The AES256 encryption used for 2FA requires exactly 32 bytes. The previous command `openssl rand -base64 32` generates a 44-character base64 string (32 bytes encoded in base64), which is too long. Changed to `openssl rand -base64 24` which generates exactly 32 characters (24 bytes encoded in base64 = 32 characters). This was causing 2FA setup failures with "Something went wrong" errors and RangeError: Invalid key length in self-hosted Docker installations. Fixes #22365 Co-authored-by: simiondolha <simiondolha@users.noreply.github.com> Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com> Co-authored-by: Keith Williams <keithwillcode@gmail.com>
Cal.com Development Guide for AI Agents
This directory contains comprehensive documentation for AI agents working on the Cal.com codebase.
Quick Navigation
- Commands - Build, test, and development commands
- Knowledge Base - Knowledge base & best practices
- Architecture Overview - System structure and patterns
Getting Started
Cal.com is a monorepo using Yarn workspaces and Turbo for build orchestration. The main application is in apps/web/ with shared packages in packages/.
Key Directories
apps/web/- Main Next.js applicationpackages/prisma/- Database schema and migrationspackages/trpc/- API layer using tRPCpackages/ui/- Shared UI componentspackages/features/- Feature-specific codepackages/app-store/- Third-party app integrations
Architecture Overview
Database Layer
- Prisma ORM with PostgreSQL
- Schema in
packages/prisma/schema.prisma - Always use
selectinstead ofincludefor better performance - Never expose
credential.keyfield in API responses
API Layer
- tRPC for type-safe APIs
- Routers in
packages/trpc/server/routers/ - Authentication handled via NextAuth.js
Frontend
- Next.js 13+ with App Router in some areas
- React 18 with TypeScript
- Tailwind CSS for styling
- Internationalization with
next-i18next
Common Patterns
Error Handling
- Use early returns to reduce nesting
- Throw descriptive errors with proper error codes
- Prefer composition over prop drilling
Performance
- Avoid O(n²) logic in backend code
- Minimize Day.js usage in performance-critical paths
- Use
selectqueries to only fetch needed data - Consider using
.utc()for Day.js operations
Security
- Never commit secrets or API keys
- Always validate input data
- Use proper authentication checks
- Never expose sensitive credential fields
Testing Strategy
- Unit tests with Vitest
- Integration tests for complex workflows
- E2E tests with Playwright
- Test files use
.test.tsor.spec.tsextensions
Pull Request Guidelines
For large PRs (>500 lines or >10 files):
- Split by feature boundaries
- Separate database migrations, backend logic, frontend components
- Create dependency chains that can be merged sequentially
- Pattern: Database → Backend → Frontend → Tests