* fix(companion): separate dev and prod build scripts to prevent localhost in production
- Add ext:build-dev and ext:build-prod scripts with clear separation
- Add BUILD_FOR_STORE flag to force production URL in store builds
- Add visual build indicators (store / dev) for clarity
- Prevent EXPO_PUBLIC_COMPANION_DEV_URL from leaking into production builds
* update commands to work for ci
* update version
---------
Co-authored-by: Volnei Munhoz <volnei@cal.com>
- Add CalComPageStatus handling in NotFound and ErrorPage components using useLayoutEffect
- Remove redundant pageStatus logic from PageWrapperAppDir.tsx since App Router error/notFound pages set status themselves
- Refactor embed-iframe.ts: split checkPageStatusAndHandleError into hasPageError() and handlePageError()
- Add page status checks before firing linkReady to catch errors set after initialization
- Ensures linkFailed event fires correctly for all error status codes in embed scenarios
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat(booking-audit): extract core audit system changes from PR 25125
This PR extracts core audit infrastructure changes without integration changes:
1. New action services introduced:
- SeatBookedAuditActionService
- SeatRescheduledAuditActionService
2. Simplification of ActionService interface:
- Streamlined IAuditActionService interface
- Reduced TypeScript burden with cleaner type definitions
3. ActionSource support:
- Added BookingAuditSource enum (API_V1, API_V2, WEBAPP, WEBHOOK, UNKNOWN)
- Added source and operationId fields to BookingAudit model
4. New AuditAction types:
- SEAT_BOOKED
- SEAT_RESCHEDULED
- APP actor type
5. New BookingAuditAccessService:
- Permission-based access control for audit logs
- Added readTeamAuditLogs and readOrgAuditLogs permissions
6. Fixes in the logs viewer flow:
- Enhanced BookingAuditViewerService with improved filtering
- Local AttendeeRepository for actor enrichment
Changes are contained within packages/features/booking-audit with minimal
outside changes (permission registry only).
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* refactor(booking-audit): streamline action handling and enhance localization
- Replaced action icon retrieval with a mapping object for improved clarity and performance.
- Introduced constants for actor role labels to simplify role retrieval.
- Added new localization strings for audit log permission errors and organization requirements.
- Updated various service and repository interfaces to enhance type safety and clarity.
- Removed deprecated architecture documentation and adjusted related imports for consistency.
These changes aim to improve code maintainability and user experience in the booking audit system.
* fix(booking-audit): enhance actor role localization and operation ID tracking
- Updated actor role labels in the booking logs view to use lowercase for consistency.
- Improved localization by wrapping actor role display in a translation function.
- Added operationId field to audit logs for better correlation of actions across multiple bookings.
- Enhanced BookingAuditViewerService to include operationId in enriched audit logs.
- Updated integration tests to verify consistent operationId across related audit logs.
These changes aim to improve localization accuracy and facilitate better tracking of user actions in the booking audit system.
* feat: integrate credential repository and enhance app actor handling
- Added CredentialRepository to manage app credentials, including a method to find credentials by ID.
- Updated BookingAudit system to support app actors identified by credential ID, improving actor attribution and audit clarity.
- Introduced a new utility function to map app slugs to display names, enhancing the user experience in audit logs.
- Modified relevant interfaces and types to accommodate the new credential handling and app actor structure.
- Enhanced BookingAuditViewerService to display app names based on credentials, ensuring accurate representation in audit logs.
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix: allow required check to pass when E2E tests are skipped due to missing label
Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com>
* revert: remove unnecessary integration-test condition change
Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com>
* chore: trigger fresh CI run
Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com>
* all should pass to allow merge
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2025-12-18 08:49:12 -03:00
Eunjae LeeGitHubeunjae@cal.com <hey@eunjae.dev>eunjae@cal.com <hey@eunjae.dev>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat: add enabled column to UserFeatures and TeamFeatures for tri-state semantics
- Add enabled Boolean column to UserFeatures model with default true
- Add enabled Boolean column to TeamFeatures model with default true
- Update FeaturesRepository to use tri-state semantics:
- enabled=true: feature is explicitly enabled
- enabled=false: feature is explicitly disabled (blocks inheritance)
- No row: inherit from team/org level
- Update SQL queries to check enabled=true for feature access
- Add enableFeatureForTeam method to interface and implementation
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* update comments
* add integration tests
* add more test
* select enabled only
* no @default(true)
* fix types and tests
* add missing enabled
* add missing enabled
* rename enableFeatureForTeam to updateFeatureForTeam and support FeatureState
* refactor: rename updateFeatureForTeam to setTeamFeatureState
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix integration test
* fix tests
* add more tests
* add missing enabled
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* add webhook version schema
* version the code
* update version from numeric to date val
* migration
* update schema and build factory
* update string
* move version picker
* tooltip instead of infobadge
* --
* fix type
* --
* fix type
* fix type
* --
* fix messed up merge
* improvements to payloadfactory
* extract version off of DB and instead keep it in IWebhookRepository
* fix webhookform
* fix type safety and routing ambiguity
* scalable with easier factory extensions and base definition
* fix types
* --
* --
* clean up prisma/client type imports
* fix
* type fix
* type fix
* cleanup
* add tests and registry changes
* unintended file inclusion
* type-fix
* select in repo
* --
* explicit return type
* --
* fix type
* fixes
* feedback 1
* feedback 2
* use enum instead of string
* fixes
* Isolate companion build
* Fix typo
* Update .github/workflows/pr.yml
* Improve branch protection
* integration tests missing
* fix typo
* fix to only have required
* fix to only have required
* fix to only have required
* adjust to keep as before
---------
Co-authored-by: Peer Richelsen <peeroke@gmail.com>
* chore: Change atoms build command to build-npm to avoid turbo compilations
* Updated turbo.json atoms#build reference
* Updated atoms production build for CI
* fix: prevent Prisma conditional types from leaking into .d.ts files
This PR addresses TypeScript performance issues caused by Prisma's conditional types leaking through the type graph:
1. Replace Prisma.UserGetPayload with explicit UpdatedUserResult type in updateProfile.handler.ts
2. Replace Prisma.EventTypeGetPayload with explicit UpdatedEventTypeResult type in update.handler.ts
3. Replace Prisma.OutOfOfficeEntryGetPayload with explicit OOOEntryResult type in outOfOfficeCreateOrUpdate.handler.ts
4. Replace Prisma.CredentialGetPayload with explicit Credential type in getUserConnectedApps.handler.ts
5. Fix inconsistent DI usage in EventTypeRepository - use this.prismaClient instead of global prisma singleton
These changes prevent massive recursive Prisma types from propagating through the type graph and being emitted in .d.ts files, which improves TypeScript performance.
Co-Authored-By: keith@cal.com <keithwillcode@gmail.com>
* fix: correct reasonId type to number | null in OOOEntryResult
Co-Authored-By: keith@cal.com <keithwillcode@gmail.com>
* perf: add z.ZodType annotations to reduce .d.ts file sizes
- Annotate exported Zod schemas with z.ZodType<T> to prevent full Zod generic tree from being emitted in declaration files
- eventTypes/types.d.ts reduced from 231KB to 115KB (50% reduction)
- _app.d.ts reduced from 782KB to 753KB (3.7% reduction)
- viewer/_router.d.ts reduced from 722KB to 695KB (3.7% reduction)
- workflows/getAllActiveWorkflows.schema.d.ts significantly reduced
- routing-forms/formMutation.schema.d.ts significantly reduced
Files modified:
- packages/trpc/server/routers/viewer/eventTypes/types.ts
- packages/trpc/server/routers/viewer/workflows/getAllActiveWorkflows.schema.ts
- packages/trpc/server/routers/apps/routing-forms/formMutation.schema.ts
- packages/features/eventtypes/lib/types.ts
Co-Authored-By: keith@cal.com <keithwillcode@gmail.com>
* perf: comprehensive z.ZodType annotations to reduce .d.ts file sizes
Applied z.ZodType<T> annotations to 89 schema files across the tRPC package.
This prevents TypeScript from emitting the full Zod generic tree in .d.ts files,
reducing declaration file sizes for downstream consumers.
Files modified include schemas in:
- viewer/teams (round-robin, managed events, invitations, etc.)
- viewer/bookings (get, find, confirm, etc.)
- viewer/eventTypes (get, delete, getByViewer, etc.)
- viewer/workflows (list, delete, verify, etc.)
- viewer/auth (changePassword, verifyPassword, etc.)
- viewer/apiKeys (create, delete, edit, etc.)
- viewer/sso (get, update, delete, updateOIDC)
- viewer/oAuth (addClient, generateAuthCode)
- viewer/calendars (setDestinationCalendar)
- viewer/deploymentSetup (update, validateLicense)
- apps/routing-forms (formQuery, deleteForm, etc.)
- publicViewer (submitRating, markHostAsNoShow, etc.)
- loggedInViewer (eventTypeOrder, routingFormOrder, etc.)
Co-Authored-By: keith@cal.com <keithwillcode@gmail.com>
* fix: revert slots/types.ts z.ZodType annotation that caused type mismatch
The slots/types.ts schema has a transform that converts duration from
string to number, which makes the z.ZodType<T> annotation incompatible.
Reverting to original to fix Unit test failure.
Co-Authored-By: keith@cal.com <keithwillcode@gmail.com>
* fix: use 3-generic z.ZodType pattern for schemas with .default() modifiers
For schemas with .default() modifiers, the input and output types differ:
- Input type: field is optional (what callers send)
- Output type: field is required (what handlers receive after parsing)
This commit:
1. Fixes get.schema.ts (offset has .default(0))
2. Fixes removeMember.schema.ts (isOrg has .default(false))
3. Fixes resendInvitation.schema.ts (isOrg has .default(false))
4. Fixes listMembers.schema.ts (limit has .default(10))
5. Fixes getByViewer.schema.ts (limit has .default(10))
6. Reverts eventTypes/types.ts (complex transforms hard to model)
7. Reverts features/eventtypes/lib/types.ts (complex transforms hard to model)
The 3-generic pattern z.ZodType<Output, z.ZodTypeDef, Input> properly models
the difference between input and output types while still preventing the full
Zod generic tree from being emitted in .d.ts files.
Co-Authored-By: keith@cal.com <keithwillcode@gmail.com>
* fix: use 3-generic z.ZodType pattern for schemas with transforms/defaults
- organizations/update.schema.ts: orgId has .transform() that converts string to number, so input type is string | number but output type is number
- publicViewer/event.schema.ts: fromRedirectOfNonOrgLink has .default(false), so input has it optional but output has it required
Co-Authored-By: keith@cal.com <keithwillcode@gmail.com>
* fix: use 3-generic z.ZodType pattern for updateProfile.schema.ts
Address reviewer feedback: isDeleted field in secondaryEmails has .default(false),
so input type has it optional but output type has it required.
Co-Authored-By: keith@cal.com <keithwillcode@gmail.com>
* chore: remove explanatory comments from schema files
Co-Authored-By: keith@cal.com <keithwillcode@gmail.com>
* fix: use 3-generic z.ZodType pattern for addClient.schema.ts enablePkce field
Co-Authored-By: keith@cal.com <keithwillcode@gmail.com>
* fix: address Hariom's PR feedback
- Rename TGetInputSchemaInput to TGetInputRawSchema in get.schema.ts
- Use Prisma-free JsonValue type from @calcom/types/Json in updateProfile.handler.ts
- Fix publish.schema.ts with 3-generic pattern for z.coerce.number()
Co-Authored-By: keith@cal.com <keithwillcode@gmail.com>
* fix: add sort field to TGetInputSchema types
Added sort field to both TGetInputRawSchema and TGetInputSchema types
to match the Zod schema that was updated in main branch.
Co-Authored-By: keith@cal.com <keithwillcode@gmail.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Hey team,
[**Lingo.dev**](https://lingo.dev) here with fresh translations!
### In this update
- Added missing translations
- Performed brand voice, context and glossary checks
- Enhanced translations using Lingo.dev Localization Engine
### Next Steps
- [x] Review the changes
- [x] Merge when ready
* chore: update dependencies and update event types screen header
* refactor: simplify EventTypeListItem component by removing unused imports and code
- Removed unnecessary imports such as Tooltip and Svg.
- Cleaned up the component by eliminating commented-out code and unused props.
- Streamlined the button rendering in the context menu for better readability.
* feat: enhance EventTypes header with blur effect and clean up code
- Added blurEffect property to Stack.Header for improved visual aesthetics.
- Removed commented-out code to streamline the EventTypes component.
- Updated search bar properties for better user experience.
* refactor: update TabLayout and EventTypes for improved platform handling
- Simplified TabLayout by removing the liquid glass effect check and adding a WebTabs fallback for web support.
- Updated EventTypes header to conditionally apply blur effect based on liquid glass availability, enhancing visual consistency across platforms.
* feat: enhance TabLayout with MaterialCommunityIcons for improved UI
- Updated TabLayout to use MaterialCommunityIcons for tab icons, enhancing visual consistency.
- Added softwareKeyboardLayoutMode to app.json for better keyboard handling on mobile devices.
* feat: update TabLayout to prevent transparent background on iOS 18
- Added disableTransparentOnScrollEdge prop to NativeTabs to ensure a solid background on iOS 18 and older versions.
2025-12-17 15:37:52 +00:00
Anik Dhabal BabuGitHubDevin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
The event type description is stored as HTML from the rich text editor.
When converting to plain text for calendar events, the HTML tags were
being stripped without preserving the formatting, causing:
- Newlines to be lost (text runs together)
- Links to be broken
This fix:
- Converts <br>, </p>, </div>, </li>, </h1-6> tags to newlines
- Preserves links in readable format: 'text (url)' or just 'url'
- Normalizes multiple newlines to max 2 for cleaner output
Affects all calendar integrations (Google, Outlook, etc.)
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* refactor(data-table): clean up DateRangeFilter range options
- Replace 'past' | 'custom' with 'past' | 'future' | 'any' | 'customOnly'
- Add direction field to PresetOption for preset compatibility filtering
- Derive presets visibility automatically based on compatible presets
- Update bookings list to use new range values:
- past -> 'past'
- upcoming -> 'future'
- unconfirmed/recurring/cancelled -> 'any'
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* feat(playground): add DateRangeFilter playground page with E2E tests
- Add playground page at /settings/admin/playground/date-range-filter
- Demonstrate all 4 range options: past, future, any, customOnly
- Add link to playground index page
- Add E2E tests for presets visibility and date restrictions
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix(playground): use correct meta.filter pattern for column filter config
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* clean up the playground esign
* add unit tests instead of e2e
* fix the implementation
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat(bookings): conditionally show heading/subtitle based on view
- Add heading and subtitle props back to ShellMainAppDir in page.tsx
- Use headerClassName marker to identify the heading element
- Add useLayoutEffect in BookingCalendarContainer to hide heading when calendar view is mounted
- Restore heading visibility when switching back to list view
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor(bookings): extract shell heading visibility into reusable hook
- Create useBookingsShellHeadingVisibility hook with explicit visible parameter
- Move visibility logic from BookingCalendarContainer to BookingsContent
- Use data attribute to track if we hid the header (idempotent/Strict-Mode-safe)
- Explicit show/hide based on view state instead of relying on unmount
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor(bookings): simplify shell heading visibility hook
Remove HIDDEN_DATA_ATTR tracking since the header wrapper won't have
a hidden class from any other source
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat(companion): improve extension UX for new tab and fix mobile app issues
- Open cal.com/app when extension clicked on restricted pages (chrome://newtab, etc.)
- Auto-open sidebar when redirected to cal.com/app with ?openExtension=true
- Fix duplicate search bar in event types on web/extension
- Fix tab order mismatch on extension (Event Types, Bookings, Availability, More)
- Add logout confirmation modal for web since Alert.alert doesn't work
- Default COMPANION_DEV_URL to empty string for production builds
* fix(companion): use URL API for query parameter cleanup
Replace regex-based URL cleanup with URL API to properly handle
all query parameter positions. The previous regex produced invalid
URLs when openExtension=true was the first of multiple parameters
(e.g., ?openExtension=true&foo=bar became &foo=bar instead of ?foo=bar). fix(companion): wait for page load before auto-opening sidebar
Fix race condition where sidebar wouldn't auto-open on first visit
to cal.com/app. On uncached pages, now waits for the load event
before opening, while cached pages use a shorter delay.
* fix: update email validation to include pm.me domain and improve error handling in extractDomainFromEmail function
* feat(organizations): add pm.me and additional personal email domains
- Add pm.me (ProtonMail short domain) to personal email providers list
- Add googlemail.com, ymail.com, msn.com, mac.com, and other common personal email domains
- Add Mail.com variants (email.com, post.com, consultant.com, etc.)
- Add protonmail.ch, gmx.de, naver.com, and other regional providers
- Update all three locations: utils.ts, orgCreationUtils.ts, and test file
- Fix ESLint warnings for unnecessary escape characters in regex
* fix: allow organizations to sign up with existing usernames
- Update usernameCheck to check organization context when currentOrgDomain is provided
- Organizations can now use usernames that exist in other orgs or global namespace
- Only checks username availability within the specific organization
- Fixes issue where org signups were blocked by global username conflicts
Refs #25800
* Update username.ts
* chore: replace GH_ACCESS_TOKEN with GitHub App token
Replace personal access token (GH_ACCESS_TOKEN) with GitHub App token
generation using actions/create-github-app-token@v1 for improved security.
Updated workflows:
- draft-release.yml
- post-release.yml
- cleanup.yml
- cleanup-report.yml
- publish-report.yml
- i18n.yml
Benefits:
- Short-lived tokens (1 hour) vs long-lived PATs
- Fine-grained, scoped permissions
- Not tied to individual user accounts
- Better audit trail
Required setup:
- Create a GitHub App with contents:write permission
- Install the app on calcom/cal.com and calcom/test-results-2
- Add RELEASE_APP_ID and RELEASE_APP_PRIVATE_KEY secrets
Co-Authored-By: alex@cal.com <me@alexvanandel.com>
* chore: rename secrets to CI_CAL_APP_ID and CI_CAL_APP_PRIVATE_KEY
Co-Authored-By: alex@cal.com <me@alexvanandel.com>
* chore: use reusable workflow from calcom-ci-secrets for token generation
This isolates the GitHub App private key in a separate repository,
ensuring that compromised actions in cal.com can only access short-lived
tokens, not the key itself.
Co-Authored-By: alex@cal.com <me@alexvanandel.com>
* chore: use explicit secret passing instead of secrets: inherit
Only pass the two required secrets (CI_CAL_APP_ID, CI_CAL_APP_PRIVATE_KEY)
to the reusable workflow instead of inheriting all secrets.
Co-Authored-By: alex@cal.com <me@alexvanandel.com>
* chore: remove secrets block - using environment secrets from calcom-ci-secrets
Secrets are now loaded from the ci-github-app environment in
calcom-ci-secrets, so cal.com workflows no longer need to pass them.
Co-Authored-By: alex@cal.com <me@alexvanandel.com>
* chore: revert to explicit secret passing
Environment secrets in cross-repo reusable workflows don't work as expected.
Secrets must be passed explicitly from the caller repository.
Co-Authored-By: alex@cal.com <me@alexvanandel.com>
* chore: generate GitHub App token directly in workflows
Remove dependency on calcom-ci-secrets reusable workflow.
Token generation is now inline using actions/create-github-app-token
pinned to SHA 7e473efe3cb98aa54f8d4bac15400b15fad77d94 (v2.2.0).
Co-Authored-By: alex@cal.com <me@alexvanandel.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Anik Dhabal Babu <81948346+anikdhabal@users.noreply.github.com>