feat(05-03): calendar backend — model, crypto, source CRUD module
- Add CalendarSource Prisma model with encrypted credentials (AES-256-GCM) - Create CalendarCryptoService with encrypt/decrypt using CALENDAR_ENCRYPTION_KEY - Create CalendarController with source CRUD endpoints (GET/POST/PATCH/DELETE) - Create CalendarService with ownership checks and SSRF URL validation - Add DTOs with https-only URL validation and class-validator decorators - Register CalendarModule in AppModule - Install tsdav, node-ical, ews-javascript-api, @microsoft/microsoft-graph-client - Stub provider files for Task 2 compilation
This commit is contained in:
@@ -0,0 +1,47 @@
|
||||
import {
|
||||
IsBoolean,
|
||||
IsHexColor,
|
||||
IsIn,
|
||||
IsNotEmpty,
|
||||
IsOptional,
|
||||
IsString,
|
||||
IsUrl,
|
||||
} from 'class-validator';
|
||||
|
||||
/**
|
||||
* DTO for creating a new calendar source.
|
||||
*
|
||||
* Security:
|
||||
* - T-05-11: URL restricted to https only (SSRF mitigation)
|
||||
* - T-05-10: password is plaintext in transit (over TLS), encrypted at rest by CryptoService
|
||||
*/
|
||||
export class CreateCalendarSourceDto {
|
||||
@IsString()
|
||||
@IsNotEmpty()
|
||||
name!: string;
|
||||
|
||||
@IsIn(['caldav', 'ics', 'exchange'])
|
||||
type!: string;
|
||||
|
||||
@IsUrl(
|
||||
{ protocols: ['https'], require_protocol: true },
|
||||
{ message: 'URL must use HTTPS protocol' },
|
||||
)
|
||||
url!: string;
|
||||
|
||||
@IsOptional()
|
||||
@IsString()
|
||||
username?: string;
|
||||
|
||||
@IsOptional()
|
||||
@IsString()
|
||||
password?: string;
|
||||
|
||||
@IsOptional()
|
||||
@IsIn(['ews', 'graph'])
|
||||
exchangeMode?: string;
|
||||
|
||||
@IsOptional()
|
||||
@IsHexColor()
|
||||
color?: string;
|
||||
}
|
||||
Reference in New Issue
Block a user