Fix WebDAV/CalDAV/CardDAV bugs, drop username from URLs, harden concurrency
- Root handler now only serves the welcome page for GET/HEAD; all other methods (e.g. OPTIONS, PROPFIND) return 405 with an Allow header instead of always returning 200, fixing client capability probes and PROPFIND misbehavior. - Mount /files/ properly and cache one xwebdav.Handler per authenticated user so its LockSystem persists across requests instead of being recreated per-request (which broke LOCK/UNLOCK). - Remove the username segment from all DAV URLs (/cal/, /card/, /files/ are now identical for every account; the acting user is always resolved via Basic Auth, never the path). - Reintroduce a fixed literal "home" path segment (/cal/home/, /card/home/) to preserve the URL segment depth that go-webdav's caldav/carddav server relies on to classify resources (principal vs. home-set vs. collection vs. object). Removing the username had collapsed this depth, silently misclassifying requests and returning empty <multistatus> responses (DAVx5 "no resources found"). - Replace the store's single global mutex with per-user sharded locks so different users' requests no longer serialize against each other. - Add auth.NewContext test helper, WebDAV handler tests (per-user isolation, lock persistence across requests), and a concurrent multi-user store test. - Update README and copilot-instructions to document the new URL scheme and the go-webdav path-depth classification quirk. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
+10
-10
@@ -9,12 +9,12 @@ import (
|
||||
|
||||
// Config is the top-level server configuration.
|
||||
type Config struct {
|
||||
Server ServerConfig `yaml:"server"`
|
||||
Auth AuthConfig `yaml:"auth"`
|
||||
Storage StorageConfig `yaml:"storage"`
|
||||
Users map[string]UserConfig `yaml:"users"`
|
||||
TLS TLSConfig `yaml:"tls"`
|
||||
Logging LoggingConfig `yaml:"logging"`
|
||||
Server ServerConfig `yaml:"server"`
|
||||
Auth AuthConfig `yaml:"auth"`
|
||||
Storage StorageConfig `yaml:"storage"`
|
||||
Users map[string]UserConfig `yaml:"users"`
|
||||
TLS TLSConfig `yaml:"tls"`
|
||||
Logging LoggingConfig `yaml:"logging"`
|
||||
}
|
||||
|
||||
type ServerConfig struct {
|
||||
@@ -36,10 +36,10 @@ type StorageConfig struct {
|
||||
|
||||
type UserConfig struct {
|
||||
// bcrypt-hashed password (use `htpasswd -nB <user>`)
|
||||
Password string `yaml:"password"`
|
||||
DisplayName string `yaml:"display_name"`
|
||||
Email string `yaml:"email"`
|
||||
Calendars []string `yaml:"calendars"`
|
||||
Password string `yaml:"password"`
|
||||
DisplayName string `yaml:"display_name"`
|
||||
Email string `yaml:"email"`
|
||||
Calendars []string `yaml:"calendars"`
|
||||
AddressBooks []string `yaml:"address_books"`
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user