Skip to content

Commit 460b9e5

Browse files
committed
[WIP] Security Considerations
1 parent 440c091 commit 460b9e5

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

content.mkd

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -445,6 +445,10 @@ CalDAV/CardDAV servers that support WebDAV-Push SHOULD support:
445445

446446
# Security Considerations
447447

448+
WebDAV-Push operates within the usual security context of WebDAV. Servers usually restrict WebDAV access to authorized users. It makes sense to apply the same restrictions to WebDAV-Push operations (like subscription registration). It's however up to the server to define which WebDAV-Push operations are allowed and under which conditions. If a request is denied because of wrong authentication or missing privileges, the correct HTTP/WebDAV status codes MUST be used.
449+
450+
It's RECOMMENDED
451+
448452
The general requirements from {{Section 8 of RFC8030}} apply regardless of which transport is used. Especially:
449453

450454
- HTTP over TLS MUST be used for all communications.

0 commit comments

Comments
 (0)