+1

![cubic-dev-ai[bot] <1082092+cubic-dev-ai[bot]@users.noreply.github.com>](/assets/img/avatar_default.png)



![Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>](/assets/img/avatar_default.png)



Peer Richelsen
GitHub
lauris@cal.com <lauris@cal.com>
Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
eunjae@cal.com <hey@eunjae.dev>
Lauris Skraucis
supalarry
cubic-dev-ai[bot] <1082092+cubic-dev-ai[bot]@users.noreply.github.com>
CarinaWolli
lauris@cal.com <lauris@cal.com>
Morgan
a03722fd7f
* feat: add OAuth client developer settings page with approval workflow - Add new developer OAuth page at /settings/developer/oAuth for users to submit OAuth client requests - Transform admin OAuth page into management dashboard for reviewing/approving submissions - Add OAuthClientApprovalStatus enum (PENDING, APPROVED, REJECTED) to track submission status - Add userId and createdAt fields to OAuthClient model for tracking submissions - Create email notifications for admin (new submission) and user (approval) - Add sidebar navigation link in developer section below API keys - Add comprehensive translations for new UI strings - Create OAuthClientRepository for data access following repository pattern Co-Authored-By: peer@cal.com <peer@cal.com> * fix: re-export generateSecret for backward compatibility Co-Authored-By: peer@cal.com <peer@cal.com> * feat: make logo mandatory and list items clickable for OAuth clients Co-Authored-By: peer@cal.com <peer@cal.com> * fix: add missing translation keys and remove client secret from details dialog Co-Authored-By: peer@cal.com <peer@cal.com> * fix: address cubic AI reviewer comments - Remove duplicate 'there' JSON key in common.json - Add select clause to findByUserId to avoid exposing clientSecret - Add @@index([userId]) to OAuthClient model for query performance - Update migration to include the index Co-Authored-By: peer@cal.com <peer@cal.com> * fix: address PR review comments - fix indentation and use useCopy hook Co-Authored-By: eunjae@cal.com <hey@eunjae.dev> * fix: change react-dom/server import to fix Turbopack compatibility Co-Authored-By: eunjae@cal.com <hey@eunjae.dev> * Revert "fix: change react-dom/server import to fix Turbopack compatibility" This reverts commit c3e0b709c2d88fd221143cb4ce9cd25bb8c94277. * fix: use email service pattern for OAuth client notifications Co-Authored-By: eunjae@cal.com <hey@eunjae.dev> * fix: add try-catch around email sending to handle Turbopack react-dom/server issue Co-Authored-By: eunjae@cal.com <hey@eunjae.dev> * Revert "fix: add try-catch around email sending to handle Turbopack react-dom/server issue" This reverts commit fc9d47cd773505ebc5ee2696718aad4a8a98be77. * fix: improve OAuth client UI with skeleton loaders and smaller dialog styling - Replace 'Loading...' text with proper skeleton loaders in both developer and admin OAuth client views - Make client_id and copy button smaller in dialogs using size='sm' and text-sm styling - Add 'client_id' translation key to common.json for proper i18n Co-Authored-By: eunjae@cal.com <hey@eunjae.dev> * fix: improve skeleton loader to match actual OAuth client list structure - Remove divide-y from container and use conditional border-b on rows - Match the exact structure from oauth-clients-view.tsx L126-160 - Use proper spacing for text elements (mt-1 instead of space-y-2) Co-Authored-By: eunjae@cal.com <hey@eunjae.dev> * fix skeleton * rename the selected oauth client dialog * fix: address PR feedback - admin auth, dropdown styling, sidebar label - Add defense-in-depth admin authorization check in updateClientStatus handler - Fix broken dropdown menu by using DropdownItem with StartIcon prop - Fix sidebar menu label from 'oAuth' to 'oauth_clients' to match developer view Co-Authored-By: eunjae@cal.com <hey@eunjae.dev> * update common.json * feat: show client secret in approval email for confidential OAuth clients - Add regenerateSecret method to OAuthClientRepository - Regenerate secret when admin approves a PENDING confidential client - Include client secret in approval notification email - Add one-time warning message about storing the secret securely - Only regenerate on first approval (not re-approvals) Co-Authored-By: eunjae@cal.com <hey@eunjae.dev> * feat: add Website URL field, fix logo styling, show client secret after approval - Add Website URL field to OAuth client forms (admin and developer views) - Fix Upload Logo section styling by wrapping in Label div with proper gap - Display client secret in dialog after admin approves a confidential OAuth client - Add websiteUrl field to Prisma schema with migration - Update tRPC handlers and repository to support websiteUrl - Add translation keys for new UI elements Co-Authored-By: peer@cal.com <peer@cal.com> * fix: move clientSecret variable declaration outside if block for proper scoping Co-Authored-By: peer@cal.com <peer@cal.com> * refactor: dont expose client secret in emails * refactor: dont regenerate secret upon status change * refactor: reuse existing hash function * refactor: rename admin/oAuth to admin/oauth page * refactor: deduplicate oauth repositories * refactor: remove withGlobalPrisma from oauth repository * refactor: developer oauth page * refactor: oauth status by default accepted * refactor: request oauth status when creating * refactor ux * fix: address Cubic AI code review feedback - Add purpose field to plain text email body for accessibility - Convert NewOAuthClientButton to inline JSX to avoid React anti-pattern - Trigger re-approval when redirectUri changes for security - Add e.preventDefault() for Space key to prevent page scroll - Change default approvalStatus to PENDING for defense-in-depth - Use oauth_clients translation key for consistency - Add meaningful alt text to Avatar for accessibility - Remove onClick from DialogClose to prevent double-run close effects - Return NOT_FOUND for non-owner delete to prevent resource enumeration Co-Authored-By: unknown <> * common.json file * refactor: delete all prisma migrations * refactor: have just 1 prisma migration * revert: some devin changes * fix: typecheck * test: owner OAuth crud * test: admin OAuth approval / rejection * fix: address Cubic AI review feedback (confidence 9/10 issues) - schema.prisma: Remove @default("") from purpose field to make it required - schema.prisma: Use UTC-aware timezone expression for createdAt default - OAuthClientFormFields.tsx: Localize redirect URI placeholder using t() - common.json: Add redirect_uri_placeholder translation key Co-Authored-By: unknown <> * cubic changes * refactor: dont log sensitive info and rethrow error * cubic feedback * refactor: make oauth client purpose optional * refactor: admin/oauth not allowed if not logged in * refactor: admin view skeleton * refactor: rename state * refactor: get rid of redundant mapping * refactor: remove redundant handler * refactor: remove redundant handler * refactor: re-usable new oauth client button * refactor: dialogs * refactor: modals * refactor: handler names, dialog, skeleton * fix: purpose being null * refactor: rename handler and delete old oauth admin page * fix: purpose in submission * refactor: handler names * refactor: rename * refactor: update handler * refactor: rename approvalStatus -> status * refactor: simplify modal * refactor: name * dont require repproval if redirectUri changes * fix: remove integration sync index creation * refactor: require re-approval if redirectUri updated * fix: flaky e2e test * fix: flaky e2e test * fix: flaky e2e test * fix: remove duplicate common.json keys * refactor: replace team@cal.com with SUPPORT_MAIL_ADDRESS * refactor: generate client secret on handler level * fix: authorization code only available to approved clients * refactor: cubic review dont display exclamation * refactor: cubic review website_url in common json * fix: dont default in ui to approved status * refactor: optiona logo in schema create handler * fix: tests * fix: tests * fix: /authorize redirect if client not approved or show error * test: authorize page with invalid client id * refactor: dont allow refreshing tokens unless approved client * fix: flaky e2e test * fix: flaky e2e test * fix: flaky e2e test * fix: flaky e2e test * fix: flaky e2e test * fix: flaky e2e test * chore: warn that pending client is not usable * fix: approve and reject buttons * fix: /authorize show error if client not approved * refactor: info message about editing oauth client and status * change info alert to warning * try to fix ci test * debug: failing e2e test * fix: improve session propagation in oauth-client-admin E2E test - Add navigateToAdminOAuthPage helper that waits for listClients API call - If the API call doesn't arrive (session issue), reload page to force session refresh - This fixes the CI flakiness where admin page wasn't loading due to session not having ADMIN role Co-Authored-By: lauris@cal.com <lauris@cal.com> * fix: register waitForResponse before navigating in E2E test - Register the listClients waitForResponse promise BEFORE page.goto() - This ensures the response isn't missed during page load - Also register the promise before reload in the catch block Co-Authored-By: lauris@cal.com <lauris@cal.com> * fix: rename oAuth folder to oauth for case-sensitive filesystems The admin OAuth page route was at /settings/admin/oAuth (capital A) but the code references /settings/admin/oauth (lowercase). This caused 404 errors on case-sensitive filesystems (Linux). Also improved the E2E test navigation helper to retry with delays if the admin page doesn't load immediately, handling session propagation timing. Co-Authored-By: lauris@cal.com <lauris@cal.com> * test style --------- Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> Co-authored-by: eunjae@cal.com <hey@eunjae.dev> Co-authored-by: Lauris Skraucis <lauris.skraucis@gmail.com> Co-authored-by: supalarry <laurisskraucis@gmail.com> Co-authored-by: cubic-dev-ai[bot] <1082092+cubic-dev-ai[bot]@users.noreply.github.com> Co-authored-by: CarinaWolli <wollencarina@gmail.com> Co-authored-by: lauris@cal.com <lauris@cal.com> Co-authored-by: Morgan <33722304+ThyMinimalDev@users.noreply.github.com>
167 lines
6.5 KiB
TypeScript
167 lines
6.5 KiB
TypeScript
import type { PrismaClient } from "@calcom/prisma";
|
|
import { expect, type Page } from "@playwright/test";
|
|
import { test } from "../lib/fixtures";
|
|
import {
|
|
closeOAuthClientDetails,
|
|
createApprovedOAuthClientAsAdmin,
|
|
createPendingOAuthClient,
|
|
openOAuthClientDetailsFromList,
|
|
goToAdminOAuthSettings
|
|
} from "./oauth-client-helpers";
|
|
|
|
async function expectClientStatusInDb(
|
|
prisma: PrismaClient,
|
|
clientId: string,
|
|
status: "PENDING" | "APPROVED" | "REJECTED"
|
|
) {
|
|
await expect
|
|
.poll(async () => {
|
|
const row = await prisma.oAuthClient.findUnique({
|
|
where: { clientId },
|
|
select: { status: true },
|
|
});
|
|
|
|
return row?.status ?? null;
|
|
})
|
|
.toBe(status);
|
|
}
|
|
|
|
async function waitForAdminSection(page: Page, sectionTestId: string) {
|
|
const section = page.getByTestId(sectionTestId);
|
|
await expect(section).toBeVisible({ timeout: 60_000 });
|
|
return section;
|
|
}
|
|
|
|
async function expectClientInAdminSection(
|
|
page: Page,
|
|
sectionTestId: string,
|
|
clientId: string
|
|
): Promise<void> {
|
|
const section = await waitForAdminSection(page, sectionTestId);
|
|
await expect(section.getByTestId(`oauth-client-list-item-${clientId}`)).toBeVisible({ timeout: 60_000 });
|
|
}
|
|
|
|
async function expectClientNotInAdminSection(
|
|
page: Page,
|
|
sectionTestId: string,
|
|
clientId: string
|
|
): Promise<void> {
|
|
const section = await waitForAdminSection(page, sectionTestId);
|
|
await expect(section.getByTestId(`oauth-client-list-item-${clientId}`)).toHaveCount(0, { timeout: 60_000 });
|
|
}
|
|
|
|
test.describe.configure({ mode: "parallel" });
|
|
|
|
test.describe("OAuth clients admin", () => {
|
|
test.afterEach(async ({ users, prisma }, testInfo) => {
|
|
const testPrefix = `e2e-oauth-client-admin-${testInfo.testId}-`;
|
|
|
|
await prisma.oAuthClient.deleteMany({
|
|
where: {
|
|
name: {
|
|
startsWith: testPrefix,
|
|
},
|
|
},
|
|
});
|
|
|
|
await users.deleteAll();
|
|
});
|
|
|
|
test("can manage pending/approved/rejected clients and can create approved clients as admin", async ({
|
|
page,
|
|
prisma,
|
|
users,
|
|
}, testInfo) => {
|
|
const adminUser = await users.create({ role: "ADMIN" });
|
|
await adminUser.apiLogin();
|
|
|
|
const testPrefix = `e2e-oauth-client-admin-${testInfo.testId}-`;
|
|
|
|
const makeClientInput = (name: string) => ({
|
|
name,
|
|
purpose: "Used for E2E testing (admin)",
|
|
redirectUri: "https://example.com/callback",
|
|
websiteUrl: "https://example.com",
|
|
logoFileName: "cal.png",
|
|
});
|
|
|
|
const pending1Name = `${testPrefix}pending-1-${Date.now()}`;
|
|
const pending2Name = `${testPrefix}pending-2-${Date.now()}`;
|
|
const pending3Name = `${testPrefix}pending-3-${Date.now()}`;
|
|
|
|
const toBeApproved = await createPendingOAuthClient(page, makeClientInput(pending1Name));
|
|
const toBeRejected = await createPendingOAuthClient(page, makeClientInput(pending2Name));
|
|
const staysPending = await createPendingOAuthClient(page, makeClientInput(pending3Name));
|
|
|
|
await goToAdminOAuthSettings(page);
|
|
|
|
await expectClientInAdminSection(page, "oauth-client-admin-pending-section", toBeApproved.clientId);
|
|
await expectClientInAdminSection(page, "oauth-client-admin-pending-section", toBeRejected.clientId);
|
|
await expectClientInAdminSection(page, "oauth-client-admin-pending-section", staysPending.clientId);
|
|
|
|
// Preview a pending client (readonly)
|
|
const pendingDetails = await openOAuthClientDetailsFromList(page, toBeApproved.clientId);
|
|
|
|
await expect(pendingDetails.locator("#name")).toBeDisabled();
|
|
await expect(pendingDetails.locator("#purpose")).toBeDisabled();
|
|
await expect(pendingDetails.locator("#redirectUri")).toBeDisabled();
|
|
await expect(pendingDetails.locator("#websiteUrl")).toBeDisabled();
|
|
|
|
// Upload/delete actions should be hidden for admin view
|
|
await expect(page.getByTestId("open-upload-oauth-client-logo-dialog")).toHaveCount(0);
|
|
await expect(page.getByTestId("oauth-client-details-delete-trigger")).toHaveCount(0);
|
|
|
|
// Approve pending1
|
|
await page.getByTestId("oauth-client-details-approve-trigger").click();
|
|
await closeOAuthClientDetails(page);
|
|
|
|
await expectClientStatusInDb(prisma, toBeApproved.clientId, "APPROVED");
|
|
|
|
await expectClientNotInAdminSection(page, "oauth-client-admin-pending-section", toBeApproved.clientId);
|
|
await expectClientInAdminSection(page, "oauth-client-admin-approved-section", toBeApproved.clientId);
|
|
await expectClientInAdminSection(page, "oauth-client-admin-pending-section", staysPending.clientId);
|
|
|
|
// Reject pending2
|
|
const rejectionReason = `Not acceptable (${testPrefix}reason-${Date.now()})`;
|
|
await openOAuthClientDetailsFromList(page, toBeRejected.clientId);
|
|
await page.getByTestId("oauth-client-details-reject-trigger").click();
|
|
await page.getByTestId("oauth-client-details-rejection-reason").fill(rejectionReason);
|
|
await page.getByTestId("oauth-client-details-reject-confirm").click();
|
|
await closeOAuthClientDetails(page);
|
|
|
|
await expectClientStatusInDb(prisma, toBeRejected.clientId, "REJECTED");
|
|
|
|
await expectClientNotInAdminSection(page, "oauth-client-admin-pending-section", toBeRejected.clientId);
|
|
await expectClientInAdminSection(page, "oauth-client-admin-rejected-section", toBeRejected.clientId);
|
|
|
|
await page
|
|
.getByTestId("oauth-client-admin-rejected-section")
|
|
.getByTestId(`oauth-client-list-item-${toBeRejected.clientId}`)
|
|
.click();
|
|
|
|
const rejectedDetails = page.getByTestId("oauth-client-details-form");
|
|
await expect(rejectedDetails).toBeVisible();
|
|
await expect(rejectedDetails.getByTestId("oauth-client-details-rejection-reason-display")).toContainText(
|
|
rejectionReason
|
|
);
|
|
await closeOAuthClientDetails(page);
|
|
await expectClientInAdminSection(page, "oauth-client-admin-pending-section", staysPending.clientId);
|
|
|
|
// Reload to ensure list queries show consistent counts
|
|
await page.reload();
|
|
|
|
await expectClientInAdminSection(page, "oauth-client-admin-approved-section", toBeApproved.clientId);
|
|
await expectClientInAdminSection(page, "oauth-client-admin-rejected-section", toBeRejected.clientId);
|
|
await expectClientInAdminSection(page, "oauth-client-admin-pending-section", staysPending.clientId);
|
|
|
|
// Admin can create an approved client from admin page
|
|
const adminCreatedName = `${testPrefix}admin-created-${Date.now()}`;
|
|
const adminCreated = await createApprovedOAuthClientAsAdmin(page, makeClientInput(adminCreatedName));
|
|
|
|
await expectClientStatusInDb(prisma, adminCreated.clientId, "APPROVED");
|
|
|
|
// Should now be in approved list
|
|
await expect(page.getByTestId(`oauth-client-list-item-${adminCreated.clientId}`)).toBeVisible();
|
|
});
|
|
});
|