* Add endpoints for testing the flow * Add MVP * new route * Fixes * Fixes * Remove enable toggle support from domainWideDelegation * Fixes * Revert "Remove enable toggle support from domainWideDelegation" This reverts commit c29e729206cd1fa063f9c9ce0cf148ef1577d60b. * Revert yarn.lock * More fixes * Fix new workspace platform add * refactor: improvements * refactor: bug fixes and improvements * fix: type errors * fix: conflicts * chore: update test * fix: logic * chore: improvements * fix: toglle * fix: bugs * fix: type err * chore: check number type * fix: after conflicts * chore: fix type err * fix: type errors and tests * fix: tets * test * chore: remove unused * fix: google meet url on booking page and secondary calendar * fix: add property * fix: type err * fix: re assingment bug * fix: use getAllCredentials * chore: fix import * fix: installed count * fix: pass event type * fix: import * fix: [Stacked PR] Review fixes (#17958) * Review fixes * fix: destination calendar bug --------- Co-authored-by: Udit Takkar <udit222001@gmail.com> * refactor: use repository * chore: remove duplicate * fix: More review fixes for domain wide delegation (#17969) * Reuse buildCredentialPayloadForCalendar * fixes --------- Co-authored-by: Udit Takkar <53316345+Udit-takkar@users.noreply.github.com> * fix ts error * Fix getSchedule not using dwd credentials (#17995) * fix: Remove direct DWD table access from google-calendar and remove delegatedToId column from Credential (#18015) * Remove fn rename to reduce number of files changed * chore: check feature globally * test: add unit tests * chore: move function * test: add booking test * wip * Remove domain-wide-delegation team feature flag * Make sure duplicate calendars are not shown due to DWD. Show DWD when there is conflict * Fix tests and their ts errors * Fix more tests * Move findUsersForAvailabilityCheck to separate file as it has AppStore dependency causing problem with Routing Forms. Build crashes * fix: Multiple calendar connections from Google not showing up in apps/installed * DestinationCalendar must have either credentialId or domainWideDeelgationId. Also handle the case when DWD is disabled and there was a non-dwd credential that could be used * Disable deletetion of DWD as it is destructive and prefer disabling instead * Show DWD credential calendars at the top * Fixed tests * Calendar Cache DWD support * Self-Review: Verify email required and add more selectedCalendar tests * Self Review: shorten names * Self ReviewL Dead code removal * Revert "Calendar Cache DWD support" This reverts commit 009f236470fa21eba5986117d4f6e4d4c5e38c34. * Some misc fixes * fixes * Performance improvememt in slots loading and booking * More cases for handling dwd credentials * simplify the logic. Ensure that EventManager and the modules below it in the flow have CredentialForCalendarService available * Fix tests * Fix installed/conferencing not showing gogole meet * Shorten name * Fix ApI v2 tests * Add some more tests * add getSchedule tests * Improve tests * Make Google Meet default when DWD for google is enabled * Enable feature flagging for DWD * chore: bump libraries * Encrypt serviceaccount private key * Fix ts errors * bump platform libraries * org add dwd * org add dwd * bump platform libraries * fix selected calendars * fix remove selected dwd calendar * remove oauthclient id aliad in authedCalendar * remove oauthclient id aliad in authedCalendar * refactor: OrganizationsDwdController * chore: export toggleDwdEnabled from platform-libraries * feat: v2 update (enable / disable) dwd * refactor: SelectedCalendarsController check if user belongs to dwd org & for not dwd use previous logic * wip: DestinationCalendar send domainWideDelegationCredentialId from frontend to api * try fix set destination calendar api v2 * fixup! try fix set destination calendar api v2 * setting google meet as default location working for dwd * bump platform libraries version * allow office 365 workspace slug * allow office 365 workspace slug * chore: v2 create dwd MS and Google service keys input * fix: CreateDwdInput serviceAccountKey * fix: CredentialForCalendarService type * fix: check workspace slug * feat: update serviceAccessKey of DWD * testing * fixup! testing * fix: getAuthUtl bug * fix: unit tests * fix: type err and unit test * fix: e2e test * fix: credentials bug and failing unit tests * Update CalendarService.ts * chore: refactor office365 calendar service and add testDomainWideDelegationSetup * fix: office365Calendar use correct clientId/Secret for DWD * fix: office365Calendar dwd no need refresh token * test: add unit test for outlook dwd and setup * feat: added dwd support for office365 calendar * feat: added dwd support for office365 video * test: finish test for outlook dwd * fix: create dialog bug * chore: remove console logs * fix: refreshToken bug * bump version libraries * refactor: fetch dwd credentials only in findQualifiedHosts * fixup! refactor: fetch dwd credentials only in findQualifiedHosts * fix: type err * fix: type err * fix: getUserDisplayName * fix: unit test * chore: bump platform lib --------- Co-authored-by: Syed Ali Shahbaz <52925846+alishaz-polymath@users.noreply.github.com> Co-authored-by: Udit Takkar <53316345+Udit-takkar@users.noreply.github.com> Co-authored-by: Udit Takkar <udit222001@gmail.com> Co-authored-by: Morgan Vernay <morgan@cal.com> Co-authored-by: supalarry <laurisskraucis@gmail.com> Co-authored-by: Somay Chauhan <somaychauhan98@gmail.com> Co-authored-by: Morgan <33722304+ThyMinimalDev@users.noreply.github.com>
187 lines
6.4 KiB
TypeScript
187 lines
6.4 KiB
TypeScript
import { calendar_v3 } from "@googleapis/calendar";
|
|
import { OAuth2Client } from "googleapis-common";
|
|
import type { NextApiRequest, NextApiResponse } from "next";
|
|
|
|
import { updateProfilePhotoGoogle } from "@calcom/app-store/_utils/oauth/updateProfilePhotoGoogle";
|
|
import GoogleCalendarService from "@calcom/app-store/googlecalendar/lib/CalendarService";
|
|
import { renewSelectedCalendarCredentialId } from "@calcom/lib/connectedCalendar";
|
|
import {
|
|
GOOGLE_CALENDAR_SCOPES,
|
|
SCOPE_USERINFO_PROFILE,
|
|
WEBAPP_URL,
|
|
WEBAPP_URL_FOR_OAUTH,
|
|
} from "@calcom/lib/constants";
|
|
import { getSafeRedirectUrl } from "@calcom/lib/getSafeRedirectUrl";
|
|
import { HttpError } from "@calcom/lib/http-error";
|
|
import { defaultHandler } from "@calcom/lib/server/defaultHandler";
|
|
import { defaultResponder } from "@calcom/lib/server/defaultResponder";
|
|
import { CredentialRepository } from "@calcom/lib/server/repository/credential";
|
|
import { Prisma } from "@calcom/prisma/client";
|
|
|
|
import getInstalledAppPath from "../../_utils/getInstalledAppPath";
|
|
import { decodeOAuthState } from "../../_utils/oauth/decodeOAuthState";
|
|
import { getGoogleAppKeys } from "../lib/getGoogleAppKeys";
|
|
|
|
async function getHandler(req: NextApiRequest, res: NextApiResponse) {
|
|
const { code } = req.query;
|
|
const state = decodeOAuthState(req);
|
|
|
|
if (typeof code !== "string") {
|
|
if (state?.onErrorReturnTo || state?.returnTo) {
|
|
res.redirect(
|
|
getSafeRedirectUrl(state.onErrorReturnTo) ??
|
|
getSafeRedirectUrl(state?.returnTo) ??
|
|
`${WEBAPP_URL}/apps/installed`
|
|
);
|
|
return;
|
|
}
|
|
throw new HttpError({ statusCode: 400, message: "`code` must be a string" });
|
|
}
|
|
|
|
if (!req.session?.user?.id) {
|
|
throw new HttpError({ statusCode: 401, message: "You must be logged in to do this" });
|
|
}
|
|
|
|
const { client_id, client_secret } = await getGoogleAppKeys();
|
|
|
|
const redirect_uri = `${WEBAPP_URL_FOR_OAUTH}/api/integrations/googlecalendar/callback`;
|
|
|
|
const oAuth2Client = new OAuth2Client(client_id, client_secret, redirect_uri);
|
|
|
|
if (code) {
|
|
const token = await oAuth2Client.getToken(code);
|
|
const key = token.tokens;
|
|
const grantedScopes = token.tokens.scope?.split(" ") ?? [];
|
|
// Check if we have granted all required permissions
|
|
const hasMissingRequiredScopes = GOOGLE_CALENDAR_SCOPES.some((scope) => !grantedScopes.includes(scope));
|
|
if (hasMissingRequiredScopes) {
|
|
if (!state?.fromApp) {
|
|
throw new HttpError({
|
|
statusCode: 400,
|
|
message: "You must grant all permissions to use this integration",
|
|
});
|
|
}
|
|
res.redirect(
|
|
getSafeRedirectUrl(state.onErrorReturnTo) ??
|
|
getSafeRedirectUrl(state?.returnTo) ??
|
|
`${WEBAPP_URL}/apps/installed`
|
|
);
|
|
return;
|
|
}
|
|
|
|
oAuth2Client.setCredentials(key);
|
|
|
|
const gcalCredential = await CredentialRepository.create({
|
|
userId: req.session.user.id,
|
|
key,
|
|
appId: "google-calendar",
|
|
type: "google_calendar",
|
|
});
|
|
|
|
const gCalService = new GoogleCalendarService({
|
|
...gcalCredential,
|
|
user: null,
|
|
delegatedTo: null,
|
|
});
|
|
|
|
const calendar = new calendar_v3.Calendar({
|
|
auth: oAuth2Client,
|
|
});
|
|
|
|
const primaryCal = await gCalService.getPrimaryCalendar(calendar);
|
|
|
|
// If we still don't have a primary calendar skip creating the selected calendar.
|
|
// It can be toggled on later.
|
|
if (!primaryCal?.id) {
|
|
res.redirect(
|
|
getSafeRedirectUrl(state?.returnTo) ??
|
|
getInstalledAppPath({ variant: "calendar", slug: "google-calendar" })
|
|
);
|
|
return;
|
|
}
|
|
|
|
// Only attempt to update the user's profile photo if the user has granted the required scope
|
|
if (grantedScopes.includes(SCOPE_USERINFO_PROFILE)) {
|
|
await updateProfilePhotoGoogle(oAuth2Client, req.session.user.id);
|
|
}
|
|
|
|
const selectedCalendarWhereUnique = {
|
|
userId: req.session.user.id,
|
|
externalId: primaryCal.id,
|
|
integration: "google_calendar",
|
|
};
|
|
|
|
// Wrapping in a try/catch to reduce chance of race conditions-
|
|
// also this improves performance for most of the happy-paths.
|
|
try {
|
|
await gCalService.upsertSelectedCalendar({
|
|
// First install should add a user-level selectedCalendar only.
|
|
eventTypeId: null,
|
|
externalId: selectedCalendarWhereUnique.externalId,
|
|
});
|
|
} catch (error) {
|
|
let errorMessage = "something_went_wrong";
|
|
if (error instanceof Prisma.PrismaClientKnownRequestError && error.code === "P2002") {
|
|
// it is possible a selectedCalendar was orphaned, in this situation-
|
|
// we want to recover by connecting the existing selectedCalendar to the new Credential.
|
|
if (await renewSelectedCalendarCredentialId(selectedCalendarWhereUnique, gcalCredential.id)) {
|
|
res.redirect(
|
|
getSafeRedirectUrl(state?.returnTo) ??
|
|
getInstalledAppPath({ variant: "calendar", slug: "google-calendar" })
|
|
);
|
|
return;
|
|
}
|
|
// else
|
|
errorMessage = "account_already_linked";
|
|
}
|
|
await CredentialRepository.deleteById({ id: gcalCredential.id });
|
|
res.redirect(
|
|
`${
|
|
getSafeRedirectUrl(state?.onErrorReturnTo) ??
|
|
getInstalledAppPath({ variant: "calendar", slug: "google-calendar" })
|
|
}?error=${errorMessage}`
|
|
);
|
|
return;
|
|
}
|
|
}
|
|
|
|
// No need to install? Redirect to the returnTo URL
|
|
if (!state?.installGoogleVideo) {
|
|
res.redirect(
|
|
getSafeRedirectUrl(state?.returnTo) ??
|
|
getInstalledAppPath({ variant: "calendar", slug: "google-calendar" })
|
|
);
|
|
return;
|
|
}
|
|
|
|
const existingGoogleMeetCredential = await CredentialRepository.findFirstByUserIdAndType({
|
|
userId: req.session.user.id,
|
|
type: "google_video",
|
|
});
|
|
|
|
// If the user already has a google meet credential, there's nothing to do in here
|
|
if (existingGoogleMeetCredential) {
|
|
res.redirect(
|
|
getSafeRedirectUrl(`${WEBAPP_URL}/apps/installed/conferencing?hl=google-meet`) ??
|
|
getInstalledAppPath({ variant: "conferencing", slug: "google-meet" })
|
|
);
|
|
return;
|
|
}
|
|
|
|
// Create a new google meet credential
|
|
await CredentialRepository.create({
|
|
userId: req.session.user.id,
|
|
type: "google_video",
|
|
key: {},
|
|
appId: "google-meet",
|
|
});
|
|
res.redirect(
|
|
getSafeRedirectUrl(`${WEBAPP_URL}/apps/installed/conferencing?hl=google-meet`) ??
|
|
getInstalledAppPath({ variant: "conferencing", slug: "google-meet" })
|
|
);
|
|
}
|
|
|
|
export default defaultHandler({
|
|
GET: Promise.resolve({ default: defaultResponder(getHandler) }),
|
|
});
|