e073cbd5ea54d59cd8a2bfa8e0287587d5aa692c
4
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
66c5f810ea |
fix: remove singular query that was using slow OR query (#24715)
## What does this PR do? <!-- Please include a summary of the change and which issue is fixed. Please also include relevant motivation and context. List any dependencies that are required for this change. --> Removes and replaces the singular query that was still using the slow OR query from prisma. It was mainly used on the public booking page and triggered after someone entered their email (600ms debounce delay). ## Visual Demo (For contributors especially) Internal change only nothing changes on the UI or business logic. #### Video Demo (if applicable): N/A #### Image Demo (if applicable): N/A ## Mandatory Tasks (DO NOT REMOVE) - [x] I have self-reviewed the code (A decent size PR without self-review might be rejected). - [x] I have updated the developer docs in /docs if this PR makes changes that would require a [documentation change](https://cal.com/docs). If N/A, write N/A here and check the checkbox. - [x] I confirm automated tests are in place that prove my fix is effective or that my feature works. ## How should this be tested? <!-- Please describe the tests that you ran to verify your changes. Provide instructions so we can reproduce. Please also list any relevant details for your test configuration. Write details that help to start the tests --> Basically the same as https://github.com/calcom/cal.com/pull/24298 since it touches relevant code. 1. Have a user that has the setting to prevent impersonation on. 2. Go to another users public booking page of any meeting. 3. Try to enter the email of the first user into the booking for. 4. Wait 1 second and make sure the button shows "Verify email". ## Checklist <!-- Remove bullet points below that don't apply to you --> - I haven't read the [contributing guide](https://github.com/calcom/cal.com/blob/main/CONTRIBUTING.md) - My code doesn't follow the style guidelines of this project - I haven't commented my code, particularly in hard-to-understand areas - I haven't checked if my changes generate no new warnings |
||
|
|
64297f027c |
feat: add user-specific email verification setting (#24298)
* feat: add user-specific email verification setting Add requiresBookerEmailVerification boolean field to User model that allows users to protect their email from impersonation during bookings. When enabled, anyone attempting to book using the protected user's email address (as booker or guest) must complete email verification and be logged in as that email owner. Key changes: - Add requiresBookerEmailVerification field to User schema - Create settings toggle in /settings/my-account/general - Update checkIfBookerEmailIsBlocked to check booker's account setting - Update guest filtering in handleNewBooking and addGuests handlers - Add i18n translations for new setting - Check both primary and verified secondary emails Additional fixes: - Replace 'any' types with proper Prisma and zod types in user.ts - Fix member role type in sessionMiddleware.ts - Fix avatar URL generation bug in sessionMiddleware.ts These type fixes were necessary to resolve pre-commit lint warnings that were blocking the commit. Co-Authored-By: keith@cal.com <keithwillcode@gmail.com> * fix: address PR review comments - Remove unrelated Watchlist index drops from migration - Add missing Watchlist indexes to schema.prisma to fix drift - Refactor checkIfBookerEmailIsBlocked to throw ErrorWithCode - Move HttpError handling to handleNewBooking caller layer Addresses review comments on PR #24298 Co-Authored-By: keith@cal.com <keithwillcode@gmail.com> * refactor: move Prisma queries to UserRepository and remove unrelated Watchlist changes - Add findByEmailWithEmailVerificationSetting method to UserRepository - Add findManyByEmailsWithEmailVerificationSettings method to UserRepository - Refactor checkIfUserEmailVerificationRequired handler to use UserRepository - Refactor addGuests handler to use UserRepository - Remove unrelated Watchlist schema indices (organizationId/isGlobal, source) - Remove unrelated WatchlistAudit unique constraint on id Addresses review comments on PR #24298 Co-Authored-By: keith@cal.com <keithwillcode@gmail.com> * fix: better error codes + use repo * Updated db query with manully written one using UNION (#24430) * fix: resolve usage of deprecated secondary email in return value * fix: type errors from refactors * fix: address CodeRabbit PR review comments - Add NOT NULL constraint to requiresBookerEmailVerification migration - Dedupe guest input by base email to handle plus-addressing correctly - Compare attendees by base email instead of raw strings - Send emails only to filtered uniqueGuests (not all guests) - Improve error logging with actual error details Co-Authored-By: keith@cal.com <keithwillcode@gmail.com> * fix: indices added by mistake Co-authored-by: Carina Wollendorfer <30310907+CarinaWolli@users.noreply.github.com> * chore: update label of setting * fix: return matched email for guests * chore: remove whitespace * test: add comprehensive email verification tests - Add 9 test scenarios covering user email verification setting - Test main booker verification (logged in/out, with/without code) - Test secondary email verification as main booker and guest - Test guest filtering when verification is required - Test plus-addressed email handling - Test multiple guests with mixed verification requirements - Test invalid verification code error handling - Update bookingScenario helper to support requiresBookerEmailVerification and secondaryEmails Co-Authored-By: keith@cal.com <keithwillcode@gmail.com> * fix: correct guest placement in test mock data Move guests array from top-level booking data into responses object to match expected structure in getBookingData.ts which looks for responses.guests (line 74). Fixes three failing tests: - should filter out guest that requires verification - should filter out secondary email with verification when added as guest - should filter only guests requiring verification from multiple guests Co-Authored-By: keith@cal.com <keithwillcode@gmail.com> --------- Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> Co-authored-by: Rodrigo Ehlers <rodrigoehlers@outlook.com> Co-authored-by: Dhairyashil Shinde <93669429+dhairyashiil@users.noreply.github.com> Co-authored-by: Rodrigo Ehlers <rodrigo@chatbyte.ai> Co-authored-by: Carina Wollendorfer <30310907+CarinaWolli@users.noreply.github.com> |
||
|
|
09cf8885cf |
feat: add send & verify code flow to booker atom when email verification is turned on (#23074)
* feat: extract tRPC verification logic to platform libraries and create v2 atoms endpoints - Extract verifyCodeUnAuthenticated, verifyCodeAuthenticated, and sendVerifyEmailCode logic from tRPC handlers into reusable platform library functions - Create VerificationAtomsService and AtomsVerificationController following atoms pattern - Add v2 endpoints: /atoms/verification/email/send-code, /atoms/verification/email/verify-code, /atoms/verification/email/verify-code-authenticated - Update useVerifyEmail and useVerifyCode hooks to use new v2 endpoints instead of verified-resources endpoints - Export verification functions from @calcom/platform-libraries following getPublicEvent pattern - Integrate platform-specific verification hooks into BookerPlatformWrapper Co-Authored-By: somay@cal.com <somaychauhan98@gmail.com> * feat: update platform hooks to use v2 verification endpoints - Update useVerifyEmail hook to use correct response type for v2 endpoint - Update useVerifyCode hook to use v2 verification endpoint - All verification functions now properly exported from platform libraries - Type checking passes with no errors Co-Authored-By: somay@cal.com <somaychauhan98@gmail.com> * fix: update v2 API to use workspace version of platform-libraries - Change package.json dependency from pinned version to workspace version - Add proper error handling to verification service with NestJS HTTP exceptions - Convert generic Error objects to BadRequestException and UnauthorizedException - Ensure verification endpoints return proper HTTP status codes instead of 500 errors Co-Authored-By: somay@cal.com <somaychauhan98@gmail.com> * chore: update auto-generated files after package.json changes - Update OpenAPI documentation for v2 verification endpoints - Update yarn.lock after changing platform-libraries dependency Co-Authored-By: somay@cal.com <somaychauhan98@gmail.com> * refactor: extract verification logic from tRPC handlers into exportable functions - Refactor sendVerifyEmailCode.handler.ts to extract core logic into sendVerifyEmailCode function - Refactor verifyCodeUnAuthenticated.handler.ts to extract core logic into verifyCodeUnAuthenticated function - Refactor organizations/verifyCode.handler.ts to extract core logic into verifyCodeAuthenticated function - Update platform/libraries/index.ts to import from refactored handler files instead of standalone verification.ts - Remove standalone verification.ts file as requested by user - Keep original tRPC handlers as wrappers that call the extracted functions - Maintain backward compatibility for existing tRPC endpoints Co-Authored-By: somay@cal.com <somaychauhan98@gmail.com> * extract logic into seperate functions * Update index.ts * refactor: remove unused type imports from verification-atom service * feat: create v2 atoms input/output types for verification endpoints - Add SendVerificationEmailInput and VerifyEmailCodeInput with validation decorators - Add SendVerificationEmailOutput and VerifyEmailCodeOutput following v2 atoms patterns - Update atoms verification controller to use custom types instead of platform types - Auto-update openapi.json with new type definitions Co-Authored-By: somay@cal.com <somaychauhan98@gmail.com> * fix: add missing type imports to verification service - Import ZVerifyCodeInputSchema from @calcom/prisma/zod-utils - Import VerifyCodeAuthenticatedInput from organizations handler - Import TSendVerifyEmailCodeSchema from sendVerifyEmailCode schema - Resolves CI build failure in API v2 tests Co-Authored-By: somay@cal.com <somaychauhan98@gmail.com> * feat: add email verification check endpoint and refactor verification flow * added Throttle * added chagelog * chore: update platform libraries to 0.0.317 * refactor: remove unused context and update email verification query key dependencies * chore: bump @calcom/platform-libraries from 0.0.318 to 0.0.319 * Update verifyCode.handler.ts * chore: bump @calcom/platform-libraries from 0.0.319 to 0.0.320 --------- Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> |
||
|
|
3b1de34451 |
chore: Add guest email blacklist (#15255)
* chore: Add guest email blacklist * types * Added check to only log when we've removed one * feat: add verification logic * chore: use base exftract email * Added toLowerCase for guest email checks --------- Co-authored-by: Udit Takkar <udit222001@gmail.com> |