[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fIYvitW1CEDIdnOqSy721b2y-D6XFw3iZcX_aQcGBDpo":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},61,"How can I view folder sharing configurations using the Zimbra SOAP API?","You can view folder sharing configurations by sending a `GetFolderRequest` SOAP request to the `BatchRequest` endpoint. The response will contain an `acl` node with `grant` elements that list shared folders and their permissions. This technique supplements the method described in [Zimbra SOAP API Development Guide 4 - Email Export and Folder Sharing](\u002Fnews\u002Fzimbra-soap-api-development-guide-4-email-export-and-folder-sharing) and is detailed in the [Zimbra SOAP API Development Guide 5 - Email Forwarding](\u002Fnews\u002Fzimbra-soap-api-development-guide-5-email-forwarding).","\u003Cp>You can view folder sharing configurations by sending a `GetFolderRequest` SOAP request to the `BatchRequest` endpoint. The response will contain an `acl` node with `grant` elements that list shared folders and their permissions. This technique supplements the method described in [Zimbra SOAP API Development Guide 4 - Email Export and Folder Sharing](\u002Fnews\u002Fzimbra-soap-api-development-guide-4-email-export-and-folder-sharing) and is detailed in the [Zimbra SOAP API Development Guide 5 - Email Forwarding](\u002Fnews\u002Fzimbra-soap-api-development-guide-5-email-forwarding).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fzimbra-soap-api-development-guide-5-email-forwarding\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-i-view-folder-sharing-configurations-using-the-zimbra-soap-api-1777485406969","folder sharing, GetFolderRequest, BatchRequest, Zimbra SOAP API, ACL",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},16,"Zimbra SOAP API Development Guide 5 - Email Forwarding","zimbra-soap-api-development-guide-5-email-forwarding","Learn to implement email forwarding and view folder sharing configurations using Zimbra SOAP API with Python code examples and packet analysis.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will further expand the functionality of the open-source code Zimbra_SOAP_API_Manage, implementing email forwarding by modifying configurations through the Zimbra SOAP API, and sharing development details.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Adding email forwarding\u003C\u002Fli>\u003Cli>Viewing email forwarding configurations\u003C\u002Fli>\u003Cli>Viewing folder sharing configurations\u003C\u002Fli>\u003Cli>Open-source code\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Adding Email Forwarding\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Zimbra supports forwarding received emails to another mailbox. The operation method via the web interface is as follows:\u003C\u002Fp>\u003Cp>After logging into the mailbox, navigate to Preferences -&gt; Mail, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019774188_0_16f580ada3.png\">\u003C\u002Fp>\u003Cp>After setting up the forwarding email, click Save\u003C\u002Fp>\u003Cp>If you want to forward to multiple email addresses, you can use , to separate them. An example of forwarding to two email addresses simultaneously: test1@test.com,test2@test.com\u003C\u002Fp>\u003Cp>Next, analyze the implementation process by packet capture, and then use a program to implement this functionality\u003C\u002Fp>\u003Cp>Example of SOAP format obtained from packet capture:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Csoap:body>\u003Cbr>\u003Cbatchrequest xmlns=\"urn:zimbra\" onerror=\"stop\">\u003Cbr>\u003Cmodifyprefsrequest xmlns=\"urn:zimbraAccount\" requestid=\"0\">\u003Cbr>\u003Cpref name=\"zimbraPrefMailForwardingAddress\">test1@test.com\u003C\u002Fpref>\u003Cbr>\u003C\u002Fmodifyprefsrequest>\u003Cbr>\u003C\u002Fbatchrequest>\u003Cbr>\u003C\u002Fsoap:body>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Implementation code example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>def addforward_request(uri,token):\u003Cbr>    print(\"[*] Input the mailbox to forward:\")\u003Cbr>    print(\"    Eg :test1@test.com,test2@@test.com\")\u003Cbr>    mailbox = input(\"[&gt;]: \")\u003Cbr>    request_body=\"\"\"\u003Csoap:envelope xmlns:soap=\"http:\u002F\u002Fwww.w3.org\u002F2003\u002F05\u002Fsoap-envelope\">\u003Cbr>       \u003Csoap:header>\u003Cbr>           \u003Ccontext xmlns=\"urn:zimbra\">\u003Cbr>               \u003Cauthtoken>{token}\u003C\u002Fauthtoken>\u003Cbr>           \u003C\u002Fcontext>\u003Cbr>       \u003C\u002Fsoap:header>\u003Cbr>       \u003Csoap:body>\u003Cbr>            \u003Cbatchrequest xmlns=\"urn:zimbra\" onerror=\"stop\">\u003Cbr>                \u003Cnooprequest xmlns=\"urn:zimbraMail\" requestid=\"0\">\u003Cbr>                \u003Cmodifyprefsrequest xmlns=\"urn:zimbraAccount\" requestid=\"1\">\u003Cbr>                    \u003Cpref name=\"zimbraPrefMailForwardingAddress\">{mailbox}\u003C\u002Fpref>\u003Cbr>                \u003C\u002Fmodifyprefsrequest>\u003Cbr>            \u003C\u002Fnooprequest>\u003C\u002Fbatchrequest>\u003Cbr>       \u003C\u002Fsoap:body>\u003Cbr>    \u003C\u002Fsoap:envelope>\u003Cbr>    \"\"\"\u003Cbr>    try:\u003Cbr>        r=requests.post(uri+\"\u002Fservice\u002Fsoap\",headers=headers,data=request_body.format(token=token,mailbox=mailbox),verify=False,timeout=15)\u003Cbr>        if r.status_code == 200:\u003Cbr>            print(\"[+] Add success\")\u003Cbr>        else:    \u003Cbr>            print(r.status_code)\u003Cbr>            print(r.text)        \u003Cbr>        \u003Cbr>    except Exception as e:\u003Cbr>        print(\"[!] Error:%s\"%(e))\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To clear the email forwarding settings, simply set the email address to empty\u003C\u002Fp>\u003Ch2>0x03 View Email Forwarding Configuration\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Before adding email forwarding, we typically need to first obtain the email forwarding configuration.\u003C\u002Fp>\u003Cp>Through packet capture, it was discovered that when accessing the web homepage, if email forwarding settings exist, the returned data will include the following additional content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"zimbraPrefMailForwardingAddress\":\"test@test.com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If email forwarding settings do not exist, the returned data will not contain the string zimbraPrefMailForwardingAddress.\u003C\u002Fp>\u003Cp>In terms of program implementation, accessing the web homepage requires adding a Cookie, and then filtering out the specified content using regular expressions.\u003C\u002Fp>\u003Cp>Example implementation code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>def getforward_request(uri,token):\u003Cbr>    try:\u003Cbr>        headers[\"Cookie\"]=\"ZM_AUTH_TOKEN=\"+token+\";\"\u003Cbr>        r=requests.get(uri,headers=headers,verify=False,timeout=15)\u003Cbr>        if r.status_code == 200 and 'zimbraPrefMailForwardingAddress' in r.text:\u003Cbr>            print(\"[+] Forward\")\u003Cbr>            pattern_name = re.compile(r\"\\\"zimbraPrefMailForwardingAddress\\\":\\\"(.*?)\\\"\")\u003Cbr>            name = pattern_name.findall(r.text)\u003Cbr>            print(\"    \" + name[0])\u003Cbr>        else:           \u003Cbr>            print(r.status_code)\u003Cbr>            print(\"[-] No Forward\")\u003Cbr>        \u003Cbr>    except Exception as e:\u003Cbr>        print(\"[!] Error:%s\"%(e))\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 View Folder Sharing Configuration\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous article \"Zimbra-SOAP-API Development Guide 4 - Email Export and Folder Sharing\" lacked a method for viewing folder sharing configuration. This article serves as a supplement.\u003C\u002Fp>\u003Cp>Analyze through packet capture\u003C\u002Fp>\u003Cp>Example of URL sent: https:\u002F\u002F\u003Curl>\u002Fservice\u002Fsoap\u002FBatchRequest\u003C\u002Furl>\u003C\u002Fp>\u003Cp>Example of content sent:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>{\"Header\":{\"context\":{\"_jsns\":\"urn:zimbra\",\"userAgent\":{\"name\":\"ZimbraWebClient - GC103 (Win)\",\"version\":\"8.8.12_GA_3844\"},\"session\":{\"_content\":123,\"id\":123},\"account\":{\"_content\":\"admin@test.com\",\"by\":\"name\"},\"csrfToken\":\"0_71c4fc5d29c57ec1863d1630a77bb4834f0cd67c\"}},\"Body\":{\"BatchRequest\":{\"_jsns\":\"urn:zimbra\",\"onerror\":\"continue\",\"GetFolderRequest\":[{\"_jsns\":\"urn:zimbraMail\",\"folder\":{\"l\":\"2\"},\"requestId\":0}]}}}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example of content returned:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>{\"Header\":{\"context\":{\"session\":{\"id\":\"123\",\"_content\":\"123\"},\"change\":{\"token\":151},\"_jsns\":\"urn:zimbra\"}},\"Body\":{\"BatchResponse\":{\"GetFolderResponse\":[{\"folder\":[{\"id\":\"2\",\"uuid\":\"68dd08c1-26ea-4460-9716-14eee9103a45\",\"deletable\":false,\"name\":\"Inbox\",\"absFolderPath\":\"\u002FInbox\",\"l\":\"1\",\"luuid\":\"0e366bb5-f76c-40ce-9a92-28def5720d67\",\"f\":\"ui\",\"u\":14,\"view\":\"message\",\"rev\":1,\"ms\":147,\"webOfflineSyncDays\":30,\"activesyncdisabled\":false,\"n\":14,\"s\":24088,\"i4ms\":112,\"i4next\":273,\"acl\":{\"grant\":[{\"zid\":\"f87692f9-0ab9-441d-9870-ef5b6dd6f375\",\"gt\":\"usr\",\"perm\":\"r\",\"d\":\"test1@test.com\"}]}}],\"requestId\":\"0\",\"_jsns\":\"urn:zimbraMail\"}],\"_jsns\":\"urn:zimbra\"}},\"_jsns\":\"urn:zimbraSoap\"}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>From the above content, it can be seen that the relevant request is GetFolderRequest\u003C\u002Fp>\u003Cp>View the usage of GetFolderRequest: https:\u002F\u002Ffiles.zimbra.com\u002Fdocs\u002Fsoap_api\u002F8.8.15\u002Fapi-reference\u002FzimbraMail\u002FGetFolder.html\u003C\u002Fp>\u003Cp>Based on previous accumulation, this can also be achieved through the Zimbra SOAP API by sending a GetFolderRequest and filtering the returned content\u003C\u002Fp>\u003Cp>Example of data content for file sharing in the inbox:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cfolder i4ms=\"201\" rev=\"1\" i4next=\"282\" f=\"ui\" ms=\"147\" deletable=\"0\" l=\"1\" uuid=\"68dd08c1-26ea-4460-9716-14eee9103a45\" n=\"16\" luuid=\"0e366bb5-f76c-40ce-9a92-28def5720d67\" activesyncdisabled=\"0\" absfolderpath=\"\u002FInbox\" view=\"message\" s=\"29224\" u=\"16\" name=\"Inbox\" id=\"2\" webofflinesyncdays=\"30\">\u003Cacl>\u003Cgrant zid=\"f87692f9-0ab9-441d-9870-ef5b6dd6f375\" perm=\"r\" d=\"test1@test.com\" gt=\"usr\">\u003C\u002Fgrant>\u003C\u002Facl>\u003C\u002Ffolder>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In program implementation, if the character \u003Cacl> exists in the returned result, it indicates the presence of file sharing, and the corresponding data can be extracted\u003C\u002Facl>\u003C\u002Fp>\u003Cp>Implementation code example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>def getshare_request(uri,token):\u003Cbr>    request_body=\"\"\"\u003Csoap:envelope xmlns:soap=\"http:\u002F\u002Fwww.w3.org\u002F2003\u002F05\u002Fsoap-envelope\">\u003Cbr>       \u003Csoap:header>\u003Cbr>           \u003Ccontext xmlns=\"urn:zimbra\">\u003Cbr>               \u003Cauthtoken>{token}\u003C\u002Fauthtoken>\u003Cbr>           \u003C\u002Fcontext>\u003Cbr>       \u003C\u002Fsoap:header>\u003Cbr>       \u003Csoap:body>\u003Cbr>         \u003Cgetfolderrequest xmlns=\"urn:zimbraMail\"> \u003Cbr>         \u003C\u002Fgetfolderrequest>\u003Cbr>       \u003C\u002Fsoap:body>\u003Cbr>    \u003C\u002Fsoap:envelope>\u003Cbr>    \"\"\"\u003Cbr>    try:\u003Cbr>        r=requests.post(uri+\"\u002Fservice\u002Fsoap\",headers=headers,data=request_body.format(token=token),verify=False,timeout=15)\u003Cbr>        if r.status_code == 200 and '\u003Cacl>' in r.text:\u003Cbr>            print(\"[+] Folder Share\")\u003Cbr>            pattern_name = re.compile(r\"\u003Cfolder(.*?)\u003C folder=\"\">\")\u003Cbr>            folders = pattern_name.findall(r.text)\u003Cbr>            for i in range(len(folders)):\u003Cbr>                if '\u003Cacl>' in folders[i]:\u003Cbr>                    pattern_name = re.compile(r\"name=\\\"(.*?)\\\"\")\u003Cbr>                    name = pattern_name.findall(folders[i])\u003Cbr>                    pattern_name = re.compile(r\"\u003Cacl>(.*?)\u003C\u002Facl>\")\u003Cbr>                    acl = pattern_name.findall(r.text)\u003Cbr>                    print(\"    \" + name[len(name)-1] + \":\")\u003Cbr>                    print(\"    \" + acl[0])\u003Cbr>        else:\u003Cbr>            print(r.status_code)\u003Cbr>            print(r.text)\u003Cbr>            print(\"[-] No Folder Share\")        \u003Cbr>        \u003Cbr>    except Exception as e:\u003Cbr>        print(\"[!] Error:%s\"%(e))\u003C\u002Facl>\u003C\u002Ffolder(.*?)\u003C>\u003C\u002Facl>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example of returned result:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Inbox:\u003Cbr>\u003Cgrant zid=\"f87692f9-0ab9-441d-9870-ef5b6dd6f375\" perm=\"rwidx\" d=\"test1@test.com\" gt=\"usr\">\u003C\u002Fgrant>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>When deleting folder sharing, you need to fill in the zid and the number 2 corresponding to Inbox\u003C\u002Fp>\u003Ch2>0x05 Open Source Code\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>New code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Added the following four features:\u003C\u002Fp>\u003Cul>\u003Cli>AddForward: Add email forwarding\u003C\u002Fli>\u003Cli>GetForward: View email forwarding\u003C\u002Fli>\u003Cli>GetShare: View folder sharing\u003C\u002Fli>\u003Cli>RemoveForward: Clear email forwarding settings\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article expands the Zimbra SOAP API calling methods, adding four practical features. The implementation methods and approaches can also be tested on XSS vulnerabilities.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will further expand the functionality of the open-source code Zimbra_SOAP_API_Manage, implementing email forwarding by modifying configurations through the Zimbra SOAP API, and sharing development details.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Adding email forwarding\u003C\u002Fli>\u003Cli>Viewing email forwarding configurations\u003C\u002Fli>\u003Cli>Viewing folder sharing configurations\u003C\u002Fli>\u003Cli>Open-source code\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Adding Email Forwarding\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Zimbra supports forwarding received emails to another mailbox. The operation method via the web interface is as follows:\u003C\u002Fp>\u003Cp>After logging into the mailbox, navigate to Preferences -&gt; Mail, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019774188_0_16f580ada3-1.png\">\u003C\u002Fp>\u003Cp>After setting up the forwarding email, click Save\u003C\u002Fp>\u003Cp>If you want to forward to multiple email addresses, you can use , to separate them. An example of forwarding to two email addresses simultaneously: test1@test.com,test2@test.com\u003C\u002Fp>\u003Cp>Next, analyze the implementation process by packet capture, and then use a program to implement this functionality\u003C\u002Fp>\u003Cp>Example of SOAP format obtained from packet capture:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Csoap:body>\u003Cbr>\u003Cbatchrequest xmlns=\"urn:zimbra\" onerror=\"stop\">\u003Cbr>\u003Cmodifyprefsrequest xmlns=\"urn:zimbraAccount\" requestid=\"0\">\u003Cbr>\u003Cpref name=\"zimbraPrefMailForwardingAddress\">test1@test.com\u003C\u002Fpref>\u003Cbr>\u003C\u002Fmodifyprefsrequest>\u003Cbr>\u003C\u002Fbatchrequest>\u003Cbr>\u003C\u002Fsoap:body>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Implementation code example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>def addforward_request(uri,token):\u003Cbr>    print(\"[*] Input the mailbox to forward:\")\u003Cbr>    print(\"    Eg :test1@test.com,test2@@test.com\")\u003Cbr>    mailbox = input(\"[&gt;]: \")\u003Cbr>    request_body=\"\"\"\u003Csoap:envelope xmlns:soap=\"http:\u002F\u002Fwww.w3.org\u002F2003\u002F05\u002Fsoap-envelope\">\u003Cbr>       \u003Csoap:header>\u003Cbr>           \u003Ccontext xmlns=\"urn:zimbra\">\u003Cbr>               \u003Cauthtoken>{token}\u003C\u002Fauthtoken>\u003Cbr>           \u003C\u002Fcontext>\u003Cbr>       \u003C\u002Fsoap:header>\u003Cbr>       \u003Csoap:body>\u003Cbr>            \u003Cbatchrequest xmlns=\"urn:zimbra\" onerror=\"stop\">\u003Cbr>                \u003Cnooprequest xmlns=\"urn:zimbraMail\" requestid=\"0\">\u003Cbr>                \u003Cmodifyprefsrequest xmlns=\"urn:zimbraAccount\" requestid=\"1\">\u003Cbr>                    \u003Cpref name=\"zimbraPrefMailForwardingAddress\">{mailbox}\u003C\u002Fpref>\u003Cbr>                \u003C\u002Fmodifyprefsrequest>\u003Cbr>            \u003C\u002Fnooprequest>\u003C\u002Fbatchrequest>\u003Cbr>       \u003C\u002Fsoap:body>\u003Cbr>    \u003C\u002Fsoap:envelope>\u003Cbr>    \"\"\"\u003Cbr>    try:\u003Cbr>        r=requests.post(uri+\"\u002Fservice\u002Fsoap\",headers=headers,data=request_body.format(token=token,mailbox=mailbox),verify=False,timeout=15)\u003Cbr>        if r.status_code == 200:\u003Cbr>            print(\"[+] Add success\")\u003Cbr>        else:    \u003Cbr>            print(r.status_code)\u003Cbr>            print(r.text)        \u003Cbr>        \u003Cbr>    except Exception as e:\u003Cbr>        print(\"[!] Error:%s\"%(e))\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To clear the email forwarding settings, simply set the email address to empty\u003C\u002Fp>\u003Ch2>0x03 View Email Forwarding Configuration\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Before adding email forwarding, we typically need to first obtain the email forwarding configuration.\u003C\u002Fp>\u003Cp>Through packet capture, it was discovered that when accessing the web homepage, if email forwarding settings exist, the returned data will include the following additional content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"zimbraPrefMailForwardingAddress\":\"test@test.com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If email forwarding settings do not exist, the returned data will not contain the string zimbraPrefMailForwardingAddress.\u003C\u002Fp>\u003Cp>In terms of program implementation, accessing the web homepage requires adding a Cookie, and then filtering out the specified content using regular expressions.\u003C\u002Fp>\u003Cp>Example implementation code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>def getforward_request(uri,token):\u003Cbr>    try:\u003Cbr>        headers[\"Cookie\"]=\"ZM_AUTH_TOKEN=\"+token+\";\"\u003Cbr>        r=requests.get(uri,headers=headers,verify=False,timeout=15)\u003Cbr>        if r.status_code == 200 and 'zimbraPrefMailForwardingAddress' in r.text:\u003Cbr>            print(\"[+] Forward\")\u003Cbr>            pattern_name = re.compile(r\"\\\"zimbraPrefMailForwardingAddress\\\":\\\"(.*?)\\\"\")\u003Cbr>            name = pattern_name.findall(r.text)\u003Cbr>            print(\"    \" + name[0])\u003Cbr>        else:           \u003Cbr>            print(r.status_code)\u003Cbr>            print(\"[-] No Forward\")\u003Cbr>        \u003Cbr>    except Exception as e:\u003Cbr>        print(\"[!] Error:%s\"%(e))\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 View Folder Sharing Configuration\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous article \"Zimbra-SOAP-API Development Guide 4 - Email Export and Folder Sharing\" lacked a method for viewing folder sharing configuration. This article serves as a supplement.\u003C\u002Fp>\u003Cp>Analyze through packet capture\u003C\u002Fp>\u003Cp>Example of URL sent: https:\u002F\u002F\u003Curl>\u002Fservice\u002Fsoap\u002FBatchRequest\u003C\u002Furl>\u003C\u002Fp>\u003Cp>Example of content sent:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>{\"Header\":{\"context\":{\"_jsns\":\"urn:zimbra\",\"userAgent\":{\"name\":\"ZimbraWebClient - GC103 (Win)\",\"version\":\"8.8.12_GA_3844\"},\"session\":{\"_content\":123,\"id\":123},\"account\":{\"_content\":\"admin@test.com\",\"by\":\"name\"},\"csrfToken\":\"0_71c4fc5d29c57ec1863d1630a77bb4834f0cd67c\"}},\"Body\":{\"BatchRequest\":{\"_jsns\":\"urn:zimbra\",\"onerror\":\"continue\",\"GetFolderRequest\":[{\"_jsns\":\"urn:zimbraMail\",\"folder\":{\"l\":\"2\"},\"requestId\":0}]}}}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example of content returned:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>{\"Header\":{\"context\":{\"session\":{\"id\":\"123\",\"_content\":\"123\"},\"change\":{\"token\":151},\"_jsns\":\"urn:zimbra\"}},\"Body\":{\"BatchResponse\":{\"GetFolderResponse\":[{\"folder\":[{\"id\":\"2\",\"uuid\":\"68dd08c1-26ea-4460-9716-14eee9103a45\",\"deletable\":false,\"name\":\"Inbox\",\"absFolderPath\":\"\u002FInbox\",\"l\":\"1\",\"luuid\":\"0e366bb5-f76c-40ce-9a92-28def5720d67\",\"f\":\"ui\",\"u\":14,\"view\":\"message\",\"rev\":1,\"ms\":147,\"webOfflineSyncDays\":30,\"activesyncdisabled\":false,\"n\":14,\"s\":24088,\"i4ms\":112,\"i4next\":273,\"acl\":{\"grant\":[{\"zid\":\"f87692f9-0ab9-441d-9870-ef5b6dd6f375\",\"gt\":\"usr\",\"perm\":\"r\",\"d\":\"test1@test.com\"}]}}],\"requestId\":\"0\",\"_jsns\":\"urn:zimbraMail\"}],\"_jsns\":\"urn:zimbra\"}},\"_jsns\":\"urn:zimbraSoap\"}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>From the above content, it can be seen that the relevant request is GetFolderRequest\u003C\u002Fp>\u003Cp>View the usage of GetFolderRequest: https:\u002F\u002Ffiles.zimbra.com\u002Fdocs\u002Fsoap_api\u002F8.8.15\u002Fapi-reference\u002FzimbraMail\u002FGetFolder.html\u003C\u002Fp>\u003Cp>Based on previous accumulation, this can also be achieved through the Zimbra SOAP API by sending a GetFolderRequest and filtering the returned content\u003C\u002Fp>\u003Cp>Example of data content for file sharing in the inbox:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cfolder i4ms=\"201\" rev=\"1\" i4next=\"282\" f=\"ui\" ms=\"147\" deletable=\"0\" l=\"1\" uuid=\"68dd08c1-26ea-4460-9716-14eee9103a45\" n=\"16\" luuid=\"0e366bb5-f76c-40ce-9a92-28def5720d67\" activesyncdisabled=\"0\" absfolderpath=\"\u002FInbox\" view=\"message\" s=\"29224\" u=\"16\" name=\"Inbox\" id=\"2\" webofflinesyncdays=\"30\">\u003Cacl>\u003Cgrant zid=\"f87692f9-0ab9-441d-9870-ef5b6dd6f375\" perm=\"r\" d=\"test1@test.com\" gt=\"usr\">\u003C\u002Fgrant>\u003C\u002Facl>\u003C\u002Ffolder>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In program implementation, if the character \u003Cacl> exists in the returned result, it indicates the presence of file sharing, and the corresponding data can be extracted\u003C\u002Facl>\u003C\u002Fp>\u003Cp>Implementation code example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>def getshare_request(uri,token):\u003Cbr>    request_body=\"\"\"\u003Csoap:envelope xmlns:soap=\"http:\u002F\u002Fwww.w3.org\u002F2003\u002F05\u002Fsoap-envelope\">\u003Cbr>       \u003Csoap:header>\u003Cbr>           \u003Ccontext xmlns=\"urn:zimbra\">\u003Cbr>               \u003Cauthtoken>{token}\u003C\u002Fauthtoken>\u003Cbr>           \u003C\u002Fcontext>\u003Cbr>       \u003C\u002Fsoap:header>\u003Cbr>       \u003Csoap:body>\u003Cbr>         \u003Cgetfolderrequest xmlns=\"urn:zimbraMail\"> \u003Cbr>         \u003C\u002Fgetfolderrequest>\u003Cbr>       \u003C\u002Fsoap:body>\u003Cbr>    \u003C\u002Fsoap:envelope>\u003Cbr>    \"\"\"\u003Cbr>    try:\u003Cbr>        r=requests.post(uri+\"\u002Fservice\u002Fsoap\",headers=headers,data=request_body.format(token=token),verify=False,timeout=15)\u003Cbr>        if r.status_code == 200 and '\u003Cacl>' in r.text:\u003Cbr>            print(\"[+] Folder Share\")\u003Cbr>            pattern_name = re.compile(r\"\u003Cfolder(.*?)\u003C folder=\"\">\")\u003Cbr>            folders = pattern_name.findall(r.text)\u003Cbr>            for i in range(len(folders)):\u003Cbr>                if '\u003Cacl>' in folders[i]:\u003Cbr>                    pattern_name = re.compile(r\"name=\\\"(.*?)\\\"\")\u003Cbr>                    name = pattern_name.findall(folders[i])\u003Cbr>                    pattern_name = re.compile(r\"\u003Cacl>(.*?)\u003C\u002Facl>\")\u003Cbr>                    acl = pattern_name.findall(r.text)\u003Cbr>                    print(\"    \" + name[len(name)-1] + \":\")\u003Cbr>                    print(\"    \" + acl[0])\u003Cbr>        else:\u003Cbr>            print(r.status_code)\u003Cbr>            print(r.text)\u003Cbr>            print(\"[-] No Folder Share\")        \u003Cbr>        \u003Cbr>    except Exception as e:\u003Cbr>        print(\"[!] Error:%s\"%(e))\u003C\u002Facl>\u003C\u002Ffolder(.*?)\u003C>\u003C\u002Facl>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example of returned result:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Inbox:\u003Cbr>\u003Cgrant zid=\"f87692f9-0ab9-441d-9870-ef5b6dd6f375\" perm=\"rwidx\" d=\"test1@test.com\" gt=\"usr\">\u003C\u002Fgrant>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>When deleting folder sharing, you need to fill in the zid and the number 2 corresponding to Inbox\u003C\u002Fp>\u003Ch2>0x05 Open Source Code\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>New code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Added the following four features:\u003C\u002Fp>\u003Cul>\u003Cli>AddForward: Add email forwarding\u003C\u002Fli>\u003Cli>GetForward: View email forwarding\u003C\u002Fli>\u003Cli>GetShare: View folder sharing\u003C\u002Fli>\u003Cli>RemoveForward: Clear email forwarding settings\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article expands the Zimbra SOAP API calling methods, adding four practical features. The implementation methods and approaches can also be tested on XSS vulnerabilities.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1761,"Onedaysec",4,"published","2026-02-02T08:20:05.028Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Zimbra SOAP API Email Forwarding & Folder Sharing Guide","Zimbra SOAP API, email forwarding, folder sharing, API development, Python, mailbox configuration",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],62,60,59,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.726Z","2026-07-23T16:00:57.102Z","draft","2026-07-23T16:03:17.582Z"]