* Add endpoints for testing the flow * Add MVP * new route * Fixes * Fixes * Remove enable toggle support from domainWideDelegation * Fixes * Revert "Remove enable toggle support from domainWideDelegation" This reverts commit c29e729206cd1fa063f9c9ce0cf148ef1577d60b. * Revert yarn.lock * More fixes * Fix new workspace platform add * refactor: improvements * refactor: bug fixes and improvements * fix: type errors * fix: conflicts * chore: update test * fix: logic * chore: improvements * fix: toglle * fix: bugs * fix: type err * chore: check number type * fix: after conflicts * chore: fix type err * fix: type errors and tests * fix: tets * test * chore: remove unused * fix: google meet url on booking page and secondary calendar * fix: add property * fix: type err * fix: re assingment bug * fix: use getAllCredentials * chore: fix import * fix: installed count * fix: pass event type * fix: import * fix: [Stacked PR] Review fixes (#17958) * Review fixes * fix: destination calendar bug --------- Co-authored-by: Udit Takkar <udit222001@gmail.com> * refactor: use repository * chore: remove duplicate * fix: More review fixes for domain wide delegation (#17969) * Reuse buildCredentialPayloadForCalendar * fixes --------- Co-authored-by: Udit Takkar <53316345+Udit-takkar@users.noreply.github.com> * fix ts error * Fix getSchedule not using dwd credentials (#17995) * fix: Remove direct DWD table access from google-calendar and remove delegatedToId column from Credential (#18015) * Remove fn rename to reduce number of files changed * chore: check feature globally * test: add unit tests * chore: move function * test: add booking test * wip * Remove domain-wide-delegation team feature flag * Make sure duplicate calendars are not shown due to DWD. Show DWD when there is conflict * Fix tests and their ts errors * Fix more tests * Move findUsersForAvailabilityCheck to separate file as it has AppStore dependency causing problem with Routing Forms. Build crashes * fix: Multiple calendar connections from Google not showing up in apps/installed * DestinationCalendar must have either credentialId or domainWideDeelgationId. Also handle the case when DWD is disabled and there was a non-dwd credential that could be used * Disable deletetion of DWD as it is destructive and prefer disabling instead * Show DWD credential calendars at the top * Fixed tests * Calendar Cache DWD support * Self-Review: Verify email required and add more selectedCalendar tests * Self Review: shorten names * Self ReviewL Dead code removal * Revert "Calendar Cache DWD support" This reverts commit 009f236470fa21eba5986117d4f6e4d4c5e38c34. * Some misc fixes * fixes * Performance improvememt in slots loading and booking * More cases for handling dwd credentials * simplify the logic. Ensure that EventManager and the modules below it in the flow have CredentialForCalendarService available * Fix tests * Fix installed/conferencing not showing gogole meet * Shorten name * Fix ApI v2 tests * Add some more tests * add getSchedule tests * Improve tests * Make Google Meet default when DWD for google is enabled * Enable feature flagging for DWD * chore: bump libraries * Encrypt serviceaccount private key * Fix ts errors * bump platform libraries * org add dwd * org add dwd * bump platform libraries * fix selected calendars * fix remove selected dwd calendar * remove oauthclient id aliad in authedCalendar * remove oauthclient id aliad in authedCalendar * refactor: OrganizationsDwdController * chore: export toggleDwdEnabled from platform-libraries * feat: v2 update (enable / disable) dwd * refactor: SelectedCalendarsController check if user belongs to dwd org & for not dwd use previous logic * wip: DestinationCalendar send domainWideDelegationCredentialId from frontend to api * try fix set destination calendar api v2 * fixup! try fix set destination calendar api v2 * setting google meet as default location working for dwd * bump platform libraries version * allow office 365 workspace slug * allow office 365 workspace slug * chore: v2 create dwd MS and Google service keys input * fix: CreateDwdInput serviceAccountKey * fix: CredentialForCalendarService type * fix: check workspace slug * feat: update serviceAccessKey of DWD * testing * fixup! testing * fix: getAuthUtl bug * fix: unit tests * fix: type err and unit test * fix: e2e test * fix: credentials bug and failing unit tests * Update CalendarService.ts * chore: refactor office365 calendar service and add testDomainWideDelegationSetup * fix: office365Calendar use correct clientId/Secret for DWD * fix: office365Calendar dwd no need refresh token * test: add unit test for outlook dwd and setup * feat: added dwd support for office365 calendar * feat: added dwd support for office365 video * test: finish test for outlook dwd * fix: create dialog bug * chore: remove console logs * fix: refreshToken bug * bump version libraries * refactor: fetch dwd credentials only in findQualifiedHosts * fixup! refactor: fetch dwd credentials only in findQualifiedHosts * fix: type err * fix: type err * fix: getUserDisplayName * fix: unit test * chore: bump platform lib --------- Co-authored-by: Syed Ali Shahbaz <52925846+alishaz-polymath@users.noreply.github.com> Co-authored-by: Udit Takkar <53316345+Udit-takkar@users.noreply.github.com> Co-authored-by: Udit Takkar <udit222001@gmail.com> Co-authored-by: Morgan Vernay <morgan@cal.com> Co-authored-by: supalarry <laurisskraucis@gmail.com> Co-authored-by: Somay Chauhan <somaychauhan98@gmail.com> Co-authored-by: Morgan <33722304+ThyMinimalDev@users.noreply.github.com>
75 lines
2.6 KiB
TypeScript
75 lines
2.6 KiB
TypeScript
import type { Prisma } from "@prisma/client";
|
|
import { z } from "zod";
|
|
|
|
import { SERVICE_ACCOUNT_ENCRYPTION_KEY } from "@calcom/lib/constants";
|
|
import { symmetricEncrypt, symmetricDecrypt } from "@calcom/lib/crypto";
|
|
import { serviceAccountKeySchema } from "@calcom/prisma/zod-utils";
|
|
|
|
export type ServiceAccountKey = z.infer<typeof serviceAccountKeySchema>;
|
|
export { serviceAccountKeySchema };
|
|
// Schema for encrypted service account key (our storage format)
|
|
export const encryptedServiceAccountKeySchema = z
|
|
.object({
|
|
client_email: z.string().optional(),
|
|
client_id: z.string(),
|
|
encrypted_credentials: z.string(),
|
|
tenant_id: z.string().optional(),
|
|
})
|
|
.passthrough();
|
|
|
|
export type EncryptedServiceAccountKey = z.infer<typeof encryptedServiceAccountKeySchema>;
|
|
|
|
export function encryptServiceAccountKey(serviceAccountKey: ServiceAccountKey): EncryptedServiceAccountKey {
|
|
if (!SERVICE_ACCOUNT_ENCRYPTION_KEY) {
|
|
throw new Error("Service account encryption key is not set");
|
|
}
|
|
|
|
// Extract private_key to encrypt
|
|
const { private_key, ...rest } = serviceAccountKey;
|
|
const sensitiveData = { private_key };
|
|
|
|
// Create a new object with encrypted credentials
|
|
return {
|
|
...rest,
|
|
encrypted_credentials: symmetricEncrypt(JSON.stringify(sensitiveData), SERVICE_ACCOUNT_ENCRYPTION_KEY),
|
|
} as EncryptedServiceAccountKey;
|
|
}
|
|
|
|
export function decryptServiceAccountKey(encryptedServiceAccountKey: Prisma.JsonValue): ServiceAccountKey {
|
|
if (!SERVICE_ACCOUNT_ENCRYPTION_KEY) {
|
|
throw new Error("Service account encryption key is not set");
|
|
}
|
|
try {
|
|
// Parse and validate the encrypted format
|
|
const parsedEncrypted = encryptedServiceAccountKeySchema.safeParse(encryptedServiceAccountKey);
|
|
if (!parsedEncrypted.success) {
|
|
throw new Error(`Invalid service account key format: ${JSON.stringify(parsedEncrypted.error)}`);
|
|
}
|
|
|
|
const { encrypted_credentials, ...rest } = parsedEncrypted.data;
|
|
|
|
// Decrypt and parse the sensitive data
|
|
const decryptedData = JSON.parse(
|
|
symmetricDecrypt(encrypted_credentials, SERVICE_ACCOUNT_ENCRYPTION_KEY)
|
|
) as Record<string, string>;
|
|
|
|
// Reconstruct and validate the decrypted format
|
|
const decrypted = {
|
|
...rest,
|
|
...decryptedData,
|
|
};
|
|
|
|
const parsedDecrypted = serviceAccountKeySchema.safeParse(decrypted);
|
|
if (!parsedDecrypted.success) {
|
|
throw new Error("Invalid decrypted service account key format");
|
|
}
|
|
|
|
return parsedDecrypted.data;
|
|
} catch (error) {
|
|
if (error instanceof Error) {
|
|
throw new Error(`Failed to decrypt service account key: ${error.message}`);
|
|
}
|
|
throw new Error("Failed to decrypt service account key");
|
|
}
|
|
}
|