* refactor: replace isTeamAdminOrOwner with PBAC team.listMembers permission
- Add canListMembers prop to BookingsProps interface
- Implement server-side permission check using PermissionCheckService
- Handle organization vs team context as specified
- Use ADMIN/OWNER fallback roles for backward compatibility
- Replace user?.isTeamAdminOrOwner check in bookings column filter
- Fix React Hook dependency arrays for ESLint compliance
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor: wrap canListMembers in permissions object and simplify server logic
- Wrap canListMembers in permissions object for future extensibility
- Simplify server-side logic to only use getTeamIdsWithPermission
- Remove unused imports (prisma, MembershipRole)
- Address user feedback on PR #24006
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* docs: add comment explaining canListMembers UI logic
- Clarify that teamIdsWithPermission.length > 0 check is for UI purposes
- Actual accurate filtering happens server-side for filter values
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* feat: add e2e test for member filter visibility
- Verify that users with the MEMBER role cannot see the member filter
- Test creates team with ADMIN and MEMBER users
- Confirms UI correctly reflects PBAC permissions
- Address user feedback on PR #24006
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: correct e2e test team member creation pattern
- Replace invalid teamId property with hasTeam and teammates pattern
- Fix TypeScript error in booking-filters.e2e.ts
- Resolve CI type check failure
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix e2e test
* remove booking.read permission from member
* add guide
* update
* resource scope
* fix markdown
* update usage
* update guide
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: sean-brydon <55134778+sean-brydon@users.noreply.github.com>
* feat: add availability and ooo permissions to PBAC registry
- Add Availability and OutOfOffice resources to Resource enum
- Add CRUD permissions for both resources with empty scope arrays
- Create migration to seed admin_role with all CRUD permissions
- Create migration to seed member_role with read-only permissions
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* feat: add i18n entries for availability and ooo permissions
- Add pbac_resource_availability and pbac_resource_out_of_office resource names
- Add description entries for all CRUD operations on both resources
- Follow existing PBAC i18n pattern for consistency
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat: add fallbackRoles parameter to getTeamIdsWithPermissions method
- Add fallbackRoles parameter to method signature in interface and implementation
- Implement second query for teams without PBAC where user has fallback roles
- Combine and deduplicate results from both PBAC-enabled and fallback role teams
- Supports fallback to role-based permissions when PBAC is disabled
- Fix linting issue in getUserMemberships method by replacing include with select
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix usages
* revert some change
* fix unit tests
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat: adds user plan info in `useHasPaidPlan` for intercom
* add to support api route
* Update constants.ts
* sql migration to backfill plans and create/change plans on upgrade/downgrade/create of teams and orgs
* fix: breaking unit tests
* test: add comprehensive tests for billing plan service and team/org flows
- Add unit tests for BillingPlanService.getUserPlanByMemberships() covering all plan determination scenarios
- Add tests for team creation handler verifying TEAMS vs ORGANIZATIONS plan assignment
- Add tests for hasTeamPlan handler integration with BillingPlanService
- Add tests for MembershipRepository.findAllMembershipsByUserIdForBilling() data fetching
- Add tests for InternalTeamBilling upgrade/downgrade flows with proper mocking
- All tests follow existing vitest patterns with proper Prisma and service mocking
- Covers both self-serve and platform billing scenarios with comprehensive edge cases
Co-Authored-By: amit@cal.com <samit91848@gmail.com>
* Revert "test: add comprehensive tests for billing plan service and team/org flows"
This reverts commit 58e511f15caf8757c3ec45f6d026caf96ee1a75e.
* fix: make `BillingPlanService` instantiable and use `TeamRepository`
* Revert "fix: make `BillingPlanService` instantiable and use `TeamRepository`"
This reverts commit ae1ff8f15b725566b828864a217d8d0e308b520f.
* revert to runtime calculations. review fixes
* remove uneccessary changes and logs
* review fixes
* review fixes
* fix: type check
---------
Co-authored-by: Keith Williams <keithwillcode@gmail.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* chore: use kysely types instead of prisma types in atoms
* fixup! chore: use kysely types instead of prisma types in atoms
* fixup! Merge branch 'main' into reduce-atoms-bundle-size-prisma-types
* fix: check if team is platform or not when sending billingPortalUrl
* update team repository
* fix: pass teamId explicitely for platform team
* fix: coderabbit feedback
* fix: merge conflicts
* fix: merge conflicts
* fix: make sure we pass in the correct subsciption id
* fix: implement PR feedback
* refactor: replace isTeamAdminOrOwner with PBAC permissions
- Remove isTeamAdminOrOwner from team-members-view.tsx, rely on server-side permissions
- Replace role checks in addMembersToEventTypes.handler.ts with eventType.update permission
- Follow PBAC refactoring guide patterns for consistent permission checking
- Fix TypeScript any type usage and unused variable warnings
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* use enum
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* refactor: implement PBAC for team member listing
- Replace membership-based team filtering with getTeamIdsWithPermission
- Use team.listMembers permission for access control
- Maintain fallback to original logic when PBAC fails
- Add comprehensive PBAC refactoring guide for future use
Fixes team fetching logic to use Permission-Based Access Control
while preserving existing functionality and privacy checks.
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* docs: move PBAC refactoring guide to packages/features/pbac/
Move the PBAC refactoring guide to the appropriate location within
the PBAC feature package for better organization and discoverability.
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor: remove unnecessary try-catch wrapper
The getTeamIdsWithPermission method already handles all errors internally
and returns an empty array instead of throwing exceptions, making the
try-catch wrapper redundant. Simplified to use direct fallback logic
based on empty array return.
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor: simplify PBAC implementation
- Remove flawed fallback logic that assumed empty array meant PBAC failure
- Use direct string 'team.listMembers' instead of PermissionMapper
- Remove unused imports (PermissionMapper, Resource, CustomAction)
- Empty array from getTeamIdsWithPermission is legitimate (no permissions)
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* docs: simplify PBAC refactoring guide
- Reduce from 260 to 87 lines by removing bloated content
- Focus on core pattern: direct permission strings, no fallback logic
- Align with actual PR implementation
- Remove verbose theoretical sections and complex patterns
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* Fallback to org admin
* Prevent accidental privilege escalation as code changes in the future
* When org admin, we don't actually need to do the db query
* Use findMany and Map to drill down permission adjustments
* Exclude .MEMBER from overriding role, we likely don't want to demote
* refactor logic
* Add tests for services/factories + removeHandler
* fix type check
---------
Co-authored-by: Alex van Andel <me@alexvanandel.com>
Co-authored-by: Sean Brydon <sean@cal.com>
* feat: add createdAt and updatedAt fields to EventType model
- Add timestamp fields to EventType schema with backward compatibility
- Update all EventType select statements across API v1, v2, and tRPC
- Update platform API output types to include timestamp fields
- Generate migration for existing database records
- Fix test files to handle new timestamp fields properly
The timestamp fields are added as optional (DateTime?) to ensure backward
compatibility - existing EventType records will have null values for these
fields, while new records will automatically get timestamps.
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* fix: remove @default(now()) from EventType createdAt to prevent existing records from getting current timestamp
- Remove @default(now()) from createdAt field in schema to ensure backward compatibility
- Create migration that only drops DEFAULT constraint without updating existing records
- Existing EventType records will keep null timestamps
- New records will get timestamps via application logic
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* feat: add createdAt and updatedAt timestamps to all EventType creation locations
- Update all seed scripts to set timestamps for new EventType records
- Ensure consistency across all EventType creation patterns
- Maintain backward compatibility with nullable timestamp fields
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* feat: add timestamps to remaining EventType creation locations in test files
- Update integration test files to include createdAt and updatedAt
- Ensure consistency across all EventType creation patterns
- Complete comprehensive update of all EventType creation locations
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* add migration
* few left
* feat: implement Prisma extension for automatic EventType timestamps
- Create eventTypeTimestampsExtension to automatically set createdAt and updatedAt
- Handle both eventType.create and eventType.createMany operations
- Revert all manual timestamp setting from application code
- Extension only sets timestamps if not already provided
- Maintains backward compatibility - existing records keep null timestamps
- New records get automatic timestamps via Prisma extension
- Follows existing Cal.com extension patterns and architecture
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* feat: remove hardcoded timestamp settings from test files
- Remove manual createdAt/updatedAt settings from routing forms controller test
- Remove manual timestamp settings from event types repository fixture
- Prisma extension now handles timestamps automatically for all EventType operations
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* update
* Update event-type.output.ts
* fix test
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Udit Takkar <53316345+Udit-takkar@users.noreply.github.com>
* fix: skip select field validation for existing responses during reschedule
- Modify hasRequiredBookingFieldsResponses to detect reschedule context
- Skip validation for select, multiselect, checkbox, and radio fields during reschedule to preserve existing responses
- Fixes validation error when rescheduling bookings with select field responses that may no longer match current field options
Resolves issue where reschedule operations fail with 'Value Travel, Adventure & Wildlife is not valid for type select for field Niche-project' error
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* fix: skip frontend validation for existing select field responses during reschedule
- Revert backend changes in bookings.service.ts as the issue is frontend-only
- Add reschedule detection in getBookingResponsesSchema.ts preprocess function
- Skip option validation for select, radio, multiselect, and checkbox fields during reschedule
- Preserves existing booking responses that may no longer match current field options
- Fixes error 'Value Travel, Adventure & Wildlife is not valid for type select for field Niche-project' during slot selection
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* fix: extend reschedule validation skip to handle multiemail fields like guests
- Add reschedule-aware logic to multiemail validation in getBookingResponsesSchema.ts
- Skip validation for existing multiemail responses during reschedule to avoid type mismatch errors
- Fixes 'Value is not valid for type text for field guests' error during slot selection
- Complements existing fix for select/radio field validation during reschedule
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* fix: disable guests field inputs for seated events
- Disable type SelectField for guests field in seated events
- Disable identifier InputField for guests field in seated events
- Add validation to prevent saving guests field changes for seated events
- Pass seatsEnabled prop from EventAdvancedTab to FormBuilder
- Use condition: seatsEnabled && formFieldType === 'multiemail' && fieldForm.getValues('name') === 'guests'
- Fix linting warnings: remove unused variable and add missing dependency
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* Update getBookingResponsesSchema.ts
* Update FormBuilder.tsx
* Update FormBuilder.tsx
* update
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix: added block display to .cal-embed
* fixed the iframe color-scheme to unset and bg transparent
* removed forced CSS
* changes reverted from iframe
* Add comments and remove background transparent as it is still not needed
---------
Co-authored-by: Anik Dhabal Babu <81948346+anikdhabal@users.noreply.github.com>
Co-authored-by: Hariom Balhara <hariombalhara@gmail.com>
* fix: always check team.parentID even if no membership
* refactor permission handling in create event type handler
* remove hasMembership
---------
Co-authored-by: Morgan <33722304+ThyMinimalDev@users.noreply.github.com>
* manage billing section
* wip billing credits
* WIP
* WIP
* Download expense log
* credit worth
* skeleton fixes
* add org tip
* add teams tip
* restore service
* type check
* type check
* fix types
* additional credits
* fix progress bar
* add dashed prop
* match new designs
* hide area with no monthly credits
* fix i18n
* show current balance label
* Update apps/web/modules/settings/billing/billing-view.tsx
Co-authored-by: Carina Wollendorfer <30310907+CarinaWolli@users.noreply.github.com>
* spacing + monthly credits not showing additional
* Remove additional credits from monthly calculations
* feat: replace add members redirect with invite modal in billing settings
- Replace Button href with onClick handler to open MemberInvitationModal
- Add MemberInvitationModalWithoutMembers import and state management
- Maintain existing team/org context support
- Follow established modal usage patterns from other components
- Fix lint error by using undefined instead of empty arrow function
Co-Authored-By: sean@cal.com <Sean@brydon.io>
* Remove redudant vars from method
* fix type check
---------
Co-authored-by: Carina Wollendorfer <30310907+CarinaWolli@users.noreply.github.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2025-09-19 16:18:42 +00:00
Eunjae LeeGitHubeunjae@cal.com <hey@eunjae.dev>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat: add ISO timestamp columns to booking CSV exports
- Add createdAt_iso, startTime_iso, endTime_iso columns to getCsvData() method
- Use .toISOString() format for new columns: 2025-09-09T13:03:55+02:00
- Keep existing timestamp columns unchanged to avoid breaking changes
- Addresses user request for parseable timestamp format in CSV downloads
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* feat: add ISO timestamp columns to routing CSV exports
- Add ISO format columns for createdAt, bookingCreatedAt, bookingStartTime, bookingEndTime
- Preserve original timestamp format to avoid breaking changes
- Complete implementation for both /insights and /insights/routing pages
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* feat: replace ISO columns with timezone-aware date/time columns
- Replace _iso columns with separate _date and _time columns
- Use user timezone for proper date/time conversion
- Add timezone parameter to CSV export methods
- Maintain backward compatibility with original timestamp format
- Date format: YYYY-MM-DD, Time format: HH:mm:ss
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: resolve TypeScript type compatibility issues
- Fix WhereForTeamOrAllTeams type compatibility in routing-events.ts
- Restructure conditional object creation to ensure required properties
- Clean up merge conflict remnants from previous rebase
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* clean up
* fix: use user profile timezone for CSV exports instead of browser timezone
- Modified rawData endpoint to use ctx.user.timeZone instead of input.timeZone
- Removed timeZone field from bookingRepositoryBaseInputSchema
- Updated useInsightsBookingParameters to remove timeZone property
- Fixed RecentNoShowGuestsChart to use useDataTable for timezone access
- Resolves timezone discrepancy where CSV exports showed incorrect time values
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* Revert "fix: use user profile timezone for CSV exports instead of browser timezone"
This reverts commit 6356657bd0c503f41349c8d1463bb4dd427b1a2c.
* default columns are formatted as iso
* address feedback
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat: make orgId optional for user and team scopes in InsightsRoutingBaseService
- User scope authorization only checks formUserId and formTeamId IS NULL
- Team scope now supports standalone teams without organizations
- Add validation logic to return NOTHING_CONDITION if team belongs to org but no orgId provided
- Add comprehensive test coverage for null/undefined orgId scenarios in both scopes
- Aligns schema with actual usage patterns and supports teams without organizations
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* feat: extend orgId optional support to InsightsBookingBaseService
- Make orgId optional for user and team scopes in InsightsBookingBaseService
- Update InsightsBookingServicePublicOptions type to allow orgId: number | null
- Add validation logic for team scope to handle missing orgId
- Add comprehensive test coverage for null/undefined orgId scenarios
- Fix type casting issues in test file
- Maintains backward compatibility while supporting teams without organizations
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: correct authorization logic for optional orgId in team scope
- Skip isOwnerOrAdmin check for team scope when orgId is null (standalone teams)
- Maintain security for org scope and team scope with orgId
- Fixes integration test failures for null orgId test cases
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: use != null instead of !== undefined for orgId checks
- Properly handle both null and undefined orgId values in authorization logic
- Fix integration test failures where null orgId was incorrectly triggering isOwnerOrAdmin check
- Ensure team scope with null orgId skips ownership validation for standalone teams
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: always validate team membership for team scope
- Remove orgId condition from isOwnerOrAdmin check for team scope
- Ensure both standalone teams and org-based teams require ownership validation
- Maintain orgId validation logic in buildTeamAuthorizationCondition methods
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: use nullish() for orgId schema validation
- Change from .optional() to .nullish() to allow both null and undefined
- Fixes schema validation when tests pass orgId: null
- Resolves authorization logic returning NOTHING_CONDITION for valid cases
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* feat: replace isOwnerOrAdmin with PBAC checkPermission in insights services
- Replace isOwnerOrAdmin method in InsightsBookingBaseService with checkPermission from PermissionCheckService
- Replace isOwnerOrAdmin method in InsightsRoutingBaseService with checkPermission from PermissionCheckService
- Use permission 'insights.read' with fallback roles MembershipRole.OWNER and MembershipRole.ADMIN
- Maintain same method signature and behavior while leveraging PBAC system
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* clean up types
* add comment
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>