The previous implementation relied on the hosts array returned from
findTeamEventTypes, which is limited to 5 hosts for display purposes.
This caused the 'Assigned' badge to not show for users who were hosts
but not in the first 5 returned by the query.
This fix queries the Host table directly with a single batch query to
get all event type IDs where the current user is a host, ensuring the
badge shows correctly regardless of how many hosts an event type has.
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: ali@cal.com <ali@cal.com>
Adds encrypted credential storage using a new keyring system:
- New `encryptedKey` column with AES-256-GCM encryption
- Decryption in getCalendarsEvents with fallback to legacy `key`
- buildCredentialCreateData service for credential creation
- Phase 1: Google Calendar only, other integrations follow
2026-01-30 09:15:13 -03:00
Joe Au-YeungGitHubClaude Opus 4.5joe@cal.com <j.auyeung419@gmail.com>joe@cal.com <j.auyeung419@gmail.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat: Add routing trace presenters
Add domain-specific presenters (SalesforceRoutingTracePresenter,
RoutingFormTracePresenter) that format trace steps into human-readable
strings, and a core RoutingTracePresenter that delegates to them based
on step domain. Includes unit tests for all presenters.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* feat: Add findByBookingUid to RoutingTraceRepository
Add method to look up a routing trace by booking UID, needed by the
routing trace presenter tRPC endpoint.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* feat: Add getRoutingTrace tRPC endpoint
Expose routing trace data for a booking via viewer.bookings.getRoutingTrace.
Tries the permanent RoutingTrace first (round robin bookings), then falls
back to PendingRoutingTrace via the booking's form response relation.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* feat: Add routing trace side sheet to booking list item
Add a route icon button on booking list items that came from routing
forms. Clicking it opens a side sheet displaying the full routing trace
as human-readable steps. Adds RoutingTraceSheet component, store state,
and translation key.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* refactor: Move routing trace action to dropdown menu
Move the routing trace button from a standalone icon on the booking list
item into the actions dropdown menu alongside "Report wrong assignment".
The RoutingTraceSheet is now rendered from BookingActionsDropdown.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* fix: Improve routing trace UI and handle unnamed routes
- Redesign RoutingTraceSheet with vertical timeline layout, domain badges,
skeleton loading state, and millisecond timestamps
- Use Salesforce app-store icon for Salesforce steps
- Fall back to "Unnamed route" when route name is missing or matches route ID
- Fix dropdown menu icon to git-merge (valid icon, unique in menu)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* test: Add tests for getRoutingTrace handler and findByBookingUid repository method
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* Abstract functions
* Fix build error
* Add permission check
* fix: Update getRoutingTrace tests to include ctx and mock BookingAccessService
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat: add invoice URL to proration and test seed scripts
- Add invoiceUrl field to MonthlyProration schema
- Update billing service to return hosted_invoice_url after finalizing
- Save invoice URL when creating proration invoices
- Add seed script for testing proration with real Stripe data
- Add cleanup script for test data removal
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* feat: add due invoice banner and invitation blocking for orgs
- Add DueInvoiceBanner component showing overdue prorations
- Add DueInvoiceService for checking blocking status and banner data
- Block invitations when proration invoices are 7+ days overdue
- Allow sub-team invites for existing org members (exception)
- Show banner to users with billing management permissions
- Link directly to Stripe invoice URL when available
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* fix: set subscriptionId in team metadata in seed script
The seed script was not setting subscriptionId on the team metadata,
causing checkIfOrgNeedsUpgrade to treat the org as needing upgrade
and showing the "trialing" banner.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* push trigger test to script
* fix mocks
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* feat: add organization.passwordReset PBAC permission
Allow org admins/owners to reset passwords for members of their
organization via a new PBAC permission. Previously this was only
available to system-level admins.
- Add PasswordReset to CustomAction enum and PERMISSION_REGISTRY
- Create migration to grant permission to admin_role (owner has wildcard)
- Add org-scoped tRPC endpoint using createOrgPbacProcedure
- Handler validates org membership, prevents self-targeting, and blocks
resetting owner passwords
- Wire permission through MemberPermissions, getOrgMembersPageData, and
the org members table UI dropdown
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* fix: use targeted select in org password reset to avoid over-fetching
Replace findById with findForPasswordReset repository method that only
selects email, name, and locale instead of the full userSelect which
includes sensitive fields like twoFactorSecret and backupCodes.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* test: add unit tests for sendPasswordReset handler
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-29 11:18:02 +00:00
Joe Au-YeungGitHubunknown <>joe@cal.com <j.auyeung419@gmail.com>joe@cal.com <j.auyeung419@gmail.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>Pedro Castro
* Add DB schema
* Init zod schema
* Init RoutingTrace and PendingRoutingTrace repository interfaces
* Create PrismaPendingRoutingTraceRepository
* Init RoutingTraceService
* Create RoutingTraceService container
* User routing trace service in routing
* Create RoutingTraceRepository and PrismaRoutingTraceRepoistory
* Add findByFormResponseId and findByQueuedFormResponseId to PendingRoutingTraceRepository
* Update DI containers
* RoutingTraceService create process booking method
* Use pending routing trace rather than URL params
* Fix schema
* Fix writing assignment reason for routed booking
* Remove from service
* Refactor RoutingTraceService to not rely on async local storage
* Pass RoutingTraceService through routing call
* Add attribute-logic-evaluated to routing trace step
* Add routing trace to trpc endpoint
* Add CRM routing trace step
* Fix extracting routing trace to assignment reason
* Add back CRM params to prevent refetching
* test: Add unit tests for RoutingTraceService and repositories
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* test: Add missing mock for RoutingTraceService in getRoutedUrl tests
Also fix pre-existing lint issues in the test file:
- Add explicit types to mockForm and mockSerializableForm variables
- Add explicit type to url parameter in mockContext
- Replace 'as any' with 'as unknown as InstanceType<typeof UserRepository>'
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* Link pending form submission to routing trace
* Clean up
* Add lookup field assignment reasons
* Rename to PendingRoutingTrace
* Add migration file
* fix: Update RoutingTraceService tests to use assignmentReasonRepository mock
- Add getStepsCount() method back to RoutingTraceService
- Add queuedFormResponseId support to processForBooking method
- Update tests to use mockAssignmentReasonRepository instead of prisma mock
- Remove test for missing routingTraceRepository (all deps now required)
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: Remove PII (organizer email) from log payload in RoutingTraceService
Addresses Cubic AI review feedback with confidence 9/10.
Logging PII violates sensitive information logging rules.
Co-Authored-By: unknown <>
* Write field values at the time of routing
* Write attributes used to route
* fix: Add CHECK constraint to ensure at least one response ID is set in routing trace tables
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: Address PR review comments for routing trace feature
- Add checkedFallback to routing trace step data (Comment 11)
- Extract hardcoded domain/step strings to constants (Comment 13)
- Use @default(now()) for createdAt in PendingRoutingTrace and RoutingTrace (Comment 15)
- Add DEFAULT CURRENT_TIMESTAMP to migration for createdAt fields
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: Use UTC-safe timezone expression for createdAt defaults in routing trace tables
Addresses Cubic AI review feedback (confidence 9/10) to prevent timezone
issues by using dbgenerated("timezone('UTC', now())") instead of bare now()
for the createdAt fields in PendingRoutingTrace and RoutingTrace models.
Co-Authored-By: unknown <>
* fix: Align migration SQL with Prisma's expected timezone syntax
Use 'UTC'::text cast in timezone() function to match Prisma's generated SQL.
Co-Authored-By: unknown <>
* fix: Revert migration SQL to match Prisma schema timezone syntax
Remove ::text cast from timezone() function to match what Prisma generates
from the schema definition.
Co-Authored-By: unknown <>
* fix: Use explicit ::text cast in timezone() for PostgreSQL compatibility
PostgreSQL normalizes timezone('UTC', now()) to timezone('UTC'::text, now())
internally. Update both schema and migration to use the explicit cast to
ensure they match and pass the migration check.
Co-Authored-By: unknown <>
* fix: Use CURRENT_TIMESTAMP for createdAt defaults (standard Cal.com pattern)
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: Use @default(now()) for createdAt in routing trace tables to match migration
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Pedro Castro <pedro@cal.com>
2026-01-28 12:45:15 -05:00
+3
Alex van AndelGitHubalex@cal.com <me@alexvanandel.com>alex@cal.com <me@alexvanandel.com>alex@cal.com <me@alexvanandel.com>alex@cal.com <me@alexvanandel.com>alex@cal.com <me@alexvanandel.com>alex@cal.com <me@alexvanandel.com>alex@cal.com <me@alexvanandel.com>alex@cal.com <me@alexvanandel.com>cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
* chore: Disables syncing of calendarList on overlay calendar fetch
* Unwrap ToggledConnectedCalendars
* Pick the right type for connectedCalendars
* further type amends
* Type fixes, tons of em
* Some further fixups consistent with what was before
* fix: resolve type incompatibility in getConnectedDestinationCalendars return type
Co-Authored-By: alex@cal.com <me@alexvanandel.com>
* fix: update DestinationCalendarProps to accept tRPC handler return type
Co-Authored-By: alex@cal.com <me@alexvanandel.com>
* fix: use generic type for DestinationCalendarProps to accept tRPC enriched types
Co-Authored-By: alex@cal.com <me@alexvanandel.com>
* fix: simplify DestinationCalendarProps type for better compatibility
Co-Authored-By: alex@cal.com <me@alexvanandel.com>
* fix: export ConnectedCalendar type for consistent type inference
Co-Authored-By: alex@cal.com <me@alexvanandel.com>
* fix: use permissive type for connectedCalendars to accept tRPC enriched types
Co-Authored-By: alex@cal.com <me@alexvanandel.com>
* fix: export ConnectedCalendar and ConnectedDestinationCalendars types from platform-libraries
Co-Authored-By: alex@cal.com <me@alexvanandel.com>
* fix: update ConnectedCalendar type to use boolean | null for primary field
Co-Authored-By: alex@cal.com <me@alexvanandel.com>
* Update ConnectedCalendarItem
* Undo some of Devins fixes, more fixes
* Fixup the destination calendar return type, historically not null
* Change init to undefined to deal with null
* Approach to connect selected calendars with the right credential
* This return type is used way too much everywhere, not refactoring
* Add the selectedCalendars to the type
* Actually fix overlay calendar
* set calendarsToLoad param as required
* Apply suggestion from @cubic-dev-ai[bot]
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
* Add new translation for 'Calendar Settings'
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
2026-01-28 14:20:19 -03:00
Alex van AndelGitHubDevin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
PERFORMANCE: The bookings/get endpoint was taking 24s due to materializing 400+ email
addresses as individual parameters in WHERE IN clauses. This caused massive UNION
queries that overwhelmed the database.
Changes:
- Replace IN clauses with Kysely subqueries for queries 4, 5, 6, and 7
- Query 4 & 5: Use subquery to get emails from users via Membership table
- Query 6: Use subquery to get event type IDs from EventType table
- Query 7: Use subquery to get user IDs from Membership table
- Only fetch user IDs when needed for userIds filter validation
- Add new getUserIdsFromTeamIds function (lighter version without emails)
Before: WHERE email IN ($1, $2, ..., $400+) - passes 400+ parameters
After: WHERE email IN (SELECT email FROM users JOIN Membership...) - passes only team IDs
This reduces parameter count from 400+ to typically 1-10 team IDs, letting the
database optimize the query execution plan.
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-01-28 12:21:49 -03:00
Eunjae LeeGitHubeunjae@cal.com <hey@eunjae.dev>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix: use FeatureOptInService for bookings-v3 check
* refactor: simplify FeatureOptInService API and fix bookings page
- Add resolveFeatureStates method that takes only userId and featureIds
- Update listFeaturesForUser to take only userId parameter
- Remove getUserOrgAndTeamIds from _router.ts (now internal to service)
- Fix bookings page to use new resolveFeatureStates method
- Parallelize getUserFeaturesStatus and resolveFeatureStates calls
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* check session?.user?.id first
* remove comment
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-01-28 14:28:36 +00:00
Keith WilliamsGitHubDevin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* chore: save progress
* chore:
* feat: add input dialog
* fix: type error
* feat: mass apply dialog
* test: per host location
* test: fix test
* fix: address Cubic AI review feedback (confidence >= 9/10)
- Remove PII (address, phone number) from tracing logs in RegularBookingService.ts
- Constrain HostLocation.type to EventLocationType["type"] for compile-time validation
Co-Authored-By: unknown <>
* fix: translation
* refactor: improvements
* fix: correct grammar in custom host locations tooltip
Change 'custom host locations is enabled' to 'custom host locations are enabled' (plural subject requires plural verb).
Addresses Cubic AI review feedback (confidence 9/10).
Co-Authored-By: unknown <>
* refactor: improvements
* fix: auth
* fix: check
* refactor: improvements
* fix: address Cubic AI review feedback (confidence >= 9/10)
- Add scheduleId to newly created hosts in update.handler.ts to persist
host-specific schedules during create operations
- Change host location deletion filter from !host.location to
host.location === null to only delete when explicitly set to null
- Fix static-link per-host locations to use actual link instead of type
in locationBodyString for bookingLocationService.ts
Co-Authored-By: unknown <>
* fix: preserve existing host scheduleId when not explicitly provided
Change scheduleId handling for existing hosts from 'host.scheduleId ?? null'
to 'host.scheduleId === undefined ? undefined : host.scheduleId' so that
when the client doesn't provide a scheduleId, the existing value is preserved
instead of being cleared to null.
Co-Authored-By: unknown <>
* fix; type erro
* fix; type erro
* fix; type erro
* refactor: move repository
* refactor: move repository
* fix: add singular/plural translations for location_applied_to_hosts
Addresses Cubic AI review feedback (confidence 9/10) to fix '1 hosts' rendering as '1 host' by using i18next plural format with _one and _other suffixes.
Co-Authored-By: unknown <>
* refactor: feedback
* fix: type err
* fix: use uuid in schema and remove attendee locaiton
* fix: type err
* fix: type err
* fix: validate eventTypeId as integer in massApplyHostLocation schema
Co-Authored-By: unknown <>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
## What does this PR do?
Implements booking audit logging for round-robin reassignment events (both manual and automatic). This is part of the booking audit integration plan (PR 7).
Changes:
- Added audit logging to `roundRobinManualReassignment.ts` for manual host reassignments
- Added audit logging to `roundRobinReassignment.ts` for automatic round-robin reassignments
- Updated tRPC handlers to pass `actionSource: "WEBAPP"` and `reassignedByUuid`
- Updated API v2 bookings service to pass `actionSource: "API_V2"` and `reassignedByUuid`
- Updated `ReassignmentAuditActionService.ts` with proper field schemas and translation keys
The audit logging uses `BookingEventHandlerService.onReassignment()` with proper actor identification and action source tracking.
## Updates since last revision
Addressed review feedback:
- Renamed `title` field to `hostName` for semantic clarity (tracks host name changes, not booking titles)
- Fixed `assignedById` schema: changed from `NumberChangeSchema` to `z.number()` (no old/new pattern needed - it's always the user who performed the reassignment)
- Fixed `reassignmentReason` schema: changed from `StringChangeSchema` to `z.string().nullable()` (no old/new pattern needed)
- Added `ValidActionSource` type that excludes `UNKNOWN` - clients must pass explicit action sources
- Made `actionSource` required in both reassignment functions (no longer optional)
- Added integration tests for `ReassignmentAuditActionService` (15 tests covering all methods)
- Updated `roundRobinManualReassign.handler.ts` to pass required `actionSource` and `reassignedByUuid` params
**Latest fixes:**
- Fixed `hasAttendeeUpdated` check in `ReassignmentAuditActionService.ts`: changed from `!== null` to `!= null` to properly handle undefined values
- Updated test expectations in `ReassignmentAuditActionService.test.ts` to match the new display JSON field names (`hostAttendeeUserUuidNew`/`hostAttendeeUserUuidOld` instead of `newAssignedRRHostUuid`/`previousAssignedRRHostUuid`)
- Fixed async `getDisplayFields` tests to properly await the Promise and include the `previous_assignee` field
- Fixed `hasAttendeeUpdated` to check for `hostAttendeeUpdated` object presence instead of optional `id` field - host changes with only `withUserUuid` populated were being ignored (identified by Cubic AI, confidence 9/10)
- Fixed test expectation in `getDisplayJson` test: removed incorrect null expectations for `hostAttendeeIdUpdated`, `hostAttendeeUserUuidNew`, `hostAttendeeUserUuidOld` - the implementation uses conditional spreading to omit these fields when `hostAttendeeUpdated` is not present, rather than setting them to null
## Mandatory Tasks (DO NOT REMOVE)
- [x] I have self-reviewed the code (A decent size PR without self-review might be rejected).
- [x] I have updated the developer docs in /docs if this PR makes changes that would require a [documentation change](https://cal.com/docs). N/A - no documentation changes needed.
- [x] I confirm automated tests are in place that prove my fix is effective or that my feature works.
## How should this be tested?
1. Trigger a manual round-robin reassignment via the webapp and verify audit logs are created with `actionSource: "WEBAPP"`
2. Trigger an automatic round-robin reassignment and verify audit logs are created
3. Use API v2 to reassign a booking and verify audit logs are created with `actionSource: "API_V2"`
4. Verify the audit data contains correct values for `organizerUuid`, `hostAttendeeUpdated`, `reassignmentReason`, and `reassignmentType`
## Checklist
- [x] My code follows the style guidelines of this project
- [x] I have checked if my changes generate no new warnings
## Human Review Checklist
- [x] Verify the `hasAttendeeUpdated` fix is correct: now checks `fields.hostAttendeeUpdated != null` to detect any host attendee update regardless of whether `id` is populated
- [x] Verify `getDisplayJson` test fix: fields are correctly omitted (not set to null) when `hostAttendeeUpdated` is not present, matching the conditional spreading implementation
- [ ] Verify all callers of reassignment functions pass required `actionSource` and `reassignedByUuid`
- [ ] Confirm `getDisplayFields` is properly awaited in all call sites (it's now async)
- [ ] Check that `ValidActionSource` type properly excludes `UNKNOWN` for client-side validation
## Important Notes for Reviewer
1. **Dependency on base PR**: The translation key changes use the format from base PR (#26046). This PR should be merged after the base PR.
2. **Schema changes**: The `organizerUuid` and `hostAttendeeUpdated` fields track both organizer changes and round-robin host attendee changes separately for complete audit trail.
---
Link to Devin run: https://app.devin.ai/sessions/e4353e2ec6ea4a51ab33313bdc630aba
Requested by: @hariombalhara
2026-01-23 08:13:22 +05:30
Peer RichelsenGitHubpeer@cal.com <peer@cal.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: peer@cal.com <peer@cal.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-01-22 16:44:29 +00:00
Keith WilliamsGitHubDevin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* perf: optimize getEventTypeIdsFromTeamIdsFilter with raw SQL query
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix: use prisma singleton for raw queries to fix runtime error
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix: use context prisma for raw queries and update test mocks
- Changed getEventTypeIdsFromTeamIdsFilter to use the context-passed prisma parameter instead of importing the singleton
- Added $queryRaw mock to test file to support raw SQL queries
- Updated test assertion to check for $queryRaw call instead of eventType.findMany
The context prisma IS the same singleton at runtime (passed via tRPC context in createContext.ts). The test was failing because the mock didn't include $queryRaw.
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* Removed extra subquery where not needed
* fix: restore subquery optimization for better query performance
Restores the subquery structure that allows PostgreSQL to use the composite
index on EventType(parentId, teamId) efficiently via Nested Loop joins,
resulting in ~66x faster execution (2.46ms vs 164ms in production benchmarks).
Identified by Cubic AI (confidence 9/10).
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* Fighting with AI
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat(flags): add @Memoize and @Unmemoize decorators for declarative caching
- Add @Memoize decorator for caching method results with Zod validation
- Add @Unmemoize decorator for cache invalidation on mutations
- Create UserFeatureRepository using decorators as example implementation
- Add comprehensive tests with 80%+ coverage (19 tests)
- Add DI module and tokens for UserFeatureRepository
- Enable experimentalDecorators in packages/features/tsconfig.json
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor(cache): use lazy Redis lookup in decorators
- Decorators now access Redis via getRedisService() instead of this.redis
- UserFeatureRepository no longer has redis property or direct redis calls
- findByUserIdAndFeatureIds now uses decorated findByUserIdAndFeatureId
- DI module simplified to only pass prisma dependency
- Tests updated to call setRedisService() in beforeEach
This ensures the repository only knows about Prisma, with all caching
handled transparently by the decorators.
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* feat(flags): add FeatureRepository and TeamFeatureRepository with decorator-based caching
- Add FeatureRepository with @Memoize decorators for findAll, findBySlug, getFeatureFlagMap
- Add TeamFeatureRepository with @Memoize/@Unmemoize decorators for all CRUD operations
- Add comprehensive Zod schemas for Feature, TeamFeatures, and AppFlags validation
- Add DI modules and tokens for both repositories
- Add comprehensive test coverage (33 tests) for both repositories
- Maintain backward compatibility with existing FEATURES_REPOSITORY tokens
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor(cache): use DI container pattern for Redis service
- Create packages/features/di/containers/Redis.ts with getRedisService()
- Update Memoize and Unmemoize decorators to import from DI container
- Remove setRedisService() and IRedisService from types.ts exports
- Update all tests to mock the container's getRedisService
- Fix import ordering issues from biome
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor(cache): remove barrel import and add root-level cache export
- Remove packages/features/cache/decorators/index.ts barrel file
- Add packages/features/cache/index.ts as root-level export for cache feature
- Update repository imports to use direct imports from source files
- Follows the pattern: avoid barrel imports at nested levels, keep at feature root
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor(flags): minimize repository methods and address PR feedback
- Remove unnecessary methods from FeatureRepository, TeamFeatureRepository, and UserFeatureRepository
- Keep only methods needed by FeatureOptInService
- Update imports to use @calcom/features/cache public API instead of relative paths
- Handle redis.del() errors gracefully in Unmemoize decorator
- Update tests to match simplified repositories
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor(cache): use Promise.allSettled for cache invalidation
Cleaner approach than Promise.all with individual .catch() handlers
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* feat(flags): add setAutoOptIn methods and replace featuresRepository usage in _router.ts
- Add setAutoOptIn method to TeamFeatureRepository with @Unmemoize decorator
- Add setAutoOptIn method to UserFeatureRepository with @Unmemoize decorator
- Replace featuresRepository usage in featureOptIn/_router.ts with new repositories
- TeamFeatureRepository.setAutoOptIn unmemoizes KEY.autoOptInByTeamId(teamId)
- UserFeatureRepository.setAutoOptIn unmemoizes KEY.autoOptInByUserId(userId)
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor(flags): use DI containers for TeamFeatureRepository and UserFeatureRepository
- Create TeamFeatureRepository.ts container with getTeamFeatureRepository()
- Create UserFeatureRepository.ts container with getUserFeatureRepository()
- Update _router.ts to use DI containers instead of direct instantiation
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor(feature-opt-in): use DI containers for FeatureOptInService dependencies
- Update FeatureOptInService to use IFeatureOptInServiceDeps with 3 repositories
- Add helper functions teamFeatureToState() and userFeatureToState()
- Update DI module to use depsMap pattern with featureRepo, teamFeatureRepo, userFeatureRepo
- Create FeatureRepository container file
- Replace all FeaturesRepository method calls with new repository methods
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* test(feature-opt-in): update FeatureOptInService tests for new IFeatureOptInServiceDeps interface
- Update mock structure to use featureRepo, teamFeatureRepo, userFeatureRepo
- Add helper functions createMockTeamFeature and createMockUserFeature
- Update all test cases to use new repository method names
- Add explicit types to satisfy biome lint rules
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor(flags): use DTOs at repository boundaries to prevent Prisma type leakage
- Create FeatureDto, TeamFeaturesDto, UserFeaturesDto in packages/lib/dto/
- Update repository interfaces to return DTOs instead of Prisma types
- Add toDto() transformation methods in repository implementations
- Update FeatureOptInService to use DTOs instead of Prisma types
- Follow data-dto-boundaries.md guidelines for architectural boundaries
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix(flags): update TeamFeatureRepository tests to match DTO structure
Remove assignedAt from test mock data since TeamFeaturesDto only includes:
teamId, featureId, enabled, assignedBy, and updatedAt
Co-Authored-By: unknown <>
* fix(cache): make Redis failures non-blocking in @Memoize decorator
Wrap Redis get and set operations in try-catch blocks to ensure
Redis failures don't break the application flow. If cache read fails,
proceed to fetch from source. If cache write fails, silently ignore
and return the result.
Co-Authored-By: unknown <>
* fix(cache): add logging for Redis failures and remove barrel import
- Add warning logs for Redis failures in @Memoize and @Unmemoize decorators
- Remove packages/lib/dto/index.ts barrel import file
- Update all imports to use direct file paths instead of barrel imports
Co-Authored-By: unknown <>
* fix(cache): sanitize log messages to avoid exposing sensitive data
- Remove cacheKey from log messages (may contain PII like user/team IDs)
- Log only error.message instead of raw error objects
- Addresses Cubic AI feedback (confidence 9/10)
Co-Authored-By: unknown <>
* sanitize log
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Volnei Munhoz <volnei@cal.com>
2026-01-22 16:26:27 +01:00
devin-ai-integration[bot]GitHubali@cal.com <ali@cal.com>ali@cal.com <ali@cal.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>ali@cal.com <ali@cal.com>
* feat: add assigned badge to team event types
Add an 'Assigned' badge to Round Robin and Collective event types
when the current user is a host/participant of the event type.
This provides visibility to users without edit permissions that
they are included in the rotation.
Changes:
- Add isCurrentUserHost flag in getEventTypesFromGroup handler
- Display blue 'Assigned' badge in event types listing view
- Add i18n translation for 'assigned' text
Co-Authored-By: ali@cal.com <ali@cal.com>
* refactor: remove redundant isTeamEvent check for assigned badge
Co-Authored-By: ali@cal.com <ali@cal.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: ali@cal.com <ali@cal.com>
2026-01-22 10:16:22 +01:00
Peer RichelsenGitHubpeer@cal.com <peer@cal.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>Volnei Munhozcubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
* feat: add Cloudflare URL Scanner integration for malicious URL detection
- Add MALICIOUS_URL_IN_WORKFLOW to LockReason enum
- Add URL_SCANNING_ENABLED constant for feature flag
- Create urlScanner.ts utility for Cloudflare Radar URL Scanner API
- Create scanWorkflowUrls task for async URL scanning with polling
- Integrate URL scanning into scanWorkflowBody task
- Add URL scanning for event type redirect URLs
- Lock user accounts when malicious URLs are detected
- Fix pre-existing lint issues (parseInt radix, optional chaining)
Co-Authored-By: peer@cal.com <peer@cal.com>
* fix: address biome lint warnings and TypeScript iterator errors
- Wrap iterators with Array.from() to fix TS2802 errors
- Add biome-ignore comments for process.env usage
- Extract helper functions to reduce function length
- Move exports to end of file per useExportsLast rule
- Remove problematic imports that cause TypeScript errors
Co-Authored-By: peer@cal.com <peer@cal.com>
* fix: address cubic-dev-ai review comments for URL scanning
- Fix P0: Re-fetch workflow steps before scheduling notifications to use actual verifiedAt values from database instead of overriding with new Date()
- Fix P1: Mark workflow step as verified in submitWorkflowStepForUrlScanning when URL scanning is disabled or no URLs found
- Fix P1: Add whitelistWorkflows parameter to submitUrlForUrlScanning for consistency
- Fix P2: Preserve URL context in error results in urlScanner.ts scanUrls function
Co-Authored-By: peer@cal.com <peer@cal.com>
* fix: add select clause to Prisma query for workflow steps
Address cubic-dev-ai P2 comment: Use select to fetch only the required
fields (id, action, sendTo, emailSubject, reminderBody, template, sender,
verifiedAt) instead of fetching all columns from workflowStep table.
Co-Authored-By: peer@cal.com <peer@cal.com>
* fix: add select clause to Prisma query in scanWorkflowBody.ts
Address cubic-dev-ai P2 review comment: Use select to fetch only the
required fields (id, action, sendTo, emailSubject, reminderBody,
template, sender, verifiedAt) instead of fetching all columns.
Co-Authored-By: peer@cal.com <peer@cal.com>
* test: add unit tests for URL scanning functionality
- Add tests for urlScanner.ts (extractUrlsFromHtml, isUrlScanningEnabled)
- Add tests for scanWorkflowUrls.ts (happy/unhappy paths for URL scanning task)
- Add tests for scanWorkflowBody.ts (happy/unhappy paths for workflow body scanning)
Tests cover:
- URL extraction from HTML content
- URL normalization and deduplication
- Handling of malicious URLs and user locking
- Fail-open behavior for API errors
- Whitelisted user handling
- Iffy spam detection integration
Co-Authored-By: peer@cal.com <peer@cal.com>
* test: remove incomplete test that provides no value
Removed the 'should mark all steps as verified when neither Iffy nor URL scanning is enabled' test as it used vi.doMock() which doesn't work after module import, had no assertions, and gave false confidence in test coverage.
Co-Authored-By: peer@cal.com <peer@cal.com>
* refactor: use Cloudflare bulk scanning endpoint to reduce API quota usage
- Added submitUrlsForBulkScanning function that uses /urlscanner/v2/bulk endpoint
- Updated scanUrls to use bulk submission instead of individual URL submissions
- Bulk endpoint accepts up to 100 URLs per request, batching is handled automatically
- Reduces API quota usage as suggested by keithwillcode
Co-Authored-By: peer@cal.com <peer@cal.com>
* Update packages/features/tasker/tasks/scanWorkflowUrls.ts
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
* fix: address cubic-dev-ai review comments
- P1: Sanitize URLs before logging to prevent exposing sensitive query parameters
- P2: Extract handleUrlScanningForStep helper function to reduce code duplication
- P2: Use vi.stubGlobal for fetch mock in tests for proper cleanup
Co-Authored-By: peer@cal.com <peer@cal.com>
* fix: address volnei review comments on PR #26387
- Move vi.unstubAllGlobals() to afterEach hook in iffyScanBody tests
- Restore updateMany optimization when URL scanning is disabled
Co-Authored-By: peer@cal.com <peer@cal.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Volnei Munhoz <volnei@cal.com>
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
2026-01-21 12:28:57 -03:00
+1
Peer RichelsenGitHublauris@cal.com <lauris@cal.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>eunjae@cal.com <hey@eunjae.dev>Lauris Skraucissupalarrycubic-dev-ai[bot] <1082092+cubic-dev-ai[bot]@users.noreply.github.com>CarinaWollilauris@cal.com <lauris@cal.com>Morgan
* feat: add OAuth client developer settings page with approval workflow
- Add new developer OAuth page at /settings/developer/oAuth for users to submit OAuth client requests
- Transform admin OAuth page into management dashboard for reviewing/approving submissions
- Add OAuthClientApprovalStatus enum (PENDING, APPROVED, REJECTED) to track submission status
- Add userId and createdAt fields to OAuthClient model for tracking submissions
- Create email notifications for admin (new submission) and user (approval)
- Add sidebar navigation link in developer section below API keys
- Add comprehensive translations for new UI strings
- Create OAuthClientRepository for data access following repository pattern
Co-Authored-By: peer@cal.com <peer@cal.com>
* fix: re-export generateSecret for backward compatibility
Co-Authored-By: peer@cal.com <peer@cal.com>
* feat: make logo mandatory and list items clickable for OAuth clients
Co-Authored-By: peer@cal.com <peer@cal.com>
* fix: add missing translation keys and remove client secret from details dialog
Co-Authored-By: peer@cal.com <peer@cal.com>
* fix: address cubic AI reviewer comments
- Remove duplicate 'there' JSON key in common.json
- Add select clause to findByUserId to avoid exposing clientSecret
- Add @@index([userId]) to OAuthClient model for query performance
- Update migration to include the index
Co-Authored-By: peer@cal.com <peer@cal.com>
* fix: address PR review comments - fix indentation and use useCopy hook
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: change react-dom/server import to fix Turbopack compatibility
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* Revert "fix: change react-dom/server import to fix Turbopack compatibility"
This reverts commit c3e0b709c2d88fd221143cb4ce9cd25bb8c94277.
* fix: use email service pattern for OAuth client notifications
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: add try-catch around email sending to handle Turbopack react-dom/server issue
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* Revert "fix: add try-catch around email sending to handle Turbopack react-dom/server issue"
This reverts commit fc9d47cd773505ebc5ee2696718aad4a8a98be77.
* fix: improve OAuth client UI with skeleton loaders and smaller dialog styling
- Replace 'Loading...' text with proper skeleton loaders in both developer and admin OAuth client views
- Make client_id and copy button smaller in dialogs using size='sm' and text-sm styling
- Add 'client_id' translation key to common.json for proper i18n
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: improve skeleton loader to match actual OAuth client list structure
- Remove divide-y from container and use conditional border-b on rows
- Match the exact structure from oauth-clients-view.tsx L126-160
- Use proper spacing for text elements (mt-1 instead of space-y-2)
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix skeleton
* rename the selected oauth client dialog
* fix: address PR feedback - admin auth, dropdown styling, sidebar label
- Add defense-in-depth admin authorization check in updateClientStatus handler
- Fix broken dropdown menu by using DropdownItem with StartIcon prop
- Fix sidebar menu label from 'oAuth' to 'oauth_clients' to match developer view
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* update common.json
* feat: show client secret in approval email for confidential OAuth clients
- Add regenerateSecret method to OAuthClientRepository
- Regenerate secret when admin approves a PENDING confidential client
- Include client secret in approval notification email
- Add one-time warning message about storing the secret securely
- Only regenerate on first approval (not re-approvals)
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* feat: add Website URL field, fix logo styling, show client secret after approval
- Add Website URL field to OAuth client forms (admin and developer views)
- Fix Upload Logo section styling by wrapping in Label div with proper gap
- Display client secret in dialog after admin approves a confidential OAuth client
- Add websiteUrl field to Prisma schema with migration
- Update tRPC handlers and repository to support websiteUrl
- Add translation keys for new UI elements
Co-Authored-By: peer@cal.com <peer@cal.com>
* fix: move clientSecret variable declaration outside if block for proper scoping
Co-Authored-By: peer@cal.com <peer@cal.com>
* refactor: dont expose client secret in emails
* refactor: dont regenerate secret upon status change
* refactor: reuse existing hash function
* refactor: rename admin/oAuth to admin/oauth page
* refactor: deduplicate oauth repositories
* refactor: remove withGlobalPrisma from oauth repository
* refactor: developer oauth page
* refactor: oauth status by default accepted
* refactor: request oauth status when creating
* refactor ux
* fix: address Cubic AI code review feedback
- Add purpose field to plain text email body for accessibility
- Convert NewOAuthClientButton to inline JSX to avoid React anti-pattern
- Trigger re-approval when redirectUri changes for security
- Add e.preventDefault() for Space key to prevent page scroll
- Change default approvalStatus to PENDING for defense-in-depth
- Use oauth_clients translation key for consistency
- Add meaningful alt text to Avatar for accessibility
- Remove onClick from DialogClose to prevent double-run close effects
- Return NOT_FOUND for non-owner delete to prevent resource enumeration
Co-Authored-By: unknown <>
* common.json file
* refactor: delete all prisma migrations
* refactor: have just 1 prisma migration
* revert: some devin changes
* fix: typecheck
* test: owner OAuth crud
* test: admin OAuth approval / rejection
* fix: address Cubic AI review feedback (confidence 9/10 issues)
- schema.prisma: Remove @default("") from purpose field to make it required
- schema.prisma: Use UTC-aware timezone expression for createdAt default
- OAuthClientFormFields.tsx: Localize redirect URI placeholder using t()
- common.json: Add redirect_uri_placeholder translation key
Co-Authored-By: unknown <>
* cubic changes
* refactor: dont log sensitive info and rethrow error
* cubic feedback
* refactor: make oauth client purpose optional
* refactor: admin/oauth not allowed if not logged in
* refactor: admin view skeleton
* refactor: rename state
* refactor: get rid of redundant mapping
* refactor: remove redundant handler
* refactor: remove redundant handler
* refactor: re-usable new oauth client button
* refactor: dialogs
* refactor: modals
* refactor: handler names, dialog, skeleton
* fix: purpose being null
* refactor: rename handler and delete old oauth admin page
* fix: purpose in submission
* refactor: handler names
* refactor: rename
* refactor: update handler
* refactor: rename approvalStatus -> status
* refactor: simplify modal
* refactor: name
* dont require repproval if redirectUri changes
* fix: remove integration sync index creation
* refactor: require re-approval if redirectUri updated
* fix: flaky e2e test
* fix: flaky e2e test
* fix: flaky e2e test
* fix: remove duplicate common.json keys
* refactor: replace team@cal.com with SUPPORT_MAIL_ADDRESS
* refactor: generate client secret on handler level
* fix: authorization code only available to approved clients
* refactor: cubic review dont display exclamation
* refactor: cubic review website_url in common json
* fix: dont default in ui to approved status
* refactor: optiona logo in schema create handler
* fix: tests
* fix: tests
* fix: /authorize redirect if client not approved or show error
* test: authorize page with invalid client id
* refactor: dont allow refreshing tokens unless approved client
* fix: flaky e2e test
* fix: flaky e2e test
* fix: flaky e2e test
* fix: flaky e2e test
* fix: flaky e2e test
* fix: flaky e2e test
* chore: warn that pending client is not usable
* fix: approve and reject buttons
* fix: /authorize show error if client not approved
* refactor: info message about editing oauth client and status
* change info alert to warning
* try to fix ci test
* debug: failing e2e test
* fix: improve session propagation in oauth-client-admin E2E test
- Add navigateToAdminOAuthPage helper that waits for listClients API call
- If the API call doesn't arrive (session issue), reload page to force session refresh
- This fixes the CI flakiness where admin page wasn't loading due to session not having ADMIN role
Co-Authored-By: lauris@cal.com <lauris@cal.com>
* fix: register waitForResponse before navigating in E2E test
- Register the listClients waitForResponse promise BEFORE page.goto()
- This ensures the response isn't missed during page load
- Also register the promise before reload in the catch block
Co-Authored-By: lauris@cal.com <lauris@cal.com>
* fix: rename oAuth folder to oauth for case-sensitive filesystems
The admin OAuth page route was at /settings/admin/oAuth (capital A) but the
code references /settings/admin/oauth (lowercase). This caused 404 errors
on case-sensitive filesystems (Linux).
Also improved the E2E test navigation helper to retry with delays if the
admin page doesn't load immediately, handling session propagation timing.
Co-Authored-By: lauris@cal.com <lauris@cal.com>
* test style
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: eunjae@cal.com <hey@eunjae.dev>
Co-authored-by: Lauris Skraucis <lauris.skraucis@gmail.com>
Co-authored-by: supalarry <laurisskraucis@gmail.com>
Co-authored-by: cubic-dev-ai[bot] <1082092+cubic-dev-ai[bot]@users.noreply.github.com>
Co-authored-by: CarinaWolli <wollencarina@gmail.com>
Co-authored-by: lauris@cal.com <lauris@cal.com>
Co-authored-by: Morgan <33722304+ThyMinimalDev@users.noreply.github.com>
2026-01-21 12:23:51 -03:00
Alex van AndelGitHubDevin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
These columns are marked as deprecated in the Prisma schema and will be
removed in a follow-up migration. This PR removes all code references to
prepare for the column removal.
Changes:
- Remove startTime/endTime from ProfileRepository userSelect and methods
- Remove startTime/endTime from UserRepository userSelect and methods
- Remove startTime/endTime from me/get.handler.ts API response
- Remove endTime from API v1 user validation schema
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
## What does this PR do?
Integrates booking audit logging for the edit location functionality, following the pattern established in PR #26046 (booking creation/rescheduling audit).
This PR adds audit logging when a booking's location is changed through:
1. **Web app** (tRPC handler): `packages/trpc/server/routers/viewer/bookings/editLocation.handler.ts`
2. **API v2**: `apps/api/v2/src/ee/bookings/2024-08-13/services/booking-location.service.ts`
### Changes:
- Added `actionSource` as a **required** parameter to `editLocationHandler` (no fallback)
- Added optional `userUuid` parameter (defaults to logged-in user's uuid)
- Added `ValidActionSource` type that excludes "UNKNOWN" for client-facing APIs
- Captures old location before update for audit data
- Calls `BookingEventHandlerService.onLocationChanged()` after successful location update
- Web app uses `actionSource: "WEBAPP"`, API v2 uses `actionSource: "API_V2"`
- Updated router to explicitly pass `actionSource: "WEBAPP"`
- Updated test to pass `actionSource: "WEBAPP"`
- **API v2**: Uses NestJS dependency injection pattern with `BookingEventHandlerService` injected via constructor
### Updates since last revision:
- **Created `BookingEventHandlerModule`** (`apps/api/v2/src/lib/modules/booking-event-handler.module.ts`) to encapsulate `BookingEventHandlerService` and its dependencies (Logger, TaskerService, HashedLinkService, BookingAuditProducerService)
- Updated both bookings modules (2024-04-15 and 2024-08-13) to import `BookingEventHandlerModule` instead of listing individual providers
- This reduces code duplication and makes dependency management cleaner
## Mandatory Tasks (DO NOT REMOVE)
- [x] I have self-reviewed the code (A decent size PR without self-review might be rejected).
- [x] I have updated the developer docs in /docs if this PR makes changes that would require a [documentation change](https://cal.com/docs). N/A - no documentation changes needed.
- [x] I confirm automated tests are in place that prove my fix is effective or that my feature works. N/A - using existing audit infrastructure that is already tested.
## How should this be tested?
1. Update a booking's location through the web app
2. Update a booking's location through API v2
3. Verify audit logs are created with:
- Correct `bookingUid`
- Correct `actor` (user who made the change)
- Correct `source` ("WEBAPP" or "API_V2")
- Correct `auditData.location.old` and `auditData.location.new` values
## Checklist
- [x] My code follows the style guidelines of this project
- [x] I have commented my code, particularly in hard-to-understand areas
- [x] I have checked if my changes generate no new warnings
## Human Review Checklist
- [ ] Verify all callers of `editLocationHandler` pass `actionSource` (router updated, test updated)
- [ ] Verify `organizationId` derivation is correct in both handlers (tRPC uses `booking.user?.profiles?.[0]?.organizationId`, API v2 uses `existingBookingHost.organizationId`)
- [ ] Confirm audit call placement after location update is intentional (audit failures would fail the operation even though location was already updated)
- [ ] Note: API v2 has its own implementation and does NOT reuse `editLocationHandler` - this is correct
- [ ] Verify `BookingEventHandlerModule` properly exports `BookingEventHandlerService` and is imported in both bookings modules
- [ ] Verify the `updateBookingLocationInDb` return value (`{ updatedLocation }`) is destructured and used correctly for audit data
- [ ] Verify API v2 uses `bookingLocation` for audit `new` value, while tRPC uses `updatedLocation` from DB update
---
Link to Devin run: https://app.devin.ai/sessions/fd1d439779674050a26ea3fa7d799943
Requested by: @hariombalhara
2026-01-20 18:40:48 +05:30
Volnei MunhozGitHubDevin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* docs: add feature opt-in banner system plan
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* docs: iterate on feature opt-in banner plan based on feedback
- Use config.ts for feature metadata instead of TRPC response
- Consolidate localStorage dismissal into single key to avoid bloat
- Replace separate success dialog with in-dialog success state for smoother UX
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* feat: implement feature opt-in banner system
- Add checkFeatureOptInEligibility TRPC procedure to check if user can opt-in
- Create useFeatureOptInBanner hook with localStorage dismissal state
- Create FeatureOptInBanner floating component for bottom-right display
- Create FeatureOptInConfirmDialog with role-based options and success state
- Integrate banner into bookings-view.tsx as example usage
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* feat: add i18n translation keys for feature opt-in banner
* refactor: create FeatureOptInBannerWrapper for simpler consumer integration
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor: use @calcom/lib/webstorage and add Zod schema for localStorage
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor: address PR review comments - use PBAC, move logic to service, improve typing
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
# Conflicts:
# packages/features/feature-opt-in/services/FeatureOptInService.ts
* test: add comprehensive tests for checkFeatureOptInEligibility method
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: correct import and Checkbox type errors
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* update message
* invalidate after dialog dismiss
* feat: simulate user opt-in to determine banner eligibility
When a feature has a strict policy and org/team hasn't explicitly
enabled it, user opt-in alone won't enable the feature. This change
simulates what would happen if the user opts in and only shows the
banner if opting in would actually enable the feature.
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: add early return for missing featureConfig and clarify simulation comment
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix repository usage
* refactor: simplify FeatureOptInConfirmDialog UI and remove unused translation
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor: replace radio buttons with multi-select dropdown in FeatureOptInConfirmDialog
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* resize banner
* refactor: use AnimatedPopover pattern for team selection and rename titleI18nKey to nameI18nKey
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: change 'Just for me' to 'For me', fix width clipping, remove divider
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* update style
* feat: make 'Just for me' mutually exclusive with teams/org and store opt-ins in localStorage
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor: remove barrel imports and update to direct imports
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: add modal prop to AnimatedPopover to fix scroll lock conflict in dialogs
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: wrap Popover.Content with Portal to prevent layout interference in dialogs
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: use flexbox gap instead of space-y to prevent popover wrapper from affecting layout
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* Revert "fix: use flexbox gap instead of space-y to prevent popover wrapper from affecting layout"
This reverts commit 8385adafa890c2f2674aa3ae3b10ca6e0c55ba5c.
* Revert "fix: wrap Popover.Content with Portal to prevent layout interference in dialogs"
This reverts commit e84301a35a99b3559d47c2d37316af290834ca2d.
* Revert "fix: add modal prop to AnimatedPopover to fix scroll lock conflict in dialogs"
This reverts commit b015af2f1cf31ef7087c02cb8535d96cc4a34125.
* feat: replace Radix Dialog and AnimatedPopover with coss-ui components
This migration uses @coss/ui Dialog and Popover components which are built on
Base UI instead of Radix. Base UI handles scroll locking and positioning
differently, which should fix the gap issue when opening the popover inside
the dialog.
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor: replace remaining @calcom/ui components with coss-ui
- Replace Divider with Separator from @coss/ui
- Replace Label with Label from @coss/ui
- Replace CheckboxField with Checkbox + Label from @coss/ui
- Replace Icon with direct lucide-react icons (UserIcon, BuildingIcon, UsersIcon, CheckIcon)
- Replace showToast with toastManager.add() from @coss/ui
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor: replace Popover with Menu component from coss-ui
- Replace Popover + FilterCheckboxField with Menu + MenuCheckboxItem
- MenuCheckboxItem provides built-in checkbox indicator and styling
- MenuSeparator provides proper menu separators
- Cleaner API with onCheckedChange callback
- Better keyboard navigation support
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: align icon and text on same line in MenuCheckboxItem, widen dialog
- Wrap icon and text in flex container with items-center gap-2
- Change dialog width from sm:max-w-md to sm:max-w-lg to prevent text wrapping
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* use dimmed bg for coss dialog title
* refactor: change nameI18nKey/descriptionI18nKey to nested i18n object
- Change OptInFeatureConfig interface to use i18n: { name, description }
- Update all component usages to use featureConfig.i18n.name and featureConfig.i18n.description
- Update test mocks to use new structure
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* feat: add i18n.title to OptInFeatureConfig type definition
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* update texts
* use title instead of name
* update banner style
* refactor: split FeatureOptInConfirmDialog into separate success and confirmation dialogs
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: don't record dismissed info in local storage after successful opt-in
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: add checkFeatureOptInEligibility to IFeatureOptInService interface
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* update common.json
* refactor: move tRPC usage from features package to apps/web/modules
Addresses Cubic AI review feedback (confidence 9/10):
- Remove @calcom/trpc import from FeatureOptInConfirmDialog.tsx
- Add FeatureOptInMutations type for passing mutation functions via props
- Move tRPC hooks to useFeatureOptInBanner hook in apps/web/modules
- Pass mutations through FeatureOptInBannerWrapper to dialog component
This maintains the architectural constraint that packages/features
should not import from @calcom/trpc to prevent circular dependencies.
Co-Authored-By: unknown <>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-01-19 18:48:26 +00:00
Joe Au-YeungGitHubDevin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
- Change 'Booking not found' to throw NOT_FOUND (404) instead of plain Error
- Preserve ErrorWithCode for ChargeCardFailure to properly map to BAD_REQUEST (400)
- Add specific error handling for 'User is not a member of the team' -> FORBIDDEN (403)
- Add specific error handling for 'User ID is required' and 'No payment credential found' -> BAD_REQUEST (400)
- Keep INTERNAL_SERVER_ERROR (500) only for actual server errors like 'Payment app not implemented'
- Update test to expect ErrorWithCode to be re-thrown instead of wrapped in translated Error
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-01-19 18:14:13 +00:00
Pedro CastroGitHubDevin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>keith@cal.com <keithwillcode@gmail.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* refactor(teams): improve membership validation for org admins
- Add organization scope validation to removeMember handler
- Ensure team operations are scoped to users organization context
- Update related tests
* test(teams): align removeMember tests with updated interface
- Add organizationId to test contexts
- Add team.findMany mock for org validation
- Add test cases for org scope validation
* refactor(teams): use TeamRepository for org validation in LegacyRemoveMemberService
- Add findByIdsAndOrgId method to TeamRepository
- Inject TeamRepository into LegacyRemoveMemberService via constructor
- Update RemoveMemberServiceFactory to instantiate and inject TeamRepository
- Update tests to mock TeamRepository instead of direct prisma calls
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
---------
Co-authored-by: keith@cal.com <keithwillcode@gmail.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Part 1 of monthly proration feature.
Adds seat change tracking infrastructure with operationId for idempotency.
**Dependency chain:**
- This PR (seat tracking)
- PR #27002 depends on this
* refactor: migrate MembershipRole usages to PBAC permission checks
- Refactor get.handler.ts to use PermissionCheckService for canUpdateTeams
- Refactor checkForInvalidAppCredentials.ts to use getTeamIdsWithPermission
- Refactor outOfOffice.utils.ts to use checkPermission for ooo.update
- Refactor checkIfOrgNeedsUpgrade.handler.ts to use organization.manageBilling
- Refactor getActiveOnOptions.handler.ts to use eventType.update permission
- Refactor WorkflowRepository.ts to use workflow.update permission
- Refactor organization.tsx to use team.update permission
- Refactor getEventTypesByViewer.ts to use eventType.update permission
- Refactor getPublicEvent.ts to use team.read permission for private teams
- Update CreateNewOutOfOfficeEntryButton.tsx to use canUpdateOOO prop
Co-Authored-By: sean@cal.com <Sean@brydon.io>
* fix: use organization.update permission instead of team.update for org management
Co-Authored-By: sean@cal.com <Sean@brydon.io>
* fix: rename teamsWithEventTypeManagePermission to teamsWithEventTypeUpdatePermission
Renamed variable to match the permission string being used (eventType.update)
Co-Authored-By: sean@cal.com <Sean@brydon.io>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-01-15 15:59:00 +01:00
Hariom BalharaGitHubhariom@cal.com <hariombalhara@gmail.com>hariom@cal.com <hariombalhara@gmail.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix: properly await async operations in addMembersToTeams
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* test: add unit tests for addMembersToTeams function
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-01-15 19:54:47 +05:30
Joe Au-YeungGitHubunknown <>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>Hariom Balharacubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
* Add db schema
* Add `CredentialRepository.findByTeamIdAndSlugs`
* Add enabled app slugs for attribute syncing
* Create repository for `IntegrationAttributeSync`
* Create zod schemas
* Create `AttributeSyncUserRuleOutputMapper`
* Create `IntegrationAttributeSyncService`
* Create DI contianer
* Create trpc endpoints
* Create page
* Include team name in `CredentialRepository.findByTeamIdAndSlugs`
* Update schema and relations
* Update types and schemas
* Add more methods to IntegrationAttributeSyncRepository
* Add more services to `IntegrationAttributeSyncService`
- getById
- Init updateIncludeRulesAndMappings
* Refactor `getTeams.handler` to use repository
* Create `createAttributeSync` trpc endpoint
* Create `updateAttributeSync` trpc endpoint
* Add router to trpc
* Create attribute sync child components
* Pass custom actions to `FormCard`
* Create `IntegrationAttributeSyncCard`
* Pass inital props via server side
* Fix prop
* Only refetch on mutation
* Fixes
* Add form error when duplicate field and attribute combo
* Add `updateTransactionWithRUleAndMappings` logic
* Adjust zod schemas
* Service add `updateIncludeRulesAndMappings`
* Pass orgId from server to component
* Rename types
* Add deleteById method to repository
* Add name to integrationAttributeSync
* Add deleteById method to service
* Rename method
* Add deleteAttributeSync trpc endpoint
* Make the IntegrationAttributeSyncCard a dummy component
* test: add tests for IntegrationAttributeSync feature
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* Move creating a attribute sync record to the service
* Add i18n strings
* Safe select credential in find by id and team
* Fix default credentialId value in form
* Update repository return types
* Add i18n string
* Make credentialId optional for form schema
* Fix label
* Add cascade deletes
* Add verification that syncs belong to org
* Create mapper for repository output
* Type fixes
* Remove old test file
* Pass `attributeOptions` from parent to children
* Infer types from zod schema
* Type fixes
* Type fix
* Clean up
* Add i18n strings
* Remove unused file
* Address feedback
* Add migration file
* Address feedback
* Add validation for new integration values
* Remove unused router
* Move away from z.infer to z.ZodType
* Clean up comments
* Type fix
* Type fixes
* Type fix
* fix: add passthrough to syncFormDataSchema to preserve extra fields
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: remove incorrect test that expected extra fields to pass through syncFormDataSchema
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* Add endpoint for SF to call
* Create scratch org config
* Create sf cli scripts
* Create package logic
* Update README
* Remove unused file
* Add indexes
* Add aria label
* Address feedback - consistent validation
* Fix import paths for attribute types
* Add `CredentialRepository.findByAppIdAndKeyValue`
* Get credential by instance URL
* Verify incoming sfdc orgId matches credential sfdc orgId
* Rename method
* Get user name integration syncs
* refactor: change attributeSyncRules array to singular attributeSyncRule
The database schema enforces a one-to-one relationship between
IntegrationAttributeSync and AttributeSyncRule (via @unique constraint),
and the UI only supports a single rule. This change makes the TypeScript
type match the database schema and UI behavior.
Changes:
- Update IntegrationAttributeSync interface to use attributeSyncRule: AttributeSyncRule | null
- Update mapper to return singular rule instead of wrapping in array
- Update UI component to access sync.attributeSyncRule directly
- Update IIntegrationAttributeSyncUpdateParams Omit type
- Update tests to use attributeSyncRule: null instead of attributeSyncRules: []
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* Convert `membershipRepository.findAllByUserId` to a normal method
* Add temp files to git ignore
* Init and process team conditions
* Biome formatting
* Add `AttributeService` to get user attributes
* Add DI container for AttributeService
* AttributeSyncService evaluate attribute conditions
* Create DI container for attributeSyncService
* Return result for full condition
* Evaluate if attribute sync should apply to user
* Add method
* Change PrismaAttributeOptionRepository to instance methods
* Init AttributeSyncFieldMappingsService and process attribute syncs
* Add AttributeSyncFieldMappingService DI container
* Refactor orgId to organizationId
* Add membership validation to sync field service
* AttributeSYncFieldMappingService use repository methods
* AttributeSyncFieldMappingService.processMappings add mapping logic
* Add DI tokens
* user-sync endpoint to implement attribute syncing
* Validate team belongs to org for rule
* test: add tests for AttributeSyncRuleService, AttributeSyncFieldMappingService, and AttributeService
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* Remove duplicate migration file
* Fix merge conflict
* fix: resolve type errors in attribute sync feature (#26814)
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* Rename variable
* Fix log typo
* Fix file name
* Add error logging
* Use credential teamId
* fix: add missing mockTeamRepository and team validation to tests
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* Fix naming
* Fix file import
* Type fix
* Pass MembershipRepository as a dep in AttributeSyncFieldMappingService
* Type fix
* fix: add mockMembershipRepository to AttributeSyncFieldMappingService tests
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* Update packages/app-store/salesforce/api/user-sync.ts
Add error handling when getting orgId from stored salesforce id
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
* fix: address Cubic code review comments
- PrismaAttributeRepository: use nested select instead of include: true for options
- CredentialRepository: use this.primaClient instead of global prisma, use select instead of include for relations
- AttributeSyncFieldMappingService: optimize O(n*m) complexity with Map lookup for O(1) access
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* Fix typo in CredentialRepository
* Update README
* Update sfdx-project
* Add SFDC package tests
* fix: improve Salesforce Apex test assertions to verify actual behavior
- Enhanced CalComHttpMock to track HTTP callout invocations and capture requests
- Updated UserUpdateHandlerTest to verify HTTP callouts are made with correct data
- Updated CalComCalloutQueueableTest to verify HTTP callouts are made correctly
- Replaced System.assert(true, ...) with meaningful assertions that verify:
- Correct number of HTTP callouts
- Request body contains expected fields
- Request method is POST
Addresses Cubic AI review feedback (confidence 9/10 issues only)
Co-Authored-By: unknown <>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Hariom Balhara <hariombalhara@gmail.com>
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
* feat: add custom calendar reminder for Google Calendar events
Allows users to set default reminder notifications (10, 30, or 60 minutes)
for events created via Cal.com bookings in Google Calendar. This addresses
the issue where Google Calendar's default reminders don't apply to
API-created events.
- Add customCalendarReminder field to DestinationCalendar model
- Create reminder selector UI in destination calendar settings
- Update GoogleCalendarService to apply custom reminders (popup + email)
- Add TRPC endpoint for updating reminder settings
* fix: address code review feedback
- Use z.union with literal values (10, 30, 60) for stricter schema validation
- Add localization for toast messages using t()
- Fix test data to use null for customCalendarReminder to match test intent
* fix: add customCalendarReminder to DestinationCalendar types
Update manually-defined DestinationCalendar types to include the new
customCalendarReminder field added in the previous commit. This fixes
type mismatches when passing Prisma-persisted destination calendars to
functions using these local type definitions.
* fix: update customCalendarReminder type in test to match Prisma schema
The customCalendarReminder field is defined as a non-nullable Int with
default value of 10 in the Prisma schema. Changed test value from null
to 10 to fix TS2345 type error.
* feat: add 'just in time' reminder option for Google Calendar events
- Add 0 (just in time) as a valid reminder option alongside 10, 30, 60 minutes
- Update TRPC schema to accept 0 as valid reminder value
- Add 'Just in time' option to reminder dropdown selector UI
- Add translation for 'just_in_time' key in English locale
- Include comprehensive test case for 0-minute (just in time) reminders
- Remove unused import from test file
This addresses reviewer feedback to provide flexible 'just in time' option that allows reminders to fire at exact event start time.
🤖 Generated with Claude Code
* fix: add customCalendarReminder to calendars service mock
- Add missing customCalendarReminder field to destination calendar mock
- Matches the Prisma schema requirement
- Fixes type error in calendars controller e2e test
* fix: add customCalendarReminder to destination calendars controller test
- Add missing customCalendarReminder field to mock destination calendar
- Matches Prisma schema requirement
- Fixes type error in destination-calendars controller e2e test
* fix: cast customCalendarReminder to ReminderMinutes type
- Add type cast for reminderValue to ensure type safety
- Use nullish coalescing (??) to preserve 0 as valid reminder value
- Ensures database number type is properly cast to ReminderMinutes union
* refactor: simplify translation logic in DestinationReminderSelector
- Remove conditional check for 'just_in_time' label
- Pass count parameter to all translations uniformly
- Translation function handles unused parameters gracefully
Addresses review feedback from @Khaan25
* refactor: make custom calendar reminder opt-in and use repository pattern
- Change default from 10 to null (opt-in feature)
- Add DestinationCalendarRepository to avoid direct Prisma usage
- Add 'Use default reminders' option to UI
* refactor: remove redundant migration file
The original migration already creates customCalendarReminder as nullable,
so this second migration to make it nullable is not needed.
* fix: type error for customCalendarReminder in destination calendar settings
* refactor: validate customCalendarReminder with Zod schema instead of type casting
* refactor: use instance methods in DestinationCalendarRepository
Changed from static to instance methods with getInstance() pattern as requested in review.
* refactor: replace singleton with DI for DestinationCalendarRepository
- Remove getInstance() singleton pattern
- Add DI tokens, module, and container
- Update GoogleCalendarService and tRPC handler to use DI
---------
Co-authored-by: Volnei Munhoz <volnei@cal.com>
Co-authored-by: Keith Williams <keithwillcode@gmail.com>
Co-authored-by: Eunjae Lee <hey@eunjae.dev>
2026-01-14 12:32:00 +01:00
MorganGitHubmorgan@cal.com <morgan@cal.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix: translate location dropdown group labels in event-type settings
Co-Authored-By: morgan@cal.com <morgan@cal.com>
* fix: use requesting user's locale for team event type translations
For team event types, the current user might not be in eventType.users,
causing translations to default to English. This fix queries the user's
locale directly from the database when not found in the event type users.
Co-Authored-By: morgan@cal.com <morgan@cal.com>
* refactor: pass userLocale as parameter instead of database call
Per PR feedback, pass the authenticated user's locale as an optional
parameter to getEventTypeById instead of making an extra database call.
The locale is passed from ctx.user.locale in the tRPC handler.
Co-Authored-By: morgan@cal.com <morgan@cal.com>
* fix: provide userLocale in apiv2 getEventTypeById
* fix: remove unused ts comments
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-01-14 08:28:31 -03:00
Eunjae LeeGitHubeunjae@cal.com <hey@eunjae.dev>eunjae@cal.com <hey@eunjae.dev>eunjae@cal.com <hey@eunjae.dev>eunjae@cal.com <hey@eunjae.dev>eunjae@cal.com <hey@eunjae.dev>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat: add scope configuration for feature opt-in
Add scope field to OptInFeatureConfig that allows features to be scoped
to specific levels (org, team, user). This enables features to be shown
only at certain settings pages rather than all three.
Changes:
- Add OptInFeatureScope type with values 'org', 'team', 'user'
- Add optional scope field to OptInFeatureConfig interface
- Add getOptInFeaturesForScope helper function to filter features by scope
- Update FeatureOptInService to filter features based on scope
- Update tRPC router to pass scope parameter for org/team endpoints
Features without a scope field default to all scopes for backward compatibility.
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* feat: add scope validation to setUserFeatureState and setTeamFeatureState
- Add isFeatureAllowedForScope helper function to check if a feature is allowed for a scope
- Update setUserFeatureState to reject if feature is not scoped to 'user'
- Update setTeamFeatureState to accept scope parameter and reject if feature is not allowed
- Update tRPC router to pass scope parameter for team and org endpoints
- Fix unit test mock to include new config exports
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* feat: use ErrorWithCode for scope validation and add tests
- Replace raw Error with ErrorWithCode using ErrorCode.BadRequest
- Add comprehensive tests for setUserFeatureState scope validation
- Add comprehensive tests for setTeamFeatureState scope validation
- Test both enabled/disabled and inherit state scenarios
- Test error messages include feature ID and scope name
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* feat: improve Features menu visibility to use scope configuration
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor: remove unused hasOptInFeaturesForScope function
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: allow features not in config at all scopes (permissive default)
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: revert permissive default and mock scope validation in integration tests
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat: add tri-state UI settings pages and auto opt-in preference
TASK 5: Tri-state UI with ToggleGroup
- Create shared TeamOrgFeaturesSettings component
- Create user features settings page (features-view.tsx)
- Create team features settings page
- Create org features settings page
TASK 6: Add auto opt-in preference
- Add autoOptInExperimentalFeatures field to User and Team models
- Add migration for new fields
- Add TRPC endpoints for auto opt-in preference (using repository pattern)
- Add auto opt-in checkboxes to settings pages
Also adds i18n keys for feature opt-in UI.
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
refactor: rename autoOptInExperimentalFeatures to autoOptInFeatures
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
refactor: apply PBAC procedure pattern to featureOptIn router
- Create createTeamPbacProcedure for team-scoped endpoints
- Create createOrgPbacProcedure for organization-scoped endpoints
- Refactor all team/org endpoints to use the new PBAC procedures
- Significantly reduces boilerplate code for permission checks
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
add features pages
implement hooks
update style
update style
rename slug to featureId
show Features page on the side bar only if OPT_IN_FEATURES.length > 0
revert unncessary renaming
revert some changes
remove some changes
* fix repository usage
* test: add unit tests for PBAC utility procedures
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* feat: add 'disabled by organization' badge for Team Level Features page
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* a little clean up
* feat: add effectiveReason to computeEffectiveStateAcrossTeams for better UI feedback
- Update computeEffectiveStateAcrossTeams to return both enabled state and reason
- Add EffectiveStateReason type with 6 possible values
- Update FeatureOptInService to include effectiveReason in resolved state
- Simplify useUserFeatureOptIn.getBlockedWarning to use effectiveReason directly
- Add feature_no_explicit_enablement_warning translation
- Invalidate feature list when auto-opt-in setting changes in all hooks
* test: add tests for FeatureOptInService.listFeaturesForTeam and refactor router to use TeamRepository
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* make it clearer about auto opt in
* move hooks to apps/web/module
* fix
* fix: move types to packages/features/feature-opt-in, fix imports and test mocks
- Move types.ts from apps/web/modules/feature-opt-in/hooks to packages/features/feature-opt-in
- Update FeaturesSettings.tsx to import types from new location
- Update hooks to import types from @calcom/features/feature-opt-in/types
- Fix organization features-view import path (~/settings/organizations -> ~/ee/organizations)
- Fix PermissionCheckService mock in util.test.ts to use class syntax
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: add validation for team ID and remove isPublic from featureOptIn handler
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: resolve biome lint errors in feature-opt-in files
- Add explicit return types to functions and methods
- Replace ternary operators with if-else statements
- Replace forEach with for...of loops to avoid useIterableCallbackReturn
- Extract helper functions to reduce function complexity
- Add explicit type annotations to variables
- Move exports to end of file to satisfy useExportsLast rule
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: resolve type errors in featureOptIn router
- Replace ctx.organizationId with ctx.user.organization.id
- Add null checks for organizationId in org procedures
- Remove incorrect type annotation from featureOptInRouter
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor: address PR feedback on feature opt-in implementation
- Refactor createMutationCallbacks to useMutationCallbacks hook with useLocale internally
- Restore comment on featureOptIn prop in FeaturesSettings.tsx
- Revert getAllTeamIds helper, use ternary operator instead
- Use ctx.user.organizationId with proper guard clauses
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix type error
* feat: disable toggle when feature is blocked by higher level
- Add isBlockedByHigherLevel function to UseFeatureOptInResult interface
- Implement blocking detection for user level (org/team disabled)
- Implement blocking detection for team level (org disabled)
- Organization level never blocked (top level)
- Update FeaturesSettings to disable ToggleGroup when blocked
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* change order of toggle buttons
* feat: add policy field (permissive/strict) to feature opt-in config
- Add OptInFeaturePolicy type with 'permissive' and 'strict' modes
- Update computeEffectiveStateAcrossTeams to handle both policies:
- Permissive: user opt-in can activate; disables only win if ALL teams disable
- Strict: user opt-in alone not enough; ANY explicit disable blocks
- Add new EffectiveStateReason values for strict policy
- Update FeatureOptInService to read policy from config
- Add unit tests for all 9 policy scenarios from spec
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor: rewrite test file with scenario tables and make policy required
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix type
* fix types
* make policy required
* disable toggle group if blocked by higher level
* refactor: move PBAC procedures to packages/trpc/server/procedures
- Move util.ts to pbacProcedures.ts in procedures folder for better reusability
- Move util.test.ts to pbacProcedures.test.ts alongside the main file
- Update imports in _router.ts to use new location
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: remove redundant null checks in featureOptIn router
The createOrgPbacProcedure middleware already validates organizationId
and throws if null. Use non-null assertion (!) instead of redundant
runtime checks since the middleware guarantees the value exists.
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor: improve middleware typing to avoid non-null assertions
Remove explicit return type from createOrgPbacProcedure to let TypeScript
infer the extended context type. This allows handlers to use ctx.organizationId
directly (typed as number) instead of ctx.user.organizationId! assertions.
The middleware validates organizationId and adds it to the context, so
downstream handlers can safely access ctx.organizationId as a number.
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* feat(pbac): use featureOptIn permissions instead of generic team/org permissions
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* feat(pbac): add PBAC to team features page and pass canEdit to views
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: add effectiveReason to IFeatureOptInService and update listFeaturesForTeam interface
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: add feature_any_team_disabled to isUserBlockedByHigherLevel check
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: add strict-policy reasons to warning helper function
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: sean-brydon <55134778+sean-brydon@users.noreply.github.com>
* fix integration test
* fix: enable DI for FeatureOptInService
* create containers/FeaturesRepository.ts
* refactor: convert FeatureOptInService and FeaturesRepository to moduleLoader pattern
- Create feature-specific tokens in feature-opt-in/di/tokens.ts and flags/di/tokens.ts
- Update modules to use bindModuleToClassOnToken for type-safe dependency injection
- Simplify containers to use moduleLoader.loadModule() for automatic dependency loading
- Import feature-specific tokens in central tokens.ts using spread operator
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor: rename FeatureOptInServiceInterface to IFeatureOptInService
Follow the codebase convention of using 'I' prefix for interface files and names.
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: export featuresRepositoryModule for backward compatibility
The FeaturesRepository module was refactored to use moduleLoader pattern but
AvailableSlots.ts still imports featuresRepositoryModule. This adds the export
to maintain backward compatibility.
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-01-13 11:02:00 +01:00
sean-brydonGitHubunknown <>sean@cal.com <Sean@brydon.io>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat: add skip trial feature for teams/orgs billing page
Co-Authored-By: sean@cal.com <Sean@brydon.io>
* feat: add translation strings for skip trial feature and fix lint-staged config
Co-Authored-By: sean@cal.com <Sean@brydon.io>
* fix: use IS_TEAM_BILLING_ENABLED instead of IS_SELF_HOSTED
Co-Authored-By: sean@cal.com <Sean@brydon.io>
* fix: use correct DialogHeader props in billing-view.tsx
Co-Authored-By: sean@cal.com <Sean@brydon.io>
* restore lint staged config file
* invalidate trpc cache
* fix: update role filter and error message in skipTrialForTeam handler
- Changed role filter to include both OWNER and ADMIN roles to match authorization logic
- Updated error message to reflect that both owners and admins can skip the trial
Addresses Cubic AI review feedback on PR #26584
Co-Authored-By: unknown <>
* fix: optimize skipTrialForTeam to query only specific team by ID
Address Cubic AI review feedback: Replace findAllAcceptedTeamMemberships
(which fetches all teams) with TeamRepository.findById (which fetches
only the specific team needed). Authorization is already validated
earlier in the handler, so this redundant query was inefficient.
Co-Authored-By: unknown <>
* fix static methods
* feat: use pbac
* fix: remove redundant team query in getSubscriptionStatus handler
Co-Authored-By: sean@cal.com <Sean@brydon.io>
* add pbac to skip team handler
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-01-13 09:17:42 +00:00
Hariom BalharaGitHubhariom@cal.com <hariombalhara@gmail.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix: optimize routing form mutation to avoid costly name update triggers
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* Add load test script for form responses
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* Copy changes
* Move search bar inline with new button
* Get rid of no more results message
* Change hidden badge to (hidden)
* Remove Cal.ai badge from sidebar
* Add dropdown to create button when there is multiple options
* Fix delete dialog
* Saved filters updates
* More string fixes
* Switch members table to use names
* Fix member spacing
* Fix routing form identifier field
* Fix routing forms stuff
* Only show SMS hint on SMS options
* Make workflow delete button minimal
* Fix padding on workflow steps
* Remove min width on workflow title
* Fix delete workflow PR
* Fix org profile buttons
* Fix org profile screen partially scrolled down
* Improve logos & banner uploads
* Personal profile fixes
* Fix settings general view stuff
* Sentence case consistency
* Fix stuff I broke
* Fix fab
* Fix hidden translation string
* Fix text fields
* Make button small for solo users too
* fix: update E2E tests to match sentence case labels in routing forms
* fix: update tests to match sentence case label changes
- insights.e2e.ts: chart titles (14 strings)
- event-types.e2e.ts: Organizer phone number location
- EditLocationDialog.test.tsx: phone number labels
* fix: address Cubic AI review feedback (confidence 9+)
- Replace hardcoded text-gray-500 with text-muted in TextField.tsx hint section
- Replace text locator with data-testid in E2E test for location select
Co-Authored-By: unknown <>
* fix: update E2E tests for sentence case label changes
- Use data-testid selectors for location options (more reliable than text)
- Update field identifiers in routing-forms tests to match new labels
- Fix Long text selector in manage-booking-questions test
* fix: replace text locator with data-testid in manage-booking-questions E2E test
Replace fragile text="Long text" locator with resilient
page.getByTestId("select-option-textarea") selector per E2E best practices.
Addresses Cubic AI review feedback (confidence 9/10).
Co-Authored-By: unknown <>
* fix: use .last() for multiple location select items
---------
Co-authored-by: Pedro Castro <pedro@cal.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>