Read calendar event creators from the admin module, and archive the old ones #14
Reference in New Issue
Block a user
Delete Branch "feature/calendar-auth-cutover"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Step 4 of docs/calendar-auth-migration.md, and the close of DEFERRED_SECURITY.md item 1: no calendar route reads sessionId/sessionKey from the query string any more, so a live credential no longer travels through access logs, browser history and Referer headers. The four write routes sit behind requireAppAccess('calendar'), which also narrows who may edit from "any activated @nachklang.art account" to an explicit per-user permission. They answer 401 signed out and 403 without the permission, where they previously answered 403 for both. The three read routes cannot use the middleware: one URL serves an anonymous visitor, an iCal subscription holding a shared password, and a signed-in editor who should see drafts. They resolve the session optionally instead, and a signed-in user without the calendar permission is treated as anonymous rather than refused - so they keep the public calendar access anyone has. That public calendar staying anonymous is load-bearing: nachklang.art reads it to show the next upcoming event. It is now pinned at both the password-table and the route level, and so is the rule that a shared password can never be used to write. credentials.service.ts loses its session half and becomes the password table it always wanted to be. The shared passwords survive only for iCal clients, which cannot send a cookie. Writes record the author as an admin user id and no longer have a legacy int to write, which is what migration 003 makes room for. /calendar/users/* is left in place: nothing calls it and a session it mints opens nothing, but they are still live password-accepting endpoints, so removing them belongs with the rest of the legacy path in step 5. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>