fix(dav): repair CalDAV/CardDAV client connectivity (#480)
Standard CalDAV/CardDAV clients (Thunderbird, DAVx5, Apple Calendar/Contacts) failed to connect, mounted collections read-only, or could not discover address books, even though curl worked. Three protocol-compliance gaps caused this: 1. Missing Basic-auth challenge on /caldav and /carddav. The 401 returned for these surfaces carried no `WWW-Authenticate` header (only /webdav did). Spec-compliant clients never send credentials preemptively the way `curl -u` does — they wait for the challenge — so Thunderbird never authenticated and failed with "discovery failed" / 401. Extend the challenge to all DAV surfaces via shared `is_dav_path` / `dav_basic_auth_challenge` helpers. 2. Calendars always advertised read-only. The `current-user-privilege-set` write gate compared `owner_id` against the literal string "current_user_id", which never matched a real UUID, so `<D:write/>` was never emitted and clients mounted every calendar read-only. Thread the caller's id through the CalDAV adapter and grant write when the caller owns the calendar. 3. CardDAV discovery was incomplete. There was no `/.well-known/carddav` route and the root PROPFIND exposed neither `current-user-principal` nor `addressbook-home-set`, so clients could not locate address books. Add the well-known redirect and root/principal discovery responses mirroring the CalDAV adapter. Adds unit tests for the auth challenge predicate, the calendar owner/non-owner privilege split, and the CardDAV root/principal discovery responses. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016cVV9nRQjP6G6a8zbNUWMw
This commit is contained in:
@@ -307,6 +307,97 @@ mod tests {
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_root_propfind_advertises_principal_and_home_set() {
|
||||
// Regression for #480: without these discovery properties DAVx5 / Apple
|
||||
// Contacts never locate the user's address books.
|
||||
let books = vec![sample_address_book()];
|
||||
let request = PropFindRequest {
|
||||
prop_find_type: PropFindType::AllProp,
|
||||
};
|
||||
|
||||
let mut output = Vec::new();
|
||||
CardDavAdapter::generate_root_propfind_response(
|
||||
&mut output,
|
||||
&books,
|
||||
&request,
|
||||
"/carddav/",
|
||||
"testuser",
|
||||
)
|
||||
.expect("root propfind");
|
||||
|
||||
let xml = String::from_utf8(output).expect("utf8");
|
||||
assert!(
|
||||
xml.contains("/carddav/principals/testuser/"),
|
||||
"Root must expose current-user-principal href, got: {xml}"
|
||||
);
|
||||
assert!(
|
||||
xml.contains("/carddav/testuser/"),
|
||||
"Root must expose addressbook-home-set href, got: {xml}"
|
||||
);
|
||||
// Depth 1 also enumerates the books.
|
||||
assert!(xml.contains("ab-001"), "Should list address book");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_root_propfind_prop_request_returns_populated_discovery() {
|
||||
// A DAVx5-style targeted request for the two discovery properties.
|
||||
let request = PropFindRequest {
|
||||
prop_find_type: PropFindType::Prop(vec![
|
||||
QualifiedName {
|
||||
namespace: "DAV:".to_string(),
|
||||
name: "current-user-principal".to_string(),
|
||||
},
|
||||
QualifiedName {
|
||||
namespace: "urn:ietf:params:xml:ns:carddav".to_string(),
|
||||
name: "addressbook-home-set".to_string(),
|
||||
},
|
||||
]),
|
||||
};
|
||||
|
||||
let mut output = Vec::new();
|
||||
CardDavAdapter::generate_root_propfind_response(
|
||||
&mut output,
|
||||
&[],
|
||||
&request,
|
||||
"/carddav/",
|
||||
"testuser",
|
||||
)
|
||||
.expect("root propfind");
|
||||
|
||||
let xml = String::from_utf8(output).expect("utf8");
|
||||
assert!(xml.contains("/carddav/principals/testuser/"));
|
||||
assert!(xml.contains("/carddav/testuser/"));
|
||||
// Properties must be populated, not empty self-closing placeholders.
|
||||
assert!(!xml.contains("<D:current-user-principal/>"));
|
||||
assert!(!xml.contains("<CR:addressbook-home-set/>"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_principal_propfind_returns_home_set() {
|
||||
let request = PropFindRequest {
|
||||
prop_find_type: PropFindType::AllProp,
|
||||
};
|
||||
|
||||
let mut output = Vec::new();
|
||||
CardDavAdapter::generate_principal_propfind_response(&mut output, &request, "testuser")
|
||||
.expect("principal propfind");
|
||||
|
||||
let xml = String::from_utf8(output).expect("utf8");
|
||||
assert!(
|
||||
xml.contains("/carddav/principals/testuser/"),
|
||||
"Principal href should be present"
|
||||
);
|
||||
assert!(
|
||||
xml.contains("/carddav/testuser/"),
|
||||
"addressbook-home-set should be present"
|
||||
);
|
||||
assert!(
|
||||
xml.contains("D:principal"),
|
||||
"resourcetype should include principal"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_generate_addressbook_collection_propfind_depth_0() {
|
||||
let addressbook = sample_address_book();
|
||||
|
||||
Reference in New Issue
Block a user