Changed default role for calendar access to show only date and time.#7152
Open
admins-little-helper wants to merge 1 commit intomailcow:stagingfrom
Open
Changed default role for calendar access to show only date and time.#7152admins-little-helper wants to merge 1 commit intomailcow:stagingfrom
admins-little-helper wants to merge 1 commit intomailcow:stagingfrom
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Contribution Guidelines
What does this PR include?
Short Description
Currently the default calendar shareing permissions in SOGo for events marked as "public" in a personal calendar are set to "ViewAll" for all users in the same domain.
In addition by default new events are created as "public". That results in all users within a domain/org can read events of all other users by default.
To improve security I think the default should be changed to allow only to see date/time of an event ("free/busy"). Every user then still can set sharing permissions individually as needed.
Current default calendar sharing permission:

Proposed change:

Affected Containers
Did you run tests?
What did you tested?
Edited file
data/conf/sogo/sogo.confand changedto this:
Restarted containers sogo-mailcow and memcached-mailcow:
What were the final results? (Awaited, got)
Works as intendet: the default calendar sharing permissions for new and existing users are set to show date & time only ("free/busy") for events marked as public. Users can change shareing permisisons as they like. In case a user already has changed sharing permissions before, those individual permissions are not changed.