43dd24c480
* refactor: migrate TeamEventTypeForm to use PBAC instead of isTeamAdminOrOwner - Replace isTeamAdminOrOwner prop with permissions.canCreateEventType - Move permission checks to server-side using PermissionCheckService - Use eventType.create permission string as specified in PBAC guide - Update all parent components: CreateEventTypeDialog, event-types-view, CreateEventTypePlatformWrapper - Follow existing PBAC patterns from event-types-listing-view.tsx - Maintain backward compatibility with role-based fallback Co-Authored-By: eunjae@cal.com <hey@eunjae.dev> * fix: implement proper server-side PBAC permission checks - Add eventType.create permission checks to TRPC teams.get handler - Add PBAC permission checks to platform /organizations/{orgId}/teams/me endpoint - Update all three components to use server-side permission data instead of client-side async calls - Add canCreateEventTypes property to platform team types - Maintain backward compatibility with role-based fallbacks - Remove unused imports and variables Co-Authored-By: eunjae@cal.com <hey@eunjae.dev> * fix: update client components to use server-side PBAC permission data - Update event-types-view.tsx to use team.canCreateEventTypes from server - Update CreateEventTypeDialog.tsx to use team.canCreateEventTypes with fallback - Update CreateEventTypePlatformWrapper.tsx to use team.canCreateEventTypes with fallback - Remove hardcoded permission values and role-based checks - Maintain backward compatibility with existing role-based logic as fallback Co-Authored-By: eunjae@cal.com <hey@eunjae.dev> * apply correct PBAC for event type creation * revert unexpected changes * clean up * address feedback * fix type error * clean up --------- Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Enterprise Edition
Welcome to the Enterprise Edition ("/ee") of Cal.com.
The /ee subfolder is the place for all the Enterprise Edition features from our hosted plan and enterprise-grade features for Enterprise such as SSO, SAML, OIDC, SCIM, SIEM and much more or Platform plan to build a marketplace.
❗ WARNING: This repository is copyrighted (unlike our main repo). You are not allowed to use this code to host your own version of app.cal.com without obtaining a proper license first❗
Setting up Stripe
- Create a stripe account or use an existing one. For testing, you should use all stripe dashboard functions with the Test-Mode toggle in the top right activated.
- Open Stripe ApiKeys save the token starting with
pk_...toNEXT_PUBLIC_STRIPE_PUBLIC_KEYandsk_...toSTRIPE_PRIVATE_KEYin the .env file. - Open Stripe Connect Settings and activate OAuth for Standard Accounts
- Add
<CALENDSO URL>/api/integrations/stripepayment/callbackas redirect URL. - Copy your client*id (
ca*...) toSTRIPE_CLIENT_IDin the .env file. - Open Stripe Webhooks and add
<CALENDSO URL>/api/integrations/stripepayment/webhookas webhook for connected applications. - Select all
payment_intentevents for the webhook. - Copy the webhook secret (
whsec_...) toSTRIPE_WEBHOOK_SECRETin the .env file.
Setting up SAML login
- Set SAML_DATABASE_URL to a postgres database. Please use a different database than the main Cal instance since the migrations are separate for this database. For example
postgresql://postgres:@localhost:5450/cal-saml - Set SAML_ADMINS to a comma separated list of admin emails from where the SAML metadata can be uploaded and configured.
- Create a SAML application with your Identity Provider (IdP) using the instructions here - SAML Setup
- Remember to configure access to the IdP SAML app for all your users (who need access to Cal).
- You will need the XML metadata from your IdP later, so keep it accessible.
- Log in to one of the admin accounts configured in SAML_ADMINS and then navigate to Settings -> Security.
- You should see a SAML configuration section, copy and paste the XML metadata from step 5 and click on Save.
- Your provisioned users can now log into Cal using SAML.