You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何调用Roundcube邮件客户端HTTP API修改密码(Python实现及配置说明)

Roundcube 密码修改API调用与Python实现

一、Roundcube 密码API的配置与启用

Roundcube的密码修改功能依赖自带的password插件,需完成以下配置:

  1. 启用插件:编辑Roundcube主配置文件 config/config.inc.php,找到$config['plugins']数组,确保包含'password'项:
    $config['plugins'] = array(
        // 其他已启用插件...
        'password',
    );
    
  2. 开启API并设置认证:编辑插件专属配置文件 plugins/password/config.inc.php,配置API相关参数:
    // 启用密码修改API
    $config['password_api_enabled'] = true;
    // 使用HTTP Basic认证方式
    $config['password_api_auth'] = 'basic';
    
  3. 配置密码修改驱动:根据你的邮箱后端类型(SQL/LDAP等)设置对应驱动,以SQL驱动为例:
    $config['password_driver'] = 'sql';
    // 数据库连接DSN
    $config['password_db_dsn'] = 'mysql://db_user:db_pass@localhost/mail_db';
    // 修改密码的SQL语句模板
    $config['password_query'] = "UPDATE mailbox SET password=%P WHERE username=%u";
    

二、HTTP API调用方式

API端点为Roundcube安装路径下的 /password/api/update,采用POST请求,核心规则如下:

  • 认证:使用HTTP Basic认证,账号为用户邮箱,密码为当前密码
  • 请求参数:
    • current_pass:用户当前密码
    • new_pass:新密码
    • confirm_pass:确认新密码(需与new_pass完全一致)
  • 请求头:需设置Content-Type: application/x-www-form-urlencoded

curl调用示例

curl -X POST -u "user@example.com:old_password" \
  -d "current_pass=old_password&new_pass=new_password&confirm_pass=new_password" \
  https://your-roundcube-domain/password/api/update

三、Python代码实现

使用requests库完成API调用,步骤如下:

  1. 安装依赖:
    pip install requests
    
  2. 编写调用代码:
    import requests
    
    # 基础配置
    ROUNDCUBE_API_URL = "https://your-roundcube-domain/password/api/update"
    USER_EMAIL = "user@example.com"
    OLD_PASSWORD = "your_old_password"
    NEW_PASSWORD = "your_new_password"
    
    # 构建请求参数
    payload = {
        "current_pass": OLD_PASSWORD,
        "new_pass": NEW_PASSWORD,
        "confirm_pass": NEW_PASSWORD
    }
    
    # 发送请求并处理响应
    try:
        response = requests.post(
            ROUNDCUBE_API_URL,
            auth=(USER_EMAIL, OLD_PASSWORD),
            data=payload,
            verify=True  # 生产环境建议保持True,测试环境可设为False跳过证书验证
        )
        response.raise_for_status()
        result = response.json()
    
        if result.get("success"):
            print("密码修改成功")
        else:
            print(f"修改失败:{result.get('message', '未知错误')}")
    except requests.exceptions.RequestException as e:
        print(f"请求异常:{str(e)}")
    

四、常见问题排查

  • 403 Forbidden:检查password_api_enabled是否设为true,或Basic认证的账号密码是否正确
  • 密码修改失败:确认后端驱动配置(如SQL权限、LDAP绑定信息)是否正确,新密码是否符合plugins/password/config.inc.php中设置的密码策略(如password_min_length、password_require_nonalpha)
  • CSRF验证失败:若Roundcube强制CSRF校验,需先通过GET请求访问Roundcube首页,提取页面中的_token值,加入POST请求参数中

内容的提问来源于stack exchange,提问作者user956424

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 12:05:18