f1011ddd08
* feat(booking-audit): extract core audit system changes from PR 25125 This PR extracts core audit infrastructure changes without integration changes: 1. New action services introduced: - SeatBookedAuditActionService - SeatRescheduledAuditActionService 2. Simplification of ActionService interface: - Streamlined IAuditActionService interface - Reduced TypeScript burden with cleaner type definitions 3. ActionSource support: - Added BookingAuditSource enum (API_V1, API_V2, WEBAPP, WEBHOOK, UNKNOWN) - Added source and operationId fields to BookingAudit model 4. New AuditAction types: - SEAT_BOOKED - SEAT_RESCHEDULED - APP actor type 5. New BookingAuditAccessService: - Permission-based access control for audit logs - Added readTeamAuditLogs and readOrgAuditLogs permissions 6. Fixes in the logs viewer flow: - Enhanced BookingAuditViewerService with improved filtering - Local AttendeeRepository for actor enrichment Changes are contained within packages/features/booking-audit with minimal outside changes (permission registry only). Co-Authored-By: hariom@cal.com <hariombalhara@gmail.com> * refactor(booking-audit): streamline action handling and enhance localization - Replaced action icon retrieval with a mapping object for improved clarity and performance. - Introduced constants for actor role labels to simplify role retrieval. - Added new localization strings for audit log permission errors and organization requirements. - Updated various service and repository interfaces to enhance type safety and clarity. - Removed deprecated architecture documentation and adjusted related imports for consistency. These changes aim to improve code maintainability and user experience in the booking audit system. * fix(booking-audit): enhance actor role localization and operation ID tracking - Updated actor role labels in the booking logs view to use lowercase for consistency. - Improved localization by wrapping actor role display in a translation function. - Added operationId field to audit logs for better correlation of actions across multiple bookings. - Enhanced BookingAuditViewerService to include operationId in enriched audit logs. - Updated integration tests to verify consistent operationId across related audit logs. These changes aim to improve localization accuracy and facilitate better tracking of user actions in the booking audit system. * feat: integrate credential repository and enhance app actor handling - Added CredentialRepository to manage app credentials, including a method to find credentials by ID. - Updated BookingAudit system to support app actors identified by credential ID, improving actor attribution and audit clarity. - Introduced a new utility function to map app slugs to display names, enhancing the user experience in audit logs. - Modified relevant interfaces and types to accommodate the new credential handling and app actor structure. - Enhanced BookingAuditViewerService to display app names based on credentials, ensuring accurate representation in audit logs. --------- Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
400 lines
14 KiB
TypeScript
400 lines
14 KiB
TypeScript
import { z } from "zod";
|
|
import { v4 as uuidv4 } from "uuid";
|
|
import type { Tasker } from "@calcom/features/tasker/tasker";
|
|
import { IS_PRODUCTION } from "@calcom/lib/constants";
|
|
import { safeStringify } from "@calcom/lib/safeStringify";
|
|
import type { ISimpleLogger } from "@calcom/features/di/shared/services/logger.service";
|
|
|
|
import type { BookingAuditAction } from "../types/bookingAuditTask";
|
|
import type { ActionSource } from "../types/actionSource";
|
|
import { makeActorById, type PiiFreeActor, type Actor, buildActorEmail } from "../../../bookings/lib/types/actor";
|
|
import type { IAuditActorRepository } from "../repository/IAuditActorRepository";
|
|
import { AcceptedAuditActionService } from "../actions/AcceptedAuditActionService";
|
|
import { AttendeeAddedAuditActionService } from "../actions/AttendeeAddedAuditActionService";
|
|
import { AttendeeNoShowUpdatedAuditActionService } from "../actions/AttendeeNoShowUpdatedAuditActionService";
|
|
import { AttendeeRemovedAuditActionService } from "../actions/AttendeeRemovedAuditActionService";
|
|
import { CancelledAuditActionService } from "../actions/CancelledAuditActionService";
|
|
import { CreatedAuditActionService } from "../actions/CreatedAuditActionService";
|
|
import { HostNoShowUpdatedAuditActionService } from "../actions/HostNoShowUpdatedAuditActionService";
|
|
import { LocationChangedAuditActionService } from "../actions/LocationChangedAuditActionService";
|
|
import { ReassignmentAuditActionService } from "../actions/ReassignmentAuditActionService";
|
|
import { RejectedAuditActionService } from "../actions/RejectedAuditActionService";
|
|
import { RescheduleRequestedAuditActionService } from "../actions/RescheduleRequestedAuditActionService";
|
|
import { RescheduledAuditActionService } from "../actions/RescheduledAuditActionService";
|
|
import { SeatBookedAuditActionService } from "../actions/SeatBookedAuditActionService";
|
|
import { SeatRescheduledAuditActionService } from "../actions/SeatRescheduledAuditActionService";
|
|
import type { BookingAuditProducerService } from "./BookingAuditProducerService.interface";
|
|
|
|
interface BookingAuditTaskerProducerServiceDeps {
|
|
tasker: Tasker;
|
|
log: ISimpleLogger;
|
|
auditActorRepository: IAuditActorRepository;
|
|
}
|
|
|
|
/**
|
|
* BookingAuditTaskerProducerService - Tasker-based implementation of BookingAuditProducerService
|
|
*
|
|
* Producer that uses Tasker for local/background job processing.
|
|
* Task processing is handled by BookingAuditTaskConsumer.
|
|
*
|
|
* For future migration to trigger.dev, create BookingAuditTriggerProducerService
|
|
* that implements the same BookingAuditProducerService interface.
|
|
*/
|
|
export class BookingAuditTaskerProducerService implements BookingAuditProducerService {
|
|
private readonly tasker: Tasker;
|
|
private readonly log: BookingAuditTaskerProducerServiceDeps["log"];
|
|
private readonly auditActorRepository: IAuditActorRepository;
|
|
|
|
constructor(private readonly deps: BookingAuditTaskerProducerServiceDeps) {
|
|
this.tasker = deps.tasker;
|
|
this.log = deps.log;
|
|
this.auditActorRepository = deps.auditActorRepository;
|
|
}
|
|
|
|
private async getPIIFreeBookingAuditActor(params: {
|
|
actor: Actor;
|
|
}): Promise<PiiFreeActor> {
|
|
const { actor } = params;
|
|
|
|
if (actor.identifiedBy === "user" || actor.identifiedBy === "attendee" || actor.identifiedBy === "id") {
|
|
return actor;
|
|
}
|
|
|
|
if (actor.identifiedBy === "app") {
|
|
const piiFreeActor = await this.auditActorRepository.createIfNotExistsAppActor({
|
|
credentialId: actor.credentialId,
|
|
});
|
|
return makeActorById(piiFreeActor.id);
|
|
}
|
|
|
|
if (actor.identifiedBy === "appSlug") {
|
|
const email = buildActorEmail({ identifier: actor.appSlug, actorType: "app" });
|
|
const piiFreeActor = await this.auditActorRepository.createIfNotExistsAppActor({
|
|
email,
|
|
name: actor.name,
|
|
});
|
|
return makeActorById(piiFreeActor.id);
|
|
}
|
|
|
|
// Must be guest actor at this point
|
|
const piiFreeActor = await this.auditActorRepository.createIfNotExistsGuestActor({
|
|
email: actor.email,
|
|
name: actor.name ?? null,
|
|
phone: null,
|
|
});
|
|
return makeActorById(piiFreeActor.id);
|
|
}
|
|
|
|
/**
|
|
* Internal helper to queue audit task to Tasker
|
|
* @param params.action - Must be a valid BookingAuditAction value (TYPE from action services are string-typed)
|
|
* @param params.operationId - Optional operation ID for correlating bulk operations. If null, will be auto-generated.
|
|
*/
|
|
private async queueTask(params: {
|
|
bookingUid: string;
|
|
actor: Actor;
|
|
organizationId: number | null;
|
|
action: string;
|
|
source: ActionSource;
|
|
operationId?: string | null;
|
|
data: unknown;
|
|
}): Promise<void> {
|
|
// Skip queueing for non-organization bookings
|
|
if (params.organizationId === null) {
|
|
return;
|
|
}
|
|
if (IS_PRODUCTION) {
|
|
return;
|
|
}
|
|
try {
|
|
const piiFreeActor = await this.getPIIFreeBookingAuditActor({
|
|
actor: params.actor,
|
|
});
|
|
|
|
const operationId = params.operationId ?? uuidv4();
|
|
|
|
await this.tasker.create("bookingAudit", {
|
|
isBulk: false,
|
|
bookingUid: params.bookingUid,
|
|
actor: piiFreeActor,
|
|
organizationId: params.organizationId,
|
|
timestamp: Date.now(),
|
|
action: params.action as BookingAuditAction,
|
|
source: params.source,
|
|
operationId,
|
|
data: params.data,
|
|
});
|
|
} catch (error) {
|
|
this.log.error(`Error while queueing ${params.action} audit`, safeStringify(error));
|
|
}
|
|
}
|
|
|
|
async queueCreatedAudit(params: {
|
|
bookingUid: string;
|
|
actor: Actor;
|
|
organizationId: number | null;
|
|
source: ActionSource;
|
|
operationId?: string | null;
|
|
data: z.infer<typeof CreatedAuditActionService.latestFieldsSchema>;
|
|
}): Promise<void> {
|
|
await this.queueTask({
|
|
...params,
|
|
action: CreatedAuditActionService.TYPE,
|
|
});
|
|
}
|
|
|
|
async queueRescheduledAudit(params: {
|
|
bookingUid: string;
|
|
actor: Actor;
|
|
organizationId: number | null;
|
|
source: ActionSource;
|
|
operationId?: string | null;
|
|
data: z.infer<typeof RescheduledAuditActionService.latestFieldsSchema>;
|
|
}): Promise<void> {
|
|
await this.queueTask({
|
|
...params,
|
|
action: RescheduledAuditActionService.TYPE,
|
|
});
|
|
}
|
|
|
|
async queueAcceptedAudit(params: {
|
|
bookingUid: string;
|
|
actor: Actor;
|
|
organizationId: number | null;
|
|
source: ActionSource;
|
|
operationId?: string | null;
|
|
data: z.infer<typeof AcceptedAuditActionService.latestFieldsSchema>;
|
|
}): Promise<void> {
|
|
await this.queueTask({
|
|
...params,
|
|
action: AcceptedAuditActionService.TYPE,
|
|
});
|
|
}
|
|
|
|
async queueCancelledAudit(params: {
|
|
bookingUid: string;
|
|
actor: Actor;
|
|
organizationId: number | null;
|
|
source: ActionSource;
|
|
operationId?: string | null;
|
|
data: z.infer<typeof CancelledAuditActionService.latestFieldsSchema>;
|
|
}): Promise<void> {
|
|
await this.queueTask({
|
|
...params,
|
|
action: CancelledAuditActionService.TYPE,
|
|
});
|
|
}
|
|
|
|
async queueRescheduleRequestedAudit(params: {
|
|
bookingUid: string;
|
|
actor: Actor;
|
|
organizationId: number | null;
|
|
source: ActionSource;
|
|
operationId?: string | null;
|
|
data: z.infer<typeof RescheduleRequestedAuditActionService.latestFieldsSchema>;
|
|
}): Promise<void> {
|
|
await this.queueTask({
|
|
...params,
|
|
action: RescheduleRequestedAuditActionService.TYPE,
|
|
});
|
|
}
|
|
|
|
async queueAttendeeAddedAudit(params: {
|
|
bookingUid: string;
|
|
actor: Actor;
|
|
organizationId: number | null;
|
|
source: ActionSource;
|
|
operationId?: string | null;
|
|
data: z.infer<typeof AttendeeAddedAuditActionService.latestFieldsSchema>;
|
|
}): Promise<void> {
|
|
await this.queueTask({
|
|
...params,
|
|
action: AttendeeAddedAuditActionService.TYPE,
|
|
});
|
|
}
|
|
|
|
async queueHostNoShowUpdatedAudit(params: {
|
|
bookingUid: string;
|
|
actor: Actor;
|
|
organizationId: number | null;
|
|
source: ActionSource;
|
|
operationId?: string | null;
|
|
data: z.infer<typeof HostNoShowUpdatedAuditActionService.latestFieldsSchema>;
|
|
}): Promise<void> {
|
|
await this.queueTask({
|
|
...params,
|
|
action: HostNoShowUpdatedAuditActionService.TYPE,
|
|
});
|
|
}
|
|
|
|
async queueRejectedAudit(params: {
|
|
bookingUid: string;
|
|
actor: Actor;
|
|
organizationId: number | null;
|
|
source: ActionSource;
|
|
operationId?: string | null;
|
|
data: z.infer<typeof RejectedAuditActionService.latestFieldsSchema>;
|
|
}): Promise<void> {
|
|
await this.queueTask({
|
|
...params,
|
|
action: RejectedAuditActionService.TYPE,
|
|
});
|
|
}
|
|
|
|
async queueAttendeeRemovedAudit(params: {
|
|
bookingUid: string;
|
|
actor: Actor;
|
|
organizationId: number | null;
|
|
source: ActionSource;
|
|
operationId?: string | null;
|
|
data: z.infer<typeof AttendeeRemovedAuditActionService.latestFieldsSchema>;
|
|
}): Promise<void> {
|
|
await this.queueTask({
|
|
...params,
|
|
action: AttendeeRemovedAuditActionService.TYPE,
|
|
});
|
|
}
|
|
|
|
async queueReassignmentAudit(params: {
|
|
bookingUid: string;
|
|
actor: Actor;
|
|
organizationId: number | null;
|
|
source: ActionSource;
|
|
operationId?: string | null;
|
|
data: z.infer<typeof ReassignmentAuditActionService.latestFieldsSchema>;
|
|
}): Promise<void> {
|
|
await this.queueTask({
|
|
...params,
|
|
action: ReassignmentAuditActionService.TYPE,
|
|
});
|
|
}
|
|
|
|
async queueLocationChangedAudit(params: {
|
|
bookingUid: string;
|
|
actor: Actor;
|
|
organizationId: number | null;
|
|
source: ActionSource;
|
|
operationId?: string | null;
|
|
data: z.infer<typeof LocationChangedAuditActionService.latestFieldsSchema>;
|
|
}): Promise<void> {
|
|
await this.queueTask({
|
|
...params,
|
|
action: LocationChangedAuditActionService.TYPE,
|
|
});
|
|
}
|
|
|
|
async queueAttendeeNoShowUpdatedAudit(params: {
|
|
bookingUid: string;
|
|
actor: Actor;
|
|
organizationId: number | null;
|
|
source: ActionSource;
|
|
operationId?: string | null;
|
|
data: z.infer<typeof AttendeeNoShowUpdatedAuditActionService.latestFieldsSchema>;
|
|
}): Promise<void> {
|
|
await this.queueTask({
|
|
...params,
|
|
action: AttendeeNoShowUpdatedAuditActionService.TYPE,
|
|
});
|
|
}
|
|
|
|
async queueSeatBookedAudit(params: {
|
|
bookingUid: string;
|
|
actor: Actor;
|
|
organizationId: number | null;
|
|
source: ActionSource;
|
|
operationId?: string | null;
|
|
data: z.infer<typeof SeatBookedAuditActionService.latestFieldsSchema>;
|
|
}): Promise<void> {
|
|
await this.queueTask({
|
|
...params,
|
|
action: SeatBookedAuditActionService.TYPE,
|
|
});
|
|
}
|
|
|
|
async queueSeatRescheduledAudit(params: {
|
|
bookingUid: string;
|
|
actor: Actor;
|
|
organizationId: number | null;
|
|
source: ActionSource;
|
|
operationId?: string | null;
|
|
data: z.infer<typeof SeatRescheduledAuditActionService.latestFieldsSchema>;
|
|
}): Promise<void> {
|
|
await this.queueTask({
|
|
...params,
|
|
action: SeatRescheduledAuditActionService.TYPE,
|
|
});
|
|
}
|
|
|
|
private async queueBulkTask(params: {
|
|
bookings: Array<{
|
|
bookingUid: string;
|
|
data: unknown;
|
|
}>;
|
|
actor: Actor;
|
|
organizationId: number | null;
|
|
action: string;
|
|
source: ActionSource;
|
|
operationId?: string | null;
|
|
}): Promise<void> {
|
|
// Skip queueing for non-organization bookings
|
|
if (params.organizationId === null) {
|
|
return;
|
|
}
|
|
if (IS_PRODUCTION) {
|
|
return;
|
|
}
|
|
try {
|
|
const piiFreeActor = await this.getPIIFreeBookingAuditActor({
|
|
actor: params.actor,
|
|
});
|
|
|
|
const operationId = params.operationId ?? uuidv4();
|
|
|
|
await this.tasker.create("bookingAudit", {
|
|
isBulk: true,
|
|
bookings: params.bookings,
|
|
actor: piiFreeActor,
|
|
organizationId: params.organizationId,
|
|
timestamp: Date.now(),
|
|
action: params.action as BookingAuditAction,
|
|
source: params.source,
|
|
operationId,
|
|
});
|
|
} catch (error) {
|
|
this.log.error(`Error while queueing bulk ${params.action} audit`, safeStringify(error));
|
|
}
|
|
}
|
|
|
|
async queueBulkAcceptedAudit(params: {
|
|
bookings: Array<{
|
|
bookingUid: string;
|
|
data: z.infer<typeof AcceptedAuditActionService.latestFieldsSchema>;
|
|
}>;
|
|
actor: Actor;
|
|
organizationId: number | null;
|
|
source: ActionSource;
|
|
operationId?: string | null;
|
|
}): Promise<void> {
|
|
await this.queueBulkTask({
|
|
...params,
|
|
action: AcceptedAuditActionService.TYPE,
|
|
});
|
|
}
|
|
|
|
async queueBulkCancelledAudit(params: {
|
|
bookings: Array<{
|
|
bookingUid: string;
|
|
data: z.infer<typeof CancelledAuditActionService.latestFieldsSchema>;
|
|
}>;
|
|
actor: Actor;
|
|
organizationId: number | null;
|
|
source: ActionSource;
|
|
operationId?: string | null;
|
|
}): Promise<void> {
|
|
await this.queueBulkTask({
|
|
...params,
|
|
action: CancelledAuditActionService.TYPE,
|
|
});
|
|
}
|
|
}
|