radicale-modoboa-rights
A rights management plugin for Radicale provided by Modoboa.
Access to a user’s own collections and to the shared calendars of his domain is decided locally. Access to collections owned by someone else (calendars shared through Modoboa access rules, administrators) is asked to the Modoboa API and cached, so Radicale and Modoboa can run on different servers without sharing any file.
Requirements:
Radicale 3.3 or later
Modoboa 2.11 or later, which provides the rights endpoint. Modoboa is not a Python dependency of this package: it is usually installed on another server and only reached through its API.
Installation
You can install this package from PyPi using the following command:
pip install radicale-modoboa-rights
Configuration
Here is a configuration example:
[rights] type = radicale_modoboa_rights modoboa_rights_endpoint = https://<modoboa>/api/v2/calendar-rights/ # Credentials of Radicale's OAuth2 application in Modoboa modoboa_client_id = <client id> modoboa_client_secret = <client secret>
The OAuth2 application must be named Radicale and use the client credentials grant. It is the one created for Radicale’s authentication plugin.
Optional settings:
- modoboa_token_endpoint (default: /api/o/token/ on the host of modoboa_rights_endpoint)
Modoboa’s OAuth2 token endpoint.
The following optional settings are in seconds:
- modoboa_rights_cache_ttl (default: 60)
How long rights fetched from Modoboa are cached. This is also the maximum delay before a revoked access is enforced.
- modoboa_rights_refresh_interval (default: 5)
When an access is denied, rights are fetched again if they are older than this, so new shares are usable almost immediately.
- modoboa_rights_stale_max_age (default: 3600)
While the Modoboa API is unreachable, cached rights keep being used up to this age. Past it, access to other users’ collections is denied.
- modoboa_rights_timeout (default: 2)
Timeout of requests to the Modoboa API.
- modoboa_rights_retry_delay (default: 10)
After a failed request, the Modoboa API is not called again before this delay.
Permissions
Collection |
Permissions |
|---|---|
Own principal (user@domain/) |
RW |
Own calendars (user@domain/*) |
rw |
Domain shared calendars, for domain members |
rwd |
Domain collection, for its managers |
RW |
Domain shared calendars, for their managers |
rw |
User principals, for administrators |
R |
User calendars, for administrators |
rw |
Shared calendars |
returned by Modoboa |
The d permission forbids the deletion of the calendar itself when [rights] permit_delete_collection is enabled (the default).
Modoboa API
The plugin gets an access token from modoboa_token_endpoint with the OAuth2 client credentials grant (client id and secret sent with HTTP Basic). The token is kept until it is about to expire, or until the API refuses it.
It then sends POST requests to modoboa_rights_endpoint with the token (Authorization: Bearer <token>):
{"user": "bob@example.com"}
and expects the following answer:
{
"admin_domains": ["example.com"],
"managed_domains": ["example.com"],
"shares": {"alice@example.com/Work": "rwd"}
}
- admin_domains
Domains whose user calendars the user administers. "*" means every domain.
- managed_domains
Domains whose shared calendars the user manages. "*" means every domain.
- shares
Calendars shared with the user, as path: permissions. Only rwdDoOi permissions are accepted. For a share link token, the calendar the token gives access to.
All keys are optional.
Metadata
Release files for radicale-modoboa-rights 1.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| radicale_modoboa_rights-1.0.0.tar.gz | 17.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| radicale_modoboa_rights-1.0.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 27.1 kB
Release files / radicale_modoboa_rights-1.0.0.tar.gz
| Download URL | radicale_modoboa_rights-1.0.0.tar.gz |
|---|---|
| Size | 17.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
7f8001294011fc4340bfd36d98e231640a831c86386b9190d9f903d13de6b746
|
|
BLAKE2b-256 checksum How to use checksums |
0ea6bfd11ee277487841b5a248b2d54c92f71b74ed3524f4159bbec7cc689441
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.
Transparency logRelease files / radicale_modoboa_rights-1.0.0-py3-none-any.whl
| Download URL | radicale_modoboa_rights-1.0.0-py3-none-any.whl |
|---|---|
| Size | 9.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
d428bc4797c5b8c70a161a5f43afa1bf265635844b0c0e6c7bf809bc5634de50
|
|
BLAKE2b-256 checksum How to use checksums |
2c4928575960ad0bff0a2eada799ca6455e07b5bca7ac4c6a09c4023a0629d30
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.
Transparency log