Skip to content

Branches

Default: main

Tags

No tags yet

dab

Cloudflare-native DAV service that gives each tessera user a private, opaque host for WebDAV, CalDAV, and CardDAV.

Overview

Every subject gets a five-word DNS label (e.g. river-copper-lantern-velvet-maple.dab.limic.dev) and points real DAV clients — Thunderbird, Apple Calendar, DAVx5 — at it. tessera owns identity. dab owns DAV storage, Personal Access Tokens, protocol authorization, and subject-local data.

The browser UI is a minimal control plane for occasional configuration visits (minting PATs, creating collections, reviewing audit events), not a daily-use workspace.

Features

  • WebDAV (RFC 4918), CalDAV (RFC 4791), CardDAV (RFC 6352)
  • OIDC sign-in via tessera
  • Personal Access Tokens for headless DAV clients
  • Opaque per-subject hosts, fail-closed authorization
  • Conservative blob garbage collection and storage repair
  • Litmus and caldav-server-tester compatibility coverage

Tech stack

  • Runtime — Cloudflare Workers (TypeScript)
  • HTTP — Hono
  • Frontend — React 19, Vite, Tailwind 4
  • Data — D1 (control plane), Durable Object SQLite (per-subject), R2 (file blobs), Queues (BLOB_GC, REPAIR_JOBS)
  • ORM — Drizzle
  • Tests — Vitest, litmus (WebDAV), caldav-server-tester (CalDAV)

Repository layout

src/worker/      Cloudflare Worker entry, Hono app, DAV handlers, DO classes
src/client/      React SPA control-plane UI
drizzle/         Migrations for D1 and each DO SQLite
tests/           Vitest suites and protocol-compatibility harnesses
scripts/         litmus and caldav-server-tester runners
docs/            Operator and design docs
reference/       Local copies of relevant RFCs
vendor/          Pinned third-party assets
public/          Static assets served by Vite

Documentation

License

MIT. See LICENSE.