So FWIW this would be drastically easier if CalDAV/CardDAV clients "could just" use an authorization header that browsers don't accept.