Skip to content

Security fix: calendar event visibility - #116

Merged
keyxmakerx merged 1 commit into
mainfrom
claude/project-thread-bs6baq
Oct 2, 2026
Merged

keyxmakerx merged 1 commit into
mainfrom
claude/project-thread-bs6baq

Conversation

@keyxmakerx

Copy link
Copy Markdown
Owner

Requested by Key Maker · project thread

Fixes: none
Security implication: security fix; calendar events Chronicle limits to some players are no longer shown to every player in Foundry.
Consumer-verified: Chronicle serves visibility (everyone/gm-only) and visibility_rules (JSON string, allowed_users/denied_users) on events: internal/plugins/syncapi/calendar_api_handler.go (eventForWire), internal/plugins/calendar/model.go (VisibilityRules, Allows: an empty allow-list means everyone).
Foundry compatibility: not run in a live world; pure helper tested in Node, call sites syntax-checked.
Mockup: n/a

What this changes

  • New isChronicleEventPublic(event) in scripts/calendar-sync.mjs decides whether a Chronicle event may be shown to all players. GM-only events and everyone events carrying player restrictions are not public; unknown or unreadable values fail closed.
  • Modern Calendaria: such events become hidden notes, and every update re-applies visibility so an event narrowed later is hidden too.
  • Legacy Calendaria and Simple Calendar can't hide notes from this code path, so restricted events are not copied there (and are removed if an update restricts them).

Why

Found during the Foundry sync review (keyxmakerx/Chronicle#907). Security fix.

Test plan

  • node --test tools/test-*.mjs: 863 tests, 863 pass (4 new in tools/test-calendar-sync-visibility.mjs)
  • node tools/check-package-descriptor.mjs passes
  • node --check scripts/calendar-sync.mjs
  • Manual verification in Foundry: an event limited to one player in Chronicle shows as a GM-only note in Calendaria
  • CI passes

Tenet self-check

  • T-B1 security: fail closed on unknown visibility or unreadable rules
  • T-B2 plugin isolation: changes stay in the module
  • T-B3 production UI: n/a
  • T-B4 dual-audience docs: .ai.md sync wire rules updated

🤖 Generated with Claude Code

https://claude.ai/code/session_018uKa2E5HNdeubwBSD9Jn4n


Generated by Claude Code

Calendar events that Chronicle limits to some players no longer become
notes every player in Foundry can read.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018uKa2E5HNdeubwBSD9Jn4n
@keyxmakerx keyxmakerx self-assigned this Oct 2, 2026
@keyxmakerx
keyxmakerx marked this pull request as ready for review October 2, 2026 19:08
@keyxmakerx
keyxmakerx merged commit 192f1ac into main Oct 2, 2026
1 check passed
@keyxmakerx
keyxmakerx deleted the claude/project-thread-bs6baq branch October 2, 2026 19:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants