KamoCRM

Address books are found, and reached only by their owner with the web's rights

FixEmailService
Shipped
September 28, 2026 at 8:32 PM UTC
Author
Kamo
Commit
3c5468d

SP98-F-4. CardDAV wrote resourcetype as empty text for the home, every book and every card, so no client ever found an address book; a book is now **************** the home <D:collection/>, a card empty. The book's ctag is no longer sent as {DAV:}sync-token, and a sync-collection REPORT is refused (403 DAV:supported-report): contacts are deleted outright, so no token could tell a client which cards went. CardDAV also had no authorisation at all: any DAV session (a KamoJwt bearer, and since SP99 Task 2 a password) could read, write and delete the cards of any book by its number, in any organisation, and its home listed the account's books from every organisation. CardDavAccess now applies the web's rules: the book is the member's own in the session's organisation, and each act takes its right (VIEW, CREATE, EDIT, DELETE_CONTACTS, resolved through the membership as CalDAV resolves VIEW_CALENDAR); anything else is 403, as CalDAV answers.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing