* fix: dont allow email exclusion bypass with capital letters
* trim before lowercasing to filter out empty tokens
* update console message
* use only regex change to implement this
* use only regex change to implement this
## What does this PR do?
Adds a welcome modal for new organizations that appears after organization creation. The modal showcases key features of the Organizations plan and provides a better onboarding experience.
## Visual Demo (For contributors especially)
#### Image Demo:

## Mandatory Tasks (DO NOT REMOVE)
- [x] I have self-reviewed the code.
- [x] I have updated the developer docs in /docs if this PR makes changes that would require a documentation change. N/A
- [x] I confirm automated tests are in place that prove my fix is effective or that my feature works.
## How should this be tested?
1. Create a new organization through either:
- The onboarding flow
- The settings/organizations/new page
- The organization creation form
2. After successful creation and redirect, verify the welcome modal appears showing organization features.
3. Verify the modal can be closed by:
- Clicking the "Continue" button
- Clicking outside the modal
- Pressing ESC key
4. Verify the modal doesn't reappear after being closed (query param and session storage should be cleared).
## Checklist
- I have read the [contributing guide](https://github.com/calcom/cal.com/blob/main/CONTRIBUTING.md)
- My code follows the style guidelines of this project
- I have commented my code, particularly in hard-to-understand areas
- I have checked if my changes generate no new warnings
* Allow team admins to see hidden fields and UTM tracking data
- Add team admin permission check for booking data visibility
- Team admins can now view hidden booking field answers
- Team admins can now view UTM tracking parameters
- Support for managed events (parent team admins can view child event data)
- Maintain backward compatibility with existing host permissions
Fixes team admin access to booking details as requested in issue.
* feat: allow all team members to view hidden fields and UTM data
Previously only team admins could view hidden booking field answers and UTM tracking parameters. Now all team members can see this data, providing better transparency within teams.
- Changed from isTeamAdmin to isTeamMember check
- Team members (not just admins) can now view hidden booking fields
- Team members can now view UTM tracking parameters
- Maintains host permission (organizers can still see everything)
- Supports managed events (parent team members can view child event data)
* Address reviewer feedback: use existing membership pattern
- Remove custom checkIfUserIsTeamAdmin function
- Use existing userId_teamId pattern with prisma.membership.findUnique
- Revert PrismaPlugin and variable name changes
- Maintain same functionality with cleaner implementation
* fix: use existing isTeamAdmin function and remove unnecessary UI changes
* fix: Allow all team members to see hidden fields instead of just admins
- Replace isTeamAdmin with isTeamMember in booking view permissions
- Rename isLoggedInUserTeamAdmin to isLoggedInUserTeamMember for clarity
- All team members can now view hidden fields and UTM tracking data
Addresses feedback from @hariombalhara to allow all team members (not just admins) to see hidden booking data.
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* fix: Correct import path for isTeamMember function
- Change import from non-existent @calcom/lib/server/queries/teams
- Use correct path @calcom/features/ee/teams/lib/queries
- Fixes type check error: Cannot find module
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* refactor: Optimize isTeamMember check to call function only once
- Extract teamId using nullish coalescing operator
- Single isTeamMember call instead of two
- Cleaner and more efficient logic
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* simplify
---------
Co-authored-by: naaa760 <neh6a683@gmail.com>
Co-authored-by: neha <neha@posthog.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2025-10-31 12:05:02 +00:00
Eunjae LeeGitHubeunjae@cal.com <hey@eunjae.dev>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat: implement booking calendar view with weekly layout
- Create reusable WeekCalendarView component that displays bookings in a weekly calendar format
- Replace EmptyScreen in BookingsCalendar with the new calendar view
- Calendar view includes:
- Week navigation with Today, Previous, and Next buttons
- 7-day week view with time slots from 12 AM to 11 PM
- Bookings displayed as colored blocks positioned by time
- Support for event type colors and status-based colors
- Responsive design that fills the viewport
- Hover tooltips showing booking details
- Filters remain functional at the top of the view
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor: use existing Calendar component from weeklyview
- Replace custom calendar implementation with the existing Calendar component
- Use parseEventTypeColor to properly handle event type colors
- Simplify implementation by leveraging existing calendar infrastructure
- Maintain week navigation and filtering functionality
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix imports
* fix: replace isSameOrAfter with isAfter || isSame
- isSameOrAfter method does not exist in dayjs
- Use combination of isAfter and isSame instead
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* remove useBookerTime dependency from weekly calendar view
* modify date range filters
* initial callback
* sort events
* clean up FilterBar
* add showBackgroundPattern
* update styles
* update style
* update styles
* fix type error
* fix error
* update styles
* update styles
* update event colors
* rename component
* persist weekStart on the url
* use FilterBar
* apply feedback
* extract BorderColor type
* use client
* clean up
* adjust styles
* color-code events
* rename borderColor to color
* restore class name
* add feature flag
* update class name
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
- Add seatsPerTimeSlot field to EventType selection in bookings query
- Refactor conditional array pushes to use if statements instead of && operator to fix lint warnings
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* chore: BookingHydrationService - generate calendarEvent without PII
* chore: wip add build calendarEvent from booking in CalEventBuilder
* chore: build calendar event from booking
* remove hydration service
* test: add comprehensive test for CalendarEventBuilder.fromBooking with all properties
- Add vi.mock() calls for external dependencies (getBookerBaseUrl, getTranslation, getCalEventResponses)
- Add comprehensive test 'should create a complete calendar event with all properties using a booking'
- Test covers team scheduling, video calls, seats/webinar, recurring events, custom fields, and all configuration flags
- Fix import paths in CalendarEventBuilder.ts to use @calcom/features prefix
- Fix timestamp format issues in existing tests to use toISOString()
- Fix destinationCalendar length expectations to account for user calendar
- Fix responses format in seats tests to match bookingResponsesSchema
Co-Authored-By: morgan@cal.com <morgan@cal.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2025-10-31 07:31:50 +00:00
Alex van AndelGitHubDevin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
When BOOKING_LOGGING_EVENT_IDS is set to an empty string, the current
implementation splits it into [''] and Number('') returns 0, causing
any event type with ID 0 to incorrectly trigger debug logging.
This fix:
- Filters out empty/invalid event IDs (NaN, <=0)
- Filters out empty usernames
- Only matches valid, positive event type IDs
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* refactor: move org admin related logic to org server
* fix: update cancellation logic to make sure org admin can cancel seated bookings of a team user
* fix: import path
* update bookings repository
* fix: update reschedule endpoint logic to let org admin reschedule bookings for a user
* refactor: make logic more simple
* chore: update platform libraries
* more refactors
* fix: add check to make sure org admin can reschedule booking
* chore: remove unused comments
* test: add e2e tests for org admin reschedule and cancel seated bookings
- Add seated event type creation for testing
- Add test for org admin rescheduling a seated booking for a managed user
- Add test for org admin canceling a full seated booking for a managed user
- Add test for org admin canceling a specific seat in a seated booking
These tests verify the functionality added in PR #24640 which allows
org admins to reschedule and cancel seated bookings for users in their
organization.
Co-Authored-By: rajiv@cal.com <sahalrajiv6900@gmail.com>
* chore: add cubic feedback
* fix: tests for seated booking management by org admin
* chore: implement PR feedback
* fixup
* chore: update docs
* fixup: get optional user from request and then pass it down to getBookingForReschedule
* fix: validate seatUid before checking booking cancellation status
Move canRescheduleBooking call to happen after input validation
(including seatUid validation for seated bookings) but before the
actual booking creation. This ensures that when trying to reschedule
a seated booking without providing seatUid, users get the proper
'seatUid required' error instead of 'booking has been cancelled' error.
Fixes failing e2e test: 'should not be able to reschedule seated
booking if seatUid is not provided'
Co-Authored-By: rajiv@cal.com <sahalrajiv6900@gmail.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2025-10-30 16:43:05 +02:00
Eunjae LeeGitHubeunjae@cal.com <hey@eunjae.dev>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Joe Au-YeungGitHubjoe@cal.com <j.auyeung419@gmail.com>joe@cal.com <j.auyeung419@gmail.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix: use highest role for org admins accessing sub team event types
When an org admin who is also a member of a sub team (but only as MEMBER role) tries to update a sub team event type, they were being denied access. This was because the permission check logic was using the team MEMBER role instead of checking both team and org roles and using the highest one.
This fix updates PermissionCheckService.checkPermission() and checkPermissions() to use the highest role between team membership and org membership, similar to how getEventTypePermissions() already works.
Changes:
- Added getHighestRole() helper method to determine the highest role between two roles
- Updated checkPermission() to check both team and org membership and use the highest role
- Updated checkPermissions() to use the same logic
- Added test case for org admin who is team member updating sub team event type
Fixes the issue where org admins get 'permission required eventType.update' errors when updating sub team event types.
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* test: add PBAC-enabled test case for org admin accessing sub team event types
Adds a test case to verify that when PBAC is enabled, org admins who are also members of a sub team (but only with MEMBER role) can still access sub team event types through their org-level ADMIN permissions.
This complements the existing fallback (PBAC disabled) test case and ensures both code paths handle org admin permissions correctly.
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
## What does this PR do?
Currently we load /event-types for a few seconds while the onboarding hook catches up. This adds that logic to the serverside and not just client side to ensure onboarding is triggered
Adds server-side onboarding redirect checks to prevent users from accessing event types pages before completing onboarding. This implementation:
- Creates a new `checkOnboardingRedirect` utility function in a dedicated file
- Applies the redirect check on both the root page and event-types page
- Optimizes performance by using organizationId from session when available
- Handles email verification requirements before redirecting to onboarding
- Supports both legacy and v3 onboarding paths based on feature flags
## How should this be tested?
- Create a new user account that hasn't completed onboarding
- Attempt to access the root page or event-types page directly
- Verify you're redirected to the appropriate onboarding flow
- Test with email verification feature flag enabled/disabled
- Test with onboarding-v3 feature flag enabled/disabled
- Verify users who have completed onboarding can access event-types normally
- Verify organization users aren't redirected to onboarding
## Video Demo
Before:
[CleanShot 2025-10-30 at 10.54.41.mp4 <span class="graphite__hidden">(uploaded via Graphite)</span> <img class="graphite__hidden" src="https://app.graphite.dev/user-attachments/thumbnails/8282decc-a00d-4bc8-9215-fe1c4809fd8f.mp4" />](https://app.graphite.dev/user-attachments/video/8282decc-a00d-4bc8-9215-fe1c4809fd8f.mp4)
After
## [CleanShot 2025-10-30 at 10.54.06.mp4 <span class="graphite__hidden">(uploaded via Graphite)</span> <img class="graphite__hidden" src="https://app.graphite.dev/user-attachments/thumbnails/2acc7601-6c8c-496a-af4d-08dadef9aa2d.mp4" />](https://app.graphite.dev/user-attachments/video/2acc7601-6c8c-496a-af4d-08dadef9aa2d.mp4)
## Checklist
- [x] I have self-reviewed the code
- [x] I have updated the developer docs in /docs if this PR makes changes that would require a documentation change
- [x] I confirm automated tests are in place that prove my fix is effective or that my feature works
* fixed : Optimized Slots setting not updating on children event types
* updated tests to expect showOptimizedSlots sync
* fixed : Optimized Slots setting not updating on children event types
---------
Co-authored-by: Devanshu Sharma <devanshusharma658@gmail.com>
Co-authored-by: Alex van Andel <me@alexvanandel.com>
* fix: Modified teamName to be null when host is not fixed
* feat: Added test cases for round robin bookings reassignment with fixed and non-fixed hosts
* feat: improve team name handling in round robin reassignment
* refactor: improve booking title validation in reassignment tests
* feat: add bookingRequiresAuthentication validation to 2024-04-15 booking controller
- Add checkBookingRequiresAuthentication method to validate authentication requirements
- Check if user is event type owner, host, team admin/owner, or org admin/owner
- Add comprehensive e2e tests for bookingRequiresAuthentication feature
- Ensure parity with 2024-08-13 controller implementation
- Fix type issue in setPlatformAttendeesEmails method
Co-Authored-By: morgan@cal.com <morgan@cal.com>
* refactor: move Prisma calls to repository pattern
- Add findByIdIncludeHostsAndTeamMembers method to EventTypeRepository
- Inject PrismaEventTypeRepository and PrismaTeamRepository into controller
- Replace direct Prisma calls with repository methods in checkBookingRequiresAuthentication
- Use getTeamByIdIfUserIsAdmin for org admin/owner check
- Add repositories to BookingsModule_2024_04_15 providers
Co-Authored-By: morgan@cal.com <morgan@cal.com>
* handle httpException in handleBookingErrors
* test: add test case for authenticated but unauthorized user booking
- Create second user who is not authorized to book the event type
- Verify that authenticated user without proper permissions receives 403 Forbidden
- Test validates that bookingRequiresAuthentication properly checks authorization levels
- Cleanup unauthorized user in afterAll hook
Co-Authored-By: morgan@cal.com <morgan@cal.com>
* fix: add accepted filter to team members and handle org-owned event types
Addresses PR comments from cubic-dev-ai and @ThyMinimalDev:
1. Add accepted: true filter to team.members query
- Prevents pending team invitations from being treated as authorized
- Also filter by role to only fetch ADMIN and OWNER roles
- Reduces payload size and improves query performance
2. Add isOrganization field to team select
- Enables proper handling of org-owned event types
3. Update authorization logic for org-owned event types
- Handle case where team.isOrganization is true with no parent
- Ensure org admins/owners are properly authorized for org-owned events
- Matches behavior of 2024-08-13 controller
Changes:
- packages/features/eventtypes/repositories/eventTypeRepository.ts:
* Add where clause to members query with accepted: true and role filter
* Add isOrganization: true to team select
- apps/api/v2/src/ee/bookings/2024-04-15/controllers/bookings.controller.ts:
* Update authorization logic to handle org-owned event types
* Check if team.isOrganization is true when no parentId exists
Co-Authored-By: morgan@cal.com <morgan@cal.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix: prevent base64 logo/banner storage in organization onboarding
- Add processOnboardingBrandAssets helper method to BaseOnboardingService
- Process base64 images and upload them before storing in database
- Use uploadAvatar with userId to avoid foreign key issues before Team exists
- Handle both create and update/resume flows
- Ensure OrganizationOnboarding and Team records store regular URLs not base64
- Fixes header size issues when logoUrl is added to session cookies
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* fix: use processed URLs from OrganizationOnboarding record
- Update SelfHostedOnboardingService to use organizationOnboarding.logo/bannerUrl instead of raw input
- Update BillingEnabledOrgOnboardingService payment intent to use processed URLs
- Ensures Team records receive processed URLs, not base64 data
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* refactor: remove unused variables and imports
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* refactor: extract image processing to helper method and add tests
- Created private processImageField() method to eliminate code duplication
- Uses regex for more robust data URI and URL detection
- Processes logo and bannerUrl in parallel with Promise.all
- Added 2 important tests for base64 image processing:
1. Verifies base64 conversion with correct resize options (bannerUrl uses maxSize: 1500)
2. Validates undefined vs null semantics (no-op vs explicit clear)
- Fixed pre-existing lint warnings by replacing 'any' types with proper types
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* Improve code
* Fixup organizationId
* simplify
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Alex van Andel <me@alexvanandel.com>
* chore: Adding indexes for user delete cascade
* Add comments to indicate a partial index has been added on a field
---------
Co-authored-by: Morgan <33722304+ThyMinimalDev@users.noreply.github.com>
2025-10-28 22:28:40 +00:00
Joe Au-YeungGitHubjoe@cal.com <j.auyeung419@gmail.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>Udit Takkar
* Add critical logger for booking created log to prevent stdout buffering issues
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* Add comment
* Separate critialLogger into it's own file
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Udit Takkar <53316345+Udit-takkar@users.noreply.github.com>
## What does this PR do?
- Redirects users to the personal settings page after organization creation instead of the getting-started page
- Adds a new `skipToPersonal` function in `useSubmitOnboarding` hook to handle this redirection
- Creates a new `getGettingStartedPathWhenInvited` method in `OnboardingPathService` to provide the correct path for invited users
- Updates all invitation-related code to use the new path method
- Improves UI spacing in the organization invite view
## Visual Demo (For contributors especially)
#### Image Demo (if applicable):
- Before: Users were redirected to `/onboarding/getting-started` or `/getting-started` after organization creation
- After: Users are now redirected to `/onboarding/personal/settings` or `/getting-started` based on feature flag
## Mandatory Tasks (DO NOT REMOVE)
- [ ] I have self-reviewed the code.
- [ ] I have updated the developer docs in /docs if this PR makes changes that would require a documentation change. If N/A, write N/A here and check the checkbox.
- [ ] I confirm automated tests are in place that prove my fix is effective or that my feature works.
## How should this be tested?
1. Create a new organization through the onboarding flow
2. Verify you are redirected to the personal settings page instead of getting-started
3. Accept an invitation to an organization as a new user
4. Verify you are directed to the personal settings page after signup
5. Check that the UI spacing in the organization invite view looks correct
## Checklist
- I have read the [contributing guide](https://github.com/calcom/cal.com/blob/main/CONTRIBUTING.md)
- My code follows the style guidelines of this project
- I have commented my code, particularly in hard-to-understand areas
- I have checked if my changes generate no new warnings
2025-10-28 14:35:57 +00:00
Alex van AndelGitHubalex@cal.com <me@alexvanandel.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>sean-brydon
* chore: Adds a users.uuid column
* Add uuid backfill
* Remove backfill due to possible locking issues
* feat: Add batched UUID backfill to prevent database locking
Implements a batched approach for backfilling UUIDs on existing users:
- Processes 1000 rows at a time to avoid table locks
- Uses FOR UPDATE SKIP LOCKED to prevent blocking other transactions
- Includes small delays between batches (10ms) to allow other operations
- Logs progress every 10,000 rows for monitoring
This approach is safe for production databases with millions of users.
Co-Authored-By: alex@cal.com <me@alexvanandel.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: sean-brydon <55134778+sean-brydon@users.noreply.github.com>
2025-10-28 09:17:54 -03:00
devin-ai-integration[bot]GitHubmorgan@cal.com <morgan@cal.com>morgan@cal.com <morgan@cal.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>morgan@cal.com <morgan@cal.com>Morgan
* feat: update Office365 getMainTimeZone to handle new Graph API format and convert Windows timezones to IANA
- Handle new Graph API response format with 'value' field containing Windows timezone names
- Add windows-iana dependency for timezone conversion from Windows to IANA format
- Maintain backward compatibility with legacy direct string response format
- Add proper error handling with fallback to original timezone name if conversion fails
- Log conversion details for debugging and monitoring
Co-Authored-By: morgan@cal.com <morgan@cal.com>
* fix: example app select default value
* fixup! fix: example app select default value
* fix: preserve legacy string timezone behavior, only convert new object format
- Address GitHub comments from supalarry about behavior change concerns
- Preserve original behavior: return legacy string responses as-is without conversion
- Only convert Windows timezones from new Graph API object format
- Add explanatory comments about API format evolution
- Restructure conditional logic to handle formats independently
Co-Authored-By: morgan@cal.com <morgan@cal.com>
* trigger CI with ready-for-e2e label
Co-Authored-By: morgan@cal.com <morgan@cal.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: morgan@cal.com <morgan@cal.com>
Co-authored-by: Morgan <33722304+ThyMinimalDev@users.noreply.github.com>