, S3, Dropbox, Google Drive, OneDrive, Nextcloud, WebDAV), per-type config fields, delete after processing toggle - **Paperless NGX** — URL and API token - **Webhook** — no configuration needed; the form shows a quick-start guide with sample `curl` and Python snippets for uploading documents via the API 5. Click **Test Connection** to verify the settings before saving.