Repository navigation
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
GVodyanov
left a comment
There was a problem hiding this comment.
Thanks for picking this up, the previews will be a nice improvement!
One concern with the approach: OCA\DAV\CalDAV\CalDavBackend is an internal class of the DAV app, not a public API. Apps shouldn't depend on it directly. It can
change at any time without notice, and that would break the public calendar page. (That's also why psalm needed the extra ignore entries.)
Right now there's no public API to look up a public calendar by its token, so the clean way would be to add one to server first. Roughly:
- Server PR: add something like getCalendarByPublicToken(string $token): ?ICalendar to OCP\Calendar\IManager, implemented in the DAV CalendarProvider on top of
getPublicCalendar(). Ideally it returns the display name without the (uid) suffix and also gives access to the calendar owner, since ICalendar doesn't expose
that today. - This PR: use OCP\Calendar\IManager instead of CalDavBackend, and drop the psalm changes. Because we still support Nextcloud 34, we'd need to fall back to the
generic title/description when the new method isn't available.
Since this touches the public API, it's best to open an issue in nextcloud/server first so we can agree on the method's shape (especially how to expose the
owner) before writing code.
|
@GVodyanov thanks for the detailed review, that makes sense. I opened nextcloud/server#65325 to agree on the API shape, mainly how to expose the owner. Once that's settled I'll rework this PR on top of AI disclosure: this reply was drafted with help from an AI assistant. |
Assisted-by: Cursor:grok-4.7 Signed-off-by: whoalin1 <whoalin414@gmail.com>
Assisted-by: Cursor:grok-4.7 Signed-off-by: whoalin1 <whoalin414@gmail.com>
Assisted-by: Cursor:grok-4.7 Signed-off-by: whoalin1 <whoalin414@gmail.com>
de37fc9 to
8c85e00
Compare
Summary
Public calendar share links (
/p/{token}) only rendered the JS app shell, so chat/social crawlers previewed “This app requires Javascript…” instead of the calendar name and sharer.Resolve the publish token via CalDAV, set the public header title/details, and emit
og:*/twitter:*meta tags server-side (mirroringfiles_sharing) so previews work without JavaScript.Closes #609
Test plan
curl -A 'Twitterbot/1.0' -sL '<share-url>' | grep og:→og:titleis the calendar name,og:descriptionmentions the owner/embed/{token}) still works; X-Frame-Options / CSP unchangedAccept: text/calendaron/p/{token}still redirects to the DAV export URLtests/php/unit/Controller/PublicViewControllerTest.phpAI disclosure
This PR was drafted with the help of AI coding assistants (Cursor agents / LLM-based tools), including the description. I am responsible for it and happy to rework anything that doesn't fit.
All commits carry an
Assisted-by: Cursor:grok-4.7trailer.