Skip to content

Commit 8617cc1

Browse files
Arusekkbackportbot[bot]
authored andcommitted
fix(caldav): show confidential event if writable
If a party can edit the calendar/event, just display it instead of hiding the details and risking overwrites. This might be considered a change impacting privacy, but it actually improves semantics. Relevant test updates included, improving assertion correctness. I think all the relevant use cases are solved by this. Closes #5551 Closes nextcloud/calendar#4044 Closes #11214 Signed-off-by: Arusekk <[email protected]> Signed-off-by: Richard Steinmetz <[email protected]>
1 parent 7ce484e commit 8617cc1

File tree

5 files changed

+279
-17
lines changed

5 files changed

+279
-17
lines changed

apps/dav/lib/CalDAV/CalendarObject.php

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,8 @@ public function get() {
5252
}
5353

5454
// shows as busy if event is declared confidential
55-
if ($this->objectData['classification'] === CalDavBackend::CLASSIFICATION_CONFIDENTIAL) {
55+
if ($this->objectData['classification'] === CalDavBackend::CLASSIFICATION_CONFIDENTIAL
56+
&& ($this->isPublic() || !$this->canWrite())) {
5657
$this->createConfidentialObject($vObject);
5758
}
5859

@@ -134,6 +135,10 @@ private function canWrite() {
134135
return true;
135136
}
136137

138+
private function isPublic(): bool {
139+
return $this->calendarInfo['{http://owncloud.org/ns}public'] ?? false;
140+
}
141+
137142
public function getCalendarId(): int {
138143
return (int)$this->objectData['calendarid'];
139144
}
Lines changed: 138 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,138 @@
1+
<?php
2+
3+
declare(strict_types=1);
4+
5+
/**
6+
* SPDX-FileCopyrightText: 2025 Nextcloud GmbH and Nextcloud contributors
7+
* SPDX-License-Identifier: AGPL-3.0-or-later
8+
*/
9+
10+
namespace OCA\DAV\Tests\unit\CalDAV;
11+
12+
use OCA\DAV\CalDAV\CalDavBackend;
13+
use OCA\DAV\CalDAV\CalendarObject;
14+
use OCP\IL10N;
15+
use PHPUnit\Framework\Attributes\DataProvider;
16+
use PHPUnit\Framework\MockObject\MockObject;
17+
use Sabre\VObject\Component\VCalendar;
18+
use Sabre\VObject\Component\VEvent;
19+
use Sabre\VObject\Reader as VObjectReader;
20+
use Test\TestCase;
21+
22+
class CalendarObjectTest extends TestCase {
23+
private readonly CalDavBackend&MockObject $calDavBackend;
24+
private readonly IL10N&MockObject $l10n;
25+
26+
protected function setUp(): void {
27+
parent::setUp();
28+
29+
$this->calDavBackend = $this->createMock(CalDavBackend::class);
30+
$this->l10n = $this->createMock(IL10N::class);
31+
32+
$this->l10n->method('t')
33+
->willReturnArgument(0);
34+
}
35+
36+
public static function provideConfidentialObjectData(): array {
37+
return [
38+
// Shared writable
39+
[
40+
false,
41+
[
42+
'principaluri' => 'user1',
43+
'{http://owncloud.org/ns}owner-principal' => 'user2',
44+
],
45+
],
46+
[
47+
false,
48+
[
49+
'principaluri' => 'user1',
50+
'{http://owncloud.org/ns}owner-principal' => 'user2',
51+
'{http://owncloud.org/ns}read-only' => 0,
52+
],
53+
],
54+
[
55+
false,
56+
[
57+
'principaluri' => 'user1',
58+
'{http://owncloud.org/ns}owner-principal' => 'user2',
59+
'{http://owncloud.org/ns}read-only' => false,
60+
],
61+
],
62+
// Shared read-only
63+
[
64+
true,
65+
[
66+
'principaluri' => 'user1',
67+
'{http://owncloud.org/ns}owner-principal' => 'user2',
68+
'{http://owncloud.org/ns}read-only' => 1,
69+
],
70+
],
71+
[
72+
true,
73+
[
74+
'principaluri' => 'user1',
75+
'{http://owncloud.org/ns}owner-principal' => 'user2',
76+
'{http://owncloud.org/ns}read-only' => true,
77+
],
78+
],
79+
];
80+
}
81+
82+
#[DataProvider('provideConfidentialObjectData')]
83+
public function testGetWithConfidentialObject(
84+
bool $expectConfidential,
85+
array $calendarInfo,
86+
): void {
87+
$ics = <<<EOF
88+
BEGIN:VCALENDAR
89+
CALSCALE:GREGORIAN
90+
VERSION:2.0
91+
PRODID:-//IDN nextcloud.com//Calendar app 5.5.0-dev.1//EN
92+
BEGIN:VEVENT
93+
CREATED:20250820T102647Z
94+
DTSTAMP:20250820T103038Z
95+
LAST-MODIFIED:20250820T103038Z
96+
SEQUENCE:4
97+
UID:a0f55f1f-4f0e-4db8-a54b-1e8b53846591
98+
DTSTART;TZID=Europe/Berlin:20250822T110000
99+
DTEND;TZID=Europe/Berlin:20250822T170000
100+
STATUS:CONFIRMED
101+
SUMMARY:confidential-event
102+
CLASS:CONFIDENTIAL
103+
LOCATION:A location
104+
DESCRIPTION:A description
105+
END:VEVENT
106+
END:VCALENDAR
107+
EOF;
108+
VObjectReader::read($ics);
109+
110+
$calendarObject = new CalendarObject(
111+
$this->calDavBackend,
112+
$this->l10n,
113+
$calendarInfo,
114+
[
115+
'uri' => 'a0f55f1f-4f0e-4db8-a54b-1e8b53846591.ics',
116+
'calendardata' => $ics,
117+
'classification' => 2, // CalDavBackend::CLASSIFICATION_CONFIDENTIAL
118+
],
119+
);
120+
121+
$actualIcs = $calendarObject->get();
122+
$vObject = VObjectReader::read($actualIcs);
123+
124+
$this->assertInstanceOf(VCalendar::class, $vObject);
125+
$vEvent = $vObject->getBaseComponent('VEVENT');
126+
$this->assertInstanceOf(VEvent::class, $vEvent);
127+
128+
if ($expectConfidential) {
129+
$this->assertEquals('Busy', $vEvent->SUMMARY?->getValue());
130+
$this->assertNull($vEvent->DESCRIPTION);
131+
$this->assertNull($vEvent->LOCATION);
132+
} else {
133+
$this->assertEquals('confidential-event', $vEvent->SUMMARY?->getValue());
134+
$this->assertNotNull($vEvent->DESCRIPTION);
135+
$this->assertNotNull($vEvent->LOCATION);
136+
}
137+
}
138+
}

apps/dav/tests/unit/CalDAV/CalendarTest.php

Lines changed: 17 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -310,9 +310,9 @@ public function testPrivateClassification($expectedChildren, $isShared): void {
310310
}
311311
$c = new Calendar($backend, $calendarInfo, $this->l10n, $this->config, $this->logger);
312312
$children = $c->getChildren();
313-
$this->assertEquals($expectedChildren, count($children));
313+
$this->assertCount($expectedChildren, $children);
314314
$children = $c->getMultipleChildren(['event-0', 'event-1', 'event-2']);
315-
$this->assertEquals($expectedChildren, count($children));
315+
$this->assertCount($expectedChildren, $children);
316316

317317
$this->assertEquals(!$isShared, $c->childExists('event-2'));
318318
}
@@ -392,9 +392,13 @@ public function testConfidentialClassification($expectedChildren, $isShared): vo
392392
'id' => 666,
393393
'uri' => 'cal',
394394
];
395+
396+
if ($isShared) {
397+
$calendarInfo['{http://owncloud.org/ns}read-only'] = true;
398+
}
395399
$c = new Calendar($backend, $calendarInfo, $this->l10n, $this->config, $this->logger);
396400

397-
$this->assertEquals(count($c->getChildren()), $expectedChildren);
401+
$this->assertCount($expectedChildren, $c->getChildren());
398402

399403
// test private event
400404
$privateEvent = $c->getChild('event-1');
@@ -599,24 +603,24 @@ public function testRemoveVAlarms(): void {
599603
$this->assertCount(2, $roCalendar->getChildren());
600604

601605
// calendar data shall not be altered for the owner
602-
$this->assertEquals($ownerCalendar->getChild('event-0')->get(), $publicObjectData);
603-
$this->assertEquals($ownerCalendar->getChild('event-1')->get(), $confidentialObjectData);
606+
$this->assertEquals($publicObjectData, $ownerCalendar->getChild('event-0')->get());
607+
$this->assertEquals($confidentialObjectData, $ownerCalendar->getChild('event-1')->get());
604608

605609
// valarms shall not be removed for read-write shares
606610
$this->assertEquals(
607-
$this->fixLinebreak($rwCalendar->getChild('event-0')->get()),
608-
$this->fixLinebreak($publicObjectData));
611+
$this->fixLinebreak($publicObjectData),
612+
$this->fixLinebreak($rwCalendar->getChild('event-0')->get()));
609613
$this->assertEquals(
610-
$this->fixLinebreak($rwCalendar->getChild('event-1')->get()),
611-
$this->fixLinebreak($confidentialObjectCleaned));
614+
$this->fixLinebreak($confidentialObjectData),
615+
$this->fixLinebreak($rwCalendar->getChild('event-1')->get()));
612616

613617
// valarms shall be removed for read-only shares
614618
$this->assertEquals(
615-
$this->fixLinebreak($roCalendar->getChild('event-0')->get()),
616-
$this->fixLinebreak($publicObjectDataWithoutVAlarm));
619+
$this->fixLinebreak($publicObjectDataWithoutVAlarm),
620+
$this->fixLinebreak($roCalendar->getChild('event-0')->get()));
617621
$this->assertEquals(
618-
$this->fixLinebreak($roCalendar->getChild('event-1')->get()),
619-
$this->fixLinebreak($confidentialObjectCleaned));
622+
$this->fixLinebreak($confidentialObjectCleaned),
623+
$this->fixLinebreak($roCalendar->getChild('event-1')->get()));
620624
}
621625

622626
private function fixLinebreak($str) {
Lines changed: 114 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,114 @@
1+
<?php
2+
3+
declare(strict_types=1);
4+
5+
/**
6+
* SPDX-FileCopyrightText: 2025 Nextcloud GmbH and Nextcloud contributors
7+
* SPDX-License-Identifier: AGPL-3.0-or-later
8+
*/
9+
10+
namespace OCA\DAV\Tests\unit\CalDAV;
11+
12+
use OCA\DAV\CalDAV\CalDavBackend;
13+
use OCA\DAV\CalDAV\PublicCalendarObject;
14+
use OCP\IL10N;
15+
use PHPUnit\Framework\Attributes\DataProvider;
16+
use PHPUnit\Framework\MockObject\MockObject;
17+
use Sabre\VObject\Component\VCalendar;
18+
use Sabre\VObject\Component\VEvent;
19+
use Sabre\VObject\Reader as VObjectReader;
20+
use Test\TestCase;
21+
22+
class PublicCalendarObjectTest extends TestCase {
23+
private readonly CalDavBackend&MockObject $calDavBackend;
24+
private readonly IL10N&MockObject $l10n;
25+
26+
protected function setUp(): void {
27+
parent::setUp();
28+
29+
$this->calDavBackend = $this->createMock(CalDavBackend::class);
30+
$this->l10n = $this->createMock(IL10N::class);
31+
32+
$this->l10n->method('t')
33+
->willReturnArgument(0);
34+
}
35+
36+
public static function provideConfidentialObjectData(): array {
37+
// For some reason, the CalDavBackend always sets read-only to false. Hence, we test for
38+
// both cases as the property should not matter anyway.
39+
// Ref \OCA\DAV\CalDAV\CalDavBackend::getPublicCalendars (approximately in line 538)
40+
return [
41+
[
42+
[
43+
'{http://owncloud.org/ns}read-only' => true,
44+
'{http://owncloud.org/ns}public' => true,
45+
],
46+
],
47+
[
48+
[
49+
'{http://owncloud.org/ns}read-only' => false,
50+
'{http://owncloud.org/ns}public' => true,
51+
],
52+
],
53+
[
54+
[
55+
'{http://owncloud.org/ns}read-only' => 1,
56+
'{http://owncloud.org/ns}public' => true,
57+
],
58+
],
59+
[
60+
[
61+
'{http://owncloud.org/ns}read-only' => 0,
62+
'{http://owncloud.org/ns}public' => true,
63+
],
64+
],
65+
];
66+
}
67+
68+
#[DataProvider('provideConfidentialObjectData')]
69+
public function testGetWithConfidentialObject(array $calendarInfo): void {
70+
$ics = <<<EOF
71+
BEGIN:VCALENDAR
72+
CALSCALE:GREGORIAN
73+
VERSION:2.0
74+
PRODID:-//IDN nextcloud.com//Calendar app 5.5.0-dev.1//EN
75+
BEGIN:VEVENT
76+
CREATED:20250820T102647Z
77+
DTSTAMP:20250820T103038Z
78+
LAST-MODIFIED:20250820T103038Z
79+
SEQUENCE:4
80+
UID:a0f55f1f-4f0e-4db8-a54b-1e8b53846591
81+
DTSTART;TZID=Europe/Berlin:20250822T110000
82+
DTEND;TZID=Europe/Berlin:20250822T170000
83+
STATUS:CONFIRMED
84+
SUMMARY:confidential-event
85+
CLASS:CONFIDENTIAL
86+
LOCATION:A location
87+
DESCRIPTION:A description
88+
END:VEVENT
89+
END:VCALENDAR
90+
EOF;
91+
92+
$calendarObject = new PublicCalendarObject(
93+
$this->calDavBackend,
94+
$this->l10n,
95+
$calendarInfo,
96+
[
97+
'uri' => 'a0f55f1f-4f0e-4db8-a54b-1e8b53846591.ics',
98+
'calendardata' => $ics,
99+
'classification' => 2, // CalDavBackend::CLASSIFICATION_CONFIDENTIAL
100+
],
101+
);
102+
103+
$actualIcs = $calendarObject->get();
104+
$vObject = VObjectReader::read($actualIcs);
105+
106+
$this->assertInstanceOf(VCalendar::class, $vObject);
107+
$vEvent = $vObject->getBaseComponent('VEVENT');
108+
$this->assertInstanceOf(VEvent::class, $vEvent);
109+
110+
$this->assertEquals('Busy', $vEvent->SUMMARY?->getValue());
111+
$this->assertNull($vEvent->DESCRIPTION);
112+
$this->assertNull($vEvent->LOCATION);
113+
}
114+
}

apps/dav/tests/unit/CalDAV/PublicCalendarTest.php

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -50,9 +50,9 @@ public function testPrivateClassification($expectedChildren, $isShared): void {
5050
$logger = $this->createMock(LoggerInterface::class);
5151
$c = new PublicCalendar($backend, $calendarInfo, $this->l10n, $config, $logger);
5252
$children = $c->getChildren();
53-
$this->assertEquals(2, count($children));
53+
$this->assertCount(2, $children);
5454
$children = $c->getMultipleChildren(['event-0', 'event-1', 'event-2']);
55-
$this->assertEquals(2, count($children));
55+
$this->assertCount(2, $children);
5656

5757
$this->assertFalse($c->childExists('event-2'));
5858
}
@@ -131,14 +131,15 @@ public function testConfidentialClassification($expectedChildren, $isShared): vo
131131
'principaluri' => 'user2',
132132
'id' => 666,
133133
'uri' => 'cal',
134+
'{http://owncloud.org/ns}public' => true,
134135
];
135136
/** @var MockObject | IConfig $config */
136137
$config = $this->createMock(IConfig::class);
137138
/** @var MockObject | LoggerInterface $logger */
138139
$logger = $this->createMock(LoggerInterface::class);
139140
$c = new PublicCalendar($backend, $calendarInfo, $this->l10n, $config, $logger);
140141

141-
$this->assertEquals(count($c->getChildren()), 2);
142+
$this->assertCount(2, $c->getChildren());
142143

143144
// test private event
144145
$privateEvent = $c->getChild('event-1');

0 commit comments

Comments
 (0)