fix(dav): repair CalDAV/CardDAV client connectivity (#480)
Standard CalDAV/CardDAV clients (Thunderbird, DAVx5, Apple Calendar/Contacts) failed to connect, mounted collections read-only, or could not discover address books, even though curl worked. Three protocol-compliance gaps caused this: 1. Missing Basic-auth challenge on /caldav and /carddav. The 401 returned for these surfaces carried no `WWW-Authenticate` header (only /webdav did). Spec-compliant clients never send credentials preemptively the way `curl -u` does — they wait for the challenge — so Thunderbird never authenticated and failed with "discovery failed" / 401. Extend the challenge to all DAV surfaces via shared `is_dav_path` / `dav_basic_auth_challenge` helpers. 2. Calendars always advertised read-only. The `current-user-privilege-set` write gate compared `owner_id` against the literal string "current_user_id", which never matched a real UUID, so `<D:write/>` was never emitted and clients mounted every calendar read-only. Thread the caller's id through the CalDAV adapter and grant write when the caller owns the calendar. 3. CardDAV discovery was incomplete. There was no `/.well-known/carddav` route and the root PROPFIND exposed neither `current-user-principal` nor `addressbook-home-set`, so clients could not locate address books. Add the well-known redirect and root/principal discovery responses mirroring the CalDAV adapter. Adds unit tests for the auth challenge predicate, the calendar owner/non-owner privilege split, and the CardDAV root/principal discovery responses. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016cVV9nRQjP6G6a8zbNUWMw
This commit is contained in:
@@ -171,6 +171,7 @@ mod tests {
|
||||
&calendars,
|
||||
&request,
|
||||
"/caldav/",
|
||||
"user-001",
|
||||
);
|
||||
|
||||
assert!(
|
||||
@@ -210,6 +211,7 @@ mod tests {
|
||||
&request,
|
||||
"/caldav/cal-001",
|
||||
"0",
|
||||
"user-001",
|
||||
);
|
||||
|
||||
assert!(
|
||||
@@ -240,6 +242,7 @@ mod tests {
|
||||
&request,
|
||||
"/caldav/cal-001",
|
||||
"1",
|
||||
"user-001",
|
||||
);
|
||||
|
||||
assert!(
|
||||
@@ -258,6 +261,54 @@ mod tests {
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_owner_gets_write_privilege_but_non_owner_is_read_only() {
|
||||
// Regression for #480: the privilege gate previously compared owner_id
|
||||
// against the literal "current_user_id", so <D:write/> was never emitted
|
||||
// and every CalDAV client mounted calendars read-only.
|
||||
let calendar = sample_calendar(); // owner_id = "user-001"
|
||||
let request = PropFindRequest {
|
||||
prop_find_type: PropFindType::AllProp,
|
||||
};
|
||||
|
||||
// Owner → read + write.
|
||||
let mut owner_out = Vec::new();
|
||||
CalDavAdapter::generate_calendar_collection_propfind(
|
||||
&mut owner_out,
|
||||
&calendar,
|
||||
&[],
|
||||
&request,
|
||||
"/caldav/cal-001/",
|
||||
"0",
|
||||
"user-001",
|
||||
)
|
||||
.expect("owner propfind");
|
||||
let owner_xml = String::from_utf8(owner_out).expect("utf8");
|
||||
assert!(
|
||||
owner_xml.contains("D:write"),
|
||||
"Owner must be granted <D:write/>, got: {owner_xml}"
|
||||
);
|
||||
|
||||
// A different caller (e.g. a read-only share) → read only, never write.
|
||||
let mut other_out = Vec::new();
|
||||
CalDavAdapter::generate_calendar_collection_propfind(
|
||||
&mut other_out,
|
||||
&calendar,
|
||||
&[],
|
||||
&request,
|
||||
"/caldav/cal-001/",
|
||||
"0",
|
||||
"a-different-user",
|
||||
)
|
||||
.expect("non-owner propfind");
|
||||
let other_xml = String::from_utf8(other_out).expect("utf8");
|
||||
assert!(other_xml.contains("D:read"), "Non-owner keeps <D:read/>");
|
||||
assert!(
|
||||
!other_xml.contains("D:write"),
|
||||
"Non-owner must NOT get <D:write/>, got: {other_xml}"
|
||||
);
|
||||
}
|
||||
|
||||
// ========================
|
||||
// Calendar events response tests
|
||||
// ========================
|
||||
@@ -434,6 +485,7 @@ mod tests {
|
||||
&request,
|
||||
"/caldav/",
|
||||
"testuser",
|
||||
"user-001",
|
||||
);
|
||||
assert!(
|
||||
result.is_ok(),
|
||||
@@ -483,6 +535,7 @@ mod tests {
|
||||
&request,
|
||||
"/caldav/",
|
||||
"testuser",
|
||||
"user-001",
|
||||
);
|
||||
assert!(result.is_ok());
|
||||
|
||||
@@ -565,6 +618,7 @@ mod tests {
|
||||
&request,
|
||||
"/caldav/cal-001/",
|
||||
"0",
|
||||
"user-001",
|
||||
);
|
||||
assert!(result.is_ok(), "Failed: {:?}", result.err());
|
||||
|
||||
|
||||
Reference in New Issue
Block a user