Files
calendar/apps/api/v2
devin-ai-integration[bot]GitHubDevin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>morgan@cal.com <morgan@cal.com>Morgan
21422fe027 feat: enhance API v2 exception filters with user context for improved Axiom observability (#22157)
* feat: enhance API v2 exception filters with user context for improved Axiom observability

- Add extractUserContext utility to safely extract user/org/team context from request
- Enhance all 5 exception filters (HTTP, TRPC, Prisma, Zod, Calendar) with user context
- Include userId, userEmail, organizationId, teamId in Axiom logs when available
- Improve observability for debugging and monitoring authenticated requests

Co-Authored-By: morgan@cal.com <morgan@cal.com>

* chore: update yarn.lock from lint-staged hooks

Co-Authored-By: morgan@cal.com <morgan@cal.com>

* fix: use request.organization instead of request.organizationId

- Address GitHub comment feedback from ThyMinimalDev
- Extract organization ID from organization object for consistency
- Follows same pattern as user and team extraction

Co-Authored-By: morgan@cal.com <morgan@cal.com>

* fix: revert to using request.organizationId as requested in GitHub comment

- Change back from request.organization to request.organizationId
- This aligns with how auth strategies actually populate the request object
- Addresses GitHub comment from ThyMinimalDev

Co-Authored-By: morgan@cal.com <morgan@cal.com>

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: morgan@cal.com <morgan@cal.com>
Co-authored-by: Morgan <33722304+ThyMinimalDev@users.noreply.github.com>
2025-07-01 10:05:21 +03:00
..
2025-06-27 13:49:28 +02:00
2025-04-24 16:06:37 +03:00

Nest Logo

A progressive Node.js framework for building efficient and scalable server-side applications.

NPM Version Package License NPM Downloads CircleCI Coverage Discord Backers on Open Collective Sponsors on Open Collective Support us

Description

Cal.com is using the Nest framework TypeScript starter repository.

Installation

$ yarn install

Prisma setup

$ yarn prisma generate

Env setup

Copy .env.example to .env and fill values.

Add license Key to deployments table in DB

id, logo theme licenseKey agreedLicenseAt 1, null, null, 'c4234812-12ab-42s6-a1e3-55bedd4a5bb7', '2023-05-15 21:39:47.611'

your CALCOM_LICENSE_KEY env var need to contain the same value

.env CALCOM_LICENSE_KEY=c4234812-12ab-42s6-a1e3-55bedd4a5bb

Running the app

Development

$ yarn run start

OR if you don't want to use docker, you can run following command.

$ yarn dev:no-docker

Additionally you can run following command(in different terminal) to ensure that any change in any of the dependencies is rebuilt and detected. It watches platform-libraries, platform-constants, platform-enums, platform-utils, platform-types.

$ yarn run dev:build:watch

If you are making changes in packages/platform/libraries, you should run the following command too that would connect your local packages/platform/libraries to the api/v2

$ yarn local

watch mode

$ yarn run start:dev

production mode

$ yarn run start:prod





## Test

```bash
# unit tests
$ yarn run test

# e2e tests
$ yarn run test:e2e

# e2e tests in watch mode
$ yarn test:e2e:watch 

# run specific e2e test file in watch mode
$ yarn test:e2e:watch --testPathPattern=filePath

# test coverage
$ yarn run test:cov

Conventions

Guards

  1. In case a guard would return "false" for "canActivate" instead throw ForbiddenException with an error message containing guard name and the error.
  2. In case a guard would return "false" for "canActivate" DO NOT cache the result in redis, because we don't want that someone is forbidden, updates whatever was the problem, and then has to wait for cache to expire. We only cache in redis guard results where "canAccess" is "true".
  3. If you use ApiAuthGuard but want that only specific auth method is allowed, for example, api key, then you also need to add @ApiAuthGuardOnlyAllow(["API_KEY"]) under the @UseGuards(ApiAuthGuard). Shortly, use ApiAuthGuardOnlyAllow to specify which auth methods are allowed by ApiAuthGuard. If ApiAuthGuardOnlyAllow is not used or nothing is passed to it or empty array it means that all auth methods are allowed.

Support

Nest is an MIT-licensed open source project. It can grow thanks to the sponsors and support by the amazing backers. If you'd like to join them, please read more here.

Stay in touch

License

Nest is MIT licensed.