mirror of
https://github.com/opencloud-eu/opencloud-compose.git
synced 2026-10-07 03:18:16 +08:00
Clients were left guessing the CalDAV/CardDAV URLs (issue #192): the README documented how to deploy Radicale but not how to connect to it. - Add radicale/README.md with client URLs (trailing slash required), the App-Token requirement (account passwords are rejected with the default PROXY_ENABLE_BASIC_AUTH=false), GNOME Online Accounts and Thunderbird walkthroughs, and troubleshooting. - Mark the two '/.well-known/*' proxy routes as unprotected so DAV clients can run RFC 6764 service discovery before authenticating. Previously the proxy answered 401 where clients expect the 301 redirect to /caldav/ or /carddav/. Radicale serves no data on these paths (deeper paths return 404, path traversal is normalized onto the protected routes), verified against opencloud 7.5.0. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
50 lines
1.9 KiB
YAML
50 lines
1.9 KiB
YAML
# This adds four additional routes to the proxy, forwarding requests
|
|
# on '/caldav/', '/carddav/' and the respective '/.well-known'
|
|
# endpoints to the radicale container and setting the required headers.
|
|
#
|
|
# Client URLs (trailing slash required, see radicale/README.md):
|
|
# CalDAV: https://<your-domain>/caldav/
|
|
# CardDAV: https://<your-domain>/carddav/
|
|
additional_policies:
|
|
- name: default
|
|
routes:
|
|
- endpoint: /caldav/
|
|
backend: http://radicale:5232
|
|
remote_user_header: X-Remote-User
|
|
skip_x_access_token: true
|
|
additional_headers:
|
|
- X-Script-Name: /caldav
|
|
# The '.well-known' endpoints are 'unprotected' so that DAV clients
|
|
# can discover the CalDAV/CardDAV URLs (RFC 6764) before they
|
|
# authenticate. Radicale only ever answers these paths with a 301
|
|
# redirect to '/caldav/' or '/carddav/' and serves no data here
|
|
# (deeper paths return 404), so no authentication is required.
|
|
- endpoint: /.well-known/caldav
|
|
backend: http://radicale:5232
|
|
skip_x_access_token: true
|
|
unprotected: true
|
|
additional_headers:
|
|
- X-Script-Name: /caldav
|
|
- endpoint: /carddav/
|
|
backend: http://radicale:5232
|
|
remote_user_header: X-Remote-User
|
|
skip_x_access_token: true
|
|
additional_headers:
|
|
- X-Script-Name: /carddav
|
|
- endpoint: /.well-known/carddav
|
|
backend: http://radicale:5232
|
|
skip_x_access_token: true
|
|
unprotected: true
|
|
additional_headers:
|
|
- X-Script-Name: /carddav
|
|
# To enable the radicale web UI add this rule.
|
|
# "unprotected" is True because the Web UI itself ask for
|
|
# the password.
|
|
# Also set "type" to "internal" in the config/radicale/config
|
|
# - endpoint: /caldav/.web/
|
|
# backend: http://radicale:5232/
|
|
# unprotected: true
|
|
# skip_x_access_token: true
|
|
# additional_headers:
|
|
# - X-Script-Name: /caldav
|