* fix: Add email verification requirement for API v1 and v2 email updates
- API v2 (/v2/me): Implement email verification check when updating primary email
- Store new email in metadata as emailChangeWaitingForVerification when verification is required
- Send verification email using sendChangeOfEmailVerification
- Allow immediate email change if new email is already a verified secondary email
- Add hasEmailBeenChanged and sendEmailVerification flags to response
- Add tests to verify email verification behavior
- Add findVerifiedSecondaryEmail method to UsersRepository
- Add PrismaFeaturesRepository to MeModule providers
- API v1 (/v1/users/{userId}): Implement same email verification logic
- Check if email-verification feature flag is enabled
- Store new email in metadata when verification is required
- Send verification email for unverified email changes
- Allow immediate change for verified secondary emails
- Preserve existing API v1 response format
- Test fixtures: Add createSecondaryEmail method to UserRepositoryFixture
This fixes the vulnerability where users could update their primary email
without verification via API endpoints.
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* update
* update
* refactor: Extract business logic to MeService and add platform-managed bypass
- Create MeService with all business logic extracted from MeController
- Update MeController to delegate to MeService (thin controller pattern)
- Add PrismaWorkerModule to MeModule imports to provide PrismaWriteService
- Add isPlatformManaged bypass: platform-managed users can update email without verification
- Fix test cleanup to use delete by ID instead of email to avoid failures when email changes
- Remove hasEmailBeenChanged and sendEmailVerification response flags per reviewer feedback
- Add comprehensive documentation to @ApiOperation describing email verification behavior
- Update tests to remove flag assertions
Addresses PR comments:
- supalarry: Extract logic to service layer
- supalarry: Allow platform-managed users to update email without verification
- supalarry: Remove response flags and document behavior in @ApiOperation instead
- cubic-dev-ai: Fix module dependency for PrismaFeaturesRepository
- cubic-dev-ai: Fix test cleanup issue
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* docs: Simplify API operation description
Remove internal implementation details about metadata staging and shorten the description to focus on API consumer behavior.
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* fix
* update
* update
* update
* remove comment
* addressed commit
* review addressed
* use repository
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-01-08 15:51:11 +00:00
chauhan_sGitHubsomay@cal.com <somaychauhan98@gmail.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>Morgan
* feat: add endpoint to add attendees to existing bookings
- Created POST /v2/bookings/:bookingUid/attendees endpoint
- Added AddAttendeesInput_2024_08_13 for input validation
- Added AddAttendeesOutput_2024_08_13 for response format
- Created BookingAttendeesService_2024_08_13 for business logic
- Created BookingAttendeesController_2024_08_13 for API endpoint
- Added validation to check for duplicate attendee emails
- Integrated with existing booking and event type repositories
- Added validateAndTransformAddAttendeesInput method to InputBookingsService
- Fixed pre-existing ESLint no-prototype-builtins warnings
- Left placeholder for custom booking field validation logic
Co-Authored-By: somay@cal.com <somaychauhan98@gmail.com>
* refactor: move booking attendee operations to dedicated repository
* refactor: move repository files into dedicated repositories directory
* feat: validate guests field availability before adding attendees to booking
* feat: migrate addAttendees API to use existing addGuests handler
* refactor: remove unused validateAndTransformAddAttendeesInput method from InputBookingsService
* refactor: rename attendees to guests in booking API endpoints and types
* refactor: rename booking-attendees to booking-guests for consistency
* WIP: add e2e tests for add booking guests endpoint
* faet: improve guest booking tests
* refactor: extract getHtml method in email templates
* feat: add email toggle support for guest invites based on OAuth client settings
* refactor: addGuests handler
* feat: add SMS notifications when adding guests to existing bookings
* refactor: rename add-attendees to add-guests for consistent terminology
* refactor: added repository pattern in addGuests.handler
* test: add attendee scheduled email spy to booking guests tests
* fix: use event type team ID instead of user org ID for booking permission check
* Update BookingEmailSmsHandler.ts
* Remove comments
* refactor: rename booking guests to booking attendees
* refactor: rename guest-related methods to use attendees terminology for consistency
* update api docs
* refactor: restructure addGuests handler to top
* refactor: update guest email format to use object structure in booking tests
* docs: clarify API version header requirement for booking attendees endpoint
* docs: add email notification details to booking attendees API documentation
* refactor: rename booking attendees to guests for consistency
* refactor: rename attendees to guests in booking API endpoints
* feat: add email validation for guest invites
* feat: improve error handling for guest booking failures
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Morgan <33722304+ThyMinimalDev@users.noreply.github.com>