calternal_plugin_calendar::feeds
Calendar feed adapters for issue #431 and the public route in DESIGN §33.
Publication definitions live as Markdown files in a User’s Home. Their token hashes live in Security state. External subscription responses are derived cache data and never become Home files. MCP webhooks reuse the public-only DNS guard, without the admin webcal private-network allowlist (#491, DESIGN §55).
Source: crates/plugins/calendar/src/feeds/mod.rs
Functions
Section titled “Functions”public_router
Section titled “public_router”pub fn public_router(root: Root, db: Db) -> RouterBuild the unauthenticated capability route for published calendar feeds.
A token is the complete authority for this read-only route. The handler hashes it before looking up its owner and never accepts an account ID.
Source: crates/plugins/calendar/src/feeds/mod.rs:28
webhook_addresses
Section titled “webhook_addresses”pub async fn webhook_addresses(url: &Url) -> Result<Vec<SocketAddr>, &'static str>Resolve public sockets for signed webhooks (#491, DESIGN §55). This entry never applies the webcal admin allowlist: callbacks cannot reach a private address even when an admin permits a private calendar feed.
Source: crates/plugins/calendar/src/feeds/subscriptions.rs:1208