Files
calendar/agents/rules/data-prefer-select-over-include.md
Benny JooGitHubDevin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
ab21c7f805 refactor: Cal.diy (#28903)
* feat: Cal.diy — community-driven MIT-licensed fork of Cal.com

This squashed commit contains all Cal.diy changes applied on top of calcom/cal.com main:

- Rebrand Cal.com to Cal.diy across the entire codebase
- Remove Enterprise Edition (EE) features, license checks, and AGPL restrictions
- Switch license from AGPL-3.0 to MIT
- Remove docs/ directory (migrated to Nextra at cal.diy)
- Remove dead code: org tests, EE tips, platform nav, premium username, SAML/SSO, etc.
- Clean up .env.example for self-hosted Cal.diy
- Update Docker image references to calcom/cal.diy
- Update README, CONTRIBUTING.md, and issue templates for Cal.diy community fork
- Add PR welcome bot for Cal.diy contributors
- Fix API v2 breaking changes oasdiff ignore entries
- Replace Blacksmith CI runners with default GitHub Actions

3893 files changed, 20789 insertions(+), 411020 deletions(-)

Co-Authored-By: [email protected] <[email protected]>

* refactor: remove org-specific /organizations/:orgId endpoints from API v2 atoms controllers (#1701)

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix: revert Cal.diy Inc to Cal.com, Inc. in license files, copyright notices, and package metadata (#1702)

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* rip out org related comments in api v2

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-04-15 09:52:36 -03:00

1.3 KiB

title, impact, impactDescription, tags
title impact impactDescription tags
Prefer Select Over Include in Prisma Queries HIGH Reduces data transfer and improves query performance prisma, database, performance, security

Prefer Select Over Include in Prisma Queries

Impact: HIGH (Reduces data transfer and improves query performance)

Using select instead of include in Prisma queries fetches only the fields you need, improving performance and preventing accidental exposure of sensitive data.

Incorrect (using include fetches all fields):

const booking = await prisma.booking.findFirst({
  include: {
    user: true, // This gets ALL user fields including sensitive ones
  }
});

Correct (using select for specific fields):

const booking = await prisma.booking.findFirst({
  select: {
    id: true,
    title: true,
    user: {
      select: {
        id: true,
        name: true,
        email: true,
      }
    }
  }
});

Benefits:

  • Performance: Smaller payloads, faster queries
  • Security: Prevents accidental exposure of sensitive fields (e.g., credential.key)
  • Clarity: Makes data requirements explicit

Exception: Use include only when you genuinely need all fields from a relation, which is rare.

Reference: Cal.diy Engineering Standards