I now solved most of my problems here and have a test setup that does what it should do.
We only hit the issue that deleting a folder from the public namespace fails because of this issue:
https://dovecot.org/list/dovecot/2011-May/059315.html That is 10 years old ... is there a valid solution maybe? (yes, I will try to find something as well)We currently use a global ACL file and have 3 users in with full "lrwstipekxa" permissions.
Toggling off thunderbird's use of Trash isn't really wanted ...