0
0
Fork 0
mirror of https://github.com/discourse/discourse.git synced 2026-08-06 13:08:40 +08:00
discourse/plugins/discourse-calendar
discoursebot db94300baf
SECURITY: Remove stale invitee access for users removed from invited groups on private events [backport 2026.7] (#42190)
Backport of #42187 to release/2026.7.

---

## Summary

Correctly restrict private calendar event access to current group
members. The patch replaces stale invitee-row authorization with active
invited-group membership checks across event detail serialization,
attendance searches, RSVP mutations, and livestream chat metadata, and
prunes stale invitee records when a user is removed from a group.

## Source

- Patch Triage: https://patch.discourse.org/patch-triage/1377

Co-authored-by: discourse-patch-triage
<272280883+discourse-patch-triage[bot]@users.noreply.github.com>

Co-authored-by: Chris Alberti <christo@discourse.org>
2026-07-31 15:19:51 -05:00
..
app SECURITY: Remove stale invitee access for users removed from invited groups on private events [backport 2026.7] (#42190) 2026-07-31 15:19:51 -05:00
assets UX: disable chat key/focus capture on liestream topics (#42057) 2026-07-27 10:56:07 -04:00
config I18N: Update translations (#42126) 2026-07-29 11:33:44 +02:00
db UX: improve livestream chat messaging (#41750) 2026-07-21 11:07:31 +10:00
jobs FEATURE: Embedded Zoom webinar for livestream events (#40973) 2026-07-16 10:58:56 +10:00
lib SECURITY: Remove stale invitee access for users removed from invited groups on private events [backport 2026.7] (#42190) 2026-07-31 15:19:51 -05:00
spec SECURITY: Remove stale invitee access for users removed from invited groups on private events [backport 2026.7] (#42190) 2026-07-31 15:19:51 -05:00
test/javascripts UX: More Zoom livestream UI issues (#41824) 2026-07-27 15:31:41 +10:00
vendor/holidays DEV: Add 2026 Singapore holidays (#40318) 2026-05-27 06:59:10 +08:00
.prettierignore
about.json UX: improve livestream chat messaging (#41750) 2026-07-21 11:07:31 +10:00
package.json DEV: Add a script for generating external types in discourse-types (#37095) 2026-03-09 20:37:43 +01:00
plugin.rb SECURITY: Remove stale invitee access for users removed from invited groups on private events [backport 2026.7] (#42190) 2026-07-31 15:19:51 -05:00
README.md
tsconfig.json DEV: Add a script for generating external types in discourse-types (#37095) 2026-03-09 20:37:43 +01:00

Discourse Calendar

Adds the ability to create a dynamic calendar in the first post of a topic.

Topic discussing the plugin itself can be found here: https://meta.discourse.org/t/discourse-calendar/97376

Customization

Events

  • discourse_post_event_event_will_start this DiscourseEvent will be triggered one hour before an event starts
  • discourse_post_event_event_started this DiscourseEvent will be triggered when an event starts
  • discourse_post_event_event_ended this DiscourseEvent will be triggered when an event ends

Custom Fields

Custom fields can be set in plugin settings. Once added a new form will appear on event UI. These custom fields are available when a plugin event is triggered.

Holidays

See an incorrect or missing holiday? Familiarize yourself with the holiday definition Syntax. Then make your updates in the vendor/holiday/definitions directory.

Generate updated holidays as follows.

cd vendor/holidays

# Generate holiday definitions
rake generate:definitions

Install the plugin and switch to the discourse root(not the plugin directory).

# Collect all holiday regions into assets/javascripts/lib/regions.js
bin/rails javascript:update_constants

Interactions with Other Plugins

You can use an element of this plugin with the Right Sidebar Blocks component. You'll want to ensure the desired route is enabled via the events calendar categories setting. In Right Sidebar Block's settings, the block name will be upcoming-events-list, and the params use this syntax, for example MMMM D, YYYY.