When updating an event type, fields like autoTranslateDescriptionEnabled
and disableGuests were being overwritten with false/default values even
when they weren't explicitly provided in the update request.
Changes:
- autoTranslateDescriptionEnabled: Only set when explicitly provided
(not undefined) to avoid overwriting existing true values with false
- disableGuests: Only set when bookingFields is explicitly provided,
since it's derived from the guests field in bookingFields
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* refactor: replace TRPCError with ErrorWithCode in packages/features
This refactor moves error handling from throwing TRPCError directly in
packages/features to throwing ErrorWithCode instead. The conversion to
TRPCError now happens at the TRPC layer.
Changes:
- Add generic ErrorCode values (Unauthorized, Forbidden, NotFound,
BadRequest, InternalServerError) to errorCodes.ts
- Update getServerErrorFromUnknown to map new ErrorCodes to proper
HTTP status codes
- Create toTRPCError helper in packages/trpc/server/lib
- Create errorMappingMiddleware in packages/trpc/server/middlewares
- Migrate TRPCError throws in packages/features to ErrorWithCode:
- teamService.ts
- getEventTypeById.ts
- eventTypeRepository.ts
- OrganizationPermissionService.ts
- OrganizationPaymentService.ts
- sso.ts
- handleCreatePhoneCall.ts
- userCanCreateTeamGroupMapping.ts
This improves separation of concerns by making packages/features
transport-agnostic, allowing the same feature code to be reused from
tRPC, API routes, workers, etc.
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
* fix: remove isTrpcCall parameter and fix lint warning
- Remove isTrpcCall parameter from get.handler.ts call since the
feature layer no longer needs to know about tRPC
- Fix unsafe optional chaining lint warning in getEventTypesByViewer.ts
by precomputing usersSource variable
- Complete migration of getEventTypesByViewer.ts to ErrorWithCode
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
* revert
* add eslint rule
* add comment
* fix: add isTrpcCall back to getEventTypeById interface
The user reverted the removal of isTrpcCall parameter from the handler,
so we need to add it back to the interface to fix the type error.
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
* test: update teamService tests to expect ErrorWithCode instead of TRPCError
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
* refactor
* wip
* feat: integrate errorMappingMiddleware into base TRPC procedure
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
* connect middlewares
* revert
* revert
* refactor
* rename
* fix: handle ErrorWithCode in teams server-page error handling
The error handling was checking for TRPCError, but teamService now throws
ErrorWithCode. This caused the 'This invitation is not for your account'
error message to not be displayed when a wrong user tries to use an
invitation link.
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
* fix
* fix
* fix
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* wip
* wip
* feature: Booking Tasker without DI yet
* feature: Booking Tasker with DI
* fix type check 1
* fix type check 2
* fix
* comment booking tasker for now
* fix: DI regularBookingService api v2
* fix: convert trigger.dev SDK imports to dynamic imports to fix unit tests
The unit tests were failing because BookingEmailAndSmsTriggerTasker.ts had static imports of trigger files that depend on @trigger.dev/sdk. This caused Vitest to try to resolve the SDK at module load time, even though it should be optional.
Changed all imports in BookingEmailAndSmsTriggerTasker.ts from static to dynamic (using await import()) so the trigger files are only loaded when the tasker methods are actually called, not at module load time during tests.
This fixes the 'Failed to load url @trigger.dev/sdk' errors that were causing 28+ test failures.
Co-Authored-By: morgan@cal.com <morgan@cal.com>
* fix unit tests
* keep inline smsAndEmailHandler.send calls
* chore: add team feature flag
* add satisfies ModuleLoader
* fix type check app flags
* move trigger in feature
* fix: add trigger.dev prisma generator
* fix: email app statuses
* fix: CalEvtBuilder unit test
* chore: improvements, schema, config, retry
* fixup! chore: improvements, schema, config, retry
* chore: cleanup code
* chore: cleanup code
* chore: clean code and give full payload
* remove log
* add booking notifications queue
* add attendee phone number for sms
* bump trigger to 4.1.0
* add missing booking seat data in attendee
* update config
* fix logger regular booking service
* fix: prisma as external deps of trigger
* fix yarn.lock
* revert change to example app booking page
* fix: resolve circular dependencies and improve cold start performance in trigger tasks
- Convert BookingRepository import to type-only in CalendarEventBuilder.ts to eliminate circular dependency risk
- Convert EventNameObjectType, CalendarEvent, and JsonObject imports to type-only in BookingEmailAndSmsTaskService.ts
- Use dynamic imports in all trigger notification tasks (confirm, request, reschedule, rr-reschedule) to reduce cold start time
- Move heavy imports (BookingEmailSmsHandler, BookingRepository, prisma, TriggerDevLogger, BookingEmailAndSmsTaskService) inside run functions
- Eliminates module-level prisma import which violates repo guidelines and adds cold start overhead
- Reduces initial module dependency graph by deferring heavy imports (email templates, workflows, large repositories) until task execution
Co-Authored-By: morgan@cal.com <morgan@cal.com>
* fix: improve cold start performance in reminderScheduler with dynamic imports
- Remove module-level prisma import (violates 'No prisma outside repositories' guideline)
- Use dynamic imports for UserRepository (1,168 lines) - only loaded when needed in EMAIL_ATTENDEE action
- Use dynamic imports for twilio provider (386 lines) - only loaded in cancelScheduledMessagesAndScheduleEmails
- Use dynamic imports for all manager functions by action type:
- scheduleSMSReminder (387 lines) - loaded only for SMS actions
- scheduleEmailReminder (459 lines) - loaded only for Email actions
- scheduleWhatsappReminder (266 lines) - loaded only for WhatsApp actions
- scheduleAIPhoneCall (478 lines) - loaded only for AI phone call actions
- Use dynamic imports for sendOrScheduleWorkflowEmails in cancelScheduledMessagesAndScheduleEmails
- Significantly reduces cold start time by deferring heavy module loading until execution paths need them
- Eliminates module-level prisma import that violated repository pattern guidelines
Co-Authored-By: morgan@cal.com <morgan@cal.com>
* fix: improve cold start performance in BookingEmailSmsHandler with dynamic imports
- Remove module-level imports of all email-manager functions (653 LOC + 30+ email templates)
- Add dynamic imports in each method (_handleRescheduled, _handleRoundRobinRescheduled, _handleConfirmed, _handleRequested, handleAddGuests)
- Defer heavy email-manager loading until method execution
- Verified no circular dependencies between email-manager and bookings
- Significantly reduces cold start time for RegularBookingService and BookingEmailAndSmsTaskService
Co-Authored-By: morgan@cal.com <morgan@cal.com>
* fix: use dynamic imports
* update yarn lock
* code review
* trigger config project ref in env
* update yarn lock
* add .env.example trigger variables
* add .env.example trigger variables
* fix: cleanup error handling and loggin
* fix: trigger config from env
* fix: small typo fix
* fix: ai review comments
* fix: ai review comments
* ai review
* Add `create` on `WorkflowReminderRepository`
* `sendWorkflowEmails` tasker to accept lazy payload
* Add `scheduleLazyEmailWorkflow` to `WorkflowService
* Process scheduled date in `scheduleLazyEmailWorkflow`
* Type fixes
* Use `WorkflowService` to schedule
* Refactor `scheduleEmailReminderForEvt` to use
`WorkflowService.processWorkflowScheduledDate`
* Pass seat reference to lazy scheduled workflow reminder
* Refactor `WorkflowReminderRepository` to accept prisma as constructor
* Abstract `FormSubmissionData` type
* Abstract select statement and add get by uid to `BookingRepository`
* Add `FormSubmissionData` type
* Add `findByIdIncludeStepAndWorkflow` to `WorkflowReminderRepository`
* Tasker payload to accept `workflowReminderId`
* Create `BookingSeatRepository`
* Write `workflowReminderId` to tasker payload
* Add `generateCommonScheduleFunctionParams` to `WorkflowService`
* Init
* Use services in tasker
* Abstract types
* In reminderScheduler use workflowService to generate common params
* Type fix
* Return params from emailWorkflowService.generateParametersToBuildEmailWorkflowContent
* Use emailWorkflowService to generate params
* Abstract types
* Generate email content and send in EmailWorkflowService
* Move check to caller
* Use EmailWorkflowService to generate email payload in
emailReminderManager
* Fix initalizing repository
* Use evt.videoCallData first before the booking metadata
* Only get non-deleted references to build calendar event
* Remove check for videoCallData.id
* Dynamic import credit service
* BookingRepository.getByUid to only return what we need from attendee
* Type fixes
* test: Add comprehensive tests for lazy email workflow generation and fix broken tests
- Fix prisma mocks in sms-manager.test.ts and outOfOfficeCreateOrUpdate.handler.test.ts
to export both 'default' and named 'prisma' exports
- Add EmailWorkflowService.test.ts with 4 tests for error handling paths
- Add sendWorkflowEmails.test.ts with 7 tests for schema validation and email sending
- Add tests to WorkflowService.test.ts for scheduleLazyEmailWorkflow,
processWorkflowScheduledDate, and generateCommonScheduleFunctionParams methods
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* Write `seatReferenceUid`
* Return promise
* Fix log
* Change to `Promise.allSettled`
* Type fix
* Fix failing test
* fix: reorder workflow step checks to fix test failure
The test 'should throw error if workflow step not found on reminder' was failing because the code checked workflowStep.verifiedAt before checking if workflowStep exists. When workflowStep is null, this caused the error message to include 'undefined' instead of the expected workflow step id.
Fixed by reordering the checks:
1. First check if workflowStep exists
2. Then check if workflowStep.verifiedAt exists
Also updated the test expectation to match the correct error message.
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
---------
Co-authored-by: cal.com <morgan@cal.com>
Co-authored-by: Morgan <33722304+ThyMinimalDev@users.noreply.github.com>
Co-authored-by: hbjORbj <sldisek783@gmail.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Alex van Andel <me@alexvanandel.com>
* fix: break circular dependency in messageDispatcher via dependency injection
Break the 4-file circular dependency chain:
credit-service → reminderScheduler → smsReminderManager → messageDispatcher → credit-service
Solution:
- Add optional creditCheckFn parameter to messageDispatcher functions
- Thread creditCheckFn through the call chain: scheduleWorkflowReminders → scheduleSMSReminder/scheduleWhatsappReminder → messageDispatcher
- When creditCheckFn is provided, use it; otherwise fall back to dynamic CreditService import for backward compatibility
- This breaks the workflows → billing import while preserving immediate fallback behavior
Changes:
- messageDispatcher: Accept optional creditCheckFn parameter, use it if provided
- smsReminderManager: Thread creditCheckFn through scheduleSMSReminder
- whatsappReminderManager: Thread creditCheckFn through scheduleWhatsappReminder
- reminderScheduler: Add creditCheckFn to ScheduleWorkflowRemindersArgs and pass through processWorkflowStep
All type checks, lint checks, and unit tests pass.
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
* feat: wire creditCheckFn from all callers to complete circular dependency fix
- Add creditCheckFn parameter to WorkflowService.scheduleFormWorkflows
- Wire creditCheckFn from all 10 entry points that call workflow scheduling:
* formSubmissionUtils.ts (form submissions)
* roundRobinManualReassignment.ts (round-robin reassignment)
* triggerFormSubmittedNoEventWorkflow.ts (form workflow trigger)
* handleBookingRequested.ts (booking requests)
* RegularBookingService.ts (2 calls - payment initiated & new bookings)
* handleSeats.ts (seated bookings)
* handleConfirmation.ts (2 calls - confirmation & payment)
* handleMarkNoShow.ts (no-show updates)
* confirm.handler.ts (booking rejection)
- Update test expectations to use expect.objectContaining()
- Fix pre-existing lint warning in handleMarkNoShow.ts (any type)
- This completes the messageDispatcher circular dependency fix by ensuring
creditCheckFn is actually passed through the call chain, breaking the
4-file circular dependency at runtime
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
* fix: use generic type with type guard in logFailedResults to fix type check error
- Replace constrained type with generic type parameter
- Add proper type guard for rejected promises
- Fixes CI type check failure in handleMarkNoShow.ts:385
- Avoids 'any' type while accepting any fulfilled value shape
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
* wip
* wip
* wip
* revert
* revert
* feat: wire creditCheckFn from all remaining callers to eliminate fallbacks
- Wire creditCheckFn in packages/sms/sms-manager.ts (can safely import CreditService)
- Create makeHandler factory pattern for CRON endpoints (scheduleSMSReminders.ts, scheduleWhatsappReminders.ts)
- Wire creditCheckFn from apps/web CRON routes to factories
- Add warning log in messageDispatcher when fallback is used
- Complete creditCheckFn wiring from all direct callers (activateEventType.handler.ts, util.ts)
This eliminates all fallbacks to dynamic import except as a safety net for unforeseen call sites.
The circular dependency (workflows ↔ billing) remains acceptable as discussed with user (Option C).
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
* test: update formSubmissionUtils tests to expect creditCheckFn parameter
The scheduleFormWorkflows function now receives creditCheckFn as a parameter.
Updated test assertions to use expect.objectContaining() with creditCheckFn: expect.any(Function)
to account for the new dependency injection parameter.
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
* test: update sms-manager test to expect creditCheckFn parameter
The sendSmsOrFallbackEmail function now receives creditCheckFn as a parameter.
Updated test assertion to use expect.objectContaining() with creditCheckFn: expect.any(Function)
to account for the new dependency injection parameter. Also removed teamId: undefined
assertion as the key may be omitted entirely from the actual call.
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
* feat: make creditCheckFn required to fully break circular dependency
This commit completes the circular dependency fix by making creditCheckFn
required throughout the call chain, eliminating the dynamic import fallback
entirely.
Changes:
- Make creditCheckFn required in messageDispatcher functions (sendSmsOrFallbackEmail, scheduleSmsOrFallbackEmail)
- Remove dynamic import fallback and warning log from messageDispatcher
- Make creditCheckFn required in ScheduleTextReminderArgs (smsReminderManager)
- Make creditCheckFn required in processWorkflowStep and ScheduleWorkflowRemindersArgs (reminderScheduler)
- Add creditCheckFn to SendCancelledRemindersArgs and wire from handleCancelBooking
The circular dependency is now fully broken - no more dynamic imports of
CreditService from within the workflows package. All callers must explicitly
provide creditCheckFn via dependency injection.
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
* fix: make creditCheckFn required in WorkflowService.scheduleFormWorkflows
This commit fixes the CI type check error by making creditCheckFn required
in WorkflowService.scheduleFormWorkflows. Previously, creditCheckFn was
optional in scheduleFormWorkflows but required in scheduleWorkflowReminders,
causing a type mismatch.
Changes:
- Make creditCheckFn required in scheduleFormWorkflows signature
- Update WorkflowService.test.ts to pass mock creditCheckFn in all test cases
- Add responseId and routedEventTypeId to test calls for completeness
All callers of scheduleFormWorkflows already pass creditCheckFn, so this
change is safe and completes the circular dependency fix.
Co-Authored-By: benny@cal.com <sldisek783@gmail.com>
* remove
* fix
* refactor
* refactor
* refactor
* wip
* fix
* fix
* rm
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* chore: Fix circular dependency in tanstack-table.d.ts
* fix: Re-export TextFilterOperator
* Unable to export non-type values from @calcom/types
* Refactor data-table types in a way that ensures type-safety as before
* Add FilterPopover and further fixups
* Fix further type errors missed earlier
* More hidden type errors
* Type error in useFilterValue
* add public client
* implement PKCE
* pass codeChallenge and codeChallengeMethod to handler
* fixes for secure oauth flow
* fix type error
* clean up refresh token endpoint
* only support S256
* fix type error
* remove comment
* add tests
* fix type errors in route.test.ts
* add missing support for refresh token
* add e2e test for public client refresh tokens
* allow pkce for confidential clients
* fix type error
* fix e2e
* fix option pkce for confidential clients
* e2e test improvements
* fix test
* remove only
* add delay
* fix e2e tests
* remove only
* don't skip pkce if codeChallenge is set
* add service functions for token endpoint
* use service function in refreshToken endpoint
* use repository
* remove return types
* e2e test fixes
* fix e2e test
* remove .only in e2e test
* remove pause
* fix error responses in token endpoints
* adjust tests to new error responses
* fix error responses
* e2e improvements
* redirect on error
* adjust tests
* Update apps/web/modules/auth/oauth2/authorize-view.tsx
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
---------
Co-authored-by: CarinaWolli <wollencarina@gmail.com>
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
## What does this PR do?
This PR implements attributes PBAC - router checks + UI
## Visual Demo (For contributors especially)
A visual demonstration is strongly recommended, for both the original and new change **(video / image - any one)**.
#### Video Demo (if applicable):
- Show screen recordings of the issue or feature.
- Demonstrate how to reproduce the issue, the behavior before and after the change.
#### Image Demo (if applicable):
- Add side-by-side screenshots of the original and updated change.
- Highlight any significant change(s).
## Mandatory Tasks (DO NOT REMOVE)
- [ ] I have self-reviewed the code (A decent size PR without self-review might be rejected).
- [ ] I have updated the developer docs in /docs if this PR makes changes that would require a [documentation change](https://cal.com/docs). If N/A, write N/A here and check the checkbox.
- [ ] I confirm automated tests are in place that prove my fix is effective or that my feature works.
## How should this be tested?
Enable PBAC on an org
Create a custom role -> advanced -> organizations -> "editUser"
Assign it to a user
impersonate user
test they have access to all things attributes
remove permissions
check they dont have permissions.
## Checklist
<!-- Remove bullet points below that don't apply to you -->
- I haven't read the [contributing guide](https://github.com/calcom/cal.com/blob/main/CONTRIBUTING.md)
- My code doesn't follow the style guidelines of this project
- I haven't commented my code, particularly in hard-to-understand areas
- I haven't checked if my changes generate no new warnings
<!-- This is an auto-generated description by cubic. -->
---
## Summary by cubic
Adds a new PBAC “editUsers” permission and read gating for Attributes, updating the UI and backend so users can view and edit attributes only when allowed.
- **New Features**
- Added CustomAction.EditUsers to the permission registry for organization-scoped attribute editing.
- Settings computes canViewAttributes and shows the Attributes tab only when allowed.
- Members page fetches Attributes permissions and exposes canViewAttributes and canEditAttributesForUser to the UI.
- User Edit Sheet hides attributes without read permission and shows attribute editing and the bulk “Mass Assign Attributes” action only with editUsers; other user edits depend on changeMemberRole.
- Attributes TRPC router gates create/edit/delete/toggle via PBAC and requires organization.attributes.editUsers for assign/bulk-assign; added a helper to create PBAC-aware procedures.
- **Migration**
- Run the new Prisma migration to seed the admin role with editUsers.
- If using custom roles, grant Edit Users under Attributes as needed.
<sup>Written for commit 856aa2e8e1521fc22cd71cb0fa6d720036efe8a2. Summary will update automatically on new commits.</sup>
<!-- End of auto-generated description by cubic. -->
* feat: google ads conversion tracking
* gaClientid
* store gclid in stripe metadata
* tracking only in the us
* track google campaign id as well
* rename gclid -> google ads
* fix: build
* fix
* refactor
* fix: type check
* fix: type check
* fix: type check
* fix: type check
* fix: store it in cookie
* refactor
* fix
* cleanup
* linked ads tracking
* refactor checkout session tracking
* Change arg name from `bookingUId` to `bookingUid`
* Lint fix
* Use `BookingRepository` to find booking to reschedule
* Move early return further up if no booking is found
* Use `PermissionCheckService` if request rescheduling a team booking
* Remove redundent check
* Remove redundent eventType query
* Using `BookingRepository` to update the booking to rescheduled
* Update type in `getUsersCredentialsIncludeServiceAccountKey` to only
require params that are required
* Get booking organizer credentials
* Type fixes
* test: Add tests for team admin request reschedule with organizer credentials
- Add test for team admin requesting reschedule with proper permissions
- Add test verifying organizer's credentials are used (not requester's)
- Add test for team member without permissions (should fail)
These tests cover the fix in PR #24645 which ensures that when a team admin
requests a reschedule, the booking organizer's credentials are used to delete
calendar events instead of the requester's credentials.
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: Address code review comments for request reschedule
- Change user: true to user: { select: { id, email } } to only fetch required fields
- Change eventType include to select with explicit fields including teamId
- Remove sensitive information (user object, cancellationReason) from debug log
- All integration tests passing locally
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* Type fix
* Remove businesss logic references from repository methods.
* Move business logic to handler
* Type fix
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2025-11-25 07:27:07 +00:00
Hariom BalharaGitHubhariom@cal.com <hariombalhara@gmail.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>Udit Takkar
* feat: add backend validation for conflicting team slugs during org onboarding
- Added findOwnedTeamsByUserId method to TeamRepository
- Created buildTeamsAndInvites method in BaseOnboardingService that automatically:
- Detects teams with same slug as organization
- Marks conflicting teams for migration (isBeingMigrated: true)
- Filters empty team names and invite emails
- Updated BillingEnabledOrgOnboardingService to use new method
- Updated SelfHostedOnboardingService to use new method
- Added comprehensive tests for slug conflict scenarios
This ensures backend validation even if frontend is bypassed, preventing
slug conflicts during organization creation. All inheriting classes
automatically get this validation without code changes.
* refactor: use TeamRepository in listOwnedTeamsHandler
Refactored listOwnedTeamsHandler to use TeamRepository.findOwnedTeamsByUserId
instead of direct Prisma queries. This:
- Reduces code duplication
- Ensures consistency across the codebase
- Follows repository pattern
- Makes the handler more maintainable
* fix: update tests to use renamed buildTeamsAndInvites method
- Renamed testFilterTeamsAndInvites to testBuildTeamsAndInvites
- Made test wrapper method async to match the async buildTeamsAndInvites
- Added orgSlug parameter to all test calls
- Updated all 9 test cases to use await with the new method signature
- Fixed lint warnings by using proper types instead of 'any'
- Imported OnboardingIntentResult and User types
- Used Pick<User> for mockUser type
- Removed all 'as any' type casts
Fixes test failures where filterTeamsAndInvites was renamed to buildTeamsAndInvites in the base service.
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* fix: mock TeamRepository in tests to prevent database calls
Added vi.mock for TeamRepository to avoid database calls in unit tests.
The buildTeamsAndInvites method now calls ensureConflictingSlugTeamIsMigrated
which uses TeamRepository.findOwnedTeamsByUserId(). Mocking this prevents
Prisma errors in CI while keeping the tests focused on filtering logic.
The mock returns an empty array so no teams are found for migration,
allowing the tests to verify the filtering behavior without database access.
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* refactor: improve readability of ensureConflictingSlugTeamIsMigrated
Refactored the conditional logic in ensureConflictingSlugTeamIsMigrated
for better readability while preserving exact behavior. Changed from
manual array manipulation to using .map() for updating team migration
status. This is a cosmetic change with no functional differences.
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Udit Takkar <53316345+Udit-takkar@users.noreply.github.com>
* Add check that event type belongs to team
* Add `findAcceptedMembershipsByUserIdsInTeam` to `MembershipRepository`
* Validate that passed `userIds` belong to a team
* Add tests
* Typo fix
2025-11-21 10:26:22 -05:00
sean-brydonGitHubDevin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* chore: Remove all code related to the old cache system
* Removed some redundant tests, some type fixes
* Further type fixes
* More type fixes re. tests
* Next iteration, couple of fixes remaining
* Remove cache from CredentialActionsDropdown
* Fix tests by mocking credential, instead of db queries
* Remove Cache DI wiring from v2
* Make sure apiv2 build passes
* Remove another cache cron
* Remove old tokens for calendar-cache v1
2025-11-20 18:02:18 +02:00
Joe Au-YeungGitHubjoe@cal.com <j.auyeung419@gmail.com>joe@cal.com <j.auyeung419@gmail.com>joe@cal.com <j.auyeung419@gmail.com>joe@cal.com <j.auyeung419@gmail.com>joe@cal.com <j.auyeung419@gmail.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix: prevent bulk update of locked locations in child managed event types
- Filter out child managed event types with locked locations in getBulkUserEventTypes
- Add validation in bulkUpdateEventsToDefaultLocation to prevent updating locked fields
- Implements defense in depth with validation at multiple layers
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* Abstract filtering logic
* test: add comprehensive tests for bulk location update filtering
- Add unit tests for filterEventTypesWhereLocationUpdateIsAllowed
- Add unit tests for bulkUpdateEventsToDefaultLocation
- Add integration tests for getBulkUserEventTypes
- Fix bug: change unlockedFields?.locations check from !== undefined to === true
This ensures that locations: false is properly treated as locked, addressing
the security issue identified in PR review comments
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: filter locked managed event types on app installation page
- Add parentId to eventTypeSelect in getEventTypes function
- Apply filterEventTypesWhereLocationUpdateIsAllowed to both team and user event types
- Only filter when isConferencing is true to avoid affecting other app types
- Fixes issue where locked managed event types were showing in the event type selection list on /apps/installation/event-types page
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix(embed-react): remove obsolete availabilityLoaded event listener
The availabilityLoaded event does not exist in the EventDataMap type system
in embed-core. This code was causing 5 TypeScript errors in CI:
- Type 'availabilityLoaded' does not satisfy constraint 'keyof EventDataMap'
- 'data' is of type 'unknown' (2 occurrences)
- Type 'availabilityLoaded' is not assignable to action union (2 occurrences)
Since this is an example file and the event is not defined in the type system,
removing this obsolete code resolves the type errors.
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: correct Prisma type for metadata in test helper function
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: use flexible PrismaLike type for better test compatibility
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: properly type mock Prisma objects in test files
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: properly mock Prisma methods in test file
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* Filter out metadata
* Undo change in embed file
* Address feedback
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2025-11-19 15:46:05 -05:00
Joe Au-YeungGitHubjoe@cal.com <j.auyeung419@gmail.com>cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>Syed Ali Shahbaz
* Move TeamBillingRepositories
* WIP refactor team internal billing service
* Remove duplicate billing repository files
* Remove logic check in repository for billing is enabled
* Rename repository to `TeamBillingData`
* Use repository factory in main service
* Fix new import paths
* Rename to
* Ensure `IS_TEAM_BILLING_ENABLED` is of type boolean
* Rename classes to TeamBillingService and TeamBillingServiceFactory
* Implement DI in `BookingServiceFactory`
* `TeamBillingService` use repository in `getOrgIfNeeded`
* DI `isTeamBillingEnabled` to `TeamBillingServiceFactory`
* Rename files for consistency
* Return stub BillingRepository if billing is not enabled
* Move Stripe billing service to service folder
* Rename file
* `StripeBillingService.getSubscriptionStatus` return `SubscriptionStatus`
* Type fices in StripeBillingService
* Type fix in `stubTeamBillingService`
* DI the `BillingProviderService` into the `TeamBillingService`
* Implement DI in `skipTeamTrials.handler`
* Implement DI for team billing in `inviteMember.handler`
* `skipTeamTrials.handler` use `team.isOrganization`
* Implement DI for billing in `hasActiveTeamPlan.handler`
* Type fixes
* Implement DI in `bulkDeleteUsers.handler`
* Implement `BillingProviderServiceFactory` in `updateProfile.handler`
* Implment `BillingProviderServiceFactory` in `buyCredits.handler`
* Fix import in `stripeCustomer.handler`
* Add a constructor to `teamBillingServiceFactory`
* Add DI to `PrismaTeamBillingRepository`
* Add DI to `StripeBillingService`
* Implement singleton in `BillingProviderServiceFactory`
* Add DI folder and contents to billing folder
* Use `getTeamBillingServiceFactory` in `inviteMember.handler`
* Add `saveTeamBilling` method to `ITeamBillingService`
* Implement DI in new team route
* Implement DI in `teamService`
* Implement DI in `OrganizationPaymentService`
* Implement DI in `credit-service`
* In `StripeBillingService` remove `static` from status methods
* Implemnt DI in `_invoice.paid.org`
* Refactor `hasActiveTeamPlan` to use `getTeamBillingFactory`
* Refactor `skipTeamTrials` to use `getTeamBillingFactory`
* Refactor `skipTeamTrials` to use `getTeamBillingServiceFactory`
* `stripeCustomer.handler` to use `getBillingProviderService`
* Remove old factories
* Type fix
* Remove unused factory
* Refactor `updateProfile.handler` to use `getBillingProviderService`
* Change name to `TeamBillingDataRepositoryFactory`
* Type Prisma return in `prisma.module`
* Type fix
* Refactor `buyCredits.handler` to use `getBillingProviderService`
* Refactor `credit-service` to use billing DI containers
* Type fix
* Add `getTeamBillingDataRepository`
* Refactor `_invoice.paid.org` to use DI container
* Refactor `_customer.subscription.deleted.team-plan` to use DI container
* Refactor `calcomHandler` to use DI container
* Refactor `getCustomerAndCheckoutSession` to use DI container
* Refactor `verify-email` to use DI containers
* Refactor `api/create/route` to use DI container
* Refactor downgradeUsers to use DI container
* Type fix
* Clean up console.logs
* Add await to `this.billingRepository.create` in `saveTeamBilling`
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
* Fix type errors
* Address comments
* fix: update tests to work with new DI pattern
- Update teamBillingService.test.ts to properly inject DI dependencies
- Remove unused billingModule import and mock
- Fix import naming in teamService.integration-test.ts (remove unused rename)
- Fix import path for TeamBillingPublishResponseStatus
All tests now properly mock IBillingProviderService, ITeamBillingDataRepository,
and IBillingRepository instead of using the old BillingRepositoryFactory pattern.
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: add compatibility layer and env setup for unit tests
- Add STRIPE_PRIVATE_KEY dummy value to vitest.config.ts to prevent DI module errors
- Fix import paths in credit-service.test.ts (StripeBillingService, TeamBillingService)
- Create compatibility barrel at packages/features/ee/billing/teams/index.ts for test mocking
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: update unit tests to mock DI container properly
- Update teamService.test.ts to mock getTeamBillingServiceFactory() instead of TeamBilling.findAndInit
- Update teamService.alternative.test.ts to mock DI container
- Update credit-service.test.ts to mock getBillingProviderService() and use SubscriptionStatus enum values
- Update OrganizationPaymentService.test.ts to mock DI container instead of direct StripeBillingService import
- Remove all 'as any' type casting to comply with Cal.com coding standards
- Fix unused variable warnings by prefixing with underscore
All 53 tests now passing (16 + 1 + 30 + 6)
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: update remaining unit tests to use DI pattern
- Fix StripeBillingService.test.ts to inject mock Stripe client directly
- Fix teamBillingFactory.test.ts to mock getTeamBillingServiceFactory() from DI container
- Fix skipTeamTrials.test.ts to mock DI container and use SubscriptionStatus enum
All 11 previously failing tests now pass (5 + 5 + 1)
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* Undo changes made to Prisma module
* fix: address test-related PR comments
- Fix OrganizationPaymentService.test.ts mock path from @calcom/ee to @calcom/features/ee
- Refactor teamBillingFactory.test.ts to test real factory logic instead of mocking container
- Remove duplicate teamBillingService.test..ts file with incorrect double-dot filename
All three test files now pass successfully with proper DI patterns.
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* Address feedback
* fix: update teamService integration test to mock new DI factory pattern
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* refactor: remove duplicate imports in credit-service.test.ts
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* Remove unused index file
* `getBySubscriptionId` to return team or null
* Address feedback
* Merge fix
* Refactor file names
* fix: correct mockStripe variable name to stripeMock in StripeBillingService.test.ts
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* refactor: update internal-team-billing.test.ts to use new DI structure with TeamBillingService
- Replace InternalTeamBilling with TeamBillingService
- Use constructor injection with mock dependencies instead of factory pattern
- Remove BillingRepositoryFactory mock and import
- Update all test cases to use mockBillingProviderService, mockTeamBillingDataRepository, and mockBillingRepository
- Simplify saveTeamBilling tests to focus on repository.create calls
- All 11 tests now pass with the new DI structure
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: update createWithPaymentIntent.handler.test.ts to mock DI container's getBillingProviderService
- OrganizationPaymentService now uses getBillingProviderService() from DI container
- Test was mocking @calcom/features/ee/payments/server/stripe directly, which no longer works
- Added mock for @calcom/features/ee/billing/di/containers/Billing module
- Mock returns fake billing provider that delegates to mockSharedStripe
- Preserves all existing test assertions and helpers
- Fixed lint error by prefixing unused lastCreatedSessionId with underscore
- All 11 tests now pass (1 skipped as expected)
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
---------
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Syed Ali Shahbaz <52925846+alishaz-polymath@users.noreply.github.com>
* feat: add organization-level autofill disable setting
- Create DisableAutofillOnBookingPageSwitch component following existing patterns
- Add toggle to organization general page alongside other settings
- Update tRPC organizations update handler to support new field
- Add organization-level check to useShouldBeDisabledDueToPrefill hook
- Add translation keys for new autofill disable setting
- Include database migration for disableAutofillOnBookingPage field
- Maintain backward compatibility with individual field settings
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* feat: complete autofill disable implementation
- Add disableAutofillOnBookingPage to orgSettings type definition
- Update Prisma schema with new organization setting field
- Clean up test file formatting
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* fix: resolve tRPC mocking issues in tests and add missing disableAutofillOnBookingPage to organization repository
- Fix tRPC module mocking in useShouldBeDisabledDueToPrefill tests
- Add disableAutofillOnBookingPage to organization repository select and return statements
- All form builder tests now pass (24/24)
- Organization-level autofill disable tests working correctly
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* test: simplify autofill disable test to single focused test
- Replace multiple tests with one test that verifies org setting blocks autocomplete
- Test includes searchParams with prefill data to verify blocking behavior
- Removes unnecessary test complexity as requested
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* fix: add missing disableAutofillOnBookingPage to organizationSettings select statements
- Add disableAutofillOnBookingPage to both parent and main organizationSettings select statements in getTeamWithMembers
- Resolves TypeScript error in getServerSideProps.tsx where MinimumOrganizationSettings type requires this property
- Ensures organization settings type compatibility across the codebase
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* Remove disableAutofillOnBookingPage setting
Removed 'disableAutofillOnBookingPage' setting from organization configuration.
* update
* Remove duplicate settings in common.json
Removed duplicate entries for automatic transcription and autofill settings.
* Fix syntax error in common.json
* update
* add tests
* Remove comments for autofill disabled check
Removed comments explaining scenarios for autofill check.
* addressed review
* fix
* change
* Add handling for disableAutofillOnBookingPage input
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
I am refactoring create teams handler to a service in another PR - thought we should improve the test in the mean time.
<!-- This is an auto-generated description by cubic. -->
---
## Summary by cubic
Expand and restructure tests for createTeamsHandler to cover auth, org/slug validation, team creation and migration, redirects, credits, invites, and subscriptions. This improves reliability ahead of the service refactor.
- **Refactors**
- Rewrote tests into scenario-based suites for Authorization, Organization Validation, Slug Validation, Team Creation/Migration, Redirects, and Edge Cases.
- Added helpers (createTestProfile, flexible createScenario/createTestMembership) and organization/profile support to model slug collisions.
- Assert TRPCError codes/messages and redirect records; cover platform orgs, unpublished/non-existent teams, and empty names.
- Mocked Stripe subscription cancel and inviteMembersWithNoInviterPermissionCheck; verified credit transfer and owner memberships.
<sup>Written for commit 8c216c670faa85bf9a06a8895030f40808fdda0e. Summary will update automatically on new commits.</sup>
<!-- End of auto-generated description by cubic. -->
* Remove auto adding users to an org
* Update tests
* Fix tests
* fix: Update organization invitation E2E tests to not expect auto-accept before signup
- Changed isMemberShipAccepted expectations from true to false before signup
- Users with emails matching orgAutoAcceptEmail are no longer auto-accepted
- They must explicitly accept the invitation after signup
- Fixed lint warnings for unused parameters
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* fix: Update E2E tests to expect pending membership after signup without auto-accept
Since auto-accept functionality was removed, users with emails matching
orgAutoAcceptEmail are no longer automatically accepted into organizations
after signup. They remain in pending state until explicitly accepted.
Updated assertions in:
- 'nonexisting user is invited to Org' test
- 'nonexisting user is invited to a team inside organization' test
Both tests now correctly expect isMemberShipAccepted: false after signup.
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* Restore `verify-email` and tests from `main`
* Add `orgAutoJoinOnSignup` to `organizationSettings`
* Update
`OrganizationRepository.findUniqueNonPlatformOrgsByMatchingAutoAcceptEmail`
to find orgs where `orgAutoJoinOnSignup` is true
* `organization.update` lint fix
* `organization.update` to handle `orgAutoJoinOnSignup`
* Create toggle for `orgAutoJoinOnSignup`
* test: Add comprehensive tests for orgAutoJoinOnSignup functionality
- Update existing test to expect null instead of error when multiple orgs match
- Add test for when orgAutoJoinOnSignup is false (should return null)
- Add test for when orgAutoJoinOnSignup is true (should return org)
- Add test for default behavior (orgAutoJoinOnSignup defaults to true)
These tests verify that the new orgAutoJoinOnSignup setting correctly controls
whether users are automatically added to organizations during email verification.
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* Type fix
* e2e: invited users should be accepted after signup (address cubic r2511916791)
Reverted post-signup isMemberShipAccepted assertions from false to true for
explicit invite scenarios. When users are explicitly invited to an org/team
and complete signup via invite link, their membership should be accepted.
This is distinct from auto-join by domain (controlled by orgAutoJoinOnSignup),
which only affects users who sign up without an invite but match the org's
email domain.
Backend sets membership.accepted = true on invite completion in:
packages/features/auth/signup/utils/createOrUpdateMemberships.ts:61,67,77,83
Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>
* Fix API V2 build
---------
Co-authored-by: Alex van Andel <me@alexvanandel.com>
Co-authored-by: Anik Dhabal Babu <81948346+anikdhabal@users.noreply.github.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* add trigger
* small fixes
* add missing workflow DTOs
* small fixes
* use activeOnWithChildren
* fix active on when switching trigger type
* remove add variable dropdown
* feat: lang support
* fix: type errors
* feat: select voice agent
* refactor: address feedback
* refactor: address feedback
* refactor: missing import
* fix: types
* add getAllWorkflowsFromRoutingForm to WorkflowService
* fix error caused by undefined evt
* fix type error
* fix type error
* fix tests
* feat: add inbound calls
* chore: formatting
* chore
* feat: finish inbound call
* chore: formatting
* fix: update bug
* fix: types
* code clean up
* final fixes and clean up
* remove console.log
* remove template text form from triggers
* add routing form repoditory function
* refactor: Agent Configuration Sheet (#23930)
* refactor: agent configuration sheet
* chore: use default phone numbre
* refactor: improvements
* refactor: improvements
* fix: types
* fix: feedback
* fix bug with key
* chore:
* fix: feedback
* fix: prompt
* add comments
* fix: review
* fix: review
* refactor: class
* refactor: class
* fix test
* allow cal ai action on form triggers
* move any reusable code to scheduleAIPhoneCall
* add missing await
* use predefined FormSubmissionData type
* add .trim() to sms message
* pass contextData instead
* finish base setup
* add missing trigger in update-workflow.input.ts
* allow cal.ai action for form triggers in handler
* chore: add support for form workflows on api v2
* fixup! chore: add support for form workflows on api v2
* ai phone call on form submissions (WIP)
* use existing type for Option array
* pass chosen event type id
* refactor: rename
* Update apps/web/public/static/locales/en/common.json
* Update apps/web/public/static/locales/en/common.json
* add missing imports
* chore: update set value
* fix: remove index
* fix: type error
* fix: update tetss
* use only repository functions in update handler
* move all prisma queries from list.handler
* review suggestions
* fix: use logger
* chore: handle workflows api v2
* chore: handle workflows api v2, split in 2 endpoints
* fix workflow step creation
* remove connect agent and fixes types
* add type to workflow
* chore: use workflow type in apiv2 WorkflowsOutputService
* update worklfow type on update
* chore: use workflow type in apiv2 WorkflowsOutputService
* fix template body for torm trigger
* some UI fixes for email subject/body
* resetting email body when changing form triggers
* use type field to query workflows
* clean up all old active on values
* remove responseId from all funciton calls
* remove undefined from updateTemplate
* refactor: don't use static
* fix: type
* refactor: split routing form and event-type workflows code
* refactor: split routing form and event-type workflows code
* fix template text when adding action
* chore: don't rename WorkflowActivationDto to avoid ci blocking
* refine update schedule to use only allowed actions
* fix type error
* don't allow whatsapp action with form trigger
* fix type error
* return early if activeOn array is empty
* fix: from step type in BaseFormWorkflowStepDto
* fixup! fix: from step type in BaseFormWorkflowStepDto
* api v2 updates
* move all prisma calls to repository (service/workflows.ts)
* use FORM_TRIGGER_WORKFLOW_EVENTS for form queries
* use userRepository
* use FORM_TRIGGER_WORKFLOW_EVENTS in isFormTrigger
* code clean up
* code clean up
* use repository functions in formSubmissionValidation.ts
* fix: schema
* refactor:
* remove action check in update handler
* add event type selection
* event type selector improvements
* adjust update.handler
* set outboundEventTypeId
* add back trpc import
* fix agent repository functions
* clean up
* fix bugs caused by merge
* pass eventTypeId to updateToolsFromAgentId
* add migration for outboundEventTypeId
* add SMS actions to allowed form action constants
* add cal ai to allowed form actions
* pick correct event type for web call
* pass correct routed event type id
* remove unsued import
* fixes for offset api v2
* add missing responseId
* fix failing test
* fix failing test
* improve error message
* remove unused imports
* chore: handle sms step action for form worklfow in dtos
* fix typo
* missing missing newStep
* minor fixes
* remove changes
* add routedEventTypeId
* fix type error
* fix type error
* fix typ error in executAPIPhoneCall.tsx
* add back inboundEventTypeId
* remove console.log
* remove outdated code
* small fixes
* don't throw error for missing phone number
* add back filtered triggerOptions
* fix eventTypeId in testCall handler
* fix type error
* update migration
* fix trigger is not defined
* convert eventTypeId to string
* only use outboundEventTypeId for FORM_SUBMITTED trigger
* show toast when no event type selected
* fix type errors
* add missing translation
* fix type error
* remove callType
* fix tests
* small fixes
* clean up AgentConfigurationSheet
* remove EventTypeSelector file
* code clean up
* clean up
* clean up
* use resusable function for TestPhoneCallDialog and WebCallDialog
* rename result
* fix types for event type id
* use repository runction in workflowReminder.ts
* fix type error
* pass eventTypeIds correctly
* fix typo
* Update apps/web/public/static/locales/en/common.json
Co-authored-by: Udit Takkar <53316345+Udit-takkar@users.noreply.github.com>
* use watch instead of getValues
* change to z.record(z.unknown()) instead of any()
* fix type of eventTypeId
* check permissinon for outBoundEventTypeId
* add isNaN check
* improve function name
* update tools when outbound agent event type id changes
* pass missing outboundEventTypeId
* update migration
* fix test
* remove cal-ai step from test
---------
Co-authored-by: CarinaWolli <wollencarina@gmail.com>
Co-authored-by: Udit Takkar <udit222001@gmail.com>
Co-authored-by: Udit Takkar <53316345+Udit-takkar@users.noreply.github.com>
Co-authored-by: Benny Joo <sldisek783@gmail.com>
Co-authored-by: cal.com <morgan@cal.com>
Co-authored-by: Morgan <33722304+ThyMinimalDev@users.noreply.github.com>
Co-authored-by: Peer Richelsen <peeroke@gmail.com>
2025-11-11 15:24:31 +02:00
MorganGitHubmorgan@cal.com <morgan@cal.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>hbjORbj
* refactor: Split EmailManager into focused service files
- Created separate service files for different email categories:
- auth-email-service.ts: Authentication and verification emails
- organization-email-service.ts: Organization and team emails
- billing-email-service.ts: Payment and credit-related emails
- integration-email-service.ts: Integration and app-related emails
- workflow-email-service.ts: Workflow and custom emails
- recording-email-service.ts: Recording and transcript emails
- Refactored email-manager.ts to keep only core booking lifecycle functions
- Removed unused imports from email-manager.ts
- Updated index.ts to export from all new service files
- Updated all imports across the codebase to use package root (@calcom/emails)
- Fixed lint warnings in handleChildrenEventTypes.ts
This reduces the import cost of EmailManager by allowing consumers to import only the specific email services they need.
Co-Authored-By: morgan@cal.com <morgan@cal.com>
* refactor: Update all imports to use direct service file paths
- Update 49 files to import directly from service files instead of barrel file
- Update packages/emails/index.ts to keep only email-manager and renderEmail exports
- Fix dynamic import in passwordResetRequest.ts
- Update renderEmail imports to use direct path
- Update test file to import from specific service module
- Fix ESLint warnings in modified files (unused variables, unused expressions)
This ensures consumers only import the specific email services they need,
reducing import cost by avoiding the barrel file pattern for service files.
Co-Authored-By: morgan@cal.com <morgan@cal.com>
* fix: Use default import for renderEmail
renderEmail is exported as a default export, not a named export.
Changed from 'import { renderEmail }' to 'import renderEmail'.
Co-Authored-By: morgan@cal.com <morgan@cal.com>
* fix: Update test mocks to use direct service file imports
- Update handleNoShowFee.test.ts to mock @calcom/emails/billing-email-service
- Update credit-service.test.ts to mock @calcom/emails/billing-email-service
- These tests were failing because they were mocking the barrel file @calcom/emails
which no longer exports service functions after the refactoring
Co-Authored-By: morgan@cal.com <morgan@cal.com>
* fix: unit test spy
* fix: unit test mock
* address cubic comments
* fix: type error sendMonthlyDigestEmail
* remove barrel file and sendEmail unused task
* fixup! remove barrel file and sendEmail unused task
* fixup! fixup! remove barrel file and sendEmail unused task
* fix: integration test mock emails
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: hbjORbj <sldisek783@gmail.com>
* test: Add comprehensive security tests for routing forms vulnerability
Add comprehensive test coverage for the getIncompleteBookingSettings handler
vulnerability and ensure entityPrismaWhereClause changes won't break functionality.
Tests added:
1. getIncompleteBookingSettings.handler.test.ts (15 tests)
- Authorization tests for personal and team forms
- Credential sanitization tests (key field should never be exposed)
- Organization hierarchy tests (parent org credentials)
- App filtering tests (only enabled apps)
- Edge cases (no credentials, form not found, etc.)
2. entityPrismaWhereClause.integration.test.ts (13 tests)
- Verifies formQuery, deleteForm, and forms handlers properly scope queries
- Ensures accepted membership is required for team access
- Validates consistent entityPrismaWhereClause usage across handlers
- Prevents regressions when adding role-based filtering
Expected Test Failures:
The getIncompleteBookingSettings tests currently have 4 expected failures that
document the existing vulnerability:
- 2 authorization tests fail (handler doesn't check user access)
- 2 sanitization tests fail (handler leaks the 'key' field with OAuth tokens)
These failures prove the vulnerability exists and document the secure behavior
that should be implemented.
Test Results:
- All 13 entityPrismaWhereClause integration tests pass
- All 18 existing routing-forms test files pass (156 tests)
- 4 security tests fail as expected (documenting the vulnerability)
The tests ensure that:
1. Fixing the vulnerability by adding entityPrismaWhereClause won't break other handlers
2. The key field is never returned in credentials
3. Only authorized users can access forms
4. Team membership requires accepted: true
5. Organization hierarchy is properly handled
Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com>
* Add suggested fix
* Add suggested fix
* fix: enforce authorization scoping and credential sanitization in routing-forms handler
Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com>
* Fix types
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Alex van Andel <me@alexvanandel.com>
* fix: APIV2 team membership addition
* feat: Add trimming for email domain and orgAutoAcceptEmail in auto-accept logic
- Trim whitespace from both user email domain and orgAutoAcceptEmail
- Ensures consistent matching even with accidental whitespace
- Addresses feedback from PR review
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* simplify
* feat: Use shared OrganizationMembershipService in TRPC for consistent auto-accept logic
- Create OrganizationMembershipService.container.ts for DI in TRPC
- Update getOrgConnectionInfo to apply trimming + case-insensitive comparison
- Precompute auto-accept decisions in createNewUsersConnectToOrgIfExists using the service
- Use service in handleNewUsersInvites for consistent auto-accept determination
- Ensures both API v2 and TRPC paths use identical trimming and normalization logic
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* Revert "feat: Use shared OrganizationMembershipService in TRPC for consistent auto-accept logic"
This reverts commit 0b2bd28b6e32e8c1d3dea139ca8ff9cbf402ac00.
* refactor: Unify OrganizationRepository and remove duplicate PrismaOrganizationRepository (#24869)
* refactor: Convert OrganizationRepository from static to instance methods
- Add constructor accepting deps object with prismaClient
- Convert all static methods to instance methods
- Add getOrganizationAutoAcceptSettings method
- Create singleton instance export in repository barrel file
- Update API v2 OrganizationsRepository to extend from OrganizationRepository
- Update all call sites to use singleton instance
- Add platform-libraries organizations.ts export
- Fix mock imports to use repository barrel
- Fix unsafe optional chaining in next-auth-options.ts
- Fix any types in test files with proper type inference
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* fix: Update all imports to use OrganizationRepository barrel export
- Update imports from direct OrganizationRepository file to barrel export
- This ensures mocks work correctly in tests
- Fixes 202 failing tests related to organizationRepository mock
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* fix: Update test mocks to use partial mock pattern
- Convert organizationMock to partial mock that preserves real class
- Add proper prisma mocks to failing test files
- Remove old OrganizationRepository mocks from test files
- This fixes test failures related to mock interception
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* fix: Export mocked singleton and update tests to use it directly
- Export mockedSingleton as organizationRepositoryMock from organizationMock
- Update delegationCredential.test.ts to import and use the exported mock
- This fixes 'vi.mocked(...).mockResolvedValue is not a function' errors
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* fix: Use platform-libraries import for API v2 OrganizationRepository
API v2 should import shared features through @calcom/platform-libraries
instead of directly from @calcom/features to maintain proper architectural
boundaries and packaging/licensing separation.
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* refactor: Implement DI pattern for OrganizationRepository
- Create OrganizationRepository.module.ts and .container.ts for DI
- Replace singleton pattern with getOrganizationRepository() across 20 files
- Update platform-libraries to export getOrganizationRepository
- Delete duplicate PrismaOrganizationRepository.ts
- Remove singleton export file (repositories/index.ts)
- Update test mocks to use DI container pattern
- All type checks and unit tests passing
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* fix: Implement read/write client separation in OrganizationRepository
- Updated OrganizationRepository constructor to accept optional prismaWriteClient parameter
- Routed all write operations (create, update) through prismaWrite client
- Routed all read operations (find, get) through prismaRead client
- Updated API v2 OrganizationsRepository to pass both dbRead.prisma and dbWrite.prisma to super()
- Optimized getOrganizationRepository() calls by storing in local variables to avoid repeated function calls
- This fixes the critical issue where API v2 was passing read-only client to base class with write methods
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* fix: Fix mock setup and optimize getOrganizationRepository() calls
- Fixed verify-email.test.ts mock to return mocked repository instance instead of scenario helper object
- Added mockReset to organizationMock.ts beforeEach to properly reset mock implementations between tests
- Added local variables in page.tsx to store getOrganizationRepository() result for consistency
This fixes the issue where getOrganizationRepository() was returning organizationScenarios.organizationRepository (scenario helper) instead of the actual mocked repository instance, causing findUniqueNonPlatformOrgsByMatchingAutoAcceptEmail to be undefined.
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* refactor: Simplify OrganizationRepository to use single prismaClient
- Updated base OrganizationRepository constructor to accept only { prismaClient } instead of { prismaClient, prismaWriteClient? }
- Replaced this.prismaRead and this.prismaWrite with single this.prismaClient property
- Updated API v2 OrganizationsRepository to pass only dbWrite.prisma as prismaClient
- Removed unused PrismaReadService import from API v2
- All read and write operations now use the same client instance
This simplifies the architecture as requested - API v2 uses write client for all operations, and apps/web uses the client from DI container.
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix: Match OrganizationsRepository.findById signature with base class
The findById method in OrganizationsRepository was using a different signature
than the base OrganizationRepository class, causing type errors in CI.
Changed from: findById(organizationId: number)
Changed to: findById({ id }: { id: number })
This matches the base class signature and resolves the CI unit test failures.
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* fix: Update all findById call sites to use object parameter
Fixed 6 call sites in API v2 that were calling findById with a number
instead of the required { id: number } object parameter:
- is-org.guard.ts
- is-admin-api-enabled.guard.ts
- is-webhook-in-org.guard.ts
- organizations.service.ts
- managed-organizations.service.ts (2 call sites)
This resolves the API v2 build failure caused by the signature change
in OrganizationsRepository.findById to match the base class.
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* fix: Remove redundant findById override from OrganizationsRepository
The findById method was duplicating the base class OrganizationRepository
implementation. Both methods had identical logic (filtering by isOrganization: true),
so the override was unnecessary.
Since OrganizationsRepository extends OrganizationRepository and passes
dbWrite.prisma to the base constructor, the base class method already
provides the exact same functionality.
This resolves the API v2 build failure by eliminating the duplicate method
that was causing conflicts.
Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com>
* Remove unncessary changes
* Store in variable
* Revert "Remove unncessary changes"
This reverts commit af9351786a21616c9508c441191c17f2374fb2cc.
* Revert dbRead/dbWrite changes
* Add organizations library to tsconfig.json
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Morgan <33722304+ThyMinimalDev@users.noreply.github.com>
## What does this PR do?
- Redesigns and streamlines the onboarding flow for personal, team, and organization accounts
- Consolidates shared components and improves code organization
- Adds browser preview for better user experience during onboarding
- Simplifies the personal onboarding flow by removing the video integration step
- Enhances team onboarding with CSV upload functionality
## Visual Demo (For contributors especially)
#### Image Demo:
- The PR adds a new browser preview component that shows users how their profile/team will look during onboarding
- Redesigned UI with a more consistent layout across all onboarding steps
- Improved mobile responsiveness with better component organization
## Mandatory Tasks (DO NOT REMOVE)
- [x] I have self-reviewed the code.
- [x] I have updated the developer docs in /docs if this PR makes changes that would require a documentation change. If N/A, write N/A here and check the checkbox.
- [x] I confirm automated tests are in place that prove my fix is effective or that my feature works.
## How should this be tested?
1. Test the complete onboarding flow for personal accounts:
- Start at `/onboarding/getting-started`
- Proceed through personal details and calendar setup
- Verify the flow completes successfully
2. Test the team onboarding flow:
- Start at `/onboarding/getting-started` and select team
- Complete team details
- Test the invite options including CSV upload
- Verify team creation works correctly
3. Test the organization onboarding flow:
- Start at `/onboarding/getting-started` and select organization
- Complete organization details and branding
- Test member invitations
- Verify organization creation works correctly
4. Verify browser preview functionality:
- Check that the preview updates in real-time as you enter information
- Confirm it displays correctly on different screen sizes
## Checklist
- I have read the [contributing guide](https://github.com/calcom/cal.com/blob/main/CONTRIBUTING.md)
- My code follows the style guidelines of this project
- I have commented my code, particularly in hard-to-understand areas
- I have checked if my changes generate no new warnings
- Remove cal.cache query parameter parsing from booking and slots flows
- Set shouldServeCache to false for all booking availability checks
- Remove _shouldServeCache from schemas and type definitions
- Clean up all references in platform atoms and API endpoints
This ensures fresh Google Calendar data is always fetched for conflict checking,
preventing bookings when there are actual calendar conflicts.
* fix: align booking limit timezone between availability and validation
- Use eventType.schedule?.timeZone for booking limits in availability calculation
- Previously used user's timezone causing day boundary mismatch
- Add unit tests to verify timezone alignment
- Fixes issue where slots remain available after reaching booking limit
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* Rename variable limitsTz to eventTimeZone
* update
* fix: correct timezone fallback to include user timezone without forcing UTC
- Changed fallback chain to: schedule → event → user → undefined
- Treats empty strings as missing timezones
- Does not force UTC when all timezones are missing
- Aligns with validation behavior when timezone is undefined
- Fixes getSchedule.test.ts failures
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* Revert "fix: correct timezone fallback to include user timezone without forcing UTC"
This reverts commit 721e0bdfd7b08004e68df6bdf5b97b9bd6cf3d5c.
* test: remove complex unit tests with 'as any' casts
- Removed Booking Limits Timezone Alignment tests that required heavy mocking
- These tests relied on spying private methods and had many 'as any' casts
- Timezone alignment is already covered by integration tests in getSchedule.test.ts
- Kept BookingDateInPastError test which has no type issues
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* address review
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>