* feat: add Webhook resource to PBAC system with permission enforcement - Add Webhook resource to PBAC permission registry with CRUD actions - Implement PBAC permission checks in webhook handlers (create, edit, delete) - Add webhook permission translations to common.json - Use PermissionCheckService with fallback roles [ADMIN, OWNER] for team webhooks - Maintain backward compatibility when PBAC is disabled - Follow same pattern as workflow PBAC implementation from PR #22845 Co-Authored-By: sean@cal.com <Sean@brydon.io> * fix: implement PBAC permission filtering in webhook list handler - Add PermissionCheckService to filter team webhooks by webhook.read permission - Only show webhooks from teams where user has proper permissions - Maintain backward compatibility with fallback to all team memberships Co-Authored-By: sean@cal.com <Sean@brydon.io> * add migration for default roles * new forUserMethod * update webhook repository * fix UI showing/hiding webhooks for webhoo.create teams * WIP pbac procedure migratoin + tests * add more roles to get fallback * permissions in cmponents instead of readOnly * passPermissions to list item * push instant events logic * Git merge * wip teamId accessable refactor * fix delete handler --------- Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
43 lines
994 B
TypeScript
43 lines
994 B
TypeScript
import { WebhookRepository } from "@calcom/lib/server/repository/webhook";
|
|
import type { Webhook } from "@calcom/prisma/client";
|
|
import type { TrpcSessionUser } from "@calcom/trpc/server/types";
|
|
|
|
type GetByViewerOptions = {
|
|
ctx: {
|
|
user: NonNullable<TrpcSessionUser>;
|
|
};
|
|
};
|
|
|
|
type WebhookGroup = {
|
|
teamId?: number | null;
|
|
profile: {
|
|
slug: string | null;
|
|
name: string | null;
|
|
image?: string;
|
|
};
|
|
metadata?: {
|
|
readOnly: boolean;
|
|
};
|
|
webhooks: Webhook[];
|
|
};
|
|
|
|
export type WebhooksByViewer = {
|
|
webhookGroups: WebhookGroup[];
|
|
profiles: {
|
|
readOnly?: boolean | undefined;
|
|
slug: string | null;
|
|
name: string | null;
|
|
image?: string | undefined;
|
|
teamId: number | null | undefined;
|
|
}[];
|
|
};
|
|
|
|
export const getByViewerHandler = async ({ ctx }: GetByViewerOptions) => {
|
|
// Use the new PBAC-aware method for fetching webhooks
|
|
|
|
return await WebhookRepository.getFilteredWebhooksForUser({
|
|
userId: ctx.user.id,
|
|
userRole: ctx.user.role,
|
|
});
|
|
};
|