Files
calendar/packages/features/webhooks/lib/service/WebhookNotificationHandler.ts
T
Rajiv SahalGitHubDevin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>Morgancal.com
e6d44ce620 feat: Add delegation credential error webhook trigger (#24871)
* feat: add delegation credential error webhook trigger

- Add DELEGATION_CREDENTIAL_ERROR to WebhookTriggerEvents enum
- Create DelegationCredentialErrorDTO type for webhook payload
- Implement DelegationCredentialErrorWebhookService
- Add translation for delegation_credential_error
- Enable webhook for API v2 organization webhooks

This webhook will send delegation credential error data to configured URLs when errors occur during calendar authentication with delegation credentials.

Co-Authored-By: rajiv@cal.com <sahalrajiv6900@gmail.com>

* fix: add delegation credential error payload type and type guards

- Add DelegationCredentialErrorPayloadType to sendPayload.ts
- Update WebhookPayloadType union to include new payload type
- Add isDelegationCredentialErrorPayload type guard function
- Update isEventPayload to exclude delegation credential errors
- Update template application logic to handle new payload type
- Add corresponding payload type to dto/types.ts for consistency

Co-Authored-By: rajiv@cal.com <sahalrajiv6900@gmail.com>

* feat: add delegation credential error handling to WebhookNotificationHandler

- Add DELEGATION_CREDENTIAL_ERROR case to createPayload switch
- Return payload with error, credential, and user data
- Ensures exhaustive type checking passes for new trigger

Co-Authored-By: rajiv@cal.com <sahalrajiv6900@gmail.com>

* feat: restrict DELEGATION_CREDENTIAL_ERROR to organization webhooks only

- Add validation in UserWebhooksService to reject DELEGATION_CREDENTIAL_ERROR
- Add validation in EventTypeWebhooksService to reject DELEGATION_CREDENTIAL_ERROR
- Ensures trigger is only available for API v2 organization webhooks as requested

Co-Authored-By: rajiv@cal.com <sahalrajiv6900@gmail.com>

* feat: wire up delegation credential error webhook emission in calendar services

- Add webhook emission calls in CalendarAuth.ts for Google Calendar delegation errors
- Add webhook emission calls in Office365 CalendarService.ts for Azure AD delegation errors
- Implement actual webhook emission using WebhookRepository pattern
- Fix pre-existing lint warnings in Office365 CalendarService.ts (unused catch variables, unsafe optional chaining)

Co-Authored-By: rajiv@cal.com <sahalrajiv6900@gmail.com>

* test: add e2e tests for DELEGATION_CREDENTIAL_ERROR webhook trigger

- Add comprehensive e2e tests for creating, retrieving, updating, and deleting webhooks with DELEGATION_CREDENTIAL_ERROR trigger
- Test combining DELEGATION_CREDENTIAL_ERROR with other triggers
- Fix import in triggerDelegationCredentialErrorWebhook.ts to use default import for sendPayload
- Tests follow existing patterns in organizations-webhooks.e2e-spec.ts

Co-Authored-By: rajiv@cal.com <sahalrajiv6900@gmail.com>

* refactor: remove name field from webhook payload and delete unused service

- Remove name field from triggerDelegationCredentialErrorWebhook function signature and payload
- Update all call sites in GoogleCalendar and Office365 calendar services
- Update DelegationCredentialErrorDTO and DelegationCredentialErrorPayloadType to remove name field
- Delete unused DelegationCredentialErrorWebhookService.ts (dead code - not used anywhere)
- The helper function approach is more appropriate for app-store integrations without DI

Co-Authored-By: rajiv@cal.com <sahalrajiv6900@gmail.com>

* refactor: make fire-and-forget intent explicit for webhook emission

- Add void cast to all triggerDelegationCredentialErrorWebhook calls
- Remove redundant .catch() handlers (helper already handles errors internally)
- This makes it clear that webhook emission is non-blocking by design
- Avoids delaying error propagation while webhook HTTP requests complete

Co-Authored-By: rajiv@cal.com <sahalrajiv6900@gmail.com>

* feat: await webhook emission and add HTTP timeout for guaranteed delivery

- Change all triggerDelegationCredentialErrorWebhook calls from void to await
- Add 10-second timeout to webhook HTTP requests using AbortController
- Remove name field from DelegationCredentialErrorPayloadType to match payload
- Ensures webhooks are sent before error is thrown (per user requirement)
- Prevents indefinite hangs on unresponsive webhook endpoints

Co-Authored-By: rajiv@cal.com <sahalrajiv6900@gmail.com>

* fix: make getAuthUrl async and await all call sites

- Make getAuthUrl async to support awaiting webhook emission
- Add await to all 3 getAuthUrl call sites (constructor, getAzureUserId, testDelegationCredentialSetup)
- Remove leftover name field from getAzureUserId webhook call
- Fixes TS1308 error about await in non-async function

Co-Authored-By: rajiv@cal.com <sahalrajiv6900@gmail.com>

* docs: add JSDoc clarifying error handling guarantees for webhook trigger

Co-Authored-By: rajiv@cal.com <sahalrajiv6900@gmail.com>

* Revert "docs: add JSDoc clarifying error handling guarantees for webhook trigger"

This reverts commit 3e33090197bfe2f2e3fb890402b32e04c44305e3.

* Revert "fix: make getAuthUrl async and await all call sites"

This reverts commit de28b7337149104412c861fd9b05e76fffc1fed7.

* Revert "feat: await webhook emission and add HTTP timeout for guaranteed delivery"

This reverts commit 9da7241f83a8373b4fadc03ccf34e097c28adf3a.

* Revert "refactor: make fire-and-forget intent explicit for webhook emission"

This reverts commit f4f7fa06b7dfa151bfbea29905b8783261d9f353.

* feat: await webhook emission to match standard pattern

- Updated all webhook call sites to await triggerDelegationCredentialErrorWebhook
- Made getAuthUrl async and updated all 3 call sites to await it
- Removed .catch() wrappers at call sites (error handling is in trigger function)
- Matches standard pattern used in WebhookService.sendPayload with Promise.allSettled
- Ensures webhooks are sent before delegation errors are thrown

Co-Authored-By: rajiv@cal.com <sahalrajiv6900@gmail.com>

* fix: address PR feedback - add migration, remove 'as any', remove user.name

- Add Prisma migration for DELEGATION_CREDENTIAL_ERROR enum
- Replace 'as any' type casting with safe type-narrowing helper in CalendarAuth.ts
- Remove user.name field from DelegationCredentialErrorPayloadType (email is sufficient)
- Ensure all type definitions are consistent across sendPayload.ts and dto/types.ts

Addresses feedback from alishaz-polymath and morgan@cal.com

Co-Authored-By: rajiv@cal.com <sahalrajiv6900@gmail.com>

* chore: cleanup type in CalendarAuth

* fix: missing DELEGATION_CREDENTIAL_ERROR in WEBHOOK_TRIGGER_EVENTS_GROUPED_BY_APP constant

* fix: review

* fit: import webhook dto

* fit: type error

* feat: add delegation credential error webhook handling to Office365 video adapter

- Emit webhook before throwing delegation credential errors in Office365 video
- Added webhook emission in 4 locations:
  1. Missing clientId/Secret in fetchNewTokenObject
  2. Missing tenantId in getAuthUrl
  3. Missing clientId/Secret in getAzureUserId
  4. User doesn't exist in Azure AD
- Made getAuthUrl async to support webhook emission
- Follows same pattern as GoogleCalendar and Office365Calendar implementations

Co-Authored-By: morgan@cal.com <morgan@cal.com>
Co-Authored-By: rajiv@cal.com <sahalrajiv6900@gmail.com>

* fixup! Merge branch 'devin/delegation-credential-errors-webhook-1762171203' of https://git-manager.devin.ai/proxy/github.com/calcom/cal.com into devin/delegation-credential-errors-webhook-1762171203

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Morgan <33722304+ThyMinimalDev@users.noreply.github.com>
Co-authored-by: cal.com <morgan@cal.com>
2025-11-11 16:02:06 +02:00

148 lines
5.3 KiB
TypeScript

import { WebhookTriggerEvents } from "@calcom/prisma/enums";
import type { WebhookEventDTO } from "../dto/types";
import type { BookingPayloadBuilder } from "../factory/BookingPayloadBuilder";
import type { FormPayloadBuilder } from "../factory/FormPayloadBuilder";
import type { InstantMeetingBuilder } from "../factory/InstantMeetingBuilder";
import type { MeetingPayloadBuilder } from "../factory/MeetingPayloadBuilder";
import type { OOOPayloadBuilder } from "../factory/OOOPayloadBuilder";
import type { RecordingPayloadBuilder } from "../factory/RecordingPayloadBuilder";
import type { WebhookPayload } from "../factory/types";
import type { ILogger } from "../interface/infrastructure";
import type { IWebhookService } from "../interface/services";
import type { IWebhookNotificationHandler } from "../interface/webhook";
export class WebhookNotificationHandler implements IWebhookNotificationHandler {
private readonly log: ILogger;
constructor(
private readonly webhookService: IWebhookService,
private readonly bookingPayloadBuilder: BookingPayloadBuilder,
private readonly formPayloadBuilder: FormPayloadBuilder,
private readonly oooPayloadBuilder: OOOPayloadBuilder,
private readonly recordingPayloadBuilder: RecordingPayloadBuilder,
private readonly meetingPayloadBuilder: MeetingPayloadBuilder,
private readonly instantMeetingBuilder: InstantMeetingBuilder,
logger: ILogger
) {
this.log = logger.getSubLogger({ prefix: ["[WebhookNotificationHandler]"] });
}
async handleNotification(dto: WebhookEventDTO, isDryRun = false): Promise<void> {
const trigger = dto.triggerEvent;
try {
if (isDryRun) {
this.log.debug(`Dry run mode - skipping webhook notification for: ${trigger}`);
return;
}
const subscriptionParams = {
userId: dto.userId,
eventTypeId: dto.eventTypeId,
triggerEvent: trigger,
teamId: dto.teamId,
orgId: dto.orgId,
oAuthClientId: dto.platformClientId,
};
this.log.debug(`Querying for webhook subscribers with params:`, subscriptionParams);
const subscribers = await this.webhookService.getSubscribers(subscriptionParams);
if (subscribers.length === 0) {
this.log.debug(`No subscribers found for event: ${trigger}`, {
bookingId: dto.bookingId,
eventTypeId: dto.eventTypeId,
});
return;
}
const webhookPayload = this.createPayload(dto);
await this.webhookService.processWebhooks(trigger, webhookPayload, subscribers);
this.log.debug(`Successfully processed webhook notification: ${trigger}`, {
subscriberCount: subscribers.length,
bookingId: dto.bookingId,
});
} catch (error) {
this.log.error(`Error handling webhook notification: ${trigger}`, {
error: error instanceof Error ? error.message : String(error),
bookingId: dto.bookingId,
eventTypeId: dto.eventTypeId,
});
throw error;
}
}
private createPayload(dto: WebhookEventDTO): WebhookPayload {
switch (dto.triggerEvent) {
// Booking events
case WebhookTriggerEvents.BOOKING_CREATED:
case WebhookTriggerEvents.BOOKING_CANCELLED:
case WebhookTriggerEvents.BOOKING_REQUESTED:
case WebhookTriggerEvents.BOOKING_RESCHEDULED:
case WebhookTriggerEvents.BOOKING_REJECTED:
case WebhookTriggerEvents.BOOKING_PAID:
case WebhookTriggerEvents.BOOKING_PAYMENT_INITIATED:
case WebhookTriggerEvents.BOOKING_NO_SHOW_UPDATED:
return this.bookingPayloadBuilder.build(dto);
// Form events
case WebhookTriggerEvents.FORM_SUBMITTED:
case WebhookTriggerEvents.FORM_SUBMITTED_NO_EVENT:
return this.formPayloadBuilder.build(dto);
// OOO events
case WebhookTriggerEvents.OOO_CREATED:
return this.oooPayloadBuilder.build(dto);
// Recording events
case WebhookTriggerEvents.RECORDING_READY:
case WebhookTriggerEvents.RECORDING_TRANSCRIPTION_GENERATED:
return this.recordingPayloadBuilder.build(dto);
// Meeting events
case WebhookTriggerEvents.MEETING_STARTED:
case WebhookTriggerEvents.MEETING_ENDED:
return this.meetingPayloadBuilder.build(dto);
// Instant meeting events
case WebhookTriggerEvents.INSTANT_MEETING:
return this.instantMeetingBuilder.build(dto);
// No-show events (special handling)
case WebhookTriggerEvents.AFTER_HOSTS_CAL_VIDEO_NO_SHOW:
case WebhookTriggerEvents.AFTER_GUESTS_CAL_VIDEO_NO_SHOW: {
return {
triggerEvent: dto.triggerEvent,
createdAt: dto.createdAt,
payload: {
bookingId: dto.bookingId,
webhook: dto.webhook,
},
};
}
case WebhookTriggerEvents.DELEGATION_CREDENTIAL_ERROR: {
return {
triggerEvent: dto.triggerEvent,
createdAt: dto.createdAt,
payload: {
error: dto.error,
credential: dto.credential,
user: dto.user,
},
};
}
default: {
// TypeScript exhaustiveness check - this should never happen if all cases are covered
const _exhaustiveCheck: never = dto;
throw new Error(`Unsupported triggerEvent: ${JSON.stringify(_exhaustiveCheck)}`);
}
}
}
}