makiolaj ede4205b7f sync: scope the credential by the public-suffix list
The auth handler decided which hosts may receive the password by
comparing the last two labels of their names. A server at
cloud.example.co.uk therefore scoped the app password to co.uk, one at
myhome.duckdns.org to duckdns.org, and a self-hoster at 192.168.1.10 to
"any address ending .1.10". The handler sends Basic preemptively, before
any challenge, so those hosts get the password unprompted on the first
HTTPS request.

It is reachable: ServiceDiscovery accepts an SRV target outside the
domain it queried, over plain UDP DNS. Scoped correctly, an on-path
attacker needs a certificate for a name inside the victim's own
registrable domain. Scoped to co.uk, they need one for a domain they
already own.

Now topPrivateDomain(), from the list OkHttp bundles, falling back to the
exact host where there is none -- null means no restriction here, so an
IP literal or localhost must not pass one through. The handler had to
change with the caller: it re-derives the domain per request, so fixing
only the caller withholds the credential from everything.

Still trusted: two hosts under one registrable domain share an owner.
That is what iCloud's caldav/pNN-caldav split needs, and narrowing
further costs it.
2026-09-07 21:35:10 +02:00
2026-09-07 18:41:45 +02:00

Agendula

A modern Material 3 Expressive task app for Android.
Keeps your tasks on your device, or on top of a tasks provider you already use. Open standards, no account required.

CI Android 10+ Kotlin + Compose Material 3 Expressive MIT License

Agendula is the task-list sibling to Calendula. Where Calendula is a pure front-end over Android's CalendarContract, Agendula keeps its own store, designed around RFC 5545's VTODO — the same tasks DAVx5 (and SmoothSync, DecSync, …) sync out of your CalDAV server. It can also read and write a tasks provider you already have, for anyone already syncing that way.

The name rhymes with its sibling on purpose: Agendula is agenda — Latin for “things to be done” — given Calendula's -ula ending. Calendula keeps your days; Agendula keeps your to-dos. (A Calendula flower head is botanically a cluster of many small florets — so the two apps are florets of one bloom.)

Where your tasks live — your choice

Where Sync Needs
On your device (default) Agendula's own database none yet — CalDAV sync of our own is planned nothing. No account, no permissions, no other app
In a provider you already use OpenTasks or tasks.org whatever syncs it for you — DAVx5 and friends that app installed, and its read/write permission

Agendula's own store is an ordinary app database — nothing is published to other apps, so there is no authority to clash over and no permission to grant. It coexists with OpenTasks rather than replacing it: installing one never breaks the other, and if you already sync through a provider, that keeps working exactly as it did.

Recurring tasks are expanded per RFC 5545, and everything the schema does not model is round-tripped verbatim rather than dropped — so passing your tasks through Agendula does not quietly lose fields a server sent.

Your tasks are exportable as standard iCalendar .ics files at any time, because data you can't take with you isn't really yours.

Status: backend complete, UI catching up. Storage, reads and writes, smart-list filtering, a self-scheduled reminder engine, and export are built and unit-tested. The Material 3 Expressive screens are being built on top, one at a time — the storage-mode picker and export screen are not there yet. See docs/ROADMAP.md for status, docs/ARCHITECTURE.md for how it's built, and docs/STORAGE-AND-SYNC.md for why storage works the way it does.

Sync sources (by design)

In external-provider mode Agendula works with anything that writes to that provider — DAVx5 (CalDAV), SmoothSync, CalDAV-Sync, DecSync CC, or any Android sync adapter — because it builds on the provider, not on any one sync app. Google Tasks / Microsoft To Do are out of scope by design (proprietary; they would mean owning a sync stack). Open standards — CalDAV / iCalendar / DecSync — are the lane.

Translations

Agendula ships in English so far, and would like not to. Translations are managed on a self-hosted Weblate, and partial ones are fine — an untranslated string simply falls back to English.

→ Help translate Agendula

No coding needed: register on the Weblate server, pick (or request) a language, and translate the strings in your browser. You can also reach this link in the app from the top of Settings → App language.

License

MIT — see LICENSE.

S
Description
A modern Material 3 Expressive task app for Android — sibling to Calendula, over the OpenTasks provider.
Readme MIT
3.9 MiB
v1.0.0
Latest
2026-09-24 20:09:02 +00:00
Languages
Kotlin 98.3%
Python 1%
Shell 0.6%
Ruby 0.1%