* fix: filter slots by requested date range to prevent date override leakage
Co-Authored-By: morgan@cal.com <morgan@cal.com>
* refactor: move filterSlotsByRequestedDateRange to private method
Co-Authored-By: morgan@cal.com <morgan@cal.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix: use relative redirects in booking confirmation routes to fix localhost redirect issue
When Cal.com runs behind a reverse proxy, request.url may return the internal
server URL (localhost:3000) instead of the external URL. This causes users to
be redirected to localhost after confirming bookings via email links.
This fix changes the redirect URLs from using url.origin (which could be
localhost) to using relative URLs via new URL(path, request.url). This ensures
the browser resolves the redirect against whatever domain the user actually
requested, fixing the issue for self-hosted deployments behind proxies.
Fixes#20358
Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com>
* test: add tests for booking confirmation redirect URL construction
Add unit tests for verify-booking-token and link API routes to ensure:
- Redirect URLs preserve the request origin (not hardcoded localhost)
- Redirect URLs use the correct booking path (/booking/{uid})
- Error messages are properly encoded in query params
- POST handler returns correct 303 status code
These tests verify the fix for #20358 where users were redirected to
localhost:3000 instead of the proper production URL after confirming
bookings via email links.
Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com>
* fix: add second argument to GET/POST calls in test files to fix type errors
Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* feat: Add async spam check integration and decoy booking response
- Integrate SpamCheckService with handleNewBooking workflow
- Implement parallel spam check execution for minimal performance impact
- Add decoy booking response with localStorage-based success page
- Extract organization ID from event type for org-specific blocking
- Add comprehensive test coverage for spam detection scenarios
- Create reusable components for booking success cards
- Implement fail-open behavior to never block legitimate bookings
This builds on the spam blocker DI infrastructure from PR #24040 by
adding the actual integration into the booking flow and implementing
the decoy response mechanism to avoid revealing spam detection to
malicious actors.
Related: #24040
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* Do checks in paralle
* Fix leaking host name in title
* Reduce expoiry time localstorage
* refactor: Use sessionStorage instead of localStorage for decoy booking data
- Replace localStorage with sessionStorage for automatic expiration on tab close
- Remove timestamp tracking and TTL logic (no longer needed)
- Improve privacy by auto-clearing data when browser tab/window closes
- Update documentation to reflect sessionStorage behavior
This change addresses privacy concerns by ensuring decoy booking data
(including attendee email) is automatically removed when the user closes
the tab, rather than persisting for 5 minutes or requiring manual cleanup.
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* feat: Add sessionStorage wrapper to webstorage module
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* Reset RegularBookingService.ts to main's version exactly
* feat: Add 5-minute expiration timeout to decoy booking data
- Adds timestamp to DecoyBookingData interface
- Checks expiration when retrieving booking data
- Automatically removes expired data from sessionStorage
- Provides defense-in-depth against potential misuse
- Works alongside sessionStorage auto-clear on tab close
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix: hide insights submenu for free users
* fix: allow navigation access while plan pending
* refactor: update upgrade link to insights in navigation
* fix: addressed all the issues
* fix: prevent flash of premium features for free users during loading
Change from optimistic to pessimistic loading so free users don't
briefly see the Insights submenu while plan status is being fetched.
---------
Co-authored-by: Dhairyashil <dhairyashil10101010@gmail.com>
* fix: show hidden badge on mobile view for event types
* fix: update event type hidden toggle in infinite list
---------
Co-authored-by: Udit Takkar <53316345+Udit-takkar@users.noreply.github.com>
* feat: highlight recurring bookings with time shift badge across DST
* Update packages/lib/__tests__/timeShift.test.ts
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
* refactor: show time shift badge only on first shift in bookings view and occurrences
* refactor: update recurring bookings display logic and wrap booking title text
* refactor: add getFirstShiftFlags helper for time shift flags and update components
---------
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
* fix(settings): improve spacing between navigation child items
* chore: removing prettier formatting
* style: update dropdown item class names for consistent rounding
* style: add spacing and hover margin to navigation items
* style: add hover margin top to navigation item
* apply same ui changes for team profile menu
---------
Co-authored-by: Dhairyashil <dhairyashil10101010@gmail.com>
* feat: add embed prerendering support and enhance event handling
- Introduced `useIsEmbedPrerendering` hook to determine if the embed is in prerender mode.
- Updated `useAvailabilityEvents` to prevent firing events during prerendering.
- Added `bookerLoadedEvent` and `availabilityRefreshed` types to `EventDataMap`.
- Implemented `useFirebookerLoadedEvent` to manage firing the booker loaded event conditionally.
- Refactored event firing logic in `useSchedule` and `BookerWebWrapper` components to utilize new hooks.
* feat: add embed prerendering support and enhance event handling
- Introduced `useIsEmbedPrerendering` hook to determine if the embed is in prerender mode.
- Updated `useAvailabilityEvents` to prevent firing events during prerendering.
- Added `bookerLoadedEvent` and `availabilityRefreshed` types to `EventDataMap`.
- Implemented `useFirebookerLoadedEvent` to manage firing the booker loaded event conditionally.
- Refactored event firing logic in `useSchedule` and `BookerWebWrapper` components to utilize new hooks.
* feat: enhance embed event handling and introduce link reopening detection
- Added `useEmbedReopened` hook to track when the embed is reopened.
- Updated `BookerWebWrapper` to reset event firing state upon embed reopening.
- Refactored event firing logic to use `bookerViewed` instead of `bookerLoadedEvent`.
- Introduced scheduling for event firing in `useSchedule` to ensure correct order of events during prerendering.
* feat: add lifecycle diagrams for inline and modal embeds
- Introduced `inline-embed-lifecycle.mermaid` and `modal-embed-lifecycle.mermaid` files to visualize the lifecycle events and states of inline and modal embeds.
- Updated `LIFECYCLE.md` to reference the new diagrams and provide a clearer explanation of the embed lifecycle processes.
- Added `modal-prerendering-flow.mermaid` to illustrate the prerendering flow for modal embeds.
- Enhanced the routing playground with new features and improved event handling for availability and booking events.
* refactor: update event handling for booker lifecycle events
- Replaced `availabilityLoaded` event with `bookerReady` to better reflect the state when the booker view is fully loaded and ready for interaction.
- Updated related documentation and diagrams to reflect changes in event triggers and descriptions.
- Adjusted internal state management to track `viewId` instead of `reopenCount` for distinguishing between initial views and reopens.
- Added tests for new event handling logic to ensure correct firing of `bookerViewed`, `bookerReopened`, and `bookerReady` events.
* refactor: enhance embed event handling and state management
- Updated event handling for booker lifecycle events, replacing `resetViewVariables` with `resetPageData` to manage page-specific state.
- Introduced new utility functions for managing event firing states and reload initiation.
- Refactored `fireBookerViewedEvent` and `fireBookerReadyEvent` to utilize the new state management functions.
- Added comprehensive tests for the updated event handling logic and state resets to ensure correct functionality across various scenarios.
* refactor: update embed iframe configuration and utility functions
- Reduced `slotsStaleTimeMs` from 30 seconds to 10 seconds and `iframeForceReloadThresholdMs` from 100 seconds to 30 seconds for improved responsiveness.
- Refactored utility functions to use `isBrowser` for client-side checks instead of `isClientSide`.
- Removed unused `isPrerendering` function and updated related documentation for clarity.
- Enhanced event handling by exporting `useBookerEmbedEvents` from the appropriate module for better accessibility.
* refactor: update embed iframe configuration and utility functions
- Reduced `slotsStaleTimeMs` from 30 seconds to 10 seconds and `iframeForceReloadThresholdMs` from 100 seconds to 30 seconds for improved responsiveness.
- Refactored utility functions to use `isBrowser` for client-side checks instead of `isClientSide`.
- Removed unused `isPrerendering` function and updated related documentation for clarity.
- Enhanced event handling by exporting `useBookerEmbedEvents` from the appropriate module for better accessibility.
* fix cubic feedback
- Add early return when only one user is available
- Prevents unnecessary database queries, calendar API calls, and OOO checks
- Add comprehensive test to verify optimization works correctly
Fixes#19503 [CAL-5212]
* feat: ooo message on booking page
* make ooo days selectable even when no redirect booking
* handle long notes
* remove unused i18n key
* Private notes stay private on the server, No accidental data leaks through client-side payloads
* address cubics comments
* fix: replace toggle with checkbox for OOO note visibility
- Replace Switch with Checkbox for "show note publicly" option
- Remove "OOO Message:" prefix from displayed notes on booking page
- Update i18n text to "Show note on public booking page"
- Remove unused ooo_message i18n key
* fix the accessibility issue by using proper htmlFor and id association
* only allow selecting OOO dates when the note is public
* fix: cloudflare turnstile token reset
* fix: silently reset turnstile on invalid token error
* refactor: remove unused forwardRef logic from Turnstile component
- Remove forwardRef, useImperativeHandle, and useRef imports
- Remove unused TurnstileInstance type export
- Simplify to a plain function component
- The ref-based reset was replaced by key-based remount in signup-view
* refactor: remove redundant cfToken validation check
The submit button is already disabled when cfToken is missing,
making this defensive check unreachable during normal form flow.
* revert prettier formatiing
* chore: revert yarn.lock changes
* refactor(auth): use shared constant for cloudflare token error message
Replace hardcoded "Invalid cloudflare token" string with an exported
constant to prevent silent breakage if the error message changes.