File
Blob: README.md
dab
Cloudflare-native DAV service that gives each tessera user a private, opaque host for WebDAV, CalDAV, and CardDAV.
Overview
Every subject gets a five-word DNS label (e.g.
river-copper-lantern-velvet-maple.dab.limic.dev) and points real DAV clients
— Thunderbird, Apple Calendar, DAVx5 — at it. tessera owns identity. dab owns
DAV storage, Personal Access Tokens, protocol authorization, and subject-local
data.
The browser UI is a minimal control plane for occasional configuration visits (minting PATs, creating collections, reviewing audit events), not a daily-use workspace.
Features
- WebDAV (RFC 4918), CalDAV (RFC 4791), CardDAV (RFC 6352)
- OIDC sign-in via tessera
- Personal Access Tokens for headless DAV clients
- Opaque per-subject hosts, fail-closed authorization
- Conservative blob garbage collection and storage repair
- Litmus and caldav-server-tester compatibility coverage
Tech stack
- Runtime — Cloudflare Workers (TypeScript)
- HTTP — Hono
- Frontend — React 19, Vite, Tailwind 4
- Data — D1 (control plane), Durable Object SQLite (per-subject), R2 (file
blobs), Queues (
BLOB_GC,REPAIR_JOBS) - ORM — Drizzle
- Tests — Vitest, litmus (WebDAV), caldav-server-tester (CalDAV)
Repository layout
src/worker/ Cloudflare Worker entry, Hono app, DAV handlers, DO classes
src/client/ React SPA control-plane UI
drizzle/ Migrations for D1 and each DO SQLite
tests/ Vitest suites and protocol-compatibility harnesses
scripts/ litmus and caldav-server-tester runners
docs/ Operator and design docs
reference/ Local copies of relevant RFCs
vendor/ Pinned third-party assets
public/ Static assets served by ViteDocumentation
SPEC.md— product brief and original implementation intentPRODUCT.md— product positioningDESIGN.md— UI and visual systemAGENTS.md— working agreements and product boundariesdocs/operations.md— resource setup, migrations, validation commandsdocs/frontend-spec.md— React frontend architecturereference/— local RFC copies for protocol resolution
License
MIT. See LICENSE.