⚠️ This issue respects the following points: ⚠️
Bug description
With Nextcloud Server 34.0.4 and Calendar 6.6.1, calendar delegation can create a circular visibility path when two users already share calendars with each other.
Setup:
- User A owns calendar "Personal".
- User A shares "Personal" with User B with read/write access.
- User B owns their own "Personal" calendar and shares it with User A with read/write access.
- User B additionally delegates their calendar account to User A with read/write permissions.
After enabling delegation, User A sees their own calendar twice in the Calendar web application:
- The normal own calendar "Personal".
- Another instance of User A's calendar underneath the delegated User B account.
As a result, every event in User A's own calendar is displayed twice, although every event exists only once in the database and CalDAV data.
Disabling User A's normal Personal calendar removes one copy.
Disabling "Personal (User A)" underneath User B's delegated calendar section removes the other copy.
The Calendar UI may also remain in a loading state/spinner while both paths are enabled.
Database and CalDAV verification showed that the events themselves are NOT duplicated.
Steps to reproduce
- Create two local Nextcloud users: User A and User B.
- User A owns a calendar named "Personal".
- Share User A's Personal calendar with User B with read/write permission.
- User B owns their own Personal calendar.
- Share User B's Personal calendar with User A with read/write permission.
- As User B, delegate the calendar account to User A with write access.
- Log in as User A and open the Calendar web app.
- Enable User A's own Personal calendar and the calendars delegated by User B.
- Create a new event in User A's Personal calendar.
Result:
The new event and all existing events in User A's Personal calendar are displayed twice.
If User A disables their normal Personal calendar, one copy disappears.
If User A disables the "Personal (User A)" calendar underneath User B's delegated section, the second copy disappears.
Expected behavior
A calendar should not be exposed back to its original owner through a delegation chain.
If User A shares a calendar with User B and User B delegates their calendar account back to User A, Nextcloud should either:
- exclude calendars whose original owner is the delegatee,
- deduplicate calendars using the canonical calendar owner/URI,
- or detect the circular share/delegation relationship and warn the user.
User A's Personal calendar should appear only once and each event should be rendered only once.
Nextcloud Server version
34
Operating system
Debian/Ubuntu
PHP engine version
PHP 8.5
Web server
Apache (supported)
Database engine version
PostgreSQL
Is this bug present after an update or on a fresh install?
Fresh Nextcloud Server install
Are you using the Nextcloud Server Encryption module?
No response
What user-backends are you using?
Configuration report
{
"system": {
"htaccess.RewriteBase": "/",
"memcache.local": "\\OC\\Memcache\\APCu",
"apps_paths": [
{
"path": "/var/www/html/apps",
"url": "/apps",
"writable": false
},
{
"path": "/var/www/html/custom_apps",
"url": "/custom_apps",
"writable": true
}
],
"memcache.distributed": "\\OC\\Memcache\\Redis",
"memcache.locking": "\\OC\\Memcache\\Redis",
"redis": {
"host": "***REMOVED SENSITIVE VALUE***",
"password": "***REMOVED SENSITIVE VALUE***",
"port": 6379
},
"upgrade.disable-web": true,
"passwordsalt": "***REMOVED SENSITIVE VALUE***",
"secret": "***REMOVED SENSITIVE VALUE***",
"trusted_domains": [
"192.168.x.x",
"cloud.example.invalid"
],
"datadirectory": "***REMOVED SENSITIVE VALUE***",
"dbtype": "pgsql",
"version": "34.0.4.1",
"overwrite.cli.url": "https://cloud.example.invalid",
"instanceid": "***REMOVED SENSITIVE VALUE***",
"dbname": "***REMOVED SENSITIVE VALUE***",
"dbhost": "***REMOVED SENSITIVE VALUE***",
"dbtableprefix": "oc_",
"dbuser": "***REMOVED SENSITIVE VALUE***",
"dbpassword": "***REMOVED SENSITIVE VALUE***",
"installed": true,
"default_phone_region": "DE",
"logtimezone": "Europe/Berlin",
"trusted_proxies": "***REMOVED SENSITIVE VALUE***",
"overwriteprotocol": "https",
"overwritehost": "cloud.example.invalid",
"maintenance": false
}
}
List of activated Apps
calendar: 6.6.1
dav: 1.40.0
Nextcloud Signing status
No errors found by:
php occ integrity:check-core
php occ integrity:check-app calendar
Nextcloud Logs
Additional info
encryption: 2.22.0 [Disabled]
user_ldap: 1.25.0 [Disabled]
michael@nextcloud:~$ docker exec -u www-data nextcloud-app php occ app:list
Enabled:
- activity: 7.0.0
- app_api: 34.0.0
- appstore: 1.0.0
- bruteforcesettings: 7.0.0
- calendar: 6.6.1
- circles: 34.0.0
- cloud_federation_api: 1.18.0
- comments: 1.24.0
- contacts: 8.9.0
- contactsinteraction: 1.15.0
- dashboard: 7.14.0
- dav: 1.40.0
- deck: 1.18.5
- federatedfilesharing: 1.24.0
- federation: 1.24.0
- files: 2.6.0
- files_downloadlimit: 5.2.0
- files_lock: 34.0.1
- files_pdfviewer: 7.0.0
- files_reminders: 1.7.0
- files_sharing: 1.26.0
- files_trashbin: 1.24.0
- files_versions: 1.27.0
- firstrunwizard: 7.0.0-dev.0
- groupfolders: 22.0.6
- logreader: 7.0.0
- lookup_server_connector: 1.22.0
- mail: 5.12.1
- nextcloud_announcements: 6.0.0
- notifications: 7.0.0-dev.1
- oauth2: 1.22.0
- office: 1.0.0
- password_policy: 6.0.0-dev.0
- photos: 7.0.0
- privacy: 6.0.0-dev.1
- profile: 1.3.0
- provisioning_api: 1.24.0
- recommendations: 7.0.0
- related_resources: 5.0.0-dev.0
- richdocuments: 11.1.1
- serverinfo: 6.0.0
- settings: 1.17.0
- sharebymail: 1.24.0
- spreed: 24.0.5
- support: 6.0.0
- survey_client: 6.0.0-dev.0
- systemtags: 1.24.0
- text: 8.0.0
- theming: 2.9.0
- twofactor_backupcodes: 1.23.0
- twofactor_totp: 16.0.0
- updatenotification: 1.24.0
- user_status: 1.14.0
- viewer: 7.0.0-dev.0
- weather_status: 1.14.0
- webhook_listeners: 1.6.0
- workflowengine: 2.16.0
Disabled:
- admin_audit: 1.24.0
- encryption: 2.22.0
- files_external: 1.26.0
- suspicious_login: 12.0.0-dev.0
- twofactor_nextcloud_notification: 8.0.0
- user_ldap: 1.25.0
michael@nextcloud:~$ docker exec -u www-data nextcloud-app php occ integrity:check-core
- INVALID_HASH:
- core/js/mimetypelist.js:
- expected: cb945c6402e12d9e7d42d0359acf95a6e9a9b0c1f3bd8528f598a7fb1694e5ae34c80cf44ef6c8901eac1bfdd152de3315fc7eac007efee0f33f09ed3e518b6a
- current: 6b290ba45e633706e1fe761ca21422053c113f17b2bb35f2351f2cf1c3b893aa543af6c594077ca213c755cfa0d002e22109bb1797bbadd8fb410ca839143e0e
michael@nextcloud:$ docker exec -u www-data nextcloud-app php occ integrity:check-app calendar
michael@nextcloud:$
Bug description
With Nextcloud Server 34.0.4 and Calendar 6.6.1, calendar delegation can create a circular visibility path when two users already share calendars with each other.
Setup:
After enabling delegation, User A sees their own calendar twice in the Calendar web application:
As a result, every event in User A's own calendar is displayed twice, although every event exists only once in the database and CalDAV data.
Disabling User A's normal Personal calendar removes one copy.
Disabling "Personal (User A)" underneath User B's delegated calendar section removes the other copy.
The Calendar UI may also remain in a loading state/spinner while both paths are enabled.
Database and CalDAV verification showed that the events themselves are NOT duplicated.
Steps to reproduce
Result:
The new event and all existing events in User A's Personal calendar are displayed twice.
If User A disables their normal Personal calendar, one copy disappears.
If User A disables the "Personal (User A)" calendar underneath User B's delegated section, the second copy disappears.
Expected behavior
A calendar should not be exposed back to its original owner through a delegation chain.
If User A shares a calendar with User B and User B delegates their calendar account back to User A, Nextcloud should either:
User A's Personal calendar should appear only once and each event should be rendered only once.
Nextcloud Server version
34
Operating system
Debian/Ubuntu
PHP engine version
PHP 8.5
Web server
Apache (supported)
Database engine version
PostgreSQL
Is this bug present after an update or on a fresh install?
Fresh Nextcloud Server install
Are you using the Nextcloud Server Encryption module?
No response
What user-backends are you using?
Configuration report
{ "system": { "htaccess.RewriteBase": "/", "memcache.local": "\\OC\\Memcache\\APCu", "apps_paths": [ { "path": "/var/www/html/apps", "url": "/apps", "writable": false }, { "path": "/var/www/html/custom_apps", "url": "/custom_apps", "writable": true } ], "memcache.distributed": "\\OC\\Memcache\\Redis", "memcache.locking": "\\OC\\Memcache\\Redis", "redis": { "host": "***REMOVED SENSITIVE VALUE***", "password": "***REMOVED SENSITIVE VALUE***", "port": 6379 }, "upgrade.disable-web": true, "passwordsalt": "***REMOVED SENSITIVE VALUE***", "secret": "***REMOVED SENSITIVE VALUE***", "trusted_domains": [ "192.168.x.x", "cloud.example.invalid" ], "datadirectory": "***REMOVED SENSITIVE VALUE***", "dbtype": "pgsql", "version": "34.0.4.1", "overwrite.cli.url": "https://cloud.example.invalid", "instanceid": "***REMOVED SENSITIVE VALUE***", "dbname": "***REMOVED SENSITIVE VALUE***", "dbhost": "***REMOVED SENSITIVE VALUE***", "dbtableprefix": "oc_", "dbuser": "***REMOVED SENSITIVE VALUE***", "dbpassword": "***REMOVED SENSITIVE VALUE***", "installed": true, "default_phone_region": "DE", "logtimezone": "Europe/Berlin", "trusted_proxies": "***REMOVED SENSITIVE VALUE***", "overwriteprotocol": "https", "overwritehost": "cloud.example.invalid", "maintenance": false } }List of activated Apps
Nextcloud Signing status
Nextcloud Logs
Additional info
encryption: 2.22.0 [Disabled]
user_ldap: 1.25.0 [Disabled]
michael@nextcloud:~$ docker exec -u www-data nextcloud-app php occ app:list
Enabled:
Disabled:
michael@nextcloud:~$ docker exec -u www-data nextcloud-app php occ integrity:check-core
michael@nextcloud:
$ docker exec -u www-data nextcloud-app php occ integrity:check-app calendar$michael@nextcloud: