Benny JooGitHubbenny@cal.com <sldisek783@gmail.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat: Cal.diy — community-driven MIT-licensed fork of Cal.com
This squashed commit contains all Cal.diy changes applied on top of calcom/cal.com main:
- Rebrand Cal.com to Cal.diy across the entire codebase
- Remove Enterprise Edition (EE) features, license checks, and AGPL restrictions
- Switch license from AGPL-3.0 to MIT
- Remove docs/ directory (migrated to Nextra at cal.diy)
- Remove dead code: org tests, EE tips, platform nav, premium username, SAML/SSO, etc.
- Clean up .env.example for self-hosted Cal.diy
- Update Docker image references to calcom/cal.diy
- Update README, CONTRIBUTING.md, and issue templates for Cal.diy community fork
- Add PR welcome bot for Cal.diy contributors
- Fix API v2 breaking changes oasdiff ignore entries
- Replace Blacksmith CI runners with default GitHub Actions
3893 files changed, 20789 insertions(+), 411020 deletions(-)
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
* refactor: remove org-specific /organizations/:orgId endpoints from API v2 atoms controllers (#1701)
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix: revert Cal.diy Inc to Cal.com, Inc. in license files, copyright notices, and package metadata (#1702)
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* rip out org related comments in api v2
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix: block localhost and loopback addresses in SSRF protection
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: block loopback IPs by hostname in SSRF protection
Add 127.0.0.1, ::1, [::1], and 0.0.0.0 to blocked hostnames list for
defense-in-depth protection against SSRF attacks targeting localhost.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Romit <romitgabani1.work@gmail.com>
Co-authored-by: Romit <85230081+romitg2@users.noreply.github.com>
* fix: join multiple Reply-To addresses as comma-separated string
Some SMTP providers (e.g., SendLayer) reject emails when Reply-To is
passed as an array to nodemailer, which serializes it as multiple
Reply-To headers. Using a comma-joined string is RFC 2822 compliant
and works universally across all SMTP providers.
Fixes#28610
* test: add unit tests for getReplyToHeader SMTP compatibility
- Verify replyTo is always returned as comma-separated string, not array
- Test single email, multiple emails, and empty email cases
- Add RFC 5322 compliance test for SMTP compatibility
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* docs: add RFC 5322 reference comment to getReplyToHeader tests
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Lawrence Christian <67164412+LCNDevs@users.noreply.github.com>
Co-authored-by: Romit <85230081+romitg2@users.noreply.github.com>
Co-authored-by: Romit <romitgabani1.work@gmail.com>
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* feat: Sink url shortner for sms workflow reminders
* fix: remove hardcoded dub values
* update .env.example
* fix: unit tests
* chore: add tests for scheduleSmsReminder and utils
* review refactor
* fix: type check
* review refactor
* fix: update test to account for smsReminderNumber fallback from main
Co-Authored-By: unknown <>
* feat: add feature flag for sink and more tests to verify
* fix: type check
* use proper feature flags for sink
* Apply suggestion from @keithwillcode
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Keith Williams <keithwillcode@gmail.com>
2026-03-16 20:51:28 +00:00
MorganGitHubmorgan@cal.com <morgan@cal.com>morgan@cal.com <morgan@cal.com>morgan@cal.com <morgan@cal.com>morgan@cal.com <morgan@cal.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat: add platform URL support for reschedule and cancel links in workflow emails
Co-Authored-By: morgan@cal.com <morgan@cal.com>
* feat: pass platform URL data to CalendarEventBuilder in workflow emails
Co-Authored-By: morgan@cal.com <morgan@cal.com>
* Revert "feat: pass platform URL data to CalendarEventBuilder in workflow emails"
This reverts commit 1d4d3623c93cd4eeeef18ffdad0597fe583b6a55.
* chore: provide platform metadat to workflow email task
* fixup! chore: provide platform metadat to workflow email task
* test: add unit tests for platform URL handling in EmailWorkflowService
Co-Authored-By: morgan@cal.com <morgan@cal.com>
* test: update WorkflowService tests to include platform params in tasker payload
Co-Authored-By: morgan@cal.com <morgan@cal.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat: make source required on EventBusyDetails for Troubleshooter display
- Make source a required property on EventBusyDetails type
- Update LimitManager to accept and store source when adding busy times
- Add user-friendly source names for all busy time types:
- 'Booking Limit' for booking limit busy times
- 'Duration Limit' for duration limit busy times
- 'Team Booking Limit' for team booking limit busy times
- 'Buffer Time' for seated event buffer times
- 'Calendar' for external calendar busy times
- Ensure all entries in detailedBusyTimes have source set
- Cover includeManagedEventsInLimits and teamBookingLimits branches
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* feat: add limit value and unit metadata to busy time sources
- Include limit value and unit in source strings for Troubleshooter display
- Booking Limit: shows as 'Booking Limit: 5 per day'
- Duration Limit: shows as 'Duration Limit: 120 min per week'
- Team Booking Limit: shows as 'Team Booking Limit: 10 per month'
- Preserves existing calendar sources (e.g., 'google-calendar')
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* feat: enhance busy time management with new limit sources
- Introduced new limit sources for busy times, including event booking and duration limits, with user-friendly titles for display.
- Updated LimitManager to accept and store detailed busy time information, including title and source.
- Refactored busy time addition logic across various services to utilize the new structure, improving clarity and maintainability.
* fixes
* feat: conditionally include source and translate busy time titles
- Add withSource parameter to conditionally include/exclude source from response
- Translate busy time titles on frontend using useLocale hook
- Source is only included when withSource=true (for Troubleshooter display)
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* feat: enhance user availability service and busy time handling
- Updated LargeCalendar component to include event ID check for enabling busy times.
- Added translation for "busy" in common.json for better user experience.
- Refactored getUserAvailability service to include new method for fetching user availability with busy times from limits.
- Introduced parseLimits function to streamline booking and duration limit parsing.
- Improved error handling in user handler for better user feedback.
* refactor: remove unnecessary timeZone: undefined from addBusyTime calls
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* feat: add buffer_time and calendar translation keys for busy times
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* feat: add event source to calendar components and improve busy time handling
- Updated EventList component to include event source in data attributes for better tracking.
- Enhanced LargeCalendar component to pass event
* fix: add missing source property to Date Override calendar event
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* fix: use 'date-override' as source for Date Override calendar events
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* Avoid type assertion
* fix: pass both bookingLimits and durationLimits to getStartEndDateforLimitCheck (#27898)
* test: add unit tests for getUserAvailabilityIncludingBusyTimesFromLimits
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* fix: pass both bookingLimits and durationLimits to getStartEndDateforLimitCheck
- Fix bug where bookingLimits || durationLimits was passed as single param
- Skip getBusyTimesForLimitChecks when eventType has no limits
- Remove as never casts, use proper typing for mock dependencies
- Replace expect.any(String) with exact ISO date assertions
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* refactor: replace loose assertions with exact values in tests
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix: address review feedback on busy time sources
- Fix t("busy") fallback to t("busy_time.busy") for correct translation lookup
- Add missing title property to buffer time entries for Troubleshooter display
- Use descriptive debug strings for buffer time source field
- Fix import ordering in LargeCalendar.tsx
Co-authored-by: Hariom Balhara <hariombalhara@gmail.com>
Co-Authored-By: unknown <>
* fix: preserve pre-existing busyTimesFromLimitsBookings from initialData
Address review feedback from @hariombalhara (comment #30, #31):
- Initialize busyTimesFromLimitsBookings from initialData instead of []
to avoid silently overwriting pre-existing data with an empty array
- Use conditional spread to only include busyTimesFromLimitsBookings
when it has a value
- Add test verifying pre-existing busyTimesFromLimitsBookings is
preserved and passed through to _getUserAvailability
- Add test verifying busyTimesFromLimitsBookings is not passed when
there are no limits and no initialData bookings
Co-authored-by: Hariom Balhara <hariombalhara@gmail.com>
Co-Authored-By: bot_apk <apk@cognition.ai>
* fix: pass fetched eventType to _getUserAvailability to avoid duplicate DB query
Addresses Devin Review comment r2863593564: the wrapper method fetches
eventType but wasn't passing it through, causing _getUserAvailability to
re-fetch the same eventType from the database.
Also adds a test verifying eventType is forwarded correctly.
Co-Authored-By: bot_apk <apk@cognition.ai>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Udit Takkar <53316345+Udit-takkar@users.noreply.github.com>
Co-authored-by: bot_apk <apk@cognition.ai>
The deleteDomain function had a 'return false' statement after
'return isDomainDeleted && isDnsRecordDeleted' which could never
be reached.
Co-authored-by: Harshith Kumar <mharshithkumar6@gmail.com>
* fix: trigger lingo.dev by removing duplicate value
* under progress
* wow this worked
* migrate schema
* fix types
* fix import for google login
* Add onboarding tests for Azure (Microsoft sign up)
* add comments back
* fix failing test
* fix: update Outlook login configuration and improve type safety in authentication adapter
- Set OUTLOOK_LOGIN_ENABLED to false in .env.example
- Refactor getServerSideProps to directly use samlTenantID and samlProductID
- Update linkAccount method in next-auth-custom-adapter for better type handling
- Remove redundant comment in next-auth-options related to Azure AD email verification
* remove log
* remove debug log from signin callback in next-auth options
* fixup
* chore: standardize naming
* chore: add primary calendar for outlook, verify email and auto link org for outlook
* chore: helper fns
* chore: implement cubic feedback
* cleanup
* chore: implement cubic feedback again
* WIP design#
* feat: login design
* fix: map identity provider names correctly
* 32px of mt
* fix: login UI
* fix: type check
* fix: fix type check again
* chore: update OAuth login tests
* fixup
* fix: bad import
* chore: update tests
* fixup
* fix: locales test
* chore: implement PR feedback and fix minor issues
* fix: revert token spreading change
* fix: merge conflicts
* chore: revert signup view changes
* fixup: bring back reverted changes because of merge conflicts
* fix: disable email input when microsoft sign in is in progress
* chore: implement cubic feedback
* cleanup: unused variables
* fix: address Cubic AI review feedback (confidence >= 9/10)
- Remove userId (PII) from log payloads in updateProfilePhotoMicrosoft.ts
- Replace text selectors with data-testid in locale.e2e.ts and oauth-provider.e2e.ts
- Restore callbackUrl redirect parameter in signup link in login-view.tsx
- Add data-testid='login-subtitle' to login page subtitle element
Co-Authored-By: unknown <>
* fix: use empty alt for decorative icon images in login view
MicrosoftIcon and GoogleIcon are decorative (adjacent to text labels),
so they should have empty alt attributes per accessibility best practices.
Co-Authored-By: unknown <>
* chore: implement cubic feedback
* cleanup
* fixup
* chore: implement PR feedback
* chore: implement feedback
* fix: address PR review feedback - type safety and centralize constants
- Replace non-null assertions (!) with proper null checks for OUTLOOK_CLIENT_ID/SECRET
- Replace `as any` casting with `Record<string, unknown>` for OAuth profile claims
- Remove non-null assertion on account.access_token by adding conditional check
- Centralize Outlook env constants in @calcom/lib/constants alongside MICROSOFT_CALENDAR_SCOPES
- Add explanatory comment for getNextAuthProviderName usage in get.handler.ts
Co-Authored-By: unknown <>
* Revert "fix: address PR review feedback - type safety and centralize constants"
This reverts commit 91ace141e6a28a23deea5897f7f9d6ad80319d84.
* chore: implement feedback
* chore: cleanup
* chore: implement feedback
* fix: merge conflicts
* fix: revert formatting-only changes in packages/lib/constants.ts
Co-Authored-By: unknown <>
* fix: revert IdentityProvider enum location change in schema.prisma
Co-Authored-By: unknown <>
* chore: implement more PR feedback
* fix: restore database-derived profileId from determineProfile in OAuth JWT
The profileId regression was identified by Cubic AI (confidence 9/10).
Previously, determineProfile's returned id was used to set profileId in the
JWT via 'profileResult.id ?? token.profileId ?? null'. A recent refactor
changed this to 'token.profileId ?? null', which drops the database-derived
profile ID. On first OAuth login (or when profile switcher is disabled),
token.profileId is likely null, so profileId would incorrectly be set to
null even though determineProfile returned a valid profile with an id.
This commit restores the correct priority chain:
visitorProfileId ?? token.profileId ?? null
Co-Authored-By: bot_apk <apk@cognition.ai>
* refactor: revert pure formatting and import reordering changes
Co-Authored-By: rajiv@cal.com <sahalrajiv6900@gmail.com>
* fix: normalize determineProfile return type to use consistent 'id' field
The determineProfile function returned a union type where one branch used
'id' and the other used 'profileId'. This caused TS2339 when destructuring
'id' from the result. Normalize the token.upId branch to also return 'id'
(mapped from token.profileId) so the return type is consistent.
Co-Authored-By: bot_apk <apk@cognition.ai>
* chore: add tests
* reveret: profileId changes should be in a separate PR
* fix: avoid logging entire existingUser object in OAuth JWT callback
Revert to logging only { userId, upId } instead of the full existingUser
object, which contains PII (email, name, identity provider details).
This restores the previous safe logging pattern.
Co-Authored-By: bot_apk <apk@cognition.ai>
* chore: remove profileId related tests
---------
Co-authored-by: amrit <iamamrit27@gmail.com>
Co-authored-by: Devanshu Sharma <devanshusharma658@gmail.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Sean Brydon <sean@cal.com>
Co-authored-by: bot_apk <apk@cognition.ai>
* feat: workflow auto translation
* tests: add unit tests
* refactor: tests and workflow
* fix: type err
* fix: type err
* fix: remove redundant index on WorkflowStepTranslation
The @@index on [workflowStepId, field, targetLocale] duplicates the @@unique
constraint on the same columns. A unique index already provides efficient
lookups, so the separate @@index adds storage overhead and write latency
without benefit.
Addresses Cubic AI review feedback (confidence 9/10).
Co-Authored-By: unknown <>
* fix: correct locale mapping when translation API returns null
Map translations with their corresponding locales before filtering to
preserve correct locale-to-translation associations. Previously, filtering
out null translations would reindex the array, causing incorrect locale
mappings when any translation in the batch failed.
Also fixes pre-existing lint warnings:
- Move exports to end of file
- Add explicit return type to processTranslations
- Replace ternary with if-else for upsertMany selection
Co-Authored-By: udit@cal.com <udit222001@gmail.com>
* fix: address review feedback for workflow auto-translation
- Add change detection before creating translation tasks
- Rename userLocale to sourceLocale in task props for clarity
- Show source language in UI with new translation key
- Extract SUPPORTED_LOCALES to shared translationConstants.ts
- Fix locale mapping bug in translateEventTypeData.ts
- Add WhatsApp translation support
- Abstract translation lookup into shared translationLookup.ts helper
- Restore if-else readability for SCANNING_WORKFLOW_STEPS
Co-authored-by: Udit Takkar <udit.takkar@cal.com>
Co-Authored-By: unknown <>
* fix: update test to use sourceLocale instead of userLocale
Co-Authored-By: unknown <>
* refactor: feedback
* fix: handle first time
* fix: tests
* fix: tests
* fix: address Cubic AI review feedback (confidence 9/10 issues)
- WhatsApp translation: Apply variable substitution using getSMSMessageWithVariables
and clear contentSid when using translated body to ensure Twilio uses the
translated text instead of the original template
- update.handler.ts: Change sourceLocale assignment from ?? to || for consistency
with tasker payload behavior (line 481)
- ITranslationService.ts: Rename methods from plural to singular naming:
- getWorkflowStepTranslations -> getWorkflowStepTranslation
- getEventTypeTranslations -> getEventTypeTranslation
Updated all call sites and tests accordingly
Co-Authored-By: unknown <>
* fix: address Cubic AI review feedback (confidence 9/10+ issues)
- Fix getSMSMessageWithVariables to handle WHATSAPP_ATTENDEE action for
locale and timezone (confidence 9/10)
- Remove WhatsApp translation feature that set contentSid to undefined
since Twilio ignores body parameter for WhatsApp and requires
pre-approved Message Templates (confidence 10/10)
Co-Authored-By: unknown <>
* fix: translatio
* Add tests: packages/features/eventTypeTranslation/repositories/EventTypeTranslationRepository.test.ts
Generated by Paragon from proposal for PR #27087
* Add tests: packages/features/tasker/tasks/translateWorkflowStepData.test.ts
Generated by Paragon from proposal for PR #27087
* chore: nit
* chore: verfied atg
* fix: set sourceLocale for new steps, add shouldDirty to checkbox, remove spec docs
- Set sourceLocale fallback in addedSteps mapping to fix stale detection mismatch
- Add { shouldDirty: true } to autoTranslateEnabled checkbox onChange
- Remove specs/workflow-translation/ directory (planning docs, not for repo)
Co-authored-by: Udit Takkar <udit.07.takkar@gmail.com>
Co-Authored-By: unknown <>
* chore: add specs back
* fix: type error
* fix: type error
* fix: type err
* fix: tests
* refactor: feedback
* fix: type err
* refactor
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Udit Takkar <udit.takkar@cal.com>
Co-authored-by: Udit Takkar <udit.07.takkar@gmail.com>
* fix(caldav): use consistent UIDs and inject VTIMEZONE in iCalendar output
Two remaining CalDAV interop issues from #9485:
1. UID consistency: use the booking's canonical UID (event.uid) instead
of always generating a new random UUID. CalDAV servers use UID as the
event identifier — different UIDs cause duplicate calendar entries.
2. VTIMEZONE injection: the ics library generates UTC times with no
VTIMEZONE block. CalDAV servers like Fastmail read this as UTC and
send scheduling emails with wrong times. Per RFC 5545 §3.6.5,
DTSTART with TZID requires a matching VTIMEZONE component. We now
build a proper VTIMEZONE using binary-searched DST transitions for
the event's year, handling Northern/Southern hemisphere correctly.
* fix: use pre-transition offset for VTIMEZONE DTSTART per RFC 5545
The DTSTART in VTIMEZONE components must represent the local time
interpreted with the pre-transition offset (TZOFFSETFROM), not the
post-transition offset. For example, US Eastern spring forward DTSTART
should be 02:00 (EST), not 03:00 (EDT).
* Remove comments on UID handling in createEvent
Removed comments about UID handling for calendar events.
* Revise injectVTimezone documentation
Update injectVTimezone function documentation to clarify UTC handling.
---------
Co-authored-by: Anik Dhabal Babu <81948346+anikdhabal@users.noreply.github.com>
* refactor: apply biome formatting to small packages + packages/lib
Format packages/sms, packages/prisma, packages/platform/libraries,
packages/platform/examples, packages/platform/types, packages/emails,
and packages/lib.
Excludes packages/platform/examples/base/src/pages/[bookingUid].tsx
due to pre-existing lint errors.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* revert: remove packages/platform formatting changes
Revert biome formatting for packages/platform as requested.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-13 07:39:01 -03:00
Eunjae LeeGitHubeunjae@cal.com <hey@eunjae.dev>eunjae@cal.com <hey@eunjae.dev>cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
* factory and statergie
* chore: use correct method of DI
* feat: add onchagne
* add logic to HWM stat
* add webhook resolver methods to each statergy
* move seat tracking + webhooks over to own statergy
* Move to factory base approach
* move logic to correct class
* rename create -> createByTeamId
* fix: remove debug `true ||` overrides from IS_STRIPE_ENABLED and IS_TEAM_BILLING_ENABLED
Remove accidentally committed debug overrides that short-circuited
IS_STRIPE_ENABLED and IS_TEAM_BILLING_ENABLED to always be true,
bypassing Stripe credential checks. This would break self-hosted
instances without Stripe configured.
Identified by cubic (https://cubic.dev)
Co-Authored-By: unknown <>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-02-10 13:11:36 -03:00
Benny JooGitHubbenny@cal.com <sldisek783@gmail.com>benny@cal.com <sldisek783@gmail.com>benny@cal.com <sldisek783@gmail.com>benny@cal.com <sldisek783@gmail.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* refactor: move repositories from lib to features domain folders
- Move HolidayRepository to features/holidays/repositories
- Move PrismaTrackingRepository to features/bookings/repositories
- Move PrismaBookingPaymentRepository to features/bookings/repositories
- Move PrismaRoutingFormResponseRepository to features/routing-forms/repositories
- Move PrismaAssignmentReasonRepository to features/assignment-reason/repositories
- Move VerificationTokenRepository to features/auth/repositories
- Move WorkspacePlatformRepository to features/workspace-platform/repositories
- Move DTO files to their respective feature domains
- Merge lib DestinationCalendarRepository into features version
- Merge lib SelectedCalendarRepository into features version
- Update all import paths across the codebase
This follows the vertical slice architecture pattern by organizing
repositories by domain rather than by technical layer.
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
* fix: update VerificationTokenService import path to new location
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
* fix: update test file imports to use new repository locations
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
* mv
* fix structure
* fix
* refactor: merge unit tests for SelectedCalendarRepository into single file
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-02-09 08:41:04 -03:00
Benny JooGitHubbenny@cal.com <sldisek783@gmail.com>benny@cal.com <sldisek783@gmail.com>benny@cal.com <sldisek783@gmail.com>benny@cal.com <sldisek783@gmail.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix: use LOGO constant for generic OG image instead of hardcoded value
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
* test: add unit tests for OgImages module
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
* fix: remove unused LOGO import from OgImages test
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
* fix
* test: update OgImages tests to reflect LOGO_DARK constant
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
* add comment
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-02-06 14:19:00 +00:00
Pedro CastroGitHubDevin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Validates webhook URLs on create and update:
- HTTPS required (HTTP allowed for self-hosted and E2E)
- Blocks private IP ranges and localhost
- Blocks cloud metadata endpoints
Existing webhooks are preserved: validation only applies when URL is created or changed.
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat: add delayed formbricks tracking for feature opt-in
Adds delayed Formbricks survey tracking for feature opt-in. When a user
opts into a feature, this allows triggering a Formbricks action after a
configurable delay (e.g., 24 hours later) to collect feedback once
they've had time to use the feature.
Key changes:
- Added `formbricks` config option to `OptInFeatureConfig` interface
with `actionName` and `delayMs` properties
- Created `useFormbricksOptInTracking` hook that handles the delayed
tracking logic
- Added `isFeatureTracked` / `setFeatureTracked` storage helpers to
prevent duplicate tracking
- Integrated the tracking hook into `useFeatureOptInBanner`
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* upgrade formbricks
* feat: replace formbricks popup with custom feedback dialog
Instead of using Formbricks' built-in popup, we now show a custom
Cal.com-styled feedback dialog that submits responses directly to
Formbricks API via tRPC mutation.
- Add FeedbackDialog component with emoji rating selector
- Add feedback tRPC router for server-side Formbricks submission
- Update useFormbricksOptInTracking to return dialog state
- Add survey config fields (surveyId, questions) to config
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* feat: position feedback dialog at bottom-right corner
- Use base-ui Dialog primitives for custom positioning
- Position dialog at bottom-right to avoid Intercom overlap
- Use z-index 10000 (below Intercom's high z-index)
- Keep blocking backdrop for modal behavior
- Use i18n keys for title/description
- Add survey IDs for bookings-v3 feedback
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* feat: add i18n keys for feedback dialog title/description
Allow each feature to specify custom i18n keys for the feedback dialog
title and description via the formbricks config.
- Add titleKey/descriptionKey to formbricks config interface
- Pass i18n keys through feedbackDialogProps
- Add bookings_v3_feedback_title/description translation keys
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* refactor: move FeedbackDialog into FeatureOptInBannerWrapper
Better encapsulation - consumers of the feature opt-in banner
no longer need to handle the feedback dialog separately.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* feat: add 5 second delay before showing feedback dialog
Ensures the page has time to finish loading before showing
the feedback dialog, avoiding showing it while skeletons
are still visible.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* refactor: simplify feedback dialog UI
- Remove redundant question labels
- Add "(optional)" to comment placeholder
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* fix: remove emoji button borders and add footer gap
- Remove borders from rating emoji buttons
- Add proper gap between textarea and footer (pb-4)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* fix: delayMs is opt-in waiting period, not setTimeout delay
delayMs represents the minimum time that must pass since opt-in
before showing the feedback form (e.g., 3 days). If not enough
time has passed, we skip showing the form entirely instead of
setting a long setTimeout.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* feat: custom feedback dialog for feature opt-in
- Replace Formbricks popup with Cal.com-styled dialog
- Add configurable delay (waitAfterDays) before showing feedback
- Position dialog at bottom-right, non-blocking
- Add localStorage tracking to prevent duplicate feedback
- Add device targeting (showOn: desktop/mobile/all)
- Create tRPC endpoint for Formbricks API submission
- Use proper logger for error handling
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* refactor: rename tracking terminology to feedback
- Rename useFormbricksOptInTracking → useOptInFeedback
- Rename FormbricksOptInTrackingResult → OptInFeedbackState
- Rename formbricksTracking property → feedback
- Rename FormbricksTrackingState → FeedbackState
We no longer "track" events to Formbricks. Instead, we show
our custom feedback dialog when conditions are met.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* fix: set waitAfterDays to 3 for production feedback delay
Co-Authored-By: unknown <>
* fix: update formbricks JS SDK usage for v3.0.0
The @formbricks/js SDK v3.0.0 changed its API:
- setup() no longer accepts debug, userId, or attributes
- Use setUserId() and setAttributes() after setup instead
- track() now expects { hiddenFields: ... } or undefined
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix: avatar URL breaking for team/orgs in booker embed
* fix: api v2 breaking because of type mismatch
* fix: atoms build
* chore: implement PR feedback
* feat: add redirect option for non-routing form bookings
Add a new event type option that redirects to a custom URL when the booking
was not made through a routing form (no cal.routingFormResponseId or
cal.queuedFormResponseId query parameters).
Changes:
- Add redirectUrlOnNoRoutingFormResponse field to EventType schema
- Add UI toggle in Advanced tab to configure the redirect URL
- Implement redirect logic in bookingSuccessRedirect hook
- Add translations for new UI strings
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: add redirectUrlOnNoRoutingFormResponse to test builder
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: add redirectUrlOnNoRoutingFormResponse to BookerEvent type
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: add redirectUrlOnNoRoutingFormResponse to getPublicEventSelect
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: add redirect logic to getServerSideProps for non-routing form bookings
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: remove redirectUrlOnNoRoutingFormResponse from booking success flow
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: use 'in' operator for type narrowing on redirectUrlOnNoRoutingFormResponse
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: exclude redirectUrlOnNoRoutingFormResponse from test assertions
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: include redirectUrlOnNoRoutingFormResponse in test assertions and update description
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: add redirectUrlOnNoRoutingFormResponse to mockUpdatedEventType
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: remove redirect logic from instant meetings
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: add redirectUrlOnNoRoutingFormResponse to EventTypeRepository select
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: add redirectUrlOnNoRoutingFormResponse to form default values
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* Reword string
* fix: bust tRPC cache for redirectUrlOnNoRoutingFormResponse
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: guard redirect when rescheduleUid or bookingUid is present
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: add redirectUrlOnNoRoutingFormResponse to dynamicEvent defaults
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: add bookingUid guard to team getServerSideProps redirect
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Adds encrypted credential storage using a new keyring system:
- New `encryptedKey` column with AES-256-GCM encryption
- Decryption in getCalendarsEvents with fallback to legacy `key`
- buildCredentialCreateData service for credential creation
- Phase 1: Google Calendar only, other integrations follow
2026-01-30 09:15:13 -03:00
Benny JooGitHubbenny@cal.com <sldisek783@gmail.com>benny@cal.com <sldisek783@gmail.com>benny@cal.com <sldisek783@gmail.com>benny@cal.com <sldisek783@gmail.com>benny@cal.com <sldisek783@gmail.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* chore: save progress
* chore:
* feat: add input dialog
* fix: type error
* feat: mass apply dialog
* test: per host location
* test: fix test
* fix: address Cubic AI review feedback (confidence >= 9/10)
- Remove PII (address, phone number) from tracing logs in RegularBookingService.ts
- Constrain HostLocation.type to EventLocationType["type"] for compile-time validation
Co-Authored-By: unknown <>
* fix: translation
* refactor: improvements
* fix: correct grammar in custom host locations tooltip
Change 'custom host locations is enabled' to 'custom host locations are enabled' (plural subject requires plural verb).
Addresses Cubic AI review feedback (confidence 9/10).
Co-Authored-By: unknown <>
* refactor: improvements
* fix: auth
* fix: check
* refactor: improvements
* fix: address Cubic AI review feedback (confidence >= 9/10)
- Add scheduleId to newly created hosts in update.handler.ts to persist
host-specific schedules during create operations
- Change host location deletion filter from !host.location to
host.location === null to only delete when explicitly set to null
- Fix static-link per-host locations to use actual link instead of type
in locationBodyString for bookingLocationService.ts
Co-Authored-By: unknown <>
* fix: preserve existing host scheduleId when not explicitly provided
Change scheduleId handling for existing hosts from 'host.scheduleId ?? null'
to 'host.scheduleId === undefined ? undefined : host.scheduleId' so that
when the client doesn't provide a scheduleId, the existing value is preserved
instead of being cleared to null.
Co-Authored-By: unknown <>
* fix; type erro
* fix; type erro
* fix; type erro
* refactor: move repository
* refactor: move repository
* fix: add singular/plural translations for location_applied_to_hosts
Addresses Cubic AI review feedback (confidence 9/10) to fix '1 hosts' rendering as '1 host' by using i18next plural format with _one and _other suffixes.
Co-Authored-By: unknown <>
* refactor: feedback
* fix: type err
* fix: use uuid in schema and remove attendee locaiton
* fix: type err
* fix: type err
* fix: validate eventTypeId as integer in massApplyHostLocation schema
Co-Authored-By: unknown <>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
## What does this PR do?
Follow-up to #27085 and #27092 - creates the database migration to drop the deprecated `startTime` and `endTime` columns from the `users` table.
These columns were marked as `// DEPRECATED - TO BE REMOVED` in the Prisma schema. The prerequisite PRs removed all code references to these columns, making it safe to now drop them from the database.
**Changes:**
- Remove `startTime` and `endTime` fields from the `User` model in `schema.prisma`
- Add migration to drop both columns from the `users` table
- Remove `startTime` and `endTime` from test builder (`packages/lib/test/builder.ts`)
## Mandatory Tasks (DO NOT REMOVE)
- [x] I have self-reviewed the code (A decent size PR without self-review might be rejected).
- [x] I have updated the developer docs in /docs if this PR makes changes that would require a [documentation change](https://cal.com/docs). N/A - internal schema cleanup
- [x] I confirm automated tests are in place that prove my fix is effective or that my feature works. N/A - schema migration only, existing tests should continue to pass
## How should this be tested?
1. Verify PRs #27085 and #27092 have been merged (prerequisite)
2. Run `yarn prisma generate` - should complete without errors
3. Run `yarn type-check:ci --force` - should pass (no code references these columns anymore)
4. Apply migration to a test database and verify columns are dropped
## Checklist
- [x] My code follows the style guidelines of this project
- [x] I have checked if my changes generate no new warnings
## Human Review Checklist
- [ ] Confirm PRs #27085 and #27092 are merged before merging this PR
- [ ] Verify no remaining code references to `user.startTime` or `user.endTime` in the codebase
- [ ] ⚠️ **Breaking change**: This permanently drops data from the `users` table. Ensure no external systems depend on these columns.
---
Link to Devin run: https://app.devin.ai/sessions/c5a10684d905496fbce66a0b464a73a5
Requested by: @emrysal
* feat(flags): add @Memoize and @Unmemoize decorators for declarative caching
- Add @Memoize decorator for caching method results with Zod validation
- Add @Unmemoize decorator for cache invalidation on mutations
- Create UserFeatureRepository using decorators as example implementation
- Add comprehensive tests with 80%+ coverage (19 tests)
- Add DI module and tokens for UserFeatureRepository
- Enable experimentalDecorators in packages/features/tsconfig.json
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor(cache): use lazy Redis lookup in decorators
- Decorators now access Redis via getRedisService() instead of this.redis
- UserFeatureRepository no longer has redis property or direct redis calls
- findByUserIdAndFeatureIds now uses decorated findByUserIdAndFeatureId
- DI module simplified to only pass prisma dependency
- Tests updated to call setRedisService() in beforeEach
This ensures the repository only knows about Prisma, with all caching
handled transparently by the decorators.
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* feat(flags): add FeatureRepository and TeamFeatureRepository with decorator-based caching
- Add FeatureRepository with @Memoize decorators for findAll, findBySlug, getFeatureFlagMap
- Add TeamFeatureRepository with @Memoize/@Unmemoize decorators for all CRUD operations
- Add comprehensive Zod schemas for Feature, TeamFeatures, and AppFlags validation
- Add DI modules and tokens for both repositories
- Add comprehensive test coverage (33 tests) for both repositories
- Maintain backward compatibility with existing FEATURES_REPOSITORY tokens
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor(cache): use DI container pattern for Redis service
- Create packages/features/di/containers/Redis.ts with getRedisService()
- Update Memoize and Unmemoize decorators to import from DI container
- Remove setRedisService() and IRedisService from types.ts exports
- Update all tests to mock the container's getRedisService
- Fix import ordering issues from biome
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor(cache): remove barrel import and add root-level cache export
- Remove packages/features/cache/decorators/index.ts barrel file
- Add packages/features/cache/index.ts as root-level export for cache feature
- Update repository imports to use direct imports from source files
- Follows the pattern: avoid barrel imports at nested levels, keep at feature root
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor(flags): minimize repository methods and address PR feedback
- Remove unnecessary methods from FeatureRepository, TeamFeatureRepository, and UserFeatureRepository
- Keep only methods needed by FeatureOptInService
- Update imports to use @calcom/features/cache public API instead of relative paths
- Handle redis.del() errors gracefully in Unmemoize decorator
- Update tests to match simplified repositories
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor(cache): use Promise.allSettled for cache invalidation
Cleaner approach than Promise.all with individual .catch() handlers
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* feat(flags): add setAutoOptIn methods and replace featuresRepository usage in _router.ts
- Add setAutoOptIn method to TeamFeatureRepository with @Unmemoize decorator
- Add setAutoOptIn method to UserFeatureRepository with @Unmemoize decorator
- Replace featuresRepository usage in featureOptIn/_router.ts with new repositories
- TeamFeatureRepository.setAutoOptIn unmemoizes KEY.autoOptInByTeamId(teamId)
- UserFeatureRepository.setAutoOptIn unmemoizes KEY.autoOptInByUserId(userId)
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor(flags): use DI containers for TeamFeatureRepository and UserFeatureRepository
- Create TeamFeatureRepository.ts container with getTeamFeatureRepository()
- Create UserFeatureRepository.ts container with getUserFeatureRepository()
- Update _router.ts to use DI containers instead of direct instantiation
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor(feature-opt-in): use DI containers for FeatureOptInService dependencies
- Update FeatureOptInService to use IFeatureOptInServiceDeps with 3 repositories
- Add helper functions teamFeatureToState() and userFeatureToState()
- Update DI module to use depsMap pattern with featureRepo, teamFeatureRepo, userFeatureRepo
- Create FeatureRepository container file
- Replace all FeaturesRepository method calls with new repository methods
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* test(feature-opt-in): update FeatureOptInService tests for new IFeatureOptInServiceDeps interface
- Update mock structure to use featureRepo, teamFeatureRepo, userFeatureRepo
- Add helper functions createMockTeamFeature and createMockUserFeature
- Update all test cases to use new repository method names
- Add explicit types to satisfy biome lint rules
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor(flags): use DTOs at repository boundaries to prevent Prisma type leakage
- Create FeatureDto, TeamFeaturesDto, UserFeaturesDto in packages/lib/dto/
- Update repository interfaces to return DTOs instead of Prisma types
- Add toDto() transformation methods in repository implementations
- Update FeatureOptInService to use DTOs instead of Prisma types
- Follow data-dto-boundaries.md guidelines for architectural boundaries
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix(flags): update TeamFeatureRepository tests to match DTO structure
Remove assignedAt from test mock data since TeamFeaturesDto only includes:
teamId, featureId, enabled, assignedBy, and updatedAt
Co-Authored-By: unknown <>
* fix(cache): make Redis failures non-blocking in @Memoize decorator
Wrap Redis get and set operations in try-catch blocks to ensure
Redis failures don't break the application flow. If cache read fails,
proceed to fetch from source. If cache write fails, silently ignore
and return the result.
Co-Authored-By: unknown <>
* fix(cache): add logging for Redis failures and remove barrel import
- Add warning logs for Redis failures in @Memoize and @Unmemoize decorators
- Remove packages/lib/dto/index.ts barrel import file
- Update all imports to use direct file paths instead of barrel imports
Co-Authored-By: unknown <>
* fix(cache): sanitize log messages to avoid exposing sensitive data
- Remove cacheKey from log messages (may contain PII like user/team IDs)
- Log only error.message instead of raw error objects
- Addresses Cubic AI feedback (confidence 9/10)
Co-Authored-By: unknown <>
* sanitize log
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Volnei Munhoz <volnei@cal.com>
* feat: add seat tracking infrastructure for monthly proration
Add seat change logging infrastructure with operationId for idempotency.
This PR adds the foundation for monthly proration billing by tracking
seat additions and removals, gated behind the monthly-proration feature flag.
- Add operationId field to SeatChangeLog for idempotency
- Update SeatChangeLogRepository to support upsert with operationId
- Add feature flag guard in SeatChangeTrackingService
- Integrate seat tracking in team member invites
- Integrate seat tracking in bulk user deletions
- Integrate seat tracking in team service operations
- Integrate seat tracking in DSYNC user creation
When monthly-proration feature flag is disabled, seat logging is skipped
and behavior remains unchanged.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* feat: add monthly proration processing
Add monthly proration billing processing that works on top of the seat
tracking infrastructure. This PR implements the core proration logic,
webhook handlers, and integration with Stripe billing.
- Enhance MonthlyProrationService to process seat change logs
- Add payment webhook handlers (invoice.payment_succeeded, invoice.payment_failed)
- Update subscription webhook to sync billing period on renewals
- Update TeamBillingService to skip real-time updates when proration enabled
- Enhance StripeBillingService with proration capabilities
- Add Tasker enhancements for processing queues
- Update team creation/upgrade routes
Depends on: feat/monthly-proration-seat-tracking
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* fix: remove unused logger from SeatChangeTrackingService
* fix: description for calculation
* fix null check on trial
* chore: no more prisma calls
* add feature flag check
* fix stub
---------
Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-01-22 11:23:38 +00:00
Amit SharmaGitHubunknown <>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat: store utm params in stripe on signup
* fix: fallback to cookie when query params don't contain valid UTM data
Changed from else-if to separate if statement so that when query
params exist but don't contain valid UTM data, the cookie fallback
is still tried. Previously, any request with non-UTM query params
would skip the stored cookie data entirely.
Co-Authored-By: unknown <>
* fix: e2e
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix: prevent CalDAV duplicate invitations with RFC-compliant SCHEDULE-AGENT
Fixes#9485
Adds SCHEDULE-AGENT=CLIENT to ATTENDEE lines in CalDAV createEvent and
updateEvent operations per RFC 6638 Section 7.1. This tells CalDAV servers
(Fastmail, NextCloud, etc.) that the client handles scheduling, preventing
duplicate invitation emails.
Implementation includes:
- RFC 5545 compliant line folding (max 75 octets per line)
- UTF-8 aware byte counting for international names
- Proper handling of :mailto: format in ATTENDEE lines
- Skips lines that already have SCHEDULE-AGENT parameter
* fix: address Cubic review - unfold lines and case-insensitive matching
- Add unfoldLines() to handle RFC 5545 folded lines before processing
- Use case-insensitive regex (gim flag) per RFC 5545 spec
- Simplify regex to properly capture params and value separately
* fix: only unfold/refold ATTENDEE lines, preserve other lines
- Match ATTENDEE lines including folded continuations
- Unfold only the matched ATTENDEE line
- Re-fold after adding SCHEDULE-AGENT=CLIENT
- Other iCal lines remain untouched (no RFC 5545 violation)
* fix: check SCHEDULE-AGENT only in params, not value
Only check for existing SCHEDULE-AGENT in the params portion,
not the value (which contains email/CN). This prevents false
positives when email contains "schedule-agent" substring.
* fix: handle quoted colons and exact SCHEDULE-AGENT matching
1. Colon parsing: Match :mailto:/:http:/:urn: patterns, or fallback
to finding colon not inside quotes
2. SCHEDULE-AGENT check: Use regex to match exact parameter name
(preceded by ; or at start), not substring match
* add tests
* Update .env.example
---------
Co-authored-by: Anik Dhabal Babu <adhabal2002@gmail.com>
Co-authored-by: Anik Dhabal Babu <81948346+anikdhabal@users.noreply.github.com>
* fix: make linting required for CI
- Remove continue-on-error from lint workflow so CI fails on lint errors
- Fix 2 lint errors: avoid importing from @trpc/server in lib package
- Add trpcErrorUtils.ts to handle TRPC errors without circular dependencies
- Update lint-staged to show warnings but not block commits
Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com>
* fix: add message field validation to isTRPCErrorLike type guard
Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-01-21 15:01:37 -03:00
Peer RichelsenGitHubpeer@cal.com <peer@cal.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>Volnei Munhozcubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
* feat: add Cloudflare URL Scanner integration for malicious URL detection
- Add MALICIOUS_URL_IN_WORKFLOW to LockReason enum
- Add URL_SCANNING_ENABLED constant for feature flag
- Create urlScanner.ts utility for Cloudflare Radar URL Scanner API
- Create scanWorkflowUrls task for async URL scanning with polling
- Integrate URL scanning into scanWorkflowBody task
- Add URL scanning for event type redirect URLs
- Lock user accounts when malicious URLs are detected
- Fix pre-existing lint issues (parseInt radix, optional chaining)
Co-Authored-By: peer@cal.com <peer@cal.com>
* fix: address biome lint warnings and TypeScript iterator errors
- Wrap iterators with Array.from() to fix TS2802 errors
- Add biome-ignore comments for process.env usage
- Extract helper functions to reduce function length
- Move exports to end of file per useExportsLast rule
- Remove problematic imports that cause TypeScript errors
Co-Authored-By: peer@cal.com <peer@cal.com>
* fix: address cubic-dev-ai review comments for URL scanning
- Fix P0: Re-fetch workflow steps before scheduling notifications to use actual verifiedAt values from database instead of overriding with new Date()
- Fix P1: Mark workflow step as verified in submitWorkflowStepForUrlScanning when URL scanning is disabled or no URLs found
- Fix P1: Add whitelistWorkflows parameter to submitUrlForUrlScanning for consistency
- Fix P2: Preserve URL context in error results in urlScanner.ts scanUrls function
Co-Authored-By: peer@cal.com <peer@cal.com>
* fix: add select clause to Prisma query for workflow steps
Address cubic-dev-ai P2 comment: Use select to fetch only the required
fields (id, action, sendTo, emailSubject, reminderBody, template, sender,
verifiedAt) instead of fetching all columns from workflowStep table.
Co-Authored-By: peer@cal.com <peer@cal.com>
* fix: add select clause to Prisma query in scanWorkflowBody.ts
Address cubic-dev-ai P2 review comment: Use select to fetch only the
required fields (id, action, sendTo, emailSubject, reminderBody,
template, sender, verifiedAt) instead of fetching all columns.
Co-Authored-By: peer@cal.com <peer@cal.com>
* test: add unit tests for URL scanning functionality
- Add tests for urlScanner.ts (extractUrlsFromHtml, isUrlScanningEnabled)
- Add tests for scanWorkflowUrls.ts (happy/unhappy paths for URL scanning task)
- Add tests for scanWorkflowBody.ts (happy/unhappy paths for workflow body scanning)
Tests cover:
- URL extraction from HTML content
- URL normalization and deduplication
- Handling of malicious URLs and user locking
- Fail-open behavior for API errors
- Whitelisted user handling
- Iffy spam detection integration
Co-Authored-By: peer@cal.com <peer@cal.com>
* test: remove incomplete test that provides no value
Removed the 'should mark all steps as verified when neither Iffy nor URL scanning is enabled' test as it used vi.doMock() which doesn't work after module import, had no assertions, and gave false confidence in test coverage.
Co-Authored-By: peer@cal.com <peer@cal.com>
* refactor: use Cloudflare bulk scanning endpoint to reduce API quota usage
- Added submitUrlsForBulkScanning function that uses /urlscanner/v2/bulk endpoint
- Updated scanUrls to use bulk submission instead of individual URL submissions
- Bulk endpoint accepts up to 100 URLs per request, batching is handled automatically
- Reduces API quota usage as suggested by keithwillcode
Co-Authored-By: peer@cal.com <peer@cal.com>
* Update packages/features/tasker/tasks/scanWorkflowUrls.ts
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
* fix: address cubic-dev-ai review comments
- P1: Sanitize URLs before logging to prevent exposing sensitive query parameters
- P2: Extract handleUrlScanningForStep helper function to reduce code duplication
- P2: Use vi.stubGlobal for fetch mock in tests for proper cleanup
Co-Authored-By: peer@cal.com <peer@cal.com>
* fix: address volnei review comments on PR #26387
- Move vi.unstubAllGlobals() to afterEach hook in iffyScanBody tests
- Restore updateMany optimization when URL scanning is disabled
Co-Authored-By: peer@cal.com <peer@cal.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Volnei Munhoz <volnei@cal.com>
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
* fix: use WEBAPP_URL for booking URLs when domains differ
For EU deployments where WEBAPP_URL (app.cal.eu) differs from
WEBSITE_URL (cal.com), use WEBAPP_URL for non-org booking URLs.
This fixes incorrect bookingUrl in API responses for EU instance.
* Created new shared utility getTldPlus1 and updated code to use shared function instead of inline copy
* use same comment
2026-01-20 12:48:30 +00:00
Volnei MunhozGitHubDevin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat: hide navigation when ?standalone=true URL parameter is present
Co-Authored-By: peer@cal.com <peer@cal.com>
* feat: standalone page config to use in companion
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: peer@cal.com <peer@cal.com>
* fix init
* remove comment
* fix to v2
* type fix
* edge case
* test fix to suit the date storage method
* fix for atoms
* backward compatibility
* fix test mock
* test fix?
* testing a theory
* address cubic
2026-01-19 10:41:53 +02:00
MorganGitHubDevin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
- Test that params are properly passed to async tasker methods
- Test that params are passed in correct order
- Test fallback to sync tasker when async tasker fails
- Test params are passed correctly to sync tasker fallback
- Test error handling when both taskers fail
- Test logging of dispatch information with args
- Test behavior when async tasker is disabled (missing env vars)
- Test error details logging
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-01-18 11:06:43 +00:00
Anik Dhabal BabuGitHubanik@cal.com <adhabal2002@gmail.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>Morgan
* refactor: calEventParser CalendarEvent ISP
* update
* fix: complete CalEventParser ISP refactoring - update call sites and fix type errors
- Update getUid call sites to pass only uid instead of whole CalendarEvent
- Update getLocation call sites to pass narrow shape with videoCallData, additionalInformation, location, uid
- Update narrow input shapes to accept null for location (matching CalendarEvent type)
- Update recurringEvent type to accept RecurringEvent | null instead of boolean
- Update videoCallData type to be more flexible ({ type?: string; url?: string })
- Fix ManageLink.tsx to pass recurringEvent directly instead of converting to boolean
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* test: update CalEventParser tests to use narrow input shapes
- Update getPublicVideoCallUrl test to pass uid instead of calEvent
- Update getVideoCallPassword tests to pass videoCallData instead of calEvent
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* few fix
* fix type error
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Morgan <33722304+ThyMinimalDev@users.noreply.github.com>
2026-01-17 10:40:01 +05:30
sean-brydonGitHubsean@cal.com <Sean@brydon.io>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat: monthly-proration-taskerh
* remove cronjob from tasker implementation
* feat: add DI for MonthlyProrationService and TriggerDevLoggerServiceModule
- Create TriggerDevLoggerServiceModule for DI injection of TriggerDevLogger
- Add tokens for TriggerDevLogger in shared.tokens.ts
- Create MonthlyProrationService DI module and container
- Update processMonthlyProrationBatch.ts to use DI container
- Use redactError in Tasker.ts to avoid logging sensitive information
Co-Authored-By: sean@cal.com <Sean@brydon.io>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix(event-types): keep slug in sync with title until manually edited
Changed from checking `touchedFields` to `dirtyFields` when deciding
whether to sync the slug with the title. This fixes the issue where
merely focusing on the slug field would stop the sync, even if the
user didn't actually edit it.
Now the slug stays in sync with the title until the user actually
modifies the slug value.
Note: The hardcoded "Slug" label for platform users was preserved from
the original code. Localizing it would be a separate enhancement.
Fixes#26265
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* fix: add ensureProtocol helper to handle URLs without protocol
Some container orchestration tools (like Coolify) strip the protocol
from URL environment variables. This causes `new URL()` to throw
`ERR_INVALID_URL` because strings like "sub.domain.com" are invalid
without a protocol prefix.
This fix adds an `ensureProtocol` helper function that:
- Returns empty string for null/undefined URLs
- Preserves URLs that already have http:// or https://
- Prepends https:// to URLs missing the protocol
Applied to WEBAPP_URL, WEBSITE_URL, and CAL_URL env var parsing.
Fixes#25774
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Clarify URL protocol handling in comments
Updated comment to clarify handling of URLs.
* Refactor slug handling in CreateEventTypeForm
---------
Co-authored-by: simiondolha <simiondolha@users.noreply.github.com>
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Anik Dhabal Babu <81948346+anikdhabal@users.noreply.github.com>