Files
calendar/apps/web/playwright/booking-race-condition.e2e.ts
T
c28eb90928 chore: Upgrade prisma to 6.7.0 (#21264)
* chore: Upgrade prisma to 6.7.0

* Build fixes

* type fixes

Signed-off-by: Omar López <zomars@me.com>

* Update schema.prisma

* Patching

* Revert "Update schema.prisma"

This reverts commit 47d8618bf89ef4d007b30084df766f17281e21a1.

* Revert "Patching"

This reverts commit a1d2e3040e71690a44d4324db95d73b4d68c6adb.

* Revert schema changes

Signed-off-by: Omar López <zomars@me.com>

* WIP

Signed-off-by: Omar López <zomars@me.com>

* Update getPublicEvent.ts

* Update imports

Signed-off-by: Omar López <zomars@me.com>

* Update gitignore

Signed-off-by: Omar López <zomars@me.com>

* update remaining imports

Signed-off-by: Omar López <zomars@me.com>

* Delete .cursor/config.json

* Discard changes to packages/features/eventtypes/lib/getPublicEvent.ts

* Update _get.ts

* Update user.ts

* Update .gitignore

* update

* Update WorkflowStepContainer.tsx

* Update next-auth-custom-adapter.ts

* Update getPublicEvent.ts

* Update workflow.ts

* Update next-auth-custom-adapter.ts

* Update next-auth-options.ts

* Update bookingScenario.ts

* fix missing imports

* upgrades prismock

Signed-off-by: Omar López <zomars@me.com>

* patches prismock

Signed-off-by: Omar López <zomars@me.com>

* Update reschedule.test.ts

* Update prisma.ts

* patch prismock

Signed-off-by: Omar López <zomars@me.com>

* fix enums imports

Signed-off-by: Omar López <zomars@me.com>

* Revert "Update prisma.ts"

This reverts commit 64edcf8db54171ff4456c209d563b5d431d99619.

* Revert "patch prismock"

This reverts commit e95819113dc9d88e7130947aa120cd42710977c8.

* fix patch

* Fix test that overrun the boundary, it shouldn't test too much

* Move prisma import to changeSMSLockState

* Bring back broken test without illegal imports

* Merge with main and fix filter hosts by same round robin host

* Fixed buildDryRunBooking fn tests

* Fix and move ooo create or update handler test

* Fix packages/features/eventtypes/lib/isCurrentlyAvailable.test.ts

* Fix packages/trpc/server/routers/viewer/organizations/listMembers.handler.test.ts

* Mock @calcom/prisma

* Fix: verify-email.test.ts

* fix: Moved WebhookService test and fixed default import mock

* Fix: Added missing prisma mock, handleNewBooking uses that of course

* We're not testing createContext here

* fix: Prisma mock fix for listMembers.test.ts

* More fixes to broken testcases

* Forgot to remove borked test

* Prevent the need to mock a lot of dependencies by moving out buildBaseWhereCondition to its own file

* Temporarily skip getCalendarEvents, needs a rewrite

* Fix: turns out you can access protected in testcases

* fix further mocks

* Added packages/features/insights/server/buildBaseWhereCondition.ts, types

* Always great to have a mock and then not use it

* And one less again.

* fix: confirm.handler.test, didn't mock prisma

* fix: Address minor nit by @eunjae & fix ImpersonationProvider test

* Updated isPrismaAvailableCheck that doesn't crash on import

* fix: Get Prisma directly from the client, it usually involves the Validator and does not need 'local' inclusion

* Add zod-prisma-types without the generator enabled (commented out)

* Uncomment and see what happens

* Change method of import as imports did not work in Input Schemas

* Remove custom 'zod' booking model, it does not belong with Prisma

* Fix all other global Model imports

* Rewrite most schema includes AND remove barrel file

* Add bookingCreateBodySchema to features/bookings

* Flurry of type fixes for compatibility with new zod gen

* Refactor out the custom prisma type createEventTypeInput

* Work around nullable eventTypeLocations

* HandlePayment type fix

* More fixes, final fix remaining is CompleteEventType

* Should fix a bunch more booking related type errors

* Missed one

* Some props missing from BookingCreateBodySchema

* Fix location type in handleChildrenEventTypes

* Little bit hacky imo but it works

* Final type error \o/

* Forgot to include Prisma

* Do not include zod-utils in booker/types

* Oops, was already including Booker/types

* Fix membership type, also disallow updating createdAt/updatedAt, make part of patch/post

* Fix api v1 type errors

* Fix EventTypeDescription typings

* Remove getParserWithGeneric, use userBodySchema with UserSchema

* use centralized timeZoneSchema

* Implement feedback by @zomars

* Couple of WIP pushes

* Fix tests

* Type fixes in `handleChildrenEventTypes` test

* Try and parse metadata before use

* Change zod-prisma-types configuration for optimal performance

* Fix prisma validator error in `prisma/selects/credential`

* Disable seperate relations model, hits a bug

* Import absolute - this makes rollup work in @platform/libraries

* Attempt at removing resolutions override

* Refactor using `Prisma.validator` to `satisfies`

* Build atoms using @calcom/prisma/client

* Build atoms using @calcom/prisma/client

* fixes

* Update eventTypeSelect.ts

* Adjust `eventTypeMetaDataSchemaWithUntypedApps` from `unknown` to `record(any)`

* `EventTypeDescription` rely on `descriptionAsSafeHTML` instead of `description`

* Add `seatsPerTimeSlot` to event type public select

* Fix typing in `users-public-view` getServerSide props

* Add missing `schedulingType` to prop

* chore: bump platform libraries

* Function return type is illegal, not sure how this passed eslint (#21567)

* Merged with main

* Update updateTokenObject.ts

* Update handleResponse.ts

* Update index.ts

* Update handleChildrenEventTypes.ts

* Update booking-idempotency-key.ts

* Update WebhookService.test.ts

* Update events.test.ts

* Update queued-response.test.ts

* Update events.test.ts

* Update getRoutedUrl.test.ts

* fix: type checks

Signed-off-by: Omar López <zomars@me.com>

* fixes

Signed-off-by: Omar López <zomars@me.com>

* chore: bump platform libraries

* Update yarn.lock

* more fixes

Signed-off-by: Omar López <zomars@me.com>

* fixes

Signed-off-by: Omar López <zomars@me.com>

* biuld fixes

* chore: bump platform libraries

* Update conferencing.repository.ts

* Update conferencing.repository.ts

* Update getCalendarsEvents.test.ts

* Update vite.config.js

* chore: bump platform libraries

* Update users.ts

* Discard changes to docs/api-reference/v2/openapi.json

* Update vite.config.ts

* updated platform libraries

* Update get.handler.test.ts

* Update get.handler.test.ts

* Update schema.prisma

* Discard changes to docs/api-reference/v2/openapi.json

* Update next-auth-custom-adapter.ts

* Update team.ts

* Flurry of type fixes

* Fix majority of insight related type errors

* Type fixes for unlink of account

* Make user nullable again

* Fixed a bunch of unit tests and one type error

* Attempted mock fix

* Attempted fix for Attribute type

* Ensure default import becomes prisma, but not direct usage

* Import default as prisma in prisma.module

* Add attributeOption to attribute type

* Fix calcom/prisma mock

* Refactor Prisma client imports to @calcom/prisma/client

Updated all imports from '@prisma/client' to '@calcom/prisma/client' across tests and repository files for consistency and to use the correct Prisma client package. This change improves maintainability and ensures the correct client is referenced throughout the codebase.

* Undo removal of max-warnings=0 to get main to merge

* Remove unit tests for e2e fixtures, provide new prisma mock

* Mock @calcom/prisma in event manager

* Mock @calcom/prisma in event manager

* Add correct format even with --no-verify

* Mock prisma in CalendarManager

* Add mock for permission-check.service

* Better injection in PrismaApiKeyRepository imports

* More mock fixes :)

* Fix listMembers.handler.test

* Fix User import

* Appropriately adjust all types to be imported as types, there were a lot of types imported as normal deps

* Why was this a thing?

* Strictly speaking; Not using prismock anymore

* Ditched patch file for prismock

* Fix output.service.ts platform type imports, need concrete for plainToClass

* Better typing and tests for unlinkConnectedAccount.handler

* Small type fix

* Disable calendar cache tests as they are dependent on prismock

* chore: bump platform lib

* getRoutedUrl test remove of unused import

* Extract select to external const on getEventTypesFromDB

* Direct select of userSelect from selects/user

* fix type error from merging 23653

* Fixed integration tests by removing hardcoded values that were possible due to mocking, but as its now directly hitting the db no longer

* fix: vite config atoms prisma client type location

* revert: example app prisma client

* revert: example app prisma client

* bump platform libs

* fix: use class instead of type for DI of PlatformBookingsService

* update platform libs

* remove unused variable

* chore: generate prisma client for api v2

* fix: api v2 e2e

* fix: atoms e2e

* fix: atoms e2e

* fix: atoms e2e

* fix: api v2 e2e

* fix: tsconfig apiv2 enums

* publish libraries

* Simplify check for existence teamId

---------

Signed-off-by: Omar López <zomars@me.com>
Co-authored-by: Alex van Andel <me@alexvanandel.com>
Co-authored-by: Joe Au-Yeung <j.auyeung419@gmail.com>
Co-authored-by: supalarry <laurisskraucis@gmail.com>
Co-authored-by: cal.com <morgan@cal.com>
Co-authored-by: Morgan <33722304+ThyMinimalDev@users.noreply.github.com>
Co-authored-by: Benny Joo <sldisek783@gmail.com>
2025-09-11 15:27:50 +01:00

445 lines
14 KiB
TypeScript

import { expect } from "@playwright/test";
import type { Page, Browser, Route, Response } from "@playwright/test";
import type { z } from "zod";
import { CalendarCacheRepository } from "@calcom/features/calendar-cache/calendar-cache.repository";
import { getTimeMin, getTimeMax } from "@calcom/features/calendar-cache/lib/datesForCache";
import { prisma } from "@calcom/prisma";
import type { Team, EventType, User } from "@calcom/prisma/client";
import { MembershipRole, SchedulingType } from "@calcom/prisma/enums";
import type { teamMetadataSchema } from "@calcom/prisma/zod-utils";
import { test } from "./lib/fixtures";
import type { Fixtures } from "./lib/fixtures";
import { bookTimeSlot, doOnOrgDomain, selectFirstAvailableTimeSlotNextMonth } from "./lib/testUtils";
/**
* Booking Race Condition Prevention Test
*
* This test validates that the calendar caching system and booking logic correctly
* prevent double-booking race conditions that occurred in production. It serves as
* a regression test to ensure the following mechanisms work properly:
*
* 1. **Race Condition Prevention**: Ensures concurrent booking requests for the same
* time slot don't result in double bookings to the same host.
*
* 2. **Calendar Cache Functionality**: Validates that the calendar cache system works
* correctly with proper cache key generation using expanded date ranges.
*
* 3. **Round-Robin Distribution**: Verifies that when both bookings succeed, they are
* distributed to different hosts as expected in round-robin scheduling.
*
* 4. **Database Constraint Protection**: Confirms that unique constraints prevent
* duplicate bookings when race conditions are detected.
*
* **Test Setup**:
* - Creates a round-robin team with multiple hosts
* - Populates calendar cache with deterministic availability data
* - Mocks Google Calendar API to simulate real-world scenarios
* - Executes concurrent booking requests at the same time slot
*
* **Expected Outcomes**:
* - [200, 409]: One booking succeeds, one fails due to constraint violation (preferred)
* - [200, 200]: Both succeed but distributed to different hosts (acceptable)
* - [200, 200] with same host: Double booking occurred (test failure - race condition)
*
* **Production Context**:
* The original race condition was caused by:
* - Stale calendar cache showing hosts as available
* - Microsecond timing differences in Date.valueOf() for idempotency keys
* - Both requests selecting the same host due to identical cache state
*
* This test recreates similar conditions but in a controlled way to verify
* the prevention mechanisms work correctly.
*/
test.describe("Booking Race Condition Prevention", () => {
test.skip("Prevents double-booking race condition and validates cache functionality", async ({
page,
users,
orgs,
browser,
}) => {
const { org, team, teamEvent, teamMembers } = await setupTeamWithRoundRobin(users, orgs);
await setupGoogleCalendarCredentials(teamMembers);
await createIdenticalBookingHistories(teamMembers, teamEvent.id);
const { selectedDate, selectedDateISO } = await getDynamicBookingDate(page, org, team, teamEvent);
const { targetHost, calendarCacheHits } = await setupCalendarCache(teamMembers, selectedDateISO);
await enableCalendarCacheFeatures(team.id);
const { firstResponse, secondResponse } = await performConcurrentBookings(
page,
browser,
org,
team,
teamEvent,
selectedDate
);
const bookingResults = await analyzeBookingResults(teamEvent.id, firstResponse, secondResponse);
expect(bookingResults.isRaceConditionPrevented).toBe(true);
console.log("Race condition prevention test results:", {
totalBookings: bookingResults.bookings.length,
responseStatuses: bookingResults.responseStatuses,
sameHostSelected: bookingResults.sameHostSelected,
preventionMechanism: bookingResults.preventionMechanism,
});
});
});
async function setupTeamWithRoundRobin(users: Fixtures["users"], orgs: Fixtures["orgs"]) {
const org = await orgs.create({ name: "TestOrg" });
const teamMatesObj = [{ name: "teammate-1" }, { name: "teammate-2" }];
const owner = await users.create(
{
username: "pro-user",
name: "pro-user",
organizationId: org.id,
roleInOrganization: MembershipRole.MEMBER,
},
{
hasTeam: true,
teammates: teamMatesObj,
schedulingType: SchedulingType.ROUND_ROBIN,
}
);
const { team } = await owner.getFirstTeamMembership();
const teamEvent = await owner.getFirstTeamEvent(team.id);
const teamMemberships = await prisma.membership.findMany({
where: { teamId: team.id },
select: {
user: true,
},
});
const teamMembers = teamMemberships.map((membership) => membership.user);
return { org, team, teamEvent, teamMembers };
}
async function setupGoogleCalendarCredentials(teamMembers: User[]) {
const googleCalendarApp = await prisma.app.findFirst({
where: { slug: "google-calendar" },
});
if (!googleCalendarApp) {
await prisma.app.create({
data: {
slug: "google-calendar",
dirName: "google-calendar",
},
});
}
for (const member of teamMembers) {
await prisma.credential.create({
data: {
type: "google_calendar",
key: {
access_token: "test_access_token",
refresh_token: "test_refresh_token",
scope: "https://www.googleapis.com/auth/calendar.events",
token_type: "Bearer",
expiry_date: Date.now() + 3600000,
},
userId: member.id,
appId: "google-calendar",
invalid: false,
},
});
}
}
async function createIdenticalBookingHistories(teamMembers: User[], eventTypeId: number) {
const identicalTimestamp = new Date(Date.now() - 24 * 60 * 60 * 1000);
for (const member of teamMembers) {
for (let i = 0; i < 3; i++) {
await prisma.booking.create({
data: {
uid: `test-booking-${member.id}-${i}-${Date.now()}`,
title: `Test booking ${i}`,
startTime: new Date(Date.now() - (i + 2) * 24 * 60 * 60 * 1000),
endTime: new Date(Date.now() - (i + 2) * 24 * 60 * 60 * 1000 + 30 * 60 * 1000),
eventTypeId,
userId: member.id,
status: "ACCEPTED",
createdAt: identicalTimestamp,
updatedAt: identicalTimestamp,
attendees: {
create: {
email: `test${i}@example.com`,
name: `Test Attendee ${i}`,
timeZone: "UTC",
},
},
},
});
}
}
}
async function getDynamicBookingDate(
page: Page,
org: any,
team: any,
teamEvent: EventType
): Promise<{ selectedDate: string; selectedDateISO: string }> {
await doOnOrgDomain({ orgSlug: org.slug, page }, async () => {
await page.goto(`/org/${org.slug}/${team.slug}/${teamEvent.slug}`);
await page.waitForSelector('[data-testid="day"]');
await page.getByTestId("incrementMonth").click();
await page.locator('[data-testid="day"][data-disabled="false"]').nth(0).waitFor();
});
const firstAvailableDayText = await page
.locator('[data-testid="day"][data-disabled="false"]')
.nth(0)
.textContent();
if (!firstAvailableDayText) {
throw new Error("No available day found");
}
const currentDate = new Date();
const nextMonth = new Date(
currentDate.getFullYear(),
currentDate.getMonth() + 1,
parseInt(firstAvailableDayText)
);
const selectedDateISO = nextMonth.toISOString();
return {
selectedDate: firstAvailableDayText,
selectedDateISO,
};
}
async function setupCalendarCache(teamMembers: User[], selectedDateISO: string) {
const cacheTimeRange = {
timeMin: getTimeMin(selectedDateISO),
timeMax: getTimeMax(selectedDateISO),
};
const credentials = await prisma.credential.findMany({
where: {
userId: { in: teamMembers.map((m) => m.id) },
type: "google_calendar",
},
});
const calendarCacheRepo = new CalendarCacheRepository(null);
const targetHost = teamMembers[0];
const calendarCacheHits: string[] = [];
for (let i = 0; i < credentials.length; i++) {
const credential = credentials[i];
const member = teamMembers[i];
const cacheArgs = {
timeMin: cacheTimeRange.timeMin,
timeMax: cacheTimeRange.timeMax,
items: [{ id: member.email! }],
};
const availabilityData = {
kind: "calendar#freeBusy",
calendars: {
[member.email!]: {
busy:
member.id === targetHost.id
? []
: [
{
start: `${selectedDateISO.slice(0, 10)}T08:00:00.000Z`,
end: `${selectedDateISO.slice(0, 10)}T08:30:00.000Z`,
},
],
},
},
};
await calendarCacheRepo.upsertCachedAvailability({
credentialId: credential.id,
userId: member.id,
args: cacheArgs,
value: availabilityData,
});
calendarCacheHits.push(`${member.email}-${credential.id}`);
}
return { targetHost, calendarCacheHits };
}
async function enableCalendarCacheFeatures(teamId: number) {
await prisma.teamFeatures.createMany({
data: [
{
teamId,
featureId: "calendar-cache",
assignedAt: new Date(),
assignedBy: "race-condition-test",
},
{
teamId,
featureId: "calendar-cache-serve",
assignedAt: new Date(),
assignedBy: "race-condition-test",
},
],
});
}
async function mockGoogleCalendarAPI(page: Page, selectedDateISO: string) {
const busyStart = `${selectedDateISO.slice(0, 10)}T08:00:00.000Z`;
const busyEnd = `${selectedDateISO.slice(0, 10)}T09:00:00.000Z`;
await page.route("**/calendar/v3/freeBusy**", async (route: Route) => {
const mockResponse = {
kind: "calendar#freeBusy",
calendars: {
"pro-user@example.com": {
busy: [
{
start: busyStart,
end: busyEnd,
},
],
},
"teammate-1@example.com": {
busy: [
{
start: busyStart,
end: busyEnd,
},
],
},
"teammate-2@example.com": {
busy: [
{
start: busyStart,
end: busyEnd,
},
],
},
},
};
await route.fulfill({
status: 200,
headers: { "Content-Type": "application/json" },
body: JSON.stringify(mockResponse),
});
});
}
export type TeamWithMetadata = Team & { metadata: z.infer<typeof teamMetadataSchema> };
async function performConcurrentBookings(
page: Page,
browser: Browser,
org: TeamWithMetadata,
team: TeamWithMetadata,
teamEvent: EventType,
selectedDate: string
) {
let firstResponse: Response | undefined;
let secondResponse: Response | undefined;
await doOnOrgDomain({ orgSlug: org.slug, page }, async () => {
const context1 = await browser.newContext();
const context2 = await browser.newContext();
const page1 = await context1.newPage();
const page2 = await context2.newPage();
const currentDate = new Date();
const nextMonth = new Date(currentDate.getFullYear(), currentDate.getMonth() + 1, parseInt(selectedDate));
const selectedDateISO = nextMonth.toISOString();
await mockGoogleCalendarAPI(page1, selectedDateISO);
await mockGoogleCalendarAPI(page2, selectedDateISO);
await page1.goto(`/org/${org.slug}/${team.slug}/${teamEvent.slug}`);
await page2.goto(`/org/${org.slug}/${team.slug}/${teamEvent.slug}`);
await selectFirstAvailableTimeSlotNextMonth(page1);
await selectFirstAvailableTimeSlotNextMonth(page2);
const responsePromise1 = page1.waitForResponse(
(response) => response.url().includes("/api/book/event") && response.request().method() === "POST"
);
const responsePromise2 = page2.waitForResponse(
(response) => response.url().includes("/api/book/event") && response.request().method() === "POST"
);
const bookingPromise1 = bookTimeSlot(page1, {
name: "Test User 1",
email: "test1@example.com",
});
const bookingPromise2 = bookTimeSlot(page2, {
name: "Test User 2",
email: "test2@example.com",
});
const [response1, response2] = await Promise.all([responsePromise1, responsePromise2]);
await Promise.allSettled([bookingPromise1, bookingPromise2]);
firstResponse = response1;
secondResponse = response2;
await context1.close();
await context2.close();
});
return { firstResponse, secondResponse };
}
async function analyzeBookingResults(
eventTypeId: number,
firstResponse?: Response,
secondResponse?: Response
) {
const bookings = await prisma.booking.findMany({
where: { eventTypeId },
include: { attendees: true },
orderBy: { createdAt: "desc" },
take: 10,
});
const responseStatuses = [firstResponse?.status(), secondResponse?.status()].filter(Boolean);
const recentBookings = bookings.slice(0, 2);
const sameHostSelected =
recentBookings.length === 2 && recentBookings[0].userId === recentBookings[1].userId;
let preventionMechanism = "unknown";
if (responseStatuses.includes(409)) {
preventionMechanism = "database-constraint";
} else if (responseStatuses.every((status) => status === 200) && !sameHostSelected) {
preventionMechanism = "round-robin-distribution";
} else if (sameHostSelected) {
preventionMechanism = "race-condition-occurred";
}
const isRaceConditionPrevented = preventionMechanism !== "race-condition-occurred";
return {
bookings,
responseStatuses,
sameHostSelected,
preventionMechanism,
isRaceConditionPrevented,
};
}