* fix: prevent base64 logo/banner storage in organization onboarding - Add processOnboardingBrandAssets helper method to BaseOnboardingService - Process base64 images and upload them before storing in database - Use uploadAvatar with userId to avoid foreign key issues before Team exists - Handle both create and update/resume flows - Ensure OrganizationOnboarding and Team records store regular URLs not base64 - Fixes header size issues when logoUrl is added to session cookies Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com> * fix: use processed URLs from OrganizationOnboarding record - Update SelfHostedOnboardingService to use organizationOnboarding.logo/bannerUrl instead of raw input - Update BillingEnabledOrgOnboardingService payment intent to use processed URLs - Ensures Team records receive processed URLs, not base64 data Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com> * refactor: remove unused variables and imports Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com> * refactor: extract image processing to helper method and add tests - Created private processImageField() method to eliminate code duplication - Uses regex for more robust data URI and URL detection - Processes logo and bannerUrl in parallel with Promise.all - Added 2 important tests for base64 image processing: 1. Verifies base64 conversion with correct resize options (bannerUrl uses maxSize: 1500) 2. Validates undefined vs null semantics (no-op vs explicit clear) - Fixed pre-existing lint warnings by replacing 'any' types with proper types Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com> * Improve code * Fixup organizationId * simplify --------- Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> Co-authored-by: Alex van Andel <me@alexvanandel.com>
Enterprise Edition
Welcome to the Enterprise Edition ("/ee") of Cal.com.
The /ee subfolder is the place for all the Enterprise Edition features from our hosted plan and enterprise-grade features for Enterprise such as SSO, SAML, OIDC, SCIM, SIEM and much more or Platform plan to build a marketplace.
❗ WARNING: This repository is copyrighted (unlike our main repo). You are not allowed to use this code to host your own version of app.cal.com without obtaining a proper license first❗
Setting up Stripe
- Create a stripe account or use an existing one. For testing, you should use all stripe dashboard functions with the Test-Mode toggle in the top right activated.
- Open Stripe ApiKeys save the token starting with
pk_...toNEXT_PUBLIC_STRIPE_PUBLIC_KEYandsk_...toSTRIPE_PRIVATE_KEYin the .env file. - Open Stripe Connect Settings and activate OAuth for Standard Accounts
- Add
<CALENDSO URL>/api/integrations/stripepayment/callbackas redirect URL. - Copy your client*id (
ca*...) toSTRIPE_CLIENT_IDin the .env file. - Open Stripe Webhooks and add
<CALENDSO URL>/api/integrations/stripepayment/webhookas webhook for connected applications. - Select all
payment_intentevents for the webhook. - Copy the webhook secret (
whsec_...) toSTRIPE_WEBHOOK_SECRETin the .env file.
Setting up SAML login
- Set SAML_DATABASE_URL to a postgres database. Please use a different database than the main Cal instance since the migrations are separate for this database. For example
postgresql://postgres:@localhost:5450/cal-saml - Set SAML_ADMINS to a comma separated list of admin emails from where the SAML metadata can be uploaded and configured.
- Create a SAML application with your Identity Provider (IdP) using the instructions here - SAML Setup
- Remember to configure access to the IdP SAML app for all your users (who need access to Cal).
- You will need the XML metadata from your IdP later, so keep it accessible.
- Log in to one of the admin accounts configured in SAML_ADMINS and then navigate to Settings -> Security.
- You should see a SAML configuration section, copy and paste the XML metadata from step 5 and click on Save.
- Your provisioned users can now log into Cal using SAML.