Per-client ICS calendar feed, replacing the shared ICS_TOKEN (#22)
Test backoffice (smb-crm) / test (push) Has been cancelled
Test backoffice (smb-crm) / test (push) Has been cancelled
Each client now gets their own clients.ics_token (lazily generated on first /owner/settings visit), which both authenticates and scopes /api/bookings.ics -- closing the gap where any shared-token holder could view another client's bookings by swapping the client_id query param. The owner settings page now surfaces a copyable subscribe URL. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -26,7 +26,6 @@ services:
|
||||
CRM_API_TOKEN: ${CRM_API_TOKEN}
|
||||
BOOKING_TOKEN_SECRET: ${BOOKING_TOKEN_SECRET}
|
||||
SESSION_SECRET_KEY: ${SESSION_SECRET_KEY}
|
||||
ICS_TOKEN: ${ICS_TOKEN}
|
||||
SMTP_HOST: ${SMTP_HOST}
|
||||
SMTP_PORT: ${SMTP_PORT}
|
||||
SMTP_USERNAME: ${SMTP_USERNAME}
|
||||
|
||||
Reference in New Issue
Block a user