Everything here came from running the account flow against a real Nextcloud rather than from reading the code. Discovery - A typed bare origin now gets the RFC 6764 well-known probe. It was returned as the only candidate, so `https://cloud.example.com` — what people actually type — was PROPFIND'd against the web UI, answered 405, and a working Nextcloud reported as "not a CalDAV server". - A same-host HTTPS→HTTP redirect is put back on TLS instead of refused (`dav` change 7). A Nextcloud behind a TLS-terminating proxy without `overwriteprotocol` builds every redirect with http://, including the /.well-known/caldav hop discovery depends on. Cross-host still throws. - Outcomes carry a `Cause` the UI translates, not the server's own words. "HTTP 405 Method Not Allowed" told someone entering an address nothing, in a language they may not read, from outside strings.xml. - An IPv6 origin keeps its brackets: `HttpUrl.host` returns "fd00::1", so the rebuilt origin did not parse and a homelab address came back as "not an address". Login Flow v2 - The poll response's scheme is coerced, never refused. Nextcloud returns the app password exactly once, so throwing there burned a live credential and left it dangling in the user's device list. The host mismatch already worked this way; the scheme now matches it. Accounts - The accounts screen observes Room and the sign-in state instead of taking a snapshot, so a sync landing — or a 401 stopping an account — reaches a screen that is already open. - A per-account detail screen, and provider identity (`CalDavProvider`) shared with the quirk table so one list drives both the icon and the warning. - The password field masks: floret-kit's `InlineTextField` gained a visual transformation, since `KeyboardType.Password` only tells the IME to drop suggestions.
38 lines
1.4 KiB
Kotlin
38 lines
1.4 KiB
Kotlin
plugins {
|
|
// No version: AGP already puts the Kotlin plugin on the build classpath, and
|
|
// asking for one here fails resolution ("already on the classpath with an
|
|
// unknown version"). The version is the catalogue's `kotlin`, via AGP.
|
|
id("org.jetbrains.kotlin.jvm")
|
|
}
|
|
|
|
// A plain JVM library on purpose: the vendored tree has no Android imports and
|
|
// must not gain any. That keeps it portable — `docs/SYNC.md` earmarks this layer
|
|
// for floret-kit's `core-dav`, and Calendula needs the same primitives.
|
|
java {
|
|
sourceCompatibility = JavaVersion.VERSION_17
|
|
targetCompatibility = JavaVersion.VERSION_17
|
|
}
|
|
|
|
kotlin {
|
|
compilerOptions {
|
|
jvmTarget = org.jetbrains.kotlin.gradle.dsl.JvmTarget.JVM_17
|
|
}
|
|
}
|
|
|
|
dependencies {
|
|
api(libs.okhttp)
|
|
|
|
// Android supplies org.xmlpull.v1 in the framework, so the 371 KB xpp3 jar is
|
|
// a compile-time stand-in only and never reaches the APK. The unit tests run
|
|
// on a plain JVM, which has no framework, so they get the real thing.
|
|
compileOnly(libs.xpp3)
|
|
testImplementation(libs.xpp3)
|
|
|
|
// Upstream's own suite, vendored with the code. It is JUnit 4 while :app is
|
|
// JUnit 5; rewriting it would forfeit the regression coverage that makes
|
|
// vendoring safe, which is the same call provider/PROVENANCE.md made.
|
|
testImplementation(libs.junit4)
|
|
testImplementation(libs.okhttp.mockwebserver)
|
|
testImplementation(libs.okhttp.tls)
|
|
}
|