- Shipped
- September 28, 2026 at 8:32 PM UTC
- Author
- Kamo
- Commit
- 3c5468d
SP98-F-4. CardDAV wrote resourcetype as empty text for the home, every book and every card, so no client ever found an address book; a book is now **************** the home <D:collection/>, a card empty. The book's ctag is no longer sent as {DAV:}sync-token, and a sync-collection REPORT is refused (403 DAV:supported-report): contacts are deleted outright, so no token could tell a client which cards went. CardDAV also had no authorisation at all: any DAV session (a KamoJwt bearer, and since SP99 Task 2 a password) could read, write and delete the cards of any book by its number, in any organisation, and its home listed the account's books from every organisation. CardDavAccess now applies the web's rules: the book is the member's own in the session's organisation, and each act takes its right (VIEW, CREATE, EDIT, DELETE_CONTACTS, resolved through the membership as CalDAV resolves VIEW_CALENDAR); anything else is 403, as CalDAV answers.
