Fixes the Nextcloud integration, which could not open its page at all on Nextcloud 34. Verified on a clean NC34 install.
This release combines everything from the 3.2.6 and 3.2.7 pre-releases.
Nextcloud: the app page failed to load
Two separate fatals, one behind the other.
\Tachyon\Util\HTTP\CSP has no report_to property and never has. Reading it produced null, and on PHP 8 passing that to array_merge() is a TypeError rather than a warning, so the policy constructor died on every request.
Behind that, OCP\Security\IContentSecurityPolicyNonceManager does not exist and never has in any Nextcloud release. OCP\Security has IContentSecurityPolicyManager, without "Nonce", from NC26 through NC34. Nextcloud exposes no public nonce API at all, so Tachyon now mints its own nonce and declares it in the policy it returns. The NextSnapMail fork settled on the same approach.
Knockout would have failed next
The protected properties inlineScriptAllowed and evalScriptAllowed no longer exist in NC34, so setting them did nothing while appearing to work. One of them mattered: Knockout evaluates its binding strings and needs unsafe-eval, which the constructor strips and used to restore through that property.
The policy is now built entirely through public methods, and unsafe-eval is passed as a script source, which Nextcloud's buildPolicy() emits verbatim. Every other OCP\ class this integration references was checked against NC34; all 40 exist.
The same class of bug was fixed in the ownCloud bridge, which read four properties that no longer exist. That integration is untested here.
CardDAV: wrong address book chosen (#17)
Discovery included Nextcloud's z-server-generated--system address book, which is read-only and access restricted, so PROPFIND on it answers 401. It could end up selected as the sync target when your own book is not named one of the well known names. Now skipped.
Tables in the HTML editor
New. An insert button with a grid size picker, plus insert row above and below, insert column left and right, delete row, delete column and delete table, which appear when the cursor is inside a table. Inserted tables carry inline styles so borders survive in recipients' mail clients.
This is the least exercised change in the release. If you hit trouble, deleting the last row or column, or operating on a table pasted from elsewhere, are the likely spots.