0
0
Fork 0
mirror of https://github.com/discourse/discourse.git synced 2026-08-06 13:08:40 +08:00
discourse/plugins/discourse-calendar
Bannon Tanner cc3e96ab31
SECURITY: Private event invitee details leak through invitees list endpoint [backport 2026.1] (#42134)
Backport of #42109 to release/2026.1.
- This one was a hand backport because the file structure is different

Summary
The invitee-list route for private events previously authorized only
host-post visibility, allowing an authenticated viewer to retrieve
attendee identities, RSVP states, and attendance totals that should be
hidden. The fix enforces the same private-event detail policy used by
EventSerializer before returning invitee data, returning a 403 error to
unauthorized viewers.
2026-07-29 11:09:19 -05:00
..
app SECURITY: Private event invitee details leak through invitees list endpoint [backport 2026.1] (#42134) 2026-07-29 11:09:19 -05:00
assets UX: avoid event node view being dragged when not selected (#37069) 2026-01-12 19:42:54 -03:00
config I18N: Update translations (#37916) 2026-02-25 09:47:58 -05:00
db/migrate FIX: event not found after being edited to earlier date (#36481) 2025-12-08 17:41:46 +01:00
jobs FIX: skip topic bump when date is in the past (#36784) 2025-12-18 21:29:06 +01:00
lib FIX: event not found after being edited to earlier date (#36481) 2025-12-08 17:41:46 +01:00
spec SECURITY: Private event invitee details leak through invitees list endpoint [backport 2026.1] (#42134) 2026-07-29 11:09:19 -05:00
test/javascripts FEATURE: inline event editor for the rich editor (#36675) 2026-01-12 09:48:53 -03:00
vendor/holidays DEV: add 2026 India holidays (#37059) 2026-01-13 14:08:31 +05:30
.prettierignore
package.json DEV: Overhaul typechecking configuration (#35794) 2025-11-12 12:54:34 +00:00
plugin.rb SECURITY: Private event invitee details leak through invitees list endpoint [backport 2026.1] (#42134) 2026-07-29 11:09:19 -05:00
README.md
tsconfig.json DEV: Overhaul typechecking configuration (#35794) 2025-11-12 12:54:34 +00:00

Discourse Calendar

Adds the ability to create a dynamic calendar in the first post of a topic.

Topic discussing the plugin itself can be found here: https://meta.discourse.org/t/discourse-calendar/97376

Customization

Events

  • discourse_post_event_event_will_start this DiscourseEvent will be triggered one hour before an event starts
  • discourse_post_event_event_started this DiscourseEvent will be triggered when an event starts
  • discourse_post_event_event_ended this DiscourseEvent will be triggered when an event ends

Custom Fields

Custom fields can be set in plugin settings. Once added a new form will appear on event UI. These custom fields are available when a plugin event is triggered.

Holidays

See an incorrect or missing holiday? Familiarize yourself with the holiday definition Syntax. Then make your updates in the vendor/holiday/definitions directory.

Generate updated holidays as follows.

cd vendor/holidays

# Generate holiday definitions
rake generate:definitions

Install the plugin and switch to the discourse root(not the plugin directory).

# Collect all holiday regions into assets/javascripts/lib/regions.js
bin/rails javascript:update_constants

Interactions with Other Plugins

You can use an element of this plugin with the Right Sidebar Blocks component. You'll want to ensure the desired route is enabled via the events calendar categories setting. In Right Sidebar Block's settings, the block name will be upcoming-events-list, and the params use this syntax, for example MMMM D, YYYY.