mirror of
https://github.com/johannesjo/super-productivity.git
synced 2026-07-29 02:30:03 +00:00
* fix(caldav): discover calendars via principal/calendar-home-set #8259 The CalDAV Events plugin populated its calendar dropdowns with a single Depth:1 PROPFIND on the exact URL the user entered, keeping only responses whose resourcetype is <calendar>. Users paste the advertised CalDAV root (Nextcloud /remote.php/dav, Fastmail /dav/), where calendars live one or two collection levels deeper, so the request succeeds but lists no calendars. The dialog then showed a green 'Options loaded' tick with empty dropdowns (loadOptions resolved with an empty array, no error), and the Schedule showed no events because no calendar could be selected. Rewrite discoverCalendars to do RFC 4791 service discovery: try the entered URL directly (back-compat for a pasted calendar-home), else PROPFIND current-user-principal, then calendar-home-set, then enumerate the home collection. Discovery now follows server-controlled hrefs, so harden resolveHref to resolve via the URL constructor and refuse any off-origin target (the SSRF boundary, since credentials attach to every request), and drop untrusted server data from thrown error messages. De-duplicate the XML parse-error guard into a shared parseXmlDoc. Add discovery test coverage (previously none), including cross-origin href refusal. * test(caldav): assert request origin instead of URL substring CodeQL flagged the cross-origin discovery test's url.includes('evil...') check (js/incomplete-url-substring-sanitization). Parse each requested URL and assert its origin equals the entered server origin instead — a stronger, alert-free assertion that no credentialed request escaped off-origin. |
||
|---|---|---|
| .. | ||
| manifest.json | ||
| plugin.spec.ts | ||
| plugin.ts | ||