docs: define CalDAV secret retirement
This commit is contained in:
@@ -48,6 +48,14 @@ environment and external-provider references are rejected. Trusted deployment
|
|||||||
code may resolve an `env:NAME` reference only through the separate deployment
|
code may resolve an `env:NAME` reference only through the separate deployment
|
||||||
configuration helper.
|
configuration helper.
|
||||||
|
|
||||||
|
Deleting a source or its calendar immediately scrubs Calendar-owned ciphertext
|
||||||
|
and provider references and emits non-secret audit evidence. If an external
|
||||||
|
secret provider cannot confirm deletion, the operation fails closed without
|
||||||
|
retiring the source or cancelling its queued work; retry is idempotent after a
|
||||||
|
database rollback. Destructive module retirement first deletes and audits all
|
||||||
|
active and legacy retained provider secrets and stops before table removal on
|
||||||
|
provider failure.
|
||||||
|
|
||||||
Inbound sync uses CalDAV `calendar-query` for full sync and `sync-collection`
|
Inbound sync uses CalDAV `calendar-query` for full sync and `sync-collection`
|
||||||
when a sync token exists. It imports all VEVENT components in a resource and
|
when a sync token exists. It imports all VEVENT components in a resource and
|
||||||
soft-deletes local events when remote resources disappear. Two-way sources also
|
soft-deletes local events when remote resources disappear. Two-way sources also
|
||||||
|
|||||||
@@ -69,6 +69,12 @@ bindings or unresolved delivery. Credential rotation does not discard committed
|
|||||||
desired state. Public event mutation cannot set sync-owned source hrefs, kinds,
|
desired state. Public event mutation cannot set sync-owned source hrefs, kinds,
|
||||||
or ETags. Deleting a synchronized collection or retiring its source is a local
|
or ETags. Deleting a synchronized collection or retiring its source is a local
|
||||||
unlink: it never deletes the remote collection or its remaining remote events.
|
unlink: it never deletes the remote collection or its remaining remote events.
|
||||||
|
The unlink immediately scrubs Calendar-owned credential ciphertext and external
|
||||||
|
provider references and audits the deletion. External provider failure blocks
|
||||||
|
retirement before queued work is changed; a later retry tolerates a provider
|
||||||
|
secret already removed by an earlier attempt whose database transaction rolled
|
||||||
|
back. Provider errors and audit details never contain credential values or
|
||||||
|
secret references.
|
||||||
The current singular ownership model permits one active sync source per
|
The current singular ownership model permits one active sync source per
|
||||||
calendar; multi-source fan-in will require per-event source routing. Celery beat
|
calendar; multi-source fan-in will require per-event source routing. Celery beat
|
||||||
triggers recovery every minute, while root-transaction after-commit dispatch
|
triggers recovery every minute, while root-transaction after-commit dispatch
|
||||||
|
|||||||
Reference in New Issue
Block a user