Calendars

Registering an application with Google and with Microsoft so that members can connect their calendars, and what iCloud needs instead.

Members can connect their own Google or Microsoft 365 calendar, so that meetings with contacts are logged in the CRM and scheduled calls and meetings reach the calendar; the user guide's Calendar page says what that does. For that to work, the installation needs an application registered with each provider it wants to offer. Each installation registers its own: the provider sends a member back to the installation's own address, and that address is part of the registration.

Nothing is set in the environment. An administrator enters each application's client id and client secret under Administration, Calendars, which also shows the one redirect address to register:

https://your-workspace.albaticket.com/account/calendar/callback

The secret is stored encrypted, is never shown again, and is kept when the form is saved with the field left empty. Members see Connect on their account page as soon as a provider has an application that is switched on.

What the server talks to

Alba Ticket makes requests to the provider only for a member who has connected a calendar: to oauth2.googleapis.com and www.googleapis.com for Google, to login.microsoftonline.com and graph.microsoft.com for Microsoft, and to caldav.icloud.com and the icloud.com server it names for iCloud. The server must be able to reach those addresses over HTTPS. The member's browser is sent to the provider's own page and back, which is a navigation: nothing is added to the Content-Security-Policy, and no script is loaded from a provider.

Google

  1. In the Google Cloud console, create a project (or choose one) and enable the Google Calendar API for it.
  2. Under Google Auth Platform, set up the consent screen: the application's name, your support address, and the audience. Internal is enough when every member is in your own Google Workspace; External lets any Google account connect, and Google then asks you to verify the application before more than a hundred people use it.
  3. Add the scope https://www.googleapis.com/auth/calendar.events. Alba Ticket also asks for openid and email, to show which account is connected.
  4. Create an OAuth client of type Web application and add the redirect address above under Authorised redirect URIs, exactly as shown.
  5. Enter the client id and the client secret under Administration, Calendars, in the Google Calendar section.

Microsoft

  1. In the Microsoft Entra admin centre, under App registrations, choose New registration.
  2. For Supported account types, choose Accounts in any organizational directory, with personal Microsoft accounts too if members use them. Alba Ticket sends members to Microsoft's common sign-in address, which refuses an application registered for a single organisation only.
  3. Under Redirect URI, choose Web and enter the redirect address above.
  4. Under API permissions, add the delegated Microsoft Graph permissions Calendars.ReadWrite, User.Read and offline_access.
  5. Under Certificates & secrets, create a client secret and copy its value at once: it is shown only then. Note when it expires; a new one is entered on the same page when it does.
  6. Enter the Application (client) ID and the secret's value under Administration, Calendars, in the Microsoft 365 section.

iCloud

Nothing is registered for iCloud, because Apple offers no application to register: an iCloud calendar is reached by CalDAV, signed in with the member's own Apple ID and an app-specific password they make in their Apple Account. So there is nothing to set up, only a switch: iCloud is off in a new installation, and offered on members' account pages once an administrator has switched iCloud calendars on under Administration, Modules and features (see Modules and features).

The server must be able to reach caldav.icloud.com and the server it names for the account (p*-caldav.icloud.com) over HTTPS. The member's Apple ID and app-specific password are sent to addresses on icloud.com only, never to one a reply points to anywhere else, and no redirect is followed. They are stored encrypted like the other providers' keys, and Alba Ticket cannot remove the password at Apple: the member does that.

Checking

Connect a calendar from your own account page, add an event with a contact's address among the attendees, and wait for the next reading (a quarter of an hour at most, or at once after connecting): the meeting appears on the contact's timeline. Then log a call with a time ahead on a contact: it appears in the calendar within moments.

A connection that fails says why on the member's account page. A message that the redirect address does not match means the address registered with the provider differs from the one shown on the page, often by a trailing slash or http for https.

What a member's connection holds

Each connection holds the provider's keys for one member's calendar, encrypted in the database with the installation's CLOAK_KEY. They are never included in a workspace export, so after importing a workspace somewhere else, members connect again. Removing an application under Administration, Calendars stops every connection made through it from being read until an application is there again.