* chore: Upgrade prisma to 6.7.0 * Build fixes * type fixes Signed-off-by: Omar López <zomars@me.com> * Update schema.prisma * Patching * Revert "Update schema.prisma" This reverts commit 47d8618bf89ef4d007b30084df766f17281e21a1. * Revert "Patching" This reverts commit a1d2e3040e71690a44d4324db95d73b4d68c6adb. * Revert schema changes Signed-off-by: Omar López <zomars@me.com> * WIP Signed-off-by: Omar López <zomars@me.com> * Update getPublicEvent.ts * Update imports Signed-off-by: Omar López <zomars@me.com> * Update gitignore Signed-off-by: Omar López <zomars@me.com> * update remaining imports Signed-off-by: Omar López <zomars@me.com> * Delete .cursor/config.json * Discard changes to packages/features/eventtypes/lib/getPublicEvent.ts * Update _get.ts * Update user.ts * Update .gitignore * update * Update WorkflowStepContainer.tsx * Update next-auth-custom-adapter.ts * Update getPublicEvent.ts * Update workflow.ts * Update next-auth-custom-adapter.ts * Update next-auth-options.ts * Update bookingScenario.ts * fix missing imports * upgrades prismock Signed-off-by: Omar López <zomars@me.com> * patches prismock Signed-off-by: Omar López <zomars@me.com> * Update reschedule.test.ts * Update prisma.ts * patch prismock Signed-off-by: Omar López <zomars@me.com> * fix enums imports Signed-off-by: Omar López <zomars@me.com> * Revert "Update prisma.ts" This reverts commit 64edcf8db54171ff4456c209d563b5d431d99619. * Revert "patch prismock" This reverts commit e95819113dc9d88e7130947aa120cd42710977c8. * fix patch * Fix test that overrun the boundary, it shouldn't test too much * Move prisma import to changeSMSLockState * Bring back broken test without illegal imports * Merge with main and fix filter hosts by same round robin host * Fixed buildDryRunBooking fn tests * Fix and move ooo create or update handler test * Fix packages/features/eventtypes/lib/isCurrentlyAvailable.test.ts * Fix packages/trpc/server/routers/viewer/organizations/listMembers.handler.test.ts * Mock @calcom/prisma * Fix: verify-email.test.ts * fix: Moved WebhookService test and fixed default import mock * Fix: Added missing prisma mock, handleNewBooking uses that of course * We're not testing createContext here * fix: Prisma mock fix for listMembers.test.ts * More fixes to broken testcases * Forgot to remove borked test * Prevent the need to mock a lot of dependencies by moving out buildBaseWhereCondition to its own file * Temporarily skip getCalendarEvents, needs a rewrite * Fix: turns out you can access protected in testcases * fix further mocks * Added packages/features/insights/server/buildBaseWhereCondition.ts, types * Always great to have a mock and then not use it * And one less again. * fix: confirm.handler.test, didn't mock prisma * fix: Address minor nit by @eunjae & fix ImpersonationProvider test * Updated isPrismaAvailableCheck that doesn't crash on import * fix: Get Prisma directly from the client, it usually involves the Validator and does not need 'local' inclusion * Add zod-prisma-types without the generator enabled (commented out) * Uncomment and see what happens * Change method of import as imports did not work in Input Schemas * Remove custom 'zod' booking model, it does not belong with Prisma * Fix all other global Model imports * Rewrite most schema includes AND remove barrel file * Add bookingCreateBodySchema to features/bookings * Flurry of type fixes for compatibility with new zod gen * Refactor out the custom prisma type createEventTypeInput * Work around nullable eventTypeLocations * HandlePayment type fix * More fixes, final fix remaining is CompleteEventType * Should fix a bunch more booking related type errors * Missed one * Some props missing from BookingCreateBodySchema * Fix location type in handleChildrenEventTypes * Little bit hacky imo but it works * Final type error \o/ * Forgot to include Prisma * Do not include zod-utils in booker/types * Oops, was already including Booker/types * Fix membership type, also disallow updating createdAt/updatedAt, make part of patch/post * Fix api v1 type errors * Fix EventTypeDescription typings * Remove getParserWithGeneric, use userBodySchema with UserSchema * use centralized timeZoneSchema * Implement feedback by @zomars * Couple of WIP pushes * Fix tests * Type fixes in `handleChildrenEventTypes` test * Try and parse metadata before use * Change zod-prisma-types configuration for optimal performance * Fix prisma validator error in `prisma/selects/credential` * Disable seperate relations model, hits a bug * Import absolute - this makes rollup work in @platform/libraries * Attempt at removing resolutions override * Refactor using `Prisma.validator` to `satisfies` * Build atoms using @calcom/prisma/client * Build atoms using @calcom/prisma/client * fixes * Update eventTypeSelect.ts * Adjust `eventTypeMetaDataSchemaWithUntypedApps` from `unknown` to `record(any)` * `EventTypeDescription` rely on `descriptionAsSafeHTML` instead of `description` * Add `seatsPerTimeSlot` to event type public select * Fix typing in `users-public-view` getServerSide props * Add missing `schedulingType` to prop * chore: bump platform libraries * Function return type is illegal, not sure how this passed eslint (#21567) * Merged with main * Update updateTokenObject.ts * Update handleResponse.ts * Update index.ts * Update handleChildrenEventTypes.ts * Update booking-idempotency-key.ts * Update WebhookService.test.ts * Update events.test.ts * Update queued-response.test.ts * Update events.test.ts * Update getRoutedUrl.test.ts * fix: type checks Signed-off-by: Omar López <zomars@me.com> * fixes Signed-off-by: Omar López <zomars@me.com> * chore: bump platform libraries * Update yarn.lock * more fixes Signed-off-by: Omar López <zomars@me.com> * fixes Signed-off-by: Omar López <zomars@me.com> * biuld fixes * chore: bump platform libraries * Update conferencing.repository.ts * Update conferencing.repository.ts * Update getCalendarsEvents.test.ts * Update vite.config.js * chore: bump platform libraries * Update users.ts * Discard changes to docs/api-reference/v2/openapi.json * Update vite.config.ts * updated platform libraries * Update get.handler.test.ts * Update get.handler.test.ts * Update schema.prisma * Discard changes to docs/api-reference/v2/openapi.json * Update next-auth-custom-adapter.ts * Update team.ts * Flurry of type fixes * Fix majority of insight related type errors * Type fixes for unlink of account * Make user nullable again * Fixed a bunch of unit tests and one type error * Attempted mock fix * Attempted fix for Attribute type * Ensure default import becomes prisma, but not direct usage * Import default as prisma in prisma.module * Add attributeOption to attribute type * Fix calcom/prisma mock * Refactor Prisma client imports to @calcom/prisma/client Updated all imports from '@prisma/client' to '@calcom/prisma/client' across tests and repository files for consistency and to use the correct Prisma client package. This change improves maintainability and ensures the correct client is referenced throughout the codebase. * Undo removal of max-warnings=0 to get main to merge * Remove unit tests for e2e fixtures, provide new prisma mock * Mock @calcom/prisma in event manager * Mock @calcom/prisma in event manager * Add correct format even with --no-verify * Mock prisma in CalendarManager * Add mock for permission-check.service * Better injection in PrismaApiKeyRepository imports * More mock fixes :) * Fix listMembers.handler.test * Fix User import * Appropriately adjust all types to be imported as types, there were a lot of types imported as normal deps * Why was this a thing? * Strictly speaking; Not using prismock anymore * Ditched patch file for prismock * Fix output.service.ts platform type imports, need concrete for plainToClass * Better typing and tests for unlinkConnectedAccount.handler * Small type fix * Disable calendar cache tests as they are dependent on prismock * chore: bump platform lib * getRoutedUrl test remove of unused import * Extract select to external const on getEventTypesFromDB * Direct select of userSelect from selects/user * fix type error from merging 23653 * Fixed integration tests by removing hardcoded values that were possible due to mocking, but as its now directly hitting the db no longer * fix: vite config atoms prisma client type location * revert: example app prisma client * revert: example app prisma client * bump platform libs * fix: use class instead of type for DI of PlatformBookingsService * update platform libs * remove unused variable * chore: generate prisma client for api v2 * fix: api v2 e2e * fix: atoms e2e * fix: atoms e2e * fix: atoms e2e * fix: api v2 e2e * fix: tsconfig apiv2 enums * publish libraries * Simplify check for existence teamId --------- Signed-off-by: Omar López <zomars@me.com> Co-authored-by: Alex van Andel <me@alexvanandel.com> Co-authored-by: Joe Au-Yeung <j.auyeung419@gmail.com> Co-authored-by: supalarry <laurisskraucis@gmail.com> Co-authored-by: cal.com <morgan@cal.com> Co-authored-by: Morgan <33722304+ThyMinimalDev@users.noreply.github.com> Co-authored-by: Benny Joo <sldisek783@gmail.com>
Permission-Based Access Control (PBAC) System
Overview
The PBAC system provides fine-grained access control for Cal.com using a combination of CRUD-based permissions and custom actions, while maintaining backward compatibility with the existing role system.
Implementation
Permission Store
The system uses a centralized Zustand store with optimized data structures for fast permission lookups:
interface TeamPermissions {
roleId: string;
permissions: Set<PermissionString>; // O(1) lookup
}
interface PermissionStore {
teamPermissions: Map<number, TeamPermissions>; // O(1) lookup
setTeamPermissions: (permissions: Record<number, { roleId: string; permissions: PermissionString[] }>) => void;
hasPermission: (teamId: number, permission: PermissionString) => boolean;
hasPermissions: (teamId: number, permissions: PermissionString[]) => boolean;
}
Context Provider
The system uses a React context provider that fetches all permissions once at the root level:
<PermissionProvider>
<App />
</PermissionProvider>
The provider automatically:
- Fetches permissions for all teams the user has access to
- Caches the results (5-minute stale time)
- Updates the central store
- Provides loading states
Permission Hooks
Two main hooks are provided for checking permissions:
// Check single permission
const { hasPermission, isLoading } = usePermission(teamId, "team.update");
// Check multiple permissions
const { hasPermissions, isLoading } = usePermissions(teamId, ["team.update", "team.invite"]);
Permission Format
Permissions follow two formats:
- CRUD Permissions:
${resource}.${action} - Custom Actions:
custom:${resource}.${action}
// CRUD Permission Examples
"eventType.create"
"booking.read"
// Custom Action Examples
"custom:team.invite"
"custom:booking.readRecordings"
Role Types
-
Default Roles (MembershipRole)
- OWNER: Full access (
*.*) - ADMIN: Extensive management permissions
- MEMBER: Basic read permissions
- OWNER: Full access (
-
Custom Roles
- Team-specific roles with granular permissions
- Can be assigned alongside default roles
Permission Structure
CRUD Actions
export enum CrudAction {
Create = 'create',
Read = 'read',
Update = 'update',
Delete = 'delete',
}
Custom Actions
export enum CustomAction {
Invite = 'invite', // Invite members to team/org
Remove = 'remove', // Remove members from team/org
Override = 'override', // Override availability
ReadRecordings = 'readRecordings', // Access booking recordings
ManageBilling = 'manageBilling', // Manage org billing
}
Resources
export enum Resource {
EventType = 'eventType',
Booking = 'booking',
Team = 'team',
Organization = 'organization',
Insights = 'insights',
Availability = 'availability',
Workflow = 'workflow',
RoutingForm = 'routingForm',
}
Usage Guide
1. Setup Provider
// app/layout.tsx or similar
import { PermissionProvider } from "@calcom/features/pbac/context/PermissionProvider";
export default function RootLayout({ children }: { children: React.ReactNode }) {
return (
<PermissionProvider>
{children}
</PermissionProvider>
);
}
2. Use in Components
import { usePermission, usePermissions } from "@calcom/features/pbac/hooks/usePermission";
function TeamSettings({ teamId }: { teamId: number }) {
// Single permission check
const { hasPermission, isLoading } = usePermission(teamId, "team.update");
// Multiple permissions check
const { hasPermissions } = usePermissions(teamId, [
"team.update",
"team.invite"
]);
if (isLoading) return <div>Loading...</div>;
return (
<div>
{hasPermission && <button>Update Team</button>}
{hasPermissions && <button>Update and Invite</button>}
</div>
);
}
3. Performance Considerations
- Permission checks are O(1) using Map and Set data structures
- Permissions are fetched once and cached for 5 minutes
- No redundant API calls for permission checks
- Automatic updates when permissions change via store
Common Permission Combinations
Event Manager Role
const permissions = [
// CRUD Permissions
"eventType.create",
"eventType.read",
"eventType.update",
"eventType.delete",
// Custom Actions
"custom:booking.readRecordings",
"custom:availability.override"
];
Analytics Role
const permissions = [
// CRUD Permissions
"insights.read",
"booking.read",
"eventType.read",
// Custom Actions
"custom:organization.manageBilling"
];
Team Admin Role
const permissions = [
// CRUD Permissions
"team.create",
"team.read",
"team.update",
// Custom Actions
"custom:team.invite",
"custom:team.remove",
"custom:availability.override"
];
Database Schema
model Role {
id String @id @default(cuid())
name String
teamId Int?
permissions RolePermission[]
}
model RolePermission {
id String @id @default(cuid())
roleId String
resource String
action String
isCustom Boolean @default(false) // Indicates if this is a custom action
role Role @relation(fields: [roleId], references: [id])
}
Example Use Cases
1. Event Type Management
// Full event type management
[
"eventType.create",
"eventType.read",
"eventType.update",
"eventType.delete"
]
// Read-only access
["eventType.read"]
2. Team Management with Custom Actions
[
"team.read",
"team.update",
"custom:team.invite",
"custom:team.remove"
]
3. Booking Management with Recordings
[
"booking.read",
"booking.update",
"custom:booking.readRecordings"
]
Usage
Server-Side (React Server Components)
import { cookies, headers } from "next/headers";
import { checkUserPermissionInTeam } from "@calcom/features/pbac/lib/server/checkPermissions";
// In a Server Component
export default async function TeamSettings({ params }: { params: { teamId: string } }) {
const session = buildLegacyRequest(await headers(), await cookies())
if(!session?.user?.id){
return null
}
const hasPermission = await checkUserPermissionInTeam({
userId: session.user.id,
teamId: parseInt(params.teamId),
permission: "team.update",
});
if (!hasPermission) {
return <div>Not authorized</div>;
}
return <div>Team Settings</div>;
}
// Check multiple permissions
const hasPermissions = await checkMultiplePermissionsInTeam({
userId: session.user.id,
teamId: teamId,
permissions: ["team.update", "team.invite"],
});
Client-Side (React Components)
import { usePermission, usePermissions } from "@calcom/features/pbac/hooks/usePermission";
// In a React Component
function TeamSettingsButton({ teamId }: { teamId: number }) {
// Single permission check
const { hasPermission, isLoading } = usePermission(teamId, "team.update");
if (isLoading) return <div>Loading...</div>;
if (!hasPermission) return null;
return <button>Update Team Settings</button>;
}
// Multiple permissions check
function TeamAdminPanel({ teamId }: { teamId: number }) {
const { hasPermissions, isLoading } = usePermissions(teamId, [
"team.update",
"team.invite"
]);
if (isLoading) return <div>Loading...</div>;
if (!hasPermissions) return <div>Insufficient permissions</div>;
return <div>Admin Panel</div>;
}
Available Permissions
Permissions follow the format resource.action where:
resourceis the entity being accessed (e.g., team, eventType, booking)actionis the operation being performed (e.g., create, read, update, delete)
Common permissions include:
team.create- Create teamsteam.update- Update team settingsteam.invite- Invite team membersteam.remove- Remove team memberseventType.create- Create event typeseventType.update- Update event typesbooking.read- Read booking details
For a complete list of permissions, see PERMISSIONS.md.
Caching
The client-side hooks automatically cache permission results for 5 minutes to reduce API calls. The cache can be invalidated by calling the TRPC mutation to update permissions.
Default Roles and Permissions
The system comes with three pre-configured default roles:
1. Owner Role (owner_role)
- Has full access to all resources via wildcard permission (
*.*) - Automatically assigned to team/organization creators
- Cannot be modified or deleted
- Permissions:
"*.*" // Grants access to all actions on all resources
2. Admin Role (admin_role)
- Has extensive management permissions
- Can manage team settings and members
- Permissions:
// Booking permissions "booking.*" // All booking operations "booking.readTeamBookings" "booking.readOrgBookings" // Event Type permissions "eventType.*" // All event type operations // Team management "team.invite" "team.remove" "team.changeMemberRole" // Organization permissions "organization.listMembers" "organization.read" "organization.update" // Other resource permissions "apiKey.*" // All API key operations "routingForm.*" // All routing form operations "workflow.*" // All workflow operations "insights.read" // Read access to insights
3. Member Role (member_role)
- Basic read access to resources
- Default role for new team members
- Permissions:
"booking.read" "eventType.read" "team.read" "organization.read" "routingForm.read"
Using Default Roles
You can reference these roles programmatically using the constants provided in @calcom/features/pbac/lib/constants:
import { DEFAULT_ROLES } from "@calcom/features/pbac/lib/constants";
// Reference roles
const ownerRoleId = DEFAULT_ROLES.OWNER; // 'owner_role'
const adminRoleId = DEFAULT_ROLES.ADMIN; // 'admin_role'
const memberRoleId = DEFAULT_ROLES.MEMBER; // 'member_role'
Role Assignment
-
Default roles are automatically assigned during:
- Team creation (creator gets OWNER role)
- Member invitation (gets MEMBER role by default)
- Role changes through team management UI
-
Roles can be changed by team owners and admins through:
- Team member management interface
- Organization member management interface
- API endpoints (with proper permissions)