Files
calendar/apps/web/modules/settings/oauth/view/OAuthClientDetailsDialog.tsx
T
+1
Peer RichelsenGitHublauris@cal.com <lauris@cal.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>eunjae@cal.com <hey@eunjae.dev>Lauris Skraucissupalarrycubic-dev-ai[bot] <1082092+cubic-dev-ai[bot]@users.noreply.github.com>CarinaWollilauris@cal.com <lauris@cal.com>Morgan
a03722fd7f feat: add OAuth client developer settings page with approval workflow (#25556)
* feat: add OAuth client developer settings page with approval workflow

- Add new developer OAuth page at /settings/developer/oAuth for users to submit OAuth client requests
- Transform admin OAuth page into management dashboard for reviewing/approving submissions
- Add OAuthClientApprovalStatus enum (PENDING, APPROVED, REJECTED) to track submission status
- Add userId and createdAt fields to OAuthClient model for tracking submissions
- Create email notifications for admin (new submission) and user (approval)
- Add sidebar navigation link in developer section below API keys
- Add comprehensive translations for new UI strings
- Create OAuthClientRepository for data access following repository pattern

Co-Authored-By: peer@cal.com <peer@cal.com>

* fix: re-export generateSecret for backward compatibility

Co-Authored-By: peer@cal.com <peer@cal.com>

* feat: make logo mandatory and list items clickable for OAuth clients

Co-Authored-By: peer@cal.com <peer@cal.com>

* fix: add missing translation keys and remove client secret from details dialog

Co-Authored-By: peer@cal.com <peer@cal.com>

* fix: address cubic AI reviewer comments

- Remove duplicate 'there' JSON key in common.json
- Add select clause to findByUserId to avoid exposing clientSecret
- Add @@index([userId]) to OAuthClient model for query performance
- Update migration to include the index

Co-Authored-By: peer@cal.com <peer@cal.com>

* fix: address PR review comments - fix indentation and use useCopy hook

Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>

* fix: change react-dom/server import to fix Turbopack compatibility

Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>

* Revert "fix: change react-dom/server import to fix Turbopack compatibility"

This reverts commit c3e0b709c2d88fd221143cb4ce9cd25bb8c94277.

* fix: use email service pattern for OAuth client notifications

Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>

* fix: add try-catch around email sending to handle Turbopack react-dom/server issue

Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>

* Revert "fix: add try-catch around email sending to handle Turbopack react-dom/server issue"

This reverts commit fc9d47cd773505ebc5ee2696718aad4a8a98be77.

* fix: improve OAuth client UI with skeleton loaders and smaller dialog styling

- Replace 'Loading...' text with proper skeleton loaders in both developer and admin OAuth client views
- Make client_id and copy button smaller in dialogs using size='sm' and text-sm styling
- Add 'client_id' translation key to common.json for proper i18n

Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>

* fix: improve skeleton loader to match actual OAuth client list structure

- Remove divide-y from container and use conditional border-b on rows
- Match the exact structure from oauth-clients-view.tsx L126-160
- Use proper spacing for text elements (mt-1 instead of space-y-2)

Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>

* fix skeleton

* rename the selected oauth client dialog

* fix: address PR feedback - admin auth, dropdown styling, sidebar label

- Add defense-in-depth admin authorization check in updateClientStatus handler
- Fix broken dropdown menu by using DropdownItem with StartIcon prop
- Fix sidebar menu label from 'oAuth' to 'oauth_clients' to match developer view

Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>

* update common.json

* feat: show client secret in approval email for confidential OAuth clients

- Add regenerateSecret method to OAuthClientRepository
- Regenerate secret when admin approves a PENDING confidential client
- Include client secret in approval notification email
- Add one-time warning message about storing the secret securely
- Only regenerate on first approval (not re-approvals)

Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>

* feat: add Website URL field, fix logo styling, show client secret after approval

- Add Website URL field to OAuth client forms (admin and developer views)
- Fix Upload Logo section styling by wrapping in Label div with proper gap
- Display client secret in dialog after admin approves a confidential OAuth client
- Add websiteUrl field to Prisma schema with migration
- Update tRPC handlers and repository to support websiteUrl
- Add translation keys for new UI elements

Co-Authored-By: peer@cal.com <peer@cal.com>

* fix: move clientSecret variable declaration outside if block for proper scoping

Co-Authored-By: peer@cal.com <peer@cal.com>

* refactor: dont expose client secret in emails

* refactor: dont regenerate secret upon status change

* refactor: reuse existing hash function

* refactor: rename admin/oAuth to admin/oauth page

* refactor: deduplicate oauth repositories

* refactor: remove withGlobalPrisma from oauth repository

* refactor: developer oauth page

* refactor: oauth status by default accepted

* refactor: request oauth status when creating

* refactor ux

* fix: address Cubic AI code review feedback

- Add purpose field to plain text email body for accessibility
- Convert NewOAuthClientButton to inline JSX to avoid React anti-pattern
- Trigger re-approval when redirectUri changes for security
- Add e.preventDefault() for Space key to prevent page scroll
- Change default approvalStatus to PENDING for defense-in-depth
- Use oauth_clients translation key for consistency
- Add meaningful alt text to Avatar for accessibility
- Remove onClick from DialogClose to prevent double-run close effects
- Return NOT_FOUND for non-owner delete to prevent resource enumeration

Co-Authored-By: unknown <>

* common.json file

* refactor: delete all prisma migrations

* refactor: have just 1 prisma migration

* revert: some devin changes

* fix: typecheck

* test: owner OAuth crud

* test: admin OAuth approval / rejection

* fix: address Cubic AI review feedback (confidence 9/10 issues)

- schema.prisma: Remove @default("") from purpose field to make it required
- schema.prisma: Use UTC-aware timezone expression for createdAt default
- OAuthClientFormFields.tsx: Localize redirect URI placeholder using t()
- common.json: Add redirect_uri_placeholder translation key

Co-Authored-By: unknown <>

* cubic changes

* refactor: dont log sensitive info and rethrow error

* cubic feedback

* refactor: make oauth client purpose optional

* refactor: admin/oauth not allowed if not logged in

* refactor: admin view skeleton

* refactor: rename state

* refactor: get rid of redundant mapping

* refactor: remove redundant handler

* refactor: remove redundant handler

* refactor: re-usable new oauth client button

* refactor: dialogs

* refactor: modals

* refactor: handler names, dialog, skeleton

* fix: purpose being null

* refactor: rename handler and delete old oauth admin page

* fix: purpose in submission

* refactor: handler names

* refactor: rename

* refactor: update handler

* refactor: rename approvalStatus -> status

* refactor: simplify modal

* refactor: name

* dont require repproval if redirectUri changes

* fix: remove integration sync index creation

* refactor: require re-approval if redirectUri updated

* fix: flaky e2e test

* fix: flaky e2e test

* fix: flaky e2e test

* fix: remove duplicate common.json keys

* refactor: replace team@cal.com with SUPPORT_MAIL_ADDRESS

* refactor: generate client secret on handler level

* fix: authorization code only available to approved clients

* refactor: cubic review dont display exclamation

* refactor: cubic review website_url in common json

* fix: dont default in ui to approved status

* refactor: optiona logo in schema create handler

* fix: tests

* fix: tests

* fix: /authorize redirect if client not approved or show error

* test: authorize page with invalid client id

* refactor: dont allow refreshing tokens unless approved client

* fix: flaky e2e test

* fix: flaky e2e test

* fix: flaky e2e test

* fix: flaky e2e test

* fix: flaky e2e test

* fix: flaky e2e test

* chore: warn that pending client is not usable

* fix: approve and reject buttons

* fix: /authorize show error if client not approved

* refactor: info message about editing oauth client and status

* change info alert to warning

* try to fix ci test

* debug: failing e2e test

* fix: improve session propagation in oauth-client-admin E2E test

- Add navigateToAdminOAuthPage helper that waits for listClients API call
- If the API call doesn't arrive (session issue), reload page to force session refresh
- This fixes the CI flakiness where admin page wasn't loading due to session not having ADMIN role

Co-Authored-By: lauris@cal.com <lauris@cal.com>

* fix: register waitForResponse before navigating in E2E test

- Register the listClients waitForResponse promise BEFORE page.goto()
- This ensures the response isn't missed during page load
- Also register the promise before reload in the catch block

Co-Authored-By: lauris@cal.com <lauris@cal.com>

* fix: rename oAuth folder to oauth for case-sensitive filesystems

The admin OAuth page route was at /settings/admin/oAuth (capital A) but the
code references /settings/admin/oauth (lowercase). This caused 404 errors
on case-sensitive filesystems (Linux).

Also improved the E2E test navigation helper to retry with delays if the
admin page doesn't load immediately, handling session propagation timing.

Co-Authored-By: lauris@cal.com <lauris@cal.com>

* test style

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: eunjae@cal.com <hey@eunjae.dev>
Co-authored-by: Lauris Skraucis <lauris.skraucis@gmail.com>
Co-authored-by: supalarry <laurisskraucis@gmail.com>
Co-authored-by: cubic-dev-ai[bot] <1082092+cubic-dev-ai[bot]@users.noreply.github.com>
Co-authored-by: CarinaWolli <wollencarina@gmail.com>
Co-authored-by: lauris@cal.com <lauris@cal.com>
Co-authored-by: Morgan <33722304+ThyMinimalDev@users.noreply.github.com>
2026-01-21 12:23:51 -03:00

367 lines
12 KiB
TypeScript

"use client";
import { useEffect, useState } from "react";
import { useForm } from "react-hook-form";
import { Dialog } from "@calcom/features/components/controlled-dialog";
import { useCopy } from "@calcom/lib/hooks/useCopy";
import { useLocale } from "@calcom/lib/hooks/useLocale";
import { Alert } from "@calcom/ui/components/alert";
import { Badge } from "@calcom/ui/components/badge";
import { Button } from "@calcom/ui/components/button";
import { ConfirmationDialogContent, DialogClose, DialogContent, DialogFooter } from "@calcom/ui/components/dialog";
import { showToast } from "@calcom/ui/components/toast";
import { Tooltip } from "@calcom/ui/components/tooltip";
import { Label, TextArea } from "@calcom/ui/components/form";
import type { OAuthClientCreateFormValues } from "../create/OAuthClientCreateModal";
import { OAuthClientFormFields } from "./OAuthClientFormFields";
type OAuthClientDetails = {
clientId: string;
name: string;
purpose?: string | null;
redirectUri?: string;
websiteUrl?: string | null;
logo?: string | null;
status?: string;
rejectionReason?: string | null;
clientSecret?: string;
isPkceEnabled?: boolean;
clientType?: string;
};
const OAuthClientDetailsDialog = ({
open,
onOpenChange,
client,
onApprove,
onReject,
onUpdate,
onDelete,
isStatusChangePending,
isUpdatePending,
isDeletePending,
}: {
open: boolean;
onOpenChange: (open: boolean) => void;
client: OAuthClientDetails | null;
onApprove?: (clientId: string) => void;
onReject?: (input: { clientId: string; rejectionReason: string }) => void;
onUpdate?: (input: {
clientId: string;
name: string;
purpose: string;
redirectUri: string;
websiteUrl: string;
logo: string;
}) => void;
onDelete?: (clientId: string) => void;
isStatusChangePending?: boolean;
isUpdatePending?: boolean;
isDeletePending?: boolean;
}) => {
const { t } = useLocale();
const { copyToClipboard } = useCopy();
const [logo, setLogo] = useState("");
const [isDeleteConfirmOpen, setIsDeleteConfirmOpen] = useState(false);
const [isRejectConfirmOpen, setIsRejectConfirmOpen] = useState(false);
const [rejectionReason, setRejectionReason] = useState("");
const [showRejectionReasonError, setShowRejectionReasonError] = useState(false);
const form = useForm<OAuthClientCreateFormValues>({
defaultValues: {
name: "",
purpose: "",
redirectUri: "",
websiteUrl: "",
logo: "",
enablePkce: false,
},
});
useEffect(() => {
if (open) return;
setIsDeleteConfirmOpen(false);
setIsRejectConfirmOpen(false);
setRejectionReason("");
setShowRejectionReasonError(false);
}, [open]);
useEffect(() => {
if (!client) return;
const enablePkce =
client.isPkceEnabled ?? (client.clientType ? client.clientType.toUpperCase() === "PUBLIC" : false);
const nextLogo = client.logo ?? "";
setLogo(nextLogo);
form.reset({
name: client.name ?? "",
purpose: client.purpose ?? "",
redirectUri: client.redirectUri ?? "",
websiteUrl: client.websiteUrl ?? "",
logo: nextLogo,
enablePkce,
});
}, [client, form]);
const status = client?.status;
const showAdminActions = Boolean(onApprove) || Boolean(onReject);
const isFormDisabled = showAdminActions;
const canEdit = Boolean(onUpdate) && !isFormDisabled;
const canDelete = Boolean(onDelete) && !showAdminActions;
const handleConfirmReject = () => {
if (!client) return;
const trimmedReason = rejectionReason.trim();
if (trimmedReason.length === 0) {
setShowRejectionReasonError(true);
return;
}
onReject?.({ clientId: client.clientId, rejectionReason: trimmedReason });
setIsRejectConfirmOpen(false);
setRejectionReason("");
setShowRejectionReasonError(false);
};
const clientId = client?.clientId;
const footerActions = (() => {
const closeButton = (
<DialogClose color="minimal" data-testid="oauth-client-details-close">
{t("close")}
</DialogClose>
);
if (showAdminActions) {
const canReject = Boolean(onReject) && (status === "PENDING" || status === "APPROVED");
const canApprove = Boolean(onApprove) && (status === "PENDING" || status === "REJECTED");
return (
<div className="flex gap-2 justify-end items-center w-full">
{closeButton}
{canReject ? (
<Button
type="button"
color="primary"
StartIcon="x"
data-testid="oauth-client-details-reject-trigger"
loading={isStatusChangePending}
onClick={() => {
setIsRejectConfirmOpen(true);
setRejectionReason("");
setShowRejectionReasonError(false);
}}>
{t("reject")}
</Button>
) : null}
{canApprove ? (
<Button
type="button"
color="primary"
StartIcon="check"
data-testid="oauth-client-details-approve-trigger"
loading={isStatusChangePending}
onClick={() => {
if (!clientId) return;
onApprove?.(clientId);
}}>
{t("approve")}
</Button>
) : null}
</div>
);
}
if (canEdit) {
return (
<div className="flex gap-2 justify-end items-center w-full">
{closeButton}
<Button type="submit" loading={isUpdatePending} data-testid="oauth-client-details-save">
{t("save")}
</Button>
</div>
);
}
return <div className="flex justify-end items-center w-full">{closeButton}</div>;
})();
return (
<Dialog open={open} onOpenChange={onOpenChange}>
<DialogContent enableOverflow type="creation">
{client ? (
<form
data-testid="oauth-client-details-form"
className="space-y-4"
onSubmit={form.handleSubmit((values) => {
if (!canEdit) return;
onUpdate?.({
clientId: client.clientId,
name: values.name.trim() || "",
purpose: values.purpose.trim() || "",
redirectUri: values.redirectUri.trim() || "",
websiteUrl: values.websiteUrl.trim() || "",
logo: values.logo,
});
})}>
{status ? (
<div className="flex justify-start items-center">
<Badge data-testid="oauth-client-details-status-badge" variant={getStatusBadgeVariant(status).variant}>
{t(getStatusBadgeVariant(status).labelKey)}
</Badge>
</div>
) : null}
{status === "PENDING" ? (
<Alert severity="warning" title={t("oauth_client_pending_info_description")} />
) : null}
{status === "APPROVED" ? (
<Alert severity="warning" title={t("oauth_client_approved_reapproval_info")} />
) : null}
{status === "REJECTED" && client.rejectionReason ? (
<div className="text-sm text-subtle" data-testid="oauth-client-details-rejection-reason-display">
<span className="font-medium">{t("oauth_client_rejection_reason")}:</span> {client.rejectionReason}
</div>
) : null}
<div>
<div className="mb-1 text-sm text-subtle">{t("client_id")}</div>
<div className="flex">
<code
data-testid="oauth-client-details-client-id"
className="px-2 py-1 w-full font-mono text-sm truncate align-middle rounded-md rounded-r-none bg-subtle text-default">
{client.clientId}
</code>
<Tooltip side="top" content={t("copy_to_clipboard")}>
<Button
onClick={() => {
copyToClipboard(client.clientId, {
onSuccess: () => showToast(t("client_id_copied"), "success"),
onFailure: () => showToast(t("error"), "error"),
});
}}
type="button"
size="sm"
className="rounded-l-none"
StartIcon="clipboard">
{t("copy")}
</Button>
</Tooltip>
</div>
</div>
<OAuthClientFormFields
form={form}
logo={logo}
setLogo={setLogo}
isClientReadOnly={isFormDisabled}
isPkceLocked
/>
{canDelete ? (
<div className="pt-2">
<Button
type="button"
color="destructive"
StartIcon="trash"
data-testid="oauth-client-details-delete-trigger"
loading={isDeletePending}
className="w-auto"
onClick={() => setIsDeleteConfirmOpen(true)}>
{t("delete_oauth_client")}
</Button>
<Dialog open={isDeleteConfirmOpen} onOpenChange={setIsDeleteConfirmOpen}>
<ConfirmationDialogContent
variety="danger"
title={t("delete_oauth_client")}
cancelBtnText={t("cancel")}
isPending={isDeletePending}
confirmBtn={
<DialogClose
data-testid="oauth-client-details-delete-confirm"
color="primary"
loading={isDeletePending}
onClick={() => {
if (!client) return;
onDelete?.(client.clientId);
}}>
{isDeletePending ? t("deleting") : t("delete")}
</DialogClose>
}>
<p className="mb-4">{t("confirm_delete_oauth_client")}</p>
</ConfirmationDialogContent>
</Dialog>
</div>
) : null}
<DialogFooter className="mt-6">
{footerActions}
</DialogFooter>
<Dialog open={isRejectConfirmOpen} onOpenChange={setIsRejectConfirmOpen}>
<ConfirmationDialogContent
variety="danger"
title={t("reject_oauth_client")}
cancelBtnText={t("cancel")}
confirmBtn={
<Button
type="button"
color="primary"
StartIcon="x"
data-testid="oauth-client-details-reject-confirm"
loading={isStatusChangePending}
className="not-disabled:hover:!bg-error not-disabled:hover:!text-white not-disabled:hover:!border-semantic-error"
onClick={handleConfirmReject}>
{t("reject")}
</Button>
}>
<div className="mt-4 space-y-2">
<Label htmlFor="oauth-rejection-reason">{t("reason_for_rejection")}</Label>
<TextArea
id="oauth-rejection-reason"
data-testid="oauth-client-details-rejection-reason"
value={rejectionReason}
onChange={(e) => {
setRejectionReason(e.target.value);
if (showRejectionReasonError && e.target.value.trim().length > 0) {
setShowRejectionReasonError(false);
}
}}
className={showRejectionReasonError ? "border-error" : undefined}
/>
{showRejectionReasonError ? (
<p className="text-sm text-error">{t("is_required")}</p>
) : null}
</div>
</ConfirmationDialogContent>
</Dialog>
</form>
) : null}
</DialogContent>
</Dialog>
);
};
function getStatusBadgeVariant(status: string) {
switch (status) {
case "APPROVED":
return { variant: "success" as const, labelKey: "approved" as const };
case "REJECTED":
return { variant: "red" as const, labelKey: "rejected" as const };
case "PENDING":
default:
return { variant: "orange" as const, labelKey: "pending" as const };
}
};
export type { OAuthClientDetails };
export { OAuthClientDetailsDialog };