* fix: remove @calcom/web imports from packages/features to eliminate circular dependency - Migrate UserTableUser and MemberPermissions types to packages/features/users/types/user-table.ts - Migrate useGeo hook to packages/features/geo/GeoContext.tsx - Migrate buildLegacyRequest to packages/lib/buildLegacyCtx.ts - Migrate Calendar component to packages/features/calendars/weeklyview/components/ - Move test utilities (bookingScenario, fixtures) to packages/features/test/ - Update all imports in packages/features to use new locations - Add re-exports in apps/web for backward compatibility Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: delete original implementation files and fix type issues - Delete original calendar component files in apps/web (keep only re-export stubs) - Migrate OutOfOfficeInSlots to packages/features/bookings/components - Convert apps/web OutOfOfficeInSlots to re-export stub - Fix className vs class issue in Calendar.tsx - Fix @calcom/trpc import violation in user-table.ts by using structural type Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: add missing isGroup and contains fields to UserTableUser attributes type Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: update customRole type to match actual Prisma Role model Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix build * fix * fix * cleanup weeklyview * fix * refactor to mv MemberPermissions to types package * add types dependency to features * fix * fix * fix * fix * fix * fix * rename * rename * migrate * migrate * migrate * fix * fix * fix * refactor: move test utilities from packages/features/test to tests/libs - Move bookingScenario utilities to tests/libs/bookingScenario - Move fixtures to tests/libs/fixtures - Update all imports in packages/features test files to use new location - Update all imports in apps/web test files to use new location - Eliminates duplication of test utilities between packages/features and apps/web Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: correct relative import paths for tests/libs in test files Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * refactor: replace test utility implementations with re-exports to tests/libs Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: fix test import paths and move signup handler tests to apps/web Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: move buildLegacyCtx to packages/lib and restore handlers to packages/features - Move buildLegacyCtx from apps/web/lib to packages/lib to break circular dependency - Update apps/web/lib/buildLegacyCtx.ts to re-export from @calcom/lib - Restore signup handlers and tests to packages/features/auth/signup/handlers - Update handler imports to use @calcom/lib/buildLegacyCtx instead of @calcom/web/lib/buildLegacyCtx Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: update recurring-event.test.ts imports to use tests/libs path Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * refactor: delete test re-export files and update imports to use tests/libs directly Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: update remaining test imports to use tests/libs directly Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: update handleRecurringEventBooking calls to match function signature (1 arg) Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * remove * migrate tests * migrate tests * refactor: update test mock imports by removing and using async for mock creators. * fix type errors * fix: add type assertion for MockUser in p2002.test-suite.ts Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: restore locale import in compareReminderBodyToTemplate.test.ts using relative path Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * feat: create @calcom/testing package and migrate tests from /tests directory - Created new @calcom/testing package in /packages/testing - Moved all files from /tests to /packages/testing - Updated all imports across the codebase to use @calcom/testing alias - Removed /tests directory at root level This allows other packages like @calcom/features and @calcom/web to import testing utilities using the @calcom/testing alias instead of relative paths. Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix * fix * fix: add missing useBookings export to @calcom/atoms package Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: add missing useCalendarsBusyTimes and useConnectedCalendars exports to @calcom/atoms Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * chore: add @calcom/testing as explicit devDependency to packages that use it Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * refactor: move setupVitest.ts into @calcom/testing package Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix * chore: add biome rules to restrict @calcom/testing imports Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix * rename libs to lib * rename libs to lib * add rule * add rule * refactor: remove @calcom/features imports from @calcom/testing - Move mockPaymentSuccessWebhookFromStripe to fresh-booking.test.ts - Replace ProfileRepository.generateProfileUid() with uuidv4() - Clone Tracking type into @calcom/testing/src/lib/types.ts - Update imports in expects.ts and getMockRequestDataForBooking.ts - Move source files into src/ folder - Move CalendarManager mock to @calcom/features Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: add explicit exports for nested paths in @calcom/testing Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * improve * improve * fix * fix * fix type checks * fix type checks * fix type checks * fix tests --------- Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
233 lines
6.7 KiB
TypeScript
233 lines
6.7 KiB
TypeScript
import prismaMock from "@calcom/testing/lib/__mocks__/prismaMock";
|
|
|
|
import { describe, expect, it, vi, beforeEach } from "vitest";
|
|
|
|
import { lockUser, LockReason } from "@calcom/features/ee/api-keys/lib/autoLock";
|
|
import { scheduleWorkflowNotifications } from "@calcom/features/ee/workflows/lib/scheduleWorkflowNotifications";
|
|
|
|
import { scanWorkflowBody, iffyScanBody } from "./scanWorkflowBody";
|
|
|
|
vi.mock("@calcom/features/ee/api-keys/lib/autoLock", async (importActual) => {
|
|
const actual = await importActual<typeof import("@calcom/features/ee/api-keys/lib/autoLock")>();
|
|
return {
|
|
...actual, // Keep all original exports
|
|
lockUser: vi.fn(), // Override just the lockUser function
|
|
};
|
|
});
|
|
|
|
vi.mock("@calcom/features/ee/workflows/lib/scheduleWorkflowNotifications", () => ({
|
|
scheduleWorkflowNotifications: vi.fn(),
|
|
}));
|
|
|
|
vi.mock("./scanWorkflowBody", async (importActual) => {
|
|
const actual = await importActual<typeof import("./scanWorkflowBody")>();
|
|
return {
|
|
...actual,
|
|
iffyScanBody: vi.fn(),
|
|
};
|
|
});
|
|
|
|
const mockWorkflowStep = {
|
|
id: 1,
|
|
reminderBody: "Test reminder body",
|
|
workflow: {
|
|
user: {
|
|
timeFormat: 24,
|
|
},
|
|
},
|
|
};
|
|
|
|
const mockWorkflow = {
|
|
id: 1,
|
|
time: 24,
|
|
timeUnit: "hour",
|
|
trigger: "BEFORE",
|
|
activeOn: [{ eventTypeId: 1 }],
|
|
team: null,
|
|
};
|
|
|
|
describe("scanWorkflowBody", () => {
|
|
const mockFetch = vi.fn();
|
|
|
|
beforeEach(() => {
|
|
vi.resetAllMocks();
|
|
vi.stubGlobal("fetch", mockFetch);
|
|
process.env.IFFY_API_KEY = "test-key";
|
|
prismaMock.workflowStep.findMany.mockResolvedValue([mockWorkflowStep]);
|
|
prismaMock.workflow.findFirst.mockResolvedValue(mockWorkflow);
|
|
});
|
|
|
|
it("should skip scan if IFFY_API_KEY is not set", async () => {
|
|
process.env.IFFY_API_KEY = "";
|
|
const payload = JSON.stringify({
|
|
userId: 1,
|
|
workflowStepIds: [1],
|
|
});
|
|
|
|
await scanWorkflowBody(payload);
|
|
|
|
expect(iffyScanBody).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it("should mark workflow step as safe if no reminder body", async () => {
|
|
const payload = JSON.stringify({
|
|
userId: 1,
|
|
workflowStepIds: [1],
|
|
});
|
|
|
|
prismaMock.workflowStep.findMany.mockResolvedValue([{ ...mockWorkflowStep, reminderBody: null }]);
|
|
prismaMock.workflow.findFirst.mockResolvedValue(mockWorkflow);
|
|
|
|
await scanWorkflowBody(payload);
|
|
|
|
expect(prismaMock.workflowStep.update).toHaveBeenCalledWith({
|
|
where: { id: 1 },
|
|
data: { verifiedAt: expect.any(Date) },
|
|
});
|
|
});
|
|
|
|
it("should mark workflow step as safe if content is not spam", async () => {
|
|
const payload = JSON.stringify({
|
|
userId: 1,
|
|
workflowStepIds: [1],
|
|
});
|
|
|
|
prismaMock.workflowStep.findMany.mockResolvedValue([mockWorkflowStep]);
|
|
prismaMock.workflow.findFirst.mockResolvedValue(mockWorkflow);
|
|
mockFetch.mockResolvedValue({
|
|
json: () => Promise.resolve({ flagged: false }),
|
|
});
|
|
|
|
await scanWorkflowBody(payload);
|
|
|
|
expect(mockFetch).toHaveBeenCalledWith("https://api.iffy.com/api/v1/moderate", {
|
|
method: "POST",
|
|
headers: {
|
|
"Content-Type": "application/json",
|
|
Authorization: `Bearer test-key`,
|
|
},
|
|
body: JSON.stringify({
|
|
clientId: "Workflow step - 1",
|
|
name: "Workflow",
|
|
entity: "WorkflowBody",
|
|
content: "Test reminder body",
|
|
passthrough: true,
|
|
}),
|
|
});
|
|
expect(prismaMock.workflowStep.update).toHaveBeenCalledWith({
|
|
where: { id: 1 },
|
|
data: { verifiedAt: expect.any(Date) },
|
|
});
|
|
});
|
|
|
|
it.skip("should lock user and not update step if content is spam", async () => {
|
|
const payload = JSON.stringify({
|
|
userId: 1,
|
|
workflowStepIds: [1],
|
|
});
|
|
|
|
prismaMock.workflowStep.findMany.mockResolvedValue([mockWorkflowStep]);
|
|
mockFetch.mockResolvedValue({
|
|
json: () => Promise.resolve({ flagged: true }),
|
|
});
|
|
|
|
await scanWorkflowBody(payload);
|
|
|
|
expect(mockFetch).toHaveBeenCalledWith("https://api.iffy.com/api/v1/moderate", {
|
|
method: "POST",
|
|
headers: {
|
|
"Content-Type": "application/json",
|
|
Authorization: `Bearer test-key`,
|
|
},
|
|
body: JSON.stringify({
|
|
clientId: "Workflow step - 1",
|
|
name: "Workflow",
|
|
entity: "WorkflowBody",
|
|
content: "Test reminder body",
|
|
passthrough: true,
|
|
}),
|
|
});
|
|
expect(prismaMock.workflowStep.update).not.toHaveBeenCalled();
|
|
expect(lockUser).toHaveBeenCalledWith("userId", "1", LockReason.SPAM_WORKFLOW_BODY);
|
|
});
|
|
|
|
it("should schedule workflow notifications after successful scan", async () => {
|
|
const payload = JSON.stringify({
|
|
userId: 1,
|
|
workflowStepIds: [1],
|
|
});
|
|
|
|
prismaMock.workflowStep.findMany.mockResolvedValue([mockWorkflowStep]);
|
|
prismaMock.workflow.findFirst.mockResolvedValue(mockWorkflow);
|
|
|
|
await scanWorkflowBody(payload);
|
|
|
|
expect(scheduleWorkflowNotifications).toHaveBeenCalledWith({
|
|
activeOn: [1],
|
|
isOrg: false,
|
|
workflowSteps: [expect.objectContaining(mockWorkflowStep)],
|
|
time: mockWorkflow.time,
|
|
timeUnit: mockWorkflow.timeUnit,
|
|
trigger: mockWorkflow.trigger,
|
|
userId: 1,
|
|
teamId: null,
|
|
});
|
|
});
|
|
|
|
it("should handle invalid payload", async () => {
|
|
const payload = "invalid-json";
|
|
|
|
await expect(scanWorkflowBody(payload)).rejects.toThrow();
|
|
});
|
|
|
|
it("should handle workflow not found", async () => {
|
|
const payload = JSON.stringify({
|
|
userId: 1,
|
|
workflowStepIds: [1],
|
|
});
|
|
|
|
prismaMock.workflowStep.findMany.mockResolvedValue([mockWorkflowStep]);
|
|
prismaMock.workflow.findFirst.mockResolvedValue(null);
|
|
|
|
await scanWorkflowBody(payload);
|
|
|
|
expect(scheduleWorkflowNotifications).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it("should handle whitelisted user being flagged as spam", async () => {
|
|
const payload = JSON.stringify({
|
|
userId: 1,
|
|
workflowStepIds: [1],
|
|
});
|
|
|
|
prismaMock.workflowStep.findMany.mockResolvedValue([
|
|
{ ...mockWorkflowStep, workflow: { user: { whitelistWorkflows: true } } },
|
|
]);
|
|
prismaMock.workflow.findFirst.mockResolvedValue(mockWorkflow);
|
|
mockFetch.mockResolvedValue({
|
|
json: () => Promise.resolve({ flagged: true }),
|
|
});
|
|
|
|
await scanWorkflowBody(payload);
|
|
|
|
expect(mockFetch).toHaveBeenCalledWith("https://api.iffy.com/api/v1/moderate", {
|
|
method: "POST",
|
|
headers: {
|
|
"Content-Type": "application/json",
|
|
Authorization: `Bearer test-key`,
|
|
},
|
|
body: JSON.stringify({
|
|
clientId: "Workflow step - 1",
|
|
name: "Workflow",
|
|
entity: "WorkflowBody",
|
|
content: "Test reminder body",
|
|
passthrough: true,
|
|
}),
|
|
});
|
|
expect(prismaMock.workflowStep.update).toHaveBeenCalled();
|
|
expect(scheduleWorkflowNotifications).toHaveBeenCalled();
|
|
|
|
expect(lockUser).not.toHaveBeenCalled();
|
|
});
|
|
});
|