Files
calendar/packages/trpc/server/routers/viewer/webhook/delete.handler.ts
T
sean-brydonGitHubDevin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
a44a3e5b84 feat: add Webhook resource to PBAC system with permission enforcement (#23614)
* feat: add Webhook resource to PBAC system with permission enforcement

- Add Webhook resource to PBAC permission registry with CRUD actions
- Implement PBAC permission checks in webhook handlers (create, edit, delete)
- Add webhook permission translations to common.json
- Use PermissionCheckService with fallback roles [ADMIN, OWNER] for team webhooks
- Maintain backward compatibility when PBAC is disabled
- Follow same pattern as workflow PBAC implementation from PR #22845

Co-Authored-By: sean@cal.com <Sean@brydon.io>

* fix: implement PBAC permission filtering in webhook list handler

- Add PermissionCheckService to filter team webhooks by webhook.read permission
- Only show webhooks from teams where user has proper permissions
- Maintain backward compatibility with fallback to all team memberships

Co-Authored-By: sean@cal.com <Sean@brydon.io>

* add migration for default roles

* new forUserMethod

* update webhook repository

* fix UI showing/hiding webhooks for webhoo.create teams

* WIP pbac procedure migratoin + tests

* add more roles to get fallback

* permissions in cmponents instead of readOnly

* passPermissions to list item

* push instant events logic

* Git merge

* wip teamId accessable refactor

* fix delete handler

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2025-09-18 07:37:45 -03:00

69 lines
1.9 KiB
TypeScript

import { PermissionCheckService } from "@calcom/features/pbac/services/permission-check.service";
import { updateTriggerForExistingBookings } from "@calcom/features/webhooks/lib/scheduleTrigger";
import { prisma } from "@calcom/prisma";
import type { Prisma } from "@calcom/prisma/client";
import { MembershipRole } from "@calcom/prisma/enums";
import type { TrpcSessionUser } from "@calcom/trpc/server/types";
import { TRPCError } from "@trpc/server";
import type { TDeleteInputSchema } from "./delete.schema";
type DeleteOptions = {
ctx: {
user: NonNullable<TrpcSessionUser>;
};
input: TDeleteInputSchema;
};
export const deleteHandler = async ({ ctx, input }: DeleteOptions) => {
const { id } = input;
const where: Prisma.WebhookWhereInput = { AND: [{ id: id }] };
if (Array.isArray(where.AND)) {
if (input.eventTypeId) {
where.AND.push({ eventTypeId: input.eventTypeId });
} else if (input.teamId) {
const permissionService = new PermissionCheckService();
const hasPermission = await permissionService.checkPermission({
userId: ctx.user.id,
teamId: input.teamId,
permission: "webhook.delete",
fallbackRoles: [MembershipRole.ADMIN, MembershipRole.OWNER],
});
if (!hasPermission) {
throw new TRPCError({
code: "UNAUTHORIZED",
});
}
where.AND.push({ teamId: input.teamId });
} else if (ctx.user.role == "ADMIN") {
where.AND.push({ OR: [{ platform: true }, { userId: ctx.user.id }] });
} else {
where.AND.push({ userId: ctx.user.id });
}
}
const webhookToDelete = await prisma.webhook.findFirst({
where,
});
if (webhookToDelete) {
await prisma.webhook.delete({
where: {
id: webhookToDelete.id,
},
});
await updateTriggerForExistingBookings(webhookToDelete, webhookToDelete.eventTriggers, []);
}
return {
id,
};
};