2026-06-20 · Engineering notes · Cadora
Letting the database do the worrying
Cadora pushes as much correctness as possible down into Postgres, where it can’t be bypassed, from offline sync to who is allowed to see what.
§ Staying in sync without the hard math
Real-time collaboration usually means reaching for a heavy CRDT engine. Cadora sidesteps that by making the data fine-grained. Each list item is its own row, so two people editing at once almost always touch different rows and merge cleanly. Offline edits write to the phone instantly and queue in an “outbox” that replays in order when the connection comes back. It’s simple, and tuned for how families actually use it.
§ Security lives in the database
Cadora enforces who can see what in the database itself, so a guest’s phone never even downloads the events they’re not allowed to see. Invite codes and other sensitive tables are locked so tightly that clients can’t touch them at all. Every use flows through a guarded database function that checks and consumes the code in one atomic step. Even third-party calendar tokens are kept encrypted, with the app only ever holding an opaque reference. The rule of thumb across all of it: cut unauthorized data before it leaves the server.
§ “My edit came back as their change”
Two-way calendar sync has a nasty trap: something you just pushed to Google comes back on the next poll looking like a brand-new change. Cadora fingerprints each event so it recognizes and skips its own echoes, and it only does real work when the provider signals something actually changed. Polling stays cheap, and an event is never rewritten just because it was re-fetched.