Files
calendar/apps/web/playwright/oauth/oauth-client-admin.e2e.ts
T
+1
Peer RichelsenGitHublauris@cal.com <lauris@cal.com>Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>eunjae@cal.com <hey@eunjae.dev>Lauris Skraucissupalarrycubic-dev-ai[bot] <1082092+cubic-dev-ai[bot]@users.noreply.github.com>CarinaWollilauris@cal.com <lauris@cal.com>Morgan
a03722fd7f feat: add OAuth client developer settings page with approval workflow (#25556)
* feat: add OAuth client developer settings page with approval workflow

- Add new developer OAuth page at /settings/developer/oAuth for users to submit OAuth client requests
- Transform admin OAuth page into management dashboard for reviewing/approving submissions
- Add OAuthClientApprovalStatus enum (PENDING, APPROVED, REJECTED) to track submission status
- Add userId and createdAt fields to OAuthClient model for tracking submissions
- Create email notifications for admin (new submission) and user (approval)
- Add sidebar navigation link in developer section below API keys
- Add comprehensive translations for new UI strings
- Create OAuthClientRepository for data access following repository pattern

Co-Authored-By: peer@cal.com <peer@cal.com>

* fix: re-export generateSecret for backward compatibility

Co-Authored-By: peer@cal.com <peer@cal.com>

* feat: make logo mandatory and list items clickable for OAuth clients

Co-Authored-By: peer@cal.com <peer@cal.com>

* fix: add missing translation keys and remove client secret from details dialog

Co-Authored-By: peer@cal.com <peer@cal.com>

* fix: address cubic AI reviewer comments

- Remove duplicate 'there' JSON key in common.json
- Add select clause to findByUserId to avoid exposing clientSecret
- Add @@index([userId]) to OAuthClient model for query performance
- Update migration to include the index

Co-Authored-By: peer@cal.com <peer@cal.com>

* fix: address PR review comments - fix indentation and use useCopy hook

Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>

* fix: change react-dom/server import to fix Turbopack compatibility

Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>

* Revert "fix: change react-dom/server import to fix Turbopack compatibility"

This reverts commit c3e0b709c2d88fd221143cb4ce9cd25bb8c94277.

* fix: use email service pattern for OAuth client notifications

Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>

* fix: add try-catch around email sending to handle Turbopack react-dom/server issue

Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>

* Revert "fix: add try-catch around email sending to handle Turbopack react-dom/server issue"

This reverts commit fc9d47cd773505ebc5ee2696718aad4a8a98be77.

* fix: improve OAuth client UI with skeleton loaders and smaller dialog styling

- Replace 'Loading...' text with proper skeleton loaders in both developer and admin OAuth client views
- Make client_id and copy button smaller in dialogs using size='sm' and text-sm styling
- Add 'client_id' translation key to common.json for proper i18n

Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>

* fix: improve skeleton loader to match actual OAuth client list structure

- Remove divide-y from container and use conditional border-b on rows
- Match the exact structure from oauth-clients-view.tsx L126-160
- Use proper spacing for text elements (mt-1 instead of space-y-2)

Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>

* fix skeleton

* rename the selected oauth client dialog

* fix: address PR feedback - admin auth, dropdown styling, sidebar label

- Add defense-in-depth admin authorization check in updateClientStatus handler
- Fix broken dropdown menu by using DropdownItem with StartIcon prop
- Fix sidebar menu label from 'oAuth' to 'oauth_clients' to match developer view

Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>

* update common.json

* feat: show client secret in approval email for confidential OAuth clients

- Add regenerateSecret method to OAuthClientRepository
- Regenerate secret when admin approves a PENDING confidential client
- Include client secret in approval notification email
- Add one-time warning message about storing the secret securely
- Only regenerate on first approval (not re-approvals)

Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>

* feat: add Website URL field, fix logo styling, show client secret after approval

- Add Website URL field to OAuth client forms (admin and developer views)
- Fix Upload Logo section styling by wrapping in Label div with proper gap
- Display client secret in dialog after admin approves a confidential OAuth client
- Add websiteUrl field to Prisma schema with migration
- Update tRPC handlers and repository to support websiteUrl
- Add translation keys for new UI elements

Co-Authored-By: peer@cal.com <peer@cal.com>

* fix: move clientSecret variable declaration outside if block for proper scoping

Co-Authored-By: peer@cal.com <peer@cal.com>

* refactor: dont expose client secret in emails

* refactor: dont regenerate secret upon status change

* refactor: reuse existing hash function

* refactor: rename admin/oAuth to admin/oauth page

* refactor: deduplicate oauth repositories

* refactor: remove withGlobalPrisma from oauth repository

* refactor: developer oauth page

* refactor: oauth status by default accepted

* refactor: request oauth status when creating

* refactor ux

* fix: address Cubic AI code review feedback

- Add purpose field to plain text email body for accessibility
- Convert NewOAuthClientButton to inline JSX to avoid React anti-pattern
- Trigger re-approval when redirectUri changes for security
- Add e.preventDefault() for Space key to prevent page scroll
- Change default approvalStatus to PENDING for defense-in-depth
- Use oauth_clients translation key for consistency
- Add meaningful alt text to Avatar for accessibility
- Remove onClick from DialogClose to prevent double-run close effects
- Return NOT_FOUND for non-owner delete to prevent resource enumeration

Co-Authored-By: unknown <>

* common.json file

* refactor: delete all prisma migrations

* refactor: have just 1 prisma migration

* revert: some devin changes

* fix: typecheck

* test: owner OAuth crud

* test: admin OAuth approval / rejection

* fix: address Cubic AI review feedback (confidence 9/10 issues)

- schema.prisma: Remove @default("") from purpose field to make it required
- schema.prisma: Use UTC-aware timezone expression for createdAt default
- OAuthClientFormFields.tsx: Localize redirect URI placeholder using t()
- common.json: Add redirect_uri_placeholder translation key

Co-Authored-By: unknown <>

* cubic changes

* refactor: dont log sensitive info and rethrow error

* cubic feedback

* refactor: make oauth client purpose optional

* refactor: admin/oauth not allowed if not logged in

* refactor: admin view skeleton

* refactor: rename state

* refactor: get rid of redundant mapping

* refactor: remove redundant handler

* refactor: remove redundant handler

* refactor: re-usable new oauth client button

* refactor: dialogs

* refactor: modals

* refactor: handler names, dialog, skeleton

* fix: purpose being null

* refactor: rename handler and delete old oauth admin page

* fix: purpose in submission

* refactor: handler names

* refactor: rename

* refactor: update handler

* refactor: rename approvalStatus -> status

* refactor: simplify modal

* refactor: name

* dont require repproval if redirectUri changes

* fix: remove integration sync index creation

* refactor: require re-approval if redirectUri updated

* fix: flaky e2e test

* fix: flaky e2e test

* fix: flaky e2e test

* fix: remove duplicate common.json keys

* refactor: replace team@cal.com with SUPPORT_MAIL_ADDRESS

* refactor: generate client secret on handler level

* fix: authorization code only available to approved clients

* refactor: cubic review dont display exclamation

* refactor: cubic review website_url in common json

* fix: dont default in ui to approved status

* refactor: optiona logo in schema create handler

* fix: tests

* fix: tests

* fix: /authorize redirect if client not approved or show error

* test: authorize page with invalid client id

* refactor: dont allow refreshing tokens unless approved client

* fix: flaky e2e test

* fix: flaky e2e test

* fix: flaky e2e test

* fix: flaky e2e test

* fix: flaky e2e test

* fix: flaky e2e test

* chore: warn that pending client is not usable

* fix: approve and reject buttons

* fix: /authorize show error if client not approved

* refactor: info message about editing oauth client and status

* change info alert to warning

* try to fix ci test

* debug: failing e2e test

* fix: improve session propagation in oauth-client-admin E2E test

- Add navigateToAdminOAuthPage helper that waits for listClients API call
- If the API call doesn't arrive (session issue), reload page to force session refresh
- This fixes the CI flakiness where admin page wasn't loading due to session not having ADMIN role

Co-Authored-By: lauris@cal.com <lauris@cal.com>

* fix: register waitForResponse before navigating in E2E test

- Register the listClients waitForResponse promise BEFORE page.goto()
- This ensures the response isn't missed during page load
- Also register the promise before reload in the catch block

Co-Authored-By: lauris@cal.com <lauris@cal.com>

* fix: rename oAuth folder to oauth for case-sensitive filesystems

The admin OAuth page route was at /settings/admin/oAuth (capital A) but the
code references /settings/admin/oauth (lowercase). This caused 404 errors
on case-sensitive filesystems (Linux).

Also improved the E2E test navigation helper to retry with delays if the
admin page doesn't load immediately, handling session propagation timing.

Co-Authored-By: lauris@cal.com <lauris@cal.com>

* test style

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: eunjae@cal.com <hey@eunjae.dev>
Co-authored-by: Lauris Skraucis <lauris.skraucis@gmail.com>
Co-authored-by: supalarry <laurisskraucis@gmail.com>
Co-authored-by: cubic-dev-ai[bot] <1082092+cubic-dev-ai[bot]@users.noreply.github.com>
Co-authored-by: CarinaWolli <wollencarina@gmail.com>
Co-authored-by: lauris@cal.com <lauris@cal.com>
Co-authored-by: Morgan <33722304+ThyMinimalDev@users.noreply.github.com>
2026-01-21 12:23:51 -03:00

167 lines
6.5 KiB
TypeScript

import type { PrismaClient } from "@calcom/prisma";
import { expect, type Page } from "@playwright/test";
import { test } from "../lib/fixtures";
import {
closeOAuthClientDetails,
createApprovedOAuthClientAsAdmin,
createPendingOAuthClient,
openOAuthClientDetailsFromList,
goToAdminOAuthSettings
} from "./oauth-client-helpers";
async function expectClientStatusInDb(
prisma: PrismaClient,
clientId: string,
status: "PENDING" | "APPROVED" | "REJECTED"
) {
await expect
.poll(async () => {
const row = await prisma.oAuthClient.findUnique({
where: { clientId },
select: { status: true },
});
return row?.status ?? null;
})
.toBe(status);
}
async function waitForAdminSection(page: Page, sectionTestId: string) {
const section = page.getByTestId(sectionTestId);
await expect(section).toBeVisible({ timeout: 60_000 });
return section;
}
async function expectClientInAdminSection(
page: Page,
sectionTestId: string,
clientId: string
): Promise<void> {
const section = await waitForAdminSection(page, sectionTestId);
await expect(section.getByTestId(`oauth-client-list-item-${clientId}`)).toBeVisible({ timeout: 60_000 });
}
async function expectClientNotInAdminSection(
page: Page,
sectionTestId: string,
clientId: string
): Promise<void> {
const section = await waitForAdminSection(page, sectionTestId);
await expect(section.getByTestId(`oauth-client-list-item-${clientId}`)).toHaveCount(0, { timeout: 60_000 });
}
test.describe.configure({ mode: "parallel" });
test.describe("OAuth clients admin", () => {
test.afterEach(async ({ users, prisma }, testInfo) => {
const testPrefix = `e2e-oauth-client-admin-${testInfo.testId}-`;
await prisma.oAuthClient.deleteMany({
where: {
name: {
startsWith: testPrefix,
},
},
});
await users.deleteAll();
});
test("can manage pending/approved/rejected clients and can create approved clients as admin", async ({
page,
prisma,
users,
}, testInfo) => {
const adminUser = await users.create({ role: "ADMIN" });
await adminUser.apiLogin();
const testPrefix = `e2e-oauth-client-admin-${testInfo.testId}-`;
const makeClientInput = (name: string) => ({
name,
purpose: "Used for E2E testing (admin)",
redirectUri: "https://example.com/callback",
websiteUrl: "https://example.com",
logoFileName: "cal.png",
});
const pending1Name = `${testPrefix}pending-1-${Date.now()}`;
const pending2Name = `${testPrefix}pending-2-${Date.now()}`;
const pending3Name = `${testPrefix}pending-3-${Date.now()}`;
const toBeApproved = await createPendingOAuthClient(page, makeClientInput(pending1Name));
const toBeRejected = await createPendingOAuthClient(page, makeClientInput(pending2Name));
const staysPending = await createPendingOAuthClient(page, makeClientInput(pending3Name));
await goToAdminOAuthSettings(page);
await expectClientInAdminSection(page, "oauth-client-admin-pending-section", toBeApproved.clientId);
await expectClientInAdminSection(page, "oauth-client-admin-pending-section", toBeRejected.clientId);
await expectClientInAdminSection(page, "oauth-client-admin-pending-section", staysPending.clientId);
// Preview a pending client (readonly)
const pendingDetails = await openOAuthClientDetailsFromList(page, toBeApproved.clientId);
await expect(pendingDetails.locator("#name")).toBeDisabled();
await expect(pendingDetails.locator("#purpose")).toBeDisabled();
await expect(pendingDetails.locator("#redirectUri")).toBeDisabled();
await expect(pendingDetails.locator("#websiteUrl")).toBeDisabled();
// Upload/delete actions should be hidden for admin view
await expect(page.getByTestId("open-upload-oauth-client-logo-dialog")).toHaveCount(0);
await expect(page.getByTestId("oauth-client-details-delete-trigger")).toHaveCount(0);
// Approve pending1
await page.getByTestId("oauth-client-details-approve-trigger").click();
await closeOAuthClientDetails(page);
await expectClientStatusInDb(prisma, toBeApproved.clientId, "APPROVED");
await expectClientNotInAdminSection(page, "oauth-client-admin-pending-section", toBeApproved.clientId);
await expectClientInAdminSection(page, "oauth-client-admin-approved-section", toBeApproved.clientId);
await expectClientInAdminSection(page, "oauth-client-admin-pending-section", staysPending.clientId);
// Reject pending2
const rejectionReason = `Not acceptable (${testPrefix}reason-${Date.now()})`;
await openOAuthClientDetailsFromList(page, toBeRejected.clientId);
await page.getByTestId("oauth-client-details-reject-trigger").click();
await page.getByTestId("oauth-client-details-rejection-reason").fill(rejectionReason);
await page.getByTestId("oauth-client-details-reject-confirm").click();
await closeOAuthClientDetails(page);
await expectClientStatusInDb(prisma, toBeRejected.clientId, "REJECTED");
await expectClientNotInAdminSection(page, "oauth-client-admin-pending-section", toBeRejected.clientId);
await expectClientInAdminSection(page, "oauth-client-admin-rejected-section", toBeRejected.clientId);
await page
.getByTestId("oauth-client-admin-rejected-section")
.getByTestId(`oauth-client-list-item-${toBeRejected.clientId}`)
.click();
const rejectedDetails = page.getByTestId("oauth-client-details-form");
await expect(rejectedDetails).toBeVisible();
await expect(rejectedDetails.getByTestId("oauth-client-details-rejection-reason-display")).toContainText(
rejectionReason
);
await closeOAuthClientDetails(page);
await expectClientInAdminSection(page, "oauth-client-admin-pending-section", staysPending.clientId);
// Reload to ensure list queries show consistent counts
await page.reload();
await expectClientInAdminSection(page, "oauth-client-admin-approved-section", toBeApproved.clientId);
await expectClientInAdminSection(page, "oauth-client-admin-rejected-section", toBeRejected.clientId);
await expectClientInAdminSection(page, "oauth-client-admin-pending-section", staysPending.clientId);
// Admin can create an approved client from admin page
const adminCreatedName = `${testPrefix}admin-created-${Date.now()}`;
const adminCreated = await createApprovedOAuthClientAsAdmin(page, makeClientInput(adminCreatedName));
await expectClientStatusInDb(prisma, adminCreated.clientId, "APPROVED");
// Should now be in approved list
await expect(page.getByTestId(`oauth-client-list-item-${adminCreated.clientId}`)).toBeVisible();
});
});