5a7e783a0a
* feat: add booking attendees endpoint to API v2 Co-Authored-By: [email protected] <[email protected]> * feat: add rate limiting to booking attendees endpoint Co-Authored-By: [email protected] <[email protected]> * refactor: simplify attendees output to id, bookingId, name, email, timeZone Co-Authored-By: [email protected] <[email protected]> * test: add E2E tests for booking attendees endpoint Co-Authored-By: [email protected] <[email protected]> * chore: update bookings repository * fixup: add pbac guards and update service logic * chore: update openapi spec * test: add rate limiting E2E test for booking attendees endpoint Co-Authored-By: [email protected] <[email protected]> * fix: tests * fix: return 404 instead of 403 for non-existent booking in BookingPbacGuard The BookingPbacGuard was returning 403 (Forbidden) for non-existent bookings because doesUserIdHaveAccessToBooking returns false when a booking doesn't exist, which the guard treated as an access denial. Added an explicit booking existence check in the guard before the access check, so non-existent bookings now correctly return 404 (Not Found) as documented in the PR description. Updated the E2E test to expect 404 for non-existent booking UIDs. Issue identified by cubic. Co-Authored-By: unknown <> * fixup * fix: return 404 instead of 403 for non-existent booking in attendees endpoint BookingPbacGuard now checks booking existence before the access check, returning 404 (Not Found) instead of 403 (Forbidden) for non-existent booking UIDs. Updated the E2E test assertion and description to match. Issue identified by cubic (confidence 9/10). Co-Authored-By: unknown <> * chore: implement PR feedback * chore: update tests * fixup * chore: update endpoint decsription * feat: endpoint to retrieve specific attendee * chore: update e2e tests * chore: implement cubic feedback * fix: update test to expect 403 for non-existent booking UID (BookingPbacGuard behavior) Co-Authored-By: [email protected] <[email protected]> * fix: merge conflicts * feat: endpoint to get attendees * chore: update findByUidIncludeEventTypeAttendeesAndUser method * chore: implement PR feedback * fix: e2e tests * chore: update e2e tests * fixup fixup * fix: remove phoneNumber assertion since it's optional and not provided in test * chore: implement PR feedback * fix: keep the same output shape for get attendees and get attendee endpoint * chore: update openapi spec --------- Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> Co-authored-by: bot_apk <[email protected]>