Mailing List Archive

User calendar viewable by other users? v 0.9.8.1
Sorry - last one got away from me..

Hi - I just got DaviCal up and running. After panicking for an hour or
so trying to find the relationships part of the admin interface I
finally got a clue about the new privileging system.

I'm not sure if it's a problem with my client (Mozilla Lightning) or the
server. Anyway, I successfully created a user and a corresponding
calendar, and then created another user with no
grants or groups or anything, just the out-of-the-box default
privileges. I tell Lightning not to remember the passwords, and when I
restart TB/Lightning, it asks for the authentication again. When I enter
the second user's login, I can still see the first user's calendar, can
make changes, etc.

I'm thinking that shouldn't be. I double-checked that I didn't make user
1's collection publicly readable, and there are no grants either way. I
tried
clearing TB's cache and do a reload of the remote calendars and the same
thing happens.

What am I missing?

KD
User calendar viewable by other users? v 0.9.8.1 [ In reply to ]
On Sun, 2010-02-07 at 04:39 -0700, Keith Drader wrote:
> Sorry - last one got away from me..
>
> Hi - I just got DaviCal up and running. After panicking for an hour or
> so trying to find the relationships part of the admin interface I
> finally got a clue about the new privileging system.
>
> I'm not sure if it's a problem with my client (Mozilla Lightning) or the
> server. Anyway, I successfully created a user and a corresponding
> calendar, and then created another user with no
> grants or groups or anything, just the out-of-the-box default
> privileges. I tell Lightning not to remember the passwords, and when I
> restart TB/Lightning, it asks for the authentication again. When I enter
> the second user's login, I can still see the first user's calendar, can
> make changes, etc.
>
> I'm thinking that shouldn't be. I double-checked that I didn't make user
> 1's collection publicly readable, and there are no grants either way. I
> tried
> clearing TB's cache and do a reload of the remote calendars and the same
> thing happens.
>
> What am I missing?

Hi Keith,

I'm not sure. When I do that here I get a little yellow exclamation
mark next to the remote calendar and the Lightning log says:

CalDAV: Status 403 on initial PROPFIND for calendar User 1

Followed by a bunch of others, generally indicating failure to access
the calendar.

If you don't see those exclamation marks next to the calendar would it
be OK for you to e-mail me a dump of your database off-list, so I can
examine closer what might be happening?

Thanks,
Andrew.

------------------------------------------------------------------------
andrew (AT) morphoss (DOT) com +64(272)DEBIAN
Think twice before speaking, but don't say "think think click click".
------------------------------------------------------------------------

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 198 bytes
Desc: This is a digitally signed message part
URL: <http://lists.morphoss.com/pipermail/davical-users/attachments/20100207/ce7529f5/attachment.pgp>
-------------- next part --------------
User calendar viewable by other users? v 0.9.8.1 [ In reply to ]
On Sun, 2010-02-07 at 22:23 -0700, Keith Drader wrote:

> Thanks for the response. I think it was an issue with Thunderbird's
> password-remembering-thingy. All is fine now.

Hi Keith,

That's great!. Though I thought it might be something like that I am
always open to the possibility. I do have a number of regression tests
for permissions stuff, but bugs can always slip into the process in
spite of my best endeavours :-)

And, of course, that can especially happen when you do something more
radical like replacing the whole permissions model..!

Cheers,
Andrew McMillan.

------------------------------------------------------------------------
andrew (AT) morphoss (DOT) com +64(272)DEBIAN
You will be the victim of a bizarre joke.
------------------------------------------------------------------------

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 198 bytes
Desc: This is a digitally signed message part
URL: <http://lists.morphoss.com/pipermail/davical-users/attachments/20100207/8181957c/attachment.pgp>
-------------- next part --------------