Skip to content

[Bug]: Calendar delegation re-exposes a calendar shared by the delegate, causing all events to appear twice #64860

Description

⚠️ This issue respects the following points: ⚠️

  • This is not a troubleshooting question, general support matter, or webserver/proxy problem, but likely a bug (if unsure, ask the Community Help Forum).
  • This issue is not already reported on Github OR solved at the Community Help Forum (I've searched!).
  • I'm using a maintained major version of Nextcloud Server and tested against the latest patch level. (Supported major versions and current patch levels).
  • I agree to follow Nextcloud's Code of Conduct.
  • I've tried my best to provide clear reproduction steps that someone unfamiliar with this bug could use to reproduce it.

Bug description

With Nextcloud Server 34.0.4 and Calendar 6.6.1, calendar delegation can create a circular visibility path when two users already share calendars with each other.

Setup:

  • User A owns calendar "Personal".
  • User A shares "Personal" with User B with read/write access.
  • User B owns their own "Personal" calendar and shares it with User A with read/write access.
  • User B additionally delegates their calendar account to User A with read/write permissions.

After enabling delegation, User A sees their own calendar twice in the Calendar web application:

  1. The normal own calendar "Personal".
  2. Another instance of User A's calendar underneath the delegated User B account.

As a result, every event in User A's own calendar is displayed twice, although every event exists only once in the database and CalDAV data.

Disabling User A's normal Personal calendar removes one copy.

Disabling "Personal (User A)" underneath User B's delegated calendar section removes the other copy.

The Calendar UI may also remain in a loading state/spinner while both paths are enabled.

Database and CalDAV verification showed that the events themselves are NOT duplicated.

Steps to reproduce

  1. Create two local Nextcloud users: User A and User B.
  2. User A owns a calendar named "Personal".
  3. Share User A's Personal calendar with User B with read/write permission.
  4. User B owns their own Personal calendar.
  5. Share User B's Personal calendar with User A with read/write permission.
  6. As User B, delegate the calendar account to User A with write access.
  7. Log in as User A and open the Calendar web app.
  8. Enable User A's own Personal calendar and the calendars delegated by User B.
  9. Create a new event in User A's Personal calendar.

Result:
The new event and all existing events in User A's Personal calendar are displayed twice.

If User A disables their normal Personal calendar, one copy disappears.
If User A disables the "Personal (User A)" calendar underneath User B's delegated section, the second copy disappears.

Expected behavior

A calendar should not be exposed back to its original owner through a delegation chain.

If User A shares a calendar with User B and User B delegates their calendar account back to User A, Nextcloud should either:

  • exclude calendars whose original owner is the delegatee,
  • deduplicate calendars using the canonical calendar owner/URI,
  • or detect the circular share/delegation relationship and warn the user.

User A's Personal calendar should appear only once and each event should be rendered only once.

Nextcloud Server version

34

Operating system

Debian/Ubuntu

PHP engine version

PHP 8.5

Web server

Apache (supported)

Database engine version

PostgreSQL

Is this bug present after an update or on a fresh install?

Fresh Nextcloud Server install

Are you using the Nextcloud Server Encryption module?

No response

What user-backends are you using?

  • Default user-backend (database)
  • LDAP/ Active Directory
  • SSO - SAML
  • Other

Configuration report

{
    "system": {
        "htaccess.RewriteBase": "/",
        "memcache.local": "\\OC\\Memcache\\APCu",
        "apps_paths": [
            {
                "path": "/var/www/html/apps",
                "url": "/apps",
                "writable": false
            },
            {
                "path": "/var/www/html/custom_apps",
                "url": "/custom_apps",
                "writable": true
            }
        ],
        "memcache.distributed": "\\OC\\Memcache\\Redis",
        "memcache.locking": "\\OC\\Memcache\\Redis",
        "redis": {
            "host": "***REMOVED SENSITIVE VALUE***",
            "password": "***REMOVED SENSITIVE VALUE***",
            "port": 6379
        },
        "upgrade.disable-web": true,
        "passwordsalt": "***REMOVED SENSITIVE VALUE***",
        "secret": "***REMOVED SENSITIVE VALUE***",
        "trusted_domains": [
            "192.168.x.x",
            "cloud.example.invalid"
        ],
        "datadirectory": "***REMOVED SENSITIVE VALUE***",
        "dbtype": "pgsql",
        "version": "34.0.4.1",
        "overwrite.cli.url": "https://cloud.example.invalid",
        "instanceid": "***REMOVED SENSITIVE VALUE***",
        "dbname": "***REMOVED SENSITIVE VALUE***",
        "dbhost": "***REMOVED SENSITIVE VALUE***",
        "dbtableprefix": "oc_",
        "dbuser": "***REMOVED SENSITIVE VALUE***",
        "dbpassword": "***REMOVED SENSITIVE VALUE***",
        "installed": true,
        "default_phone_region": "DE",
        "logtimezone": "Europe/Berlin",
        "trusted_proxies": "***REMOVED SENSITIVE VALUE***",
        "overwriteprotocol": "https",
        "overwritehost": "cloud.example.invalid",
        "maintenance": false
    }
}

List of activated Apps

calendar: 6.6.1
dav: 1.40.0

Nextcloud Signing status

No errors found by:

php occ integrity:check-core
php occ integrity:check-app calendar

Nextcloud Logs

Additional info

encryption: 2.22.0 [Disabled]
user_ldap: 1.25.0 [Disabled]
michael@nextcloud:~$ docker exec -u www-data nextcloud-app php occ app:list
Enabled:

  • activity: 7.0.0
  • app_api: 34.0.0
  • appstore: 1.0.0
  • bruteforcesettings: 7.0.0
  • calendar: 6.6.1
  • circles: 34.0.0
  • cloud_federation_api: 1.18.0
  • comments: 1.24.0
  • contacts: 8.9.0
  • contactsinteraction: 1.15.0
  • dashboard: 7.14.0
  • dav: 1.40.0
  • deck: 1.18.5
  • federatedfilesharing: 1.24.0
  • federation: 1.24.0
  • files: 2.6.0
  • files_downloadlimit: 5.2.0
  • files_lock: 34.0.1
  • files_pdfviewer: 7.0.0
  • files_reminders: 1.7.0
  • files_sharing: 1.26.0
  • files_trashbin: 1.24.0
  • files_versions: 1.27.0
  • firstrunwizard: 7.0.0-dev.0
  • groupfolders: 22.0.6
  • logreader: 7.0.0
  • lookup_server_connector: 1.22.0
  • mail: 5.12.1
  • nextcloud_announcements: 6.0.0
  • notifications: 7.0.0-dev.1
  • oauth2: 1.22.0
  • office: 1.0.0
  • password_policy: 6.0.0-dev.0
  • photos: 7.0.0
  • privacy: 6.0.0-dev.1
  • profile: 1.3.0
  • provisioning_api: 1.24.0
  • recommendations: 7.0.0
  • related_resources: 5.0.0-dev.0
  • richdocuments: 11.1.1
  • serverinfo: 6.0.0
  • settings: 1.17.0
  • sharebymail: 1.24.0
  • spreed: 24.0.5
  • support: 6.0.0
  • survey_client: 6.0.0-dev.0
  • systemtags: 1.24.0
  • text: 8.0.0
  • theming: 2.9.0
  • twofactor_backupcodes: 1.23.0
  • twofactor_totp: 16.0.0
  • updatenotification: 1.24.0
  • user_status: 1.14.0
  • viewer: 7.0.0-dev.0
  • weather_status: 1.14.0
  • webhook_listeners: 1.6.0
  • workflowengine: 2.16.0
    Disabled:
  • admin_audit: 1.24.0
  • encryption: 2.22.0
  • files_external: 1.26.0
  • suspicious_login: 12.0.0-dev.0
  • twofactor_nextcloud_notification: 8.0.0
  • user_ldap: 1.25.0
    michael@nextcloud:~$ docker exec -u www-data nextcloud-app php occ integrity:check-core
  • INVALID_HASH:
    • core/js/mimetypelist.js:
      • expected: cb945c6402e12d9e7d42d0359acf95a6e9a9b0c1f3bd8528f598a7fb1694e5ae34c80cf44ef6c8901eac1bfdd152de3315fc7eac007efee0f33f09ed3e518b6a
      • current: 6b290ba45e633706e1fe761ca21422053c113f17b2bb35f2351f2cf1c3b893aa543af6c594077ca213c755cfa0d002e22109bb1797bbadd8fb410ca839143e0e
        michael@nextcloud:$ docker exec -u www-data nextcloud-app php occ integrity:check-app calendar
        michael@nextcloud:
        $

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    0. Needs triagePending check for reproducibility or if it fits our roadmap34-feedbackbug

    Type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions