fix: URL-decode DAV paths with spaces + feat: app passwords for Basic Auth
Bug fix: - URL-decode paths in extract_webdav_path(), extract_caldav_path(), extract_carddav_path() so folders with spaces (e.g. 'My Folder') no longer return 404 when accessed via encoded URIs (%20) - Properly encode href values in PROPFIND/PROPPATCH/LOCK XML responses - Decode Destination header in MOVE/COPY operations New feature - App Passwords (API keys for DAV clients): - POST /api/auth/app-passwords → create (shows token once) - GET /api/auth/app-passwords → list (prefix only) - DELETE /api/auth/app-passwords/:id → revoke - Auth middleware now accepts both Bearer JWT and Basic Auth - Argon2 hashed, scoped (webdav/caldav/carddav), optional expiry - Compatible with DAVx5, Thunderbird, rclone, curl Tested: 12/12 E2E tests pass (create, list, WebDAV/CalDAV/CardDAV Basic Auth, URL-decode with spaces, wrong password 401, revoke, post- revoke 401).
This commit is contained in:
@@ -0,0 +1,83 @@
|
||||
//! App Password entity.
|
||||
//!
|
||||
//! Represents an application-specific password that clients (like DAVx⁵, Thunderbird)
|
||||
//! can use with HTTP Basic Auth to access WebDAV/CalDAV/CardDAV endpoints without
|
||||
//! requiring interactive OAuth flows.
|
||||
|
||||
use chrono::{DateTime, Utc};
|
||||
use uuid::Uuid;
|
||||
|
||||
/// An application password created by a user for a specific client.
|
||||
#[derive(Debug, Clone)]
|
||||
pub struct AppPassword {
|
||||
/// Unique identifier.
|
||||
pub id: String,
|
||||
/// Owner user ID.
|
||||
pub user_id: String,
|
||||
/// Human-readable label chosen by the user (e.g. "DAVx5 on Pixel 8").
|
||||
pub label: String,
|
||||
/// Argon2 hash of the generated password token.
|
||||
///
|
||||
/// The plain text token is only returned once at creation time.
|
||||
pub password_hash: String,
|
||||
/// First 8 characters of the plain text token, stored for display purposes
|
||||
/// so the user can identify which token is which.
|
||||
pub prefix: String,
|
||||
/// Comma-separated scopes (e.g. "webdav,caldav,carddav").
|
||||
pub scopes: String,
|
||||
/// When this app password was created.
|
||||
pub created_at: DateTime<Utc>,
|
||||
/// When this app password was last used for authentication.
|
||||
pub last_used_at: Option<DateTime<Utc>>,
|
||||
/// Optional expiry — `None` means never expires.
|
||||
pub expires_at: Option<DateTime<Utc>>,
|
||||
/// Whether this app password is active.
|
||||
pub active: bool,
|
||||
}
|
||||
|
||||
impl AppPassword {
|
||||
/// Create a new app password entity.
|
||||
///
|
||||
/// The caller is responsible for hashing the raw token and passing
|
||||
/// the hash and prefix.
|
||||
pub fn new(
|
||||
user_id: String,
|
||||
label: String,
|
||||
password_hash: String,
|
||||
prefix: String,
|
||||
scopes: String,
|
||||
expires_at: Option<DateTime<Utc>>,
|
||||
) -> Self {
|
||||
Self {
|
||||
id: Uuid::new_v4().to_string(),
|
||||
user_id,
|
||||
label,
|
||||
password_hash,
|
||||
prefix,
|
||||
scopes,
|
||||
created_at: Utc::now(),
|
||||
last_used_at: None,
|
||||
expires_at,
|
||||
active: true,
|
||||
}
|
||||
}
|
||||
|
||||
/// Check whether this app password has expired.
|
||||
pub fn is_expired(&self) -> bool {
|
||||
if let Some(exp) = self.expires_at {
|
||||
Utc::now() >= exp
|
||||
} else {
|
||||
false
|
||||
}
|
||||
}
|
||||
|
||||
/// Check whether this app password is usable (active and not expired).
|
||||
pub fn is_usable(&self) -> bool {
|
||||
self.active && !self.is_expired()
|
||||
}
|
||||
|
||||
/// Check whether the given scope is granted by this app password.
|
||||
pub fn has_scope(&self, scope: &str) -> bool {
|
||||
self.scopes.split(',').any(|s| s.trim() == scope)
|
||||
}
|
||||
}
|
||||
@@ -1,3 +1,4 @@
|
||||
pub mod app_password;
|
||||
pub mod calendar;
|
||||
pub mod calendar_event;
|
||||
pub mod contact;
|
||||
|
||||
Reference in New Issue
Block a user