* chore: Upgrade prisma to 6.7.0 * Build fixes * type fixes Signed-off-by: Omar López <zomars@me.com> * Update schema.prisma * Patching * Revert "Update schema.prisma" This reverts commit 47d8618bf89ef4d007b30084df766f17281e21a1. * Revert "Patching" This reverts commit a1d2e3040e71690a44d4324db95d73b4d68c6adb. * Revert schema changes Signed-off-by: Omar López <zomars@me.com> * WIP Signed-off-by: Omar López <zomars@me.com> * Update getPublicEvent.ts * Update imports Signed-off-by: Omar López <zomars@me.com> * Update gitignore Signed-off-by: Omar López <zomars@me.com> * update remaining imports Signed-off-by: Omar López <zomars@me.com> * Delete .cursor/config.json * Discard changes to packages/features/eventtypes/lib/getPublicEvent.ts * Update _get.ts * Update user.ts * Update .gitignore * update * Update WorkflowStepContainer.tsx * Update next-auth-custom-adapter.ts * Update getPublicEvent.ts * Update workflow.ts * Update next-auth-custom-adapter.ts * Update next-auth-options.ts * Update bookingScenario.ts * fix missing imports * upgrades prismock Signed-off-by: Omar López <zomars@me.com> * patches prismock Signed-off-by: Omar López <zomars@me.com> * Update reschedule.test.ts * Update prisma.ts * patch prismock Signed-off-by: Omar López <zomars@me.com> * fix enums imports Signed-off-by: Omar López <zomars@me.com> * Revert "Update prisma.ts" This reverts commit 64edcf8db54171ff4456c209d563b5d431d99619. * Revert "patch prismock" This reverts commit e95819113dc9d88e7130947aa120cd42710977c8. * fix patch * Fix test that overrun the boundary, it shouldn't test too much * Move prisma import to changeSMSLockState * Bring back broken test without illegal imports * Merge with main and fix filter hosts by same round robin host * Fixed buildDryRunBooking fn tests * Fix and move ooo create or update handler test * Fix packages/features/eventtypes/lib/isCurrentlyAvailable.test.ts * Fix packages/trpc/server/routers/viewer/organizations/listMembers.handler.test.ts * Mock @calcom/prisma * Fix: verify-email.test.ts * fix: Moved WebhookService test and fixed default import mock * Fix: Added missing prisma mock, handleNewBooking uses that of course * We're not testing createContext here * fix: Prisma mock fix for listMembers.test.ts * More fixes to broken testcases * Forgot to remove borked test * Prevent the need to mock a lot of dependencies by moving out buildBaseWhereCondition to its own file * Temporarily skip getCalendarEvents, needs a rewrite * Fix: turns out you can access protected in testcases * fix further mocks * Added packages/features/insights/server/buildBaseWhereCondition.ts, types * Always great to have a mock and then not use it * And one less again. * fix: confirm.handler.test, didn't mock prisma * fix: Address minor nit by @eunjae & fix ImpersonationProvider test * Updated isPrismaAvailableCheck that doesn't crash on import * fix: Get Prisma directly from the client, it usually involves the Validator and does not need 'local' inclusion * Add zod-prisma-types without the generator enabled (commented out) * Uncomment and see what happens * Change method of import as imports did not work in Input Schemas * Remove custom 'zod' booking model, it does not belong with Prisma * Fix all other global Model imports * Rewrite most schema includes AND remove barrel file * Add bookingCreateBodySchema to features/bookings * Flurry of type fixes for compatibility with new zod gen * Refactor out the custom prisma type createEventTypeInput * Work around nullable eventTypeLocations * HandlePayment type fix * More fixes, final fix remaining is CompleteEventType * Should fix a bunch more booking related type errors * Missed one * Some props missing from BookingCreateBodySchema * Fix location type in handleChildrenEventTypes * Little bit hacky imo but it works * Final type error \o/ * Forgot to include Prisma * Do not include zod-utils in booker/types * Oops, was already including Booker/types * Fix membership type, also disallow updating createdAt/updatedAt, make part of patch/post * Fix api v1 type errors * Fix EventTypeDescription typings * Remove getParserWithGeneric, use userBodySchema with UserSchema * use centralized timeZoneSchema * Implement feedback by @zomars * Couple of WIP pushes * Fix tests * Type fixes in `handleChildrenEventTypes` test * Try and parse metadata before use * Change zod-prisma-types configuration for optimal performance * Fix prisma validator error in `prisma/selects/credential` * Disable seperate relations model, hits a bug * Import absolute - this makes rollup work in @platform/libraries * Attempt at removing resolutions override * Refactor using `Prisma.validator` to `satisfies` * Build atoms using @calcom/prisma/client * Build atoms using @calcom/prisma/client * fixes * Update eventTypeSelect.ts * Adjust `eventTypeMetaDataSchemaWithUntypedApps` from `unknown` to `record(any)` * `EventTypeDescription` rely on `descriptionAsSafeHTML` instead of `description` * Add `seatsPerTimeSlot` to event type public select * Fix typing in `users-public-view` getServerSide props * Add missing `schedulingType` to prop * chore: bump platform libraries * Function return type is illegal, not sure how this passed eslint (#21567) * Merged with main * Update updateTokenObject.ts * Update handleResponse.ts * Update index.ts * Update handleChildrenEventTypes.ts * Update booking-idempotency-key.ts * Update WebhookService.test.ts * Update events.test.ts * Update queued-response.test.ts * Update events.test.ts * Update getRoutedUrl.test.ts * fix: type checks Signed-off-by: Omar López <zomars@me.com> * fixes Signed-off-by: Omar López <zomars@me.com> * chore: bump platform libraries * Update yarn.lock * more fixes Signed-off-by: Omar López <zomars@me.com> * fixes Signed-off-by: Omar López <zomars@me.com> * biuld fixes * chore: bump platform libraries * Update conferencing.repository.ts * Update conferencing.repository.ts * Update getCalendarsEvents.test.ts * Update vite.config.js * chore: bump platform libraries * Update users.ts * Discard changes to docs/api-reference/v2/openapi.json * Update vite.config.ts * updated platform libraries * Update get.handler.test.ts * Update get.handler.test.ts * Update schema.prisma * Discard changes to docs/api-reference/v2/openapi.json * Update next-auth-custom-adapter.ts * Update team.ts * Flurry of type fixes * Fix majority of insight related type errors * Type fixes for unlink of account * Make user nullable again * Fixed a bunch of unit tests and one type error * Attempted mock fix * Attempted fix for Attribute type * Ensure default import becomes prisma, but not direct usage * Import default as prisma in prisma.module * Add attributeOption to attribute type * Fix calcom/prisma mock * Refactor Prisma client imports to @calcom/prisma/client Updated all imports from '@prisma/client' to '@calcom/prisma/client' across tests and repository files for consistency and to use the correct Prisma client package. This change improves maintainability and ensures the correct client is referenced throughout the codebase. * Undo removal of max-warnings=0 to get main to merge * Remove unit tests for e2e fixtures, provide new prisma mock * Mock @calcom/prisma in event manager * Mock @calcom/prisma in event manager * Add correct format even with --no-verify * Mock prisma in CalendarManager * Add mock for permission-check.service * Better injection in PrismaApiKeyRepository imports * More mock fixes :) * Fix listMembers.handler.test * Fix User import * Appropriately adjust all types to be imported as types, there were a lot of types imported as normal deps * Why was this a thing? * Strictly speaking; Not using prismock anymore * Ditched patch file for prismock * Fix output.service.ts platform type imports, need concrete for plainToClass * Better typing and tests for unlinkConnectedAccount.handler * Small type fix * Disable calendar cache tests as they are dependent on prismock * chore: bump platform lib * getRoutedUrl test remove of unused import * Extract select to external const on getEventTypesFromDB * Direct select of userSelect from selects/user * fix type error from merging 23653 * Fixed integration tests by removing hardcoded values that were possible due to mocking, but as its now directly hitting the db no longer * fix: vite config atoms prisma client type location * revert: example app prisma client * revert: example app prisma client * bump platform libs * fix: use class instead of type for DI of PlatformBookingsService * update platform libs * remove unused variable * chore: generate prisma client for api v2 * fix: api v2 e2e * fix: atoms e2e * fix: atoms e2e * fix: atoms e2e * fix: api v2 e2e * fix: tsconfig apiv2 enums * publish libraries * Simplify check for existence teamId --------- Signed-off-by: Omar López <zomars@me.com> Co-authored-by: Alex van Andel <me@alexvanandel.com> Co-authored-by: Joe Au-Yeung <j.auyeung419@gmail.com> Co-authored-by: supalarry <laurisskraucis@gmail.com> Co-authored-by: cal.com <morgan@cal.com> Co-authored-by: Morgan <33722304+ThyMinimalDev@users.noreply.github.com> Co-authored-by: Benny Joo <sldisek783@gmail.com>
335 lines
9.7 KiB
TypeScript
335 lines
9.7 KiB
TypeScript
import logger from "@calcom/lib/logger";
|
|
import {
|
|
serviceAccountKeySchema,
|
|
type ServiceAccountKey,
|
|
type EncryptedServiceAccountKey,
|
|
encryptServiceAccountKey,
|
|
decryptServiceAccountKey,
|
|
} from "@calcom/lib/server/serviceAccountKey";
|
|
import { prisma } from "@calcom/prisma";
|
|
import type { Prisma } from "@calcom/prisma/client";
|
|
|
|
import { OrganizationRepository } from "./organization";
|
|
|
|
export type { ServiceAccountKey };
|
|
const repositoryLogger = logger.getSubLogger({ prefix: ["DelegationCredentialRepository"] });
|
|
const delegationCredentialSafeSelect = {
|
|
id: true,
|
|
enabled: true,
|
|
domain: true,
|
|
createdAt: true,
|
|
updatedAt: true,
|
|
organizationId: true,
|
|
lastEnabledAt: true,
|
|
lastDisabledAt: true,
|
|
workspacePlatform: {
|
|
select: {
|
|
name: true,
|
|
slug: true,
|
|
},
|
|
},
|
|
};
|
|
|
|
const delegationCredentialSelectIncludesServiceAccountKey = {
|
|
...delegationCredentialSafeSelect,
|
|
serviceAccountKey: true,
|
|
};
|
|
|
|
function doesEmailMatchDelegationCredentialDomain({
|
|
memberEmail,
|
|
delegationCredentialEmailDomain,
|
|
}: {
|
|
memberEmail: string | null;
|
|
delegationCredentialEmailDomain: string;
|
|
}) {
|
|
if (!memberEmail) return false;
|
|
const memberEmailDomain = memberEmail.split("@")[1];
|
|
return memberEmailDomain === delegationCredentialEmailDomain;
|
|
}
|
|
|
|
export class DelegationCredentialRepository {
|
|
private static encryptServiceAccountKey(serviceAccountKey: ServiceAccountKey): EncryptedServiceAccountKey {
|
|
return encryptServiceAccountKey(serviceAccountKey);
|
|
}
|
|
|
|
private static decryptServiceAccountKey(encryptedServiceAccountKey: Prisma.JsonValue): ServiceAccountKey {
|
|
return decryptServiceAccountKey(encryptedServiceAccountKey);
|
|
}
|
|
|
|
private static withParsedServiceAccountKey<T extends { serviceAccountKey: Prisma.JsonValue } | null>(
|
|
delegationCredential: T
|
|
) {
|
|
if (!delegationCredential) {
|
|
return null;
|
|
}
|
|
const { serviceAccountKey, ...rest } = delegationCredential;
|
|
|
|
// Decrypt the service account key if it exists
|
|
const decryptedKey = this.decryptServiceAccountKey(serviceAccountKey);
|
|
const parsedServiceAccountKey = serviceAccountKeySchema.safeParse(decryptedKey);
|
|
|
|
return {
|
|
...rest,
|
|
serviceAccountKey: parsedServiceAccountKey.success ? parsedServiceAccountKey.data : null,
|
|
};
|
|
}
|
|
|
|
static async create(data: {
|
|
domain: string;
|
|
enabled: boolean;
|
|
organizationId: number;
|
|
workspacePlatformId: number;
|
|
serviceAccountKey: ServiceAccountKey;
|
|
}) {
|
|
const encryptedKey = this.encryptServiceAccountKey(data.serviceAccountKey);
|
|
return await prisma.delegationCredential.create({
|
|
data: {
|
|
workspacePlatform: {
|
|
connect: {
|
|
id: data.workspacePlatformId,
|
|
},
|
|
},
|
|
domain: data.domain,
|
|
enabled: data.enabled,
|
|
organization: {
|
|
connect: {
|
|
id: data.organizationId,
|
|
},
|
|
},
|
|
// z.passthrough() is not allowed in Prisma, but we know this is trusted.
|
|
serviceAccountKey: encryptedKey as unknown as Prisma.InputJsonValue,
|
|
},
|
|
select: delegationCredentialSafeSelect,
|
|
});
|
|
}
|
|
|
|
static async findById({ id }: { id: string }) {
|
|
return await prisma.delegationCredential.findUnique({
|
|
where: { id },
|
|
select: delegationCredentialSafeSelect,
|
|
});
|
|
}
|
|
|
|
static async findUniqueByOrganizationIdAndDomainIncludeSensitiveServiceAccountKey({
|
|
organizationId,
|
|
domain,
|
|
}: {
|
|
organizationId: number;
|
|
domain: string;
|
|
}) {
|
|
const delegationCredential = await prisma.delegationCredential.findUnique({
|
|
where: { organizationId_domain: { organizationId, domain } },
|
|
select: delegationCredentialSelectIncludesServiceAccountKey,
|
|
});
|
|
return DelegationCredentialRepository.withParsedServiceAccountKey(delegationCredential);
|
|
}
|
|
|
|
static async findByIdIncludeSensitiveServiceAccountKey({ id }: { id: string }) {
|
|
const delegationCredential = await prisma.delegationCredential.findUnique({
|
|
where: { id },
|
|
select: delegationCredentialSelectIncludesServiceAccountKey,
|
|
});
|
|
if (!delegationCredential) return null;
|
|
return DelegationCredentialRepository.withParsedServiceAccountKey(delegationCredential);
|
|
}
|
|
|
|
static async findUniqueByOrgMemberEmailIncludeSensitiveServiceAccountKey({ email }: { email: string }) {
|
|
const log = repositoryLogger.getSubLogger({
|
|
prefix: ["findUniqueByOrgMemberEmailIncludeSensitiveServiceAccountKey"],
|
|
});
|
|
log.debug("called with", { email });
|
|
const organization = await OrganizationRepository.findByMemberEmail({ email });
|
|
if (!organization) {
|
|
log.debug("Email not found in any organization:", email);
|
|
return null;
|
|
}
|
|
|
|
const emailDomain = email.split("@")[1];
|
|
const delegationCredential = await prisma.delegationCredential.findUnique({
|
|
where: {
|
|
organizationId_domain: {
|
|
organizationId: organization.id,
|
|
domain: emailDomain,
|
|
},
|
|
},
|
|
select: delegationCredentialSelectIncludesServiceAccountKey,
|
|
});
|
|
|
|
return DelegationCredentialRepository.withParsedServiceAccountKey(delegationCredential);
|
|
}
|
|
|
|
static async findAllByDomain({ domain }: { domain: string }) {
|
|
return await prisma.delegationCredential.findMany({
|
|
where: { domain },
|
|
select: delegationCredentialSafeSelect,
|
|
});
|
|
}
|
|
|
|
static async updateById({
|
|
id,
|
|
data,
|
|
}: {
|
|
id: string;
|
|
data: Partial<{
|
|
workspacePlatformId: number;
|
|
domain: string;
|
|
enabled: boolean;
|
|
organizationId: number;
|
|
lastEnabledAt: Date;
|
|
lastDisabledAt: Date;
|
|
}>;
|
|
}) {
|
|
const { workspacePlatformId, organizationId, ...rest } = data;
|
|
return await prisma.delegationCredential.update({
|
|
where: { id },
|
|
data: {
|
|
...(workspacePlatformId && {
|
|
workspacePlatform: {
|
|
connect: {
|
|
id: workspacePlatformId,
|
|
},
|
|
},
|
|
}),
|
|
...(organizationId && {
|
|
organization: {
|
|
connect: {
|
|
id: organizationId,
|
|
},
|
|
},
|
|
}),
|
|
...rest,
|
|
},
|
|
select: delegationCredentialSafeSelect,
|
|
});
|
|
}
|
|
|
|
static async deleteById({ id }: { id: string }) {
|
|
return await prisma.delegationCredential.delete({
|
|
where: { id },
|
|
});
|
|
}
|
|
|
|
static async findByOrgIdIncludeSensitiveServiceAccountKey({ organizationId }: { organizationId: number }) {
|
|
return await prisma.delegationCredential.findMany({
|
|
where: { organizationId },
|
|
select: {
|
|
...delegationCredentialSelectIncludesServiceAccountKey,
|
|
workspacePlatform: {
|
|
select: {
|
|
id: true,
|
|
name: true,
|
|
slug: true,
|
|
},
|
|
},
|
|
},
|
|
});
|
|
}
|
|
|
|
static async findAllEnabledIncludeDelegatedMembers() {
|
|
const delegationCredentials = await prisma.delegationCredential.findMany({
|
|
where: {
|
|
enabled: true,
|
|
},
|
|
include: {
|
|
workspacePlatform: {
|
|
select: {
|
|
slug: true,
|
|
},
|
|
},
|
|
organization: {
|
|
include: {
|
|
members: {
|
|
select: {
|
|
id: true,
|
|
userId: true,
|
|
user: {
|
|
select: {
|
|
id: true,
|
|
email: true,
|
|
},
|
|
},
|
|
accepted: true,
|
|
},
|
|
where: {
|
|
// Note: We don't maintain anything on Membership that can identify if a Membership has been processed, so we send all and let it be on the caller to filter out
|
|
accepted: true,
|
|
},
|
|
},
|
|
},
|
|
},
|
|
},
|
|
});
|
|
|
|
return delegationCredentials.map((delegationCredential) => {
|
|
// Members for whom delegation credential is applicable
|
|
const delegatedMembers = delegationCredential.organization.members.filter((member) => {
|
|
return doesEmailMatchDelegationCredentialDomain({
|
|
memberEmail: member.user.email,
|
|
delegationCredentialEmailDomain: delegationCredential.domain,
|
|
});
|
|
});
|
|
|
|
return {
|
|
...delegationCredential,
|
|
organization: {
|
|
...delegationCredential.organization,
|
|
delegatedMembers,
|
|
},
|
|
};
|
|
});
|
|
}
|
|
|
|
static async findAllDisabledAndIncludeNextBatchOfMembersToProcess() {
|
|
const delegationCredentials = await prisma.delegationCredential.findMany({
|
|
where: {
|
|
enabled: false,
|
|
},
|
|
include: {
|
|
workspacePlatform: {
|
|
select: {
|
|
slug: true,
|
|
},
|
|
},
|
|
organization: {
|
|
include: {
|
|
members: {
|
|
select: {
|
|
id: true,
|
|
userId: true,
|
|
user: {
|
|
select: {
|
|
id: true,
|
|
email: true,
|
|
},
|
|
},
|
|
accepted: true,
|
|
},
|
|
where: {
|
|
// Note: We don't maintain anything on Membership that can identify if a Membership has been processed, so we send all and let it be on the caller to filter out
|
|
accepted: true,
|
|
},
|
|
},
|
|
},
|
|
},
|
|
},
|
|
});
|
|
|
|
return delegationCredentials.map((delegationCredential) => {
|
|
const members = delegationCredential.organization.members;
|
|
const membersThatAreActuallyPartOfDelegationCredential = members.filter((member) => {
|
|
return doesEmailMatchDelegationCredentialDomain({
|
|
memberEmail: member.user.email,
|
|
delegationCredentialEmailDomain: delegationCredential.domain,
|
|
});
|
|
});
|
|
return {
|
|
...delegationCredential,
|
|
organization: {
|
|
...delegationCredential.organization,
|
|
members: membersThatAreActuallyPartOfDelegationCredential,
|
|
},
|
|
};
|
|
});
|
|
}
|
|
}
|