diff --git a/packages/features/bookings/lib/client/decoyBookingStore.ts b/packages/features/bookings/lib/client/decoyBookingStore.ts index 88a387f0fc..dcb6ae1c08 100644 --- a/packages/features/bookings/lib/client/decoyBookingStore.ts +++ b/packages/features/bookings/lib/client/decoyBookingStore.ts @@ -1,6 +1,7 @@ -import { localStorage } from "@calcom/lib/webstorage"; +import { sessionStorage } from "@calcom/lib/webstorage"; const BOOKING_SUCCESS_STORAGE_KEY_PREFIX = "cal.successfulBooking"; +const DECOY_BOOKING_EXPIRATION_MS = 5 * 60 * 1000; interface DecoyBookingData { booking: { @@ -20,7 +21,8 @@ function getStorageKey(uid: string): string { } /** - * Stores decoy booking data in localStorage using the booking's uid + * Stores decoy booking data in sessionStorage using the booking's uid + * Data automatically expires when the browser tab/window is closed or after 5 minutes * @param booking - The booking data to store (must include uid) */ export function storeDecoyBooking(booking: Record & { uid: string }): void { @@ -29,11 +31,11 @@ export function storeDecoyBooking(booking: Record & { uid: stri timestamp: Date.now(), }; const storageKey = getStorageKey(booking.uid); - localStorage.setItem(storageKey, JSON.stringify(bookingSuccessData)); + sessionStorage.setItem(storageKey, JSON.stringify(bookingSuccessData)); } /** - * Retrieves decoy booking data from localStorage + * Retrieves decoy booking data from sessionStorage * @param uid - The booking uid * @returns The stored booking data or null if not found or expired */ @@ -43,7 +45,7 @@ export function getDecoyBooking(uid: string): DecoyBookingData | null { } const storageKey = getStorageKey(uid); - const dataStr = localStorage.getItem(storageKey); + const dataStr = sessionStorage.getItem(storageKey); if (!dataStr) { return null; @@ -52,26 +54,22 @@ export function getDecoyBooking(uid: string): DecoyBookingData | null { try { const data: DecoyBookingData = JSON.parse(dataStr); - // Check if the data is too old (5 min) - const dataAge = Date.now() - data.timestamp; - const maxAge = 5 * 60 * 1000; // 5 minutes in milliseconds - - if (dataAge > maxAge) { - // Remove the data from localStorage if expired - localStorage.removeItem(storageKey); + const isExpired = Date.now() - data.timestamp > DECOY_BOOKING_EXPIRATION_MS; + if (isExpired) { + sessionStorage.removeItem(storageKey); return null; } return data; } catch { // If parsing fails, remove the corrupted data - localStorage.removeItem(storageKey); + sessionStorage.removeItem(storageKey); return null; } } /** - * Removes decoy booking data from localStorage + * Removes decoy booking data from sessionStorage * @param uid - The booking uid */ export function removeDecoyBooking(uid: string): void { @@ -80,7 +78,7 @@ export function removeDecoyBooking(uid: string): void { } const storageKey = getStorageKey(uid); - localStorage.removeItem(storageKey); + sessionStorage.removeItem(storageKey); } export type { DecoyBookingData }; diff --git a/packages/lib/webstorage.ts b/packages/lib/webstorage.ts index ba29124189..5bd185e616 100644 --- a/packages/lib/webstorage.ts +++ b/packages/lib/webstorage.ts @@ -1,12 +1,11 @@ /** - * Provides a wrapper around localStorage to avoid errors in case of restricted storage access. + * Provides a wrapper around localStorage and sessionStorage to avoid errors in case of restricted storage access. * * TODO: In case of an embed if localStorage is not available(third party), use localStorage of parent(first party) that contains the iframe. */ export const localStorage = { getItem(key: string) { try { - // eslint-disable-next-line @calcom/eslint/avoid-web-storage return window.localStorage.getItem(key); } catch { // In case storage is restricted. Possible reasons @@ -16,7 +15,6 @@ export const localStorage = { }, setItem(key: string, value: string) { try { - // eslint-disable-next-line @calcom/eslint/avoid-web-storage window.localStorage.setItem(key, value); } catch { // In case storage is restricted. Possible reasons @@ -27,7 +25,6 @@ export const localStorage = { }, removeItem: (key: string) => { try { - // eslint-disable-next-line @calcom/eslint/avoid-web-storage window.localStorage.removeItem(key); } catch { return; @@ -35,11 +32,6 @@ export const localStorage = { }, }; -/** - * Provides a wrapper around localStorage to avoid errors in case of restricted storage access. - * - * TODO: In case of an embed if localStorage is not available(third party), use localStorage of parent(first party) that contains the iframe. - */ export const sessionStorage = { getItem(key: string) { try {