Clients were left guessing the CalDAV/CardDAV URLs (issue #192): the
README documented how to deploy Radicale but not how to connect to it.
- Add radicale/README.md with client URLs (trailing slash required),
the App-Token requirement (account passwords are rejected with the
default PROXY_ENABLE_BASIC_AUTH=false), GNOME Online Accounts and
Thunderbird walkthroughs, and troubleshooting.
- Mark the two '/.well-known/*' proxy routes as unprotected so DAV
clients can run RFC 6764 service discovery before authenticating.
Previously the proxy answered 401 where clients expect the 301
redirect to /caldav/ or /carddav/. Radicale serves no data on these
paths (deeper paths return 404, path traversal is normalized onto
the protected routes), verified against opencloud 7.5.0.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>