Read-only mode and Test still write to the server, deletes ignore ETags, credentials over plain http; CI, pins and surface imports #2
Labels
No labels
bug
documentation
enhancement
security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo-dav#2
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Found in the 2026-09-15 audit of the plugin repositories. The sync itself is solid (ETags, defusedxml); these are the gaps.
1. Read only and Test create collections on the server
sync.py:233-238) and every sync, includingread_only(:256-264), call_collection→ensure_collection.ensure_collectionrunsMKCOL/MKCALENDAR(dav.py:167-190).Fix: in read-only mode and in Test, look collections up without creating them, and report when one is missing.
2. Deletes ignore the remote ETag
sync.py:373and:513callserver.delete(link.remote_href)with noIf-Match. Deleting a record locally destroys a card or event that was edited on the phone since the last sync.Fix: pass
etag=link.etag, and turn a412 Precondition Failedinto a sync note instead of a deletion.3. Credentials over plain http
The URL field is a plain
type="url"(sync.py:174-184), and Basic auth goes to whatever scheme is typed (dav.py:94). The guarded client and TLS verification are used correctly otherwise.Fix: in
validate(), refusehttp://unless the host is private and the operator allows private destinations, or at least warn.4. CI cannot pass
.forgejo/workflows/ci.yml:39,41runsscripts/compile_messages.py, and the repository has noscripts/directory.Fix: use the
postulo-messagescompile command, and add a tag job runningpytest -m release.5. The version pin is a label
__version__is0.1.0against0.3.0inpyproject.toml, and the core is pinned with no ref to amaincommit. Version from metadata, pinv0.3.0, and stop the silent catalogue skip.6. The heaviest reach past the plugin surface
sync.py:34-45imports:postulo.applications.ical,.modelsand.services;postulo.core.phone_numbersandweb_links;postulo.jobs.models.Contact;postulo.plugins.models.SyncLink.This is the plugin most exposed to core refactors. The core's plugin-surface issue (postulo/postulo#229) proposes
SyncLinkplus a small sync facade; move onto it, and add the surface AST check to CI.