- Shipped
- September 28, 2026 at 9:42 AM UTC
- Author
- Kamo
- Commit
- 9196272
DavAuthFilter posted Basic credentials to **************** which never existed (405), so every username-and-password sign-in from iOS or DAVx5 was answered 401 (SP07 T37). It now posts to SecurityService POST /api/internal/dav/sign-in with X-Internal-Auth, relaying the client's X-Forwarded-Host, X-Forwarded-For, X-Real-IP and User-Agent so the lockout and access rules judge the phone, not this pod. - 200 proceeds as that member and workspace (ids read as text; they pass 2^53); - 401 challenges again; 403 only for SecurityService's BLOCKED verdict; 429 carries Retry-After; anything else, or no answer, is 503 rather than a password prompt; - workspace-backslash-username names the workspace (the web's ?org= hint), for a member of several workspaces on the platform host; - an accepted password is remembered for two minutes (salted per process), so a sync is one password hash rather than one per request; a refusal is never remembered; - a malformed header or an empty password is answered 401 without asking.
