fix(dav): repair CalDAV/CardDAV client connectivity (#480)
Standard CalDAV/CardDAV clients (Thunderbird, DAVx5, Apple Calendar/Contacts) failed to connect, mounted collections read-only, or could not discover address books, even though curl worked. Three protocol-compliance gaps caused this: 1. Missing Basic-auth challenge on /caldav and /carddav. The 401 returned for these surfaces carried no `WWW-Authenticate` header (only /webdav did). Spec-compliant clients never send credentials preemptively the way `curl -u` does — they wait for the challenge — so Thunderbird never authenticated and failed with "discovery failed" / 401. Extend the challenge to all DAV surfaces via shared `is_dav_path` / `dav_basic_auth_challenge` helpers. 2. Calendars always advertised read-only. The `current-user-privilege-set` write gate compared `owner_id` against the literal string "current_user_id", which never matched a real UUID, so `<D:write/>` was never emitted and clients mounted every calendar read-only. Thread the caller's id through the CalDAV adapter and grant write when the caller owns the calendar. 3. CardDAV discovery was incomplete. There was no `/.well-known/carddav` route and the root PROPFIND exposed neither `current-user-principal` nor `addressbook-home-set`, so clients could not locate address books. Add the well-known redirect and root/principal discovery responses mirroring the CalDAV adapter. Adds unit tests for the auth challenge predicate, the calendar owner/non-owner privilege split, and the CardDAV root/principal discovery responses. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016cVV9nRQjP6G6a8zbNUWMw
This commit is contained in:
@@ -17,6 +17,19 @@ use crate::application::adapters::webdav_adapter::{
|
||||
};
|
||||
use crate::application::dtos::calendar_dto::{CalendarDto, CalendarEventDto};
|
||||
|
||||
/// Returns whether `caller_id` owns `calendar`.
|
||||
///
|
||||
/// CalDAV clients (DAVx5, Apple Calendar, Thunderbird) only mount a collection
|
||||
/// read-write when its `current-user-privilege-set` advertises `<D:write/>`, so
|
||||
/// this gate decides read-only vs read-write for the caller. `caller_id` and
|
||||
/// [`CalendarDto::owner_id`] are both the user's UUID rendered via
|
||||
/// `Uuid::to_string()`, so a direct comparison is exact. Calendars merely shared
|
||||
/// with the caller (non-owner access) stay read-only for now — this never
|
||||
/// over-grants write.
|
||||
fn caller_owns_calendar(calendar: &CalendarDto, caller_id: &str) -> bool {
|
||||
!caller_id.is_empty() && calendar.owner_id == caller_id
|
||||
}
|
||||
|
||||
/// CalDAV report type
|
||||
#[derive(Debug, PartialEq)]
|
||||
pub enum CalDavReportType {
|
||||
@@ -205,6 +218,7 @@ impl CalDavAdapter {
|
||||
request: &PropFindRequest,
|
||||
base_href: &str,
|
||||
username: &str,
|
||||
caller_id: &str,
|
||||
) -> Result<()> {
|
||||
let mut xml_writer = Writer::new(writer);
|
||||
|
||||
@@ -227,6 +241,7 @@ impl CalDavAdapter {
|
||||
calendar,
|
||||
request,
|
||||
&format!("{}{}/", base_href, calendar.id),
|
||||
caller_id,
|
||||
)?;
|
||||
}
|
||||
|
||||
@@ -242,6 +257,7 @@ impl CalDavAdapter {
|
||||
calendars: &[CalendarDto],
|
||||
request: &PropFindRequest,
|
||||
base_href: &str,
|
||||
caller_id: &str,
|
||||
) -> Result<()> {
|
||||
let mut xml_writer = Writer::new(writer);
|
||||
|
||||
@@ -261,6 +277,7 @@ impl CalDavAdapter {
|
||||
calendar,
|
||||
request,
|
||||
&format!("{}{}/", base_href, calendar.id),
|
||||
caller_id,
|
||||
)?;
|
||||
}
|
||||
|
||||
@@ -557,6 +574,7 @@ impl CalDavAdapter {
|
||||
calendar: &CalendarDto,
|
||||
request: &PropFindRequest,
|
||||
href: &str,
|
||||
caller_id: &str,
|
||||
) -> Result<()> {
|
||||
// Start response element
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:response")))?;
|
||||
@@ -576,7 +594,7 @@ impl CalDavAdapter {
|
||||
match &request.prop_find_type {
|
||||
PropFindType::AllProp => {
|
||||
// Write all standard properties for a calendar
|
||||
Self::write_calendar_standard_props(xml_writer, calendar)?;
|
||||
Self::write_calendar_standard_props(xml_writer, calendar, caller_id)?;
|
||||
}
|
||||
PropFindType::PropName => {
|
||||
// Write only property names (empty elements)
|
||||
@@ -584,7 +602,7 @@ impl CalDavAdapter {
|
||||
}
|
||||
PropFindType::Prop(props) => {
|
||||
// Write requested properties
|
||||
Self::write_calendar_requested_props(xml_writer, calendar, props)?;
|
||||
Self::write_calendar_requested_props(xml_writer, calendar, props, caller_id)?;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -609,6 +627,7 @@ impl CalDavAdapter {
|
||||
fn write_calendar_standard_props<W: Write>(
|
||||
xml_writer: &mut Writer<W>,
|
||||
calendar: &CalendarDto,
|
||||
caller_id: &str,
|
||||
) -> Result<()> {
|
||||
// Common WebDAV properties
|
||||
|
||||
@@ -676,9 +695,10 @@ impl CalDavAdapter {
|
||||
xml_writer.write_event(Event::Empty(BytesStart::new("D:read")))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:privilege")))?;
|
||||
|
||||
// Only add write privilege if user owns the calendar or has write access
|
||||
if calendar.owner_id == "current_user_id" {
|
||||
// This should be replaced with actual user check
|
||||
// Advertise write only when the caller owns the calendar. Clients
|
||||
// (DAVx5, Apple Calendar, Thunderbird) mount the collection read-only
|
||||
// unless this privilege is present.
|
||||
if caller_owns_calendar(calendar, caller_id) {
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:privilege")))?;
|
||||
xml_writer.write_event(Event::Empty(BytesStart::new("D:write")))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:privilege")))?;
|
||||
@@ -735,6 +755,7 @@ impl CalDavAdapter {
|
||||
xml_writer: &mut Writer<W>,
|
||||
calendar: &CalendarDto,
|
||||
props: &[QualifiedName],
|
||||
caller_id: &str,
|
||||
) -> Result<()> {
|
||||
for prop in props {
|
||||
match (prop.namespace.as_str(), prop.name.as_str()) {
|
||||
@@ -780,9 +801,8 @@ impl CalDavAdapter {
|
||||
xml_writer.write_event(Event::Empty(BytesStart::new("D:read")))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:privilege")))?;
|
||||
|
||||
// Only add write privilege if user owns the calendar or has write access
|
||||
if calendar.owner_id == "current_user_id" {
|
||||
// This should be replaced with actual user check
|
||||
// Advertise write only when the caller owns the calendar.
|
||||
if caller_owns_calendar(calendar, caller_id) {
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:privilege")))?;
|
||||
xml_writer.write_event(Event::Empty(BytesStart::new("D:write")))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:privilege")))?;
|
||||
@@ -882,6 +902,7 @@ impl CalDavAdapter {
|
||||
request: &PropFindRequest,
|
||||
base_href: &str,
|
||||
depth: &str,
|
||||
caller_id: &str,
|
||||
) -> Result<()> {
|
||||
let mut xml_writer = Writer::new(writer);
|
||||
|
||||
@@ -894,7 +915,7 @@ impl CalDavAdapter {
|
||||
))?;
|
||||
|
||||
// Write the calendar collection itself
|
||||
Self::write_calendar_response(&mut xml_writer, calendar, request, base_href)?;
|
||||
Self::write_calendar_response(&mut xml_writer, calendar, request, base_href, caller_id)?;
|
||||
|
||||
// If depth > 0, include event resources
|
||||
if depth != "0" {
|
||||
|
||||
Reference in New Issue
Block a user