Files
calendar/packages/app-store/salesforce/api/user-sync.ts
T
Joe Au-YeungGitHubDevin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>Hariom Balharacubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
6501743e5e feat: Add attribute sync logic from Salesforce (#26517)
* Add db schema

* Add `CredentialRepository.findByTeamIdAndSlugs`

* Add enabled app slugs for attribute syncing

* Create repository for `IntegrationAttributeSync`

* Create zod schemas

* Create `AttributeSyncUserRuleOutputMapper`

* Create `IntegrationAttributeSyncService`

* Create DI contianer

* Create trpc endpoints

* Create page

* Include team name in `CredentialRepository.findByTeamIdAndSlugs`

* Update schema and relations

* Update types and schemas

* Add more methods to IntegrationAttributeSyncRepository

* Add more services to `IntegrationAttributeSyncService`
- getById
- Init updateIncludeRulesAndMappings

* Refactor `getTeams.handler` to use repository

* Create `createAttributeSync` trpc endpoint

* Create `updateAttributeSync` trpc endpoint

* Add router to trpc

* Create attribute sync child components

* Pass custom actions to `FormCard`

* Create `IntegrationAttributeSyncCard`

* Pass inital props via server side

* Fix prop

* Only refetch on mutation

* Fixes

* Add form error when duplicate field and attribute combo

* Add `updateTransactionWithRUleAndMappings` logic

* Adjust zod schemas

* Service add `updateIncludeRulesAndMappings`

* Pass orgId from server to component

* Rename types

* Add deleteById method to repository

* Add name to integrationAttributeSync

* Add deleteById method to service

* Rename method

* Add deleteAttributeSync trpc endpoint

* Make the IntegrationAttributeSyncCard a dummy component

* test: add tests for IntegrationAttributeSync feature

Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>

* Move creating a attribute sync record to the service

* Add i18n strings

* Safe select credential in find by id and team

* Fix default credentialId value in form

* Update repository return types

* Add i18n string

* Make credentialId optional for form schema

* Fix label

* Add cascade deletes

* Add verification that syncs belong to org

* Create mapper for repository output

* Type fixes

* Remove old test file

* Pass `attributeOptions` from parent to children

* Infer types from zod schema

* Type fixes

* Type fix

* Clean up

* Add i18n strings

* Remove unused file

* Address feedback

* Add migration file

* Address feedback

* Add validation for new integration values

* Remove unused router

* Move away from z.infer to z.ZodType

* Clean up comments

* Type fix

* Type fixes

* Type fix

* fix: add passthrough to syncFormDataSchema to preserve extra fields

Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>

* fix: remove incorrect test that expected extra fields to pass through syncFormDataSchema

Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>

* Add endpoint for SF to call

* Create scratch org config

* Create sf cli scripts

* Create package logic

* Update README

* Remove unused file

* Add indexes

* Add aria label

* Address feedback - consistent validation

* Fix import paths for attribute types

* Add `CredentialRepository.findByAppIdAndKeyValue`

* Get credential by instance URL

* Verify incoming sfdc orgId matches credential sfdc orgId

* Rename method

* Get user name integration syncs

* refactor: change attributeSyncRules array to singular attributeSyncRule

The database schema enforces a one-to-one relationship between
IntegrationAttributeSync and AttributeSyncRule (via @unique constraint),
and the UI only supports a single rule. This change makes the TypeScript
type match the database schema and UI behavior.

Changes:
- Update IntegrationAttributeSync interface to use attributeSyncRule: AttributeSyncRule | null
- Update mapper to return singular rule instead of wrapping in array
- Update UI component to access sync.attributeSyncRule directly
- Update IIntegrationAttributeSyncUpdateParams Omit type
- Update tests to use attributeSyncRule: null instead of attributeSyncRules: []

Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>

* Convert `membershipRepository.findAllByUserId` to a normal method

* Add temp files to git ignore

* Init  and process team conditions

* Biome formatting

* Add `AttributeService` to get user attributes

* Add DI container for AttributeService

* AttributeSyncService evaluate attribute conditions

* Create DI container for attributeSyncService

* Return result for full condition

* Evaluate if attribute sync should apply to user

* Add  method

* Change PrismaAttributeOptionRepository to instance methods

* Init AttributeSyncFieldMappingsService and process attribute syncs

* Add AttributeSyncFieldMappingService DI container

* Refactor orgId to organizationId

* Add membership validation to sync field service

* AttributeSYncFieldMappingService use repository methods

* AttributeSyncFieldMappingService.processMappings add mapping logic

* Add DI tokens

* user-sync endpoint to implement attribute syncing

* Validate team belongs to org for rule

* test: add tests for AttributeSyncRuleService, AttributeSyncFieldMappingService, and AttributeService

Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>

* Remove duplicate migration file

* Fix merge conflict

* fix: resolve type errors in attribute sync feature (#26814)

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* Rename  variable

* Fix log typo

* Fix file name

* Add error logging

* Use credential teamId

* fix: add missing mockTeamRepository and team validation to tests

Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>

* Fix naming

* Fix file import

* Type fix

* Pass MembershipRepository as a dep in AttributeSyncFieldMappingService

* Type fix

* fix: add mockMembershipRepository to AttributeSyncFieldMappingService tests

Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>

* Update packages/app-store/salesforce/api/user-sync.ts

Add error handling when getting orgId from stored salesforce id

Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>

* fix: address Cubic code review comments

- PrismaAttributeRepository: use nested select instead of include: true for options
- CredentialRepository: use this.primaClient instead of global prisma, use select instead of include for relations
- AttributeSyncFieldMappingService: optimize O(n*m) complexity with Map lookup for O(1) access

Co-Authored-By: joe@cal.com <j.auyeung419@gmail.com>

* Fix typo in CredentialRepository

* Update README

* Update sfdx-project

* Add SFDC package tests

* fix: improve Salesforce Apex test assertions to verify actual behavior

- Enhanced CalComHttpMock to track HTTP callout invocations and capture requests
- Updated UserUpdateHandlerTest to verify HTTP callouts are made with correct data
- Updated CalComCalloutQueueableTest to verify HTTP callouts are made correctly
- Replaced System.assert(true, ...) with meaningful assertions that verify:
  - Correct number of HTTP callouts
  - Request body contains expected fields
  - Request method is POST

Addresses Cubic AI review feedback (confidence 9/10 issues only)

Co-Authored-By: unknown <>

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Hariom Balhara <hariombalhara@gmail.com>
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
2026-01-15 09:19:57 -05:00

144 lines
4.7 KiB
TypeScript

import { CredentialRepository } from "@calcom/features/credentials/repositories/CredentialRepository";
import { getAttributeSyncRuleService } from "@calcom/features/ee/integration-attribute-sync/di/AttributeSyncRuleService.container";
import { getIntegrationAttributeSyncService } from "@calcom/features/ee/integration-attribute-sync/di/IntegrationAttributeSyncService.container";
import { UserRepository } from "@calcom/features/users/repositories/UserRepository";
import logger from "@calcom/lib/logger";
import { prisma } from "@calcom/prisma";
import type { NextApiRequest, NextApiResponse } from "next";
import { getAttributeSyncFieldMappingService } from "@calcom/features/ee/integration-attribute-sync/di/AttributeSyncFieldMappingService.container";
const log = logger.getSubLogger({ prefix: ["[salesforce/user-sync]"] });
export default async function handler(
req: NextApiRequest,
res: NextApiResponse
) {
if (req.method !== "POST") {
return res.status(405).json({ error: "Method not allowed" });
}
const {
instanceUrl,
orgId: sfdcOrgId,
salesforceUserId,
email,
changedFields,
timestamp,
} = req.body;
log.info("Received user sync request", {
instanceUrl,
sfdcOrgId,
salesforceUserId,
email,
changedFields,
timestamp,
});
const credentialRepository = new CredentialRepository(prisma);
const credential = await credentialRepository.findByAppIdAndKeyValue({
appId: "salesforce",
keyPath: ["instance_url"],
value: instanceUrl,
keyFields: ["id"],
});
if (!credential) {
log.error(`No credential found for ${instanceUrl}`);
return res.status(400).json({ error: "Invalid instance URL" });
}
if (!credential?.teamId) {
log.error(`Missing teamId for credential ${credential.id}`);
return res.status(400).json({ error: "Invalid credential ID" });
}
const salesforceCredentialId = (credential.key as { id?: string } | null)?.id;
if (!salesforceCredentialId) {
log.error(`Missing SFDC id for credential ${credential.id}`);
return res.status(400).json({ error: "Invalid credential ID" });
}
let storedSfdcOrgId: string | undefined;
try {
storedSfdcOrgId = new URL(salesforceCredentialId).pathname.split("/")[2];
} catch {
log.error(`Invalid SFDC credential URL format for credential ${credential.id}`);
return res.status(400).json({ error: "Invalid credential format" });
}
if (storedSfdcOrgId !== sfdcOrgId) {
log.error(`Mismatched orgId ${sfdcOrgId} for credential ${credential.id}`);
return res.status(400).json({ error: "Invalid org ID" });
}
const userRepository = new UserRepository(prisma);
const user = await userRepository.findByEmailAndTeamId({
email,
teamId: credential.teamId,
});
if (!user) {
log.error(
`User not found for email ${email} and teamId ${credential.teamId}`
);
return res.status(400).json({ error: "Invalid user" });
}
const organizationId = credential.teamId;
const integrationAttributeSyncService = getIntegrationAttributeSyncService();
const integrationAttributeSyncs =
await integrationAttributeSyncService.getAllByCredentialId(credential.id);
const attributeSyncRuleService = getAttributeSyncRuleService();
const attributeSyncFieldMappingService =
getAttributeSyncFieldMappingService();
const results = await Promise.allSettled(
integrationAttributeSyncs.map(async (sync) => {
// Only check rule if one exists - skip sync only if rule returns false
if (sync.attributeSyncRule) {
const shouldSyncApplyToUser =
await attributeSyncRuleService.shouldSyncApplyToUser({
user: {
id: user.id,
organizationId,
},
attributeSyncRule: sync.attributeSyncRule.rule,
});
if (!shouldSyncApplyToUser) return;
}
// Salesforce multi-select picklists use `;` as separator, convert to `,` for the service
const integrationFields = Object.fromEntries(
Object.entries(changedFields as Record<string, unknown>)
.filter(([, value]) => value != null)
.map(([key, value]) => [key, String(value).replaceAll(";", ",")])
);
await attributeSyncFieldMappingService.syncIntegrationFieldsToAttributes({
userId: user.id,
organizationId,
syncFieldMappings: sync.syncFieldMappings,
integrationFields,
});
})
);
const errors = results.filter(
(result): result is PromiseRejectedResult => result.status === "rejected"
);
if (errors.length > 0) {
log.error("Errors syncing user attributes", {
errors: errors.map((e) => e.reason),
});
}
return res.status(200).json({ success: true });
}