[Cosmo] search for calendars on cosmo?

Brian Moseley bcm at osafoundation.org
Mon Aug 8 17:49:14 PDT 2005


Brendan O'Connor wrote:

> random concern: there's also security and privacy issues with being able
> to query a server whether a given username exists there, because then
> you can build up a list of all users, find usernames to try to password
> crack, etc

yeah, i'm opposed to giving arbitrary software the ability to generate a 
comprehensive list of cosmo accounts.

i might be okay with the principal report that lisa suggested, but only 
with appropriate access control - the report request would have to be 
authenticated, and urls would only be returned for calendars on which 
the requesting user has read privilege.

i'm willing to hear more discussion on the topic, but for now i don't 
think that one should attempt to use a caldav server as an addressbook. 
i'd rather see folks publishing their calendar urls in vcards on the web 
or in ldap directories.



More information about the Cosmo mailing list