* fix: remove @calcom/web imports from packages/features to eliminate circular dependency - Migrate UserTableUser and MemberPermissions types to packages/features/users/types/user-table.ts - Migrate useGeo hook to packages/features/geo/GeoContext.tsx - Migrate buildLegacyRequest to packages/lib/buildLegacyCtx.ts - Migrate Calendar component to packages/features/calendars/weeklyview/components/ - Move test utilities (bookingScenario, fixtures) to packages/features/test/ - Update all imports in packages/features to use new locations - Add re-exports in apps/web for backward compatibility Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: delete original implementation files and fix type issues - Delete original calendar component files in apps/web (keep only re-export stubs) - Migrate OutOfOfficeInSlots to packages/features/bookings/components - Convert apps/web OutOfOfficeInSlots to re-export stub - Fix className vs class issue in Calendar.tsx - Fix @calcom/trpc import violation in user-table.ts by using structural type Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: add missing isGroup and contains fields to UserTableUser attributes type Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: update customRole type to match actual Prisma Role model Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix build * fix * fix * cleanup weeklyview * fix * refactor to mv MemberPermissions to types package * add types dependency to features * fix * fix * fix * fix * fix * fix * rename * rename * migrate * migrate * migrate * fix * fix * fix * refactor: move test utilities from packages/features/test to tests/libs - Move bookingScenario utilities to tests/libs/bookingScenario - Move fixtures to tests/libs/fixtures - Update all imports in packages/features test files to use new location - Update all imports in apps/web test files to use new location - Eliminates duplication of test utilities between packages/features and apps/web Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: correct relative import paths for tests/libs in test files Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * refactor: replace test utility implementations with re-exports to tests/libs Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: fix test import paths and move signup handler tests to apps/web Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: move buildLegacyCtx to packages/lib and restore handlers to packages/features - Move buildLegacyCtx from apps/web/lib to packages/lib to break circular dependency - Update apps/web/lib/buildLegacyCtx.ts to re-export from @calcom/lib - Restore signup handlers and tests to packages/features/auth/signup/handlers - Update handler imports to use @calcom/lib/buildLegacyCtx instead of @calcom/web/lib/buildLegacyCtx Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: update recurring-event.test.ts imports to use tests/libs path Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * refactor: delete test re-export files and update imports to use tests/libs directly Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: update remaining test imports to use tests/libs directly Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: update handleRecurringEventBooking calls to match function signature (1 arg) Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * remove * migrate tests * migrate tests * refactor: update test mock imports by removing and using async for mock creators. * fix type errors * fix: add type assertion for MockUser in p2002.test-suite.ts Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: restore locale import in compareReminderBodyToTemplate.test.ts using relative path Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * feat: create @calcom/testing package and migrate tests from /tests directory - Created new @calcom/testing package in /packages/testing - Moved all files from /tests to /packages/testing - Updated all imports across the codebase to use @calcom/testing alias - Removed /tests directory at root level This allows other packages like @calcom/features and @calcom/web to import testing utilities using the @calcom/testing alias instead of relative paths. Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix * fix * fix: add missing useBookings export to @calcom/atoms package Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: add missing useCalendarsBusyTimes and useConnectedCalendars exports to @calcom/atoms Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * chore: add @calcom/testing as explicit devDependency to packages that use it Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * refactor: move setupVitest.ts into @calcom/testing package Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix * chore: add biome rules to restrict @calcom/testing imports Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix * rename libs to lib * rename libs to lib * add rule * add rule * refactor: remove @calcom/features imports from @calcom/testing - Move mockPaymentSuccessWebhookFromStripe to fresh-booking.test.ts - Replace ProfileRepository.generateProfileUid() with uuidv4() - Clone Tracking type into @calcom/testing/src/lib/types.ts - Update imports in expects.ts and getMockRequestDataForBooking.ts - Move source files into src/ folder - Move CalendarManager mock to @calcom/features Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * fix: add explicit exports for nested paths in @calcom/testing Co-Authored-By: benny@cal.com <sldisek783@gmail.com> * improve * improve * fix * fix * fix type checks * fix type checks * fix type checks * fix tests --------- Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
312 lines
9.9 KiB
TypeScript
312 lines
9.9 KiB
TypeScript
import { cookies, headers } from "next/headers";
|
|
import { NextResponse } from "next/server";
|
|
|
|
import { getPremiumMonthlyPlanPriceId } from "@calcom/app-store/stripepayment/lib/utils";
|
|
import { getLocaleFromRequest } from "@calcom/features/auth/lib/getLocaleFromRequest";
|
|
import { sendEmailVerification } from "@calcom/features/auth/lib/verifyEmail";
|
|
import { createOrUpdateMemberships } from "@calcom/features/auth/signup/utils/createOrUpdateMemberships";
|
|
import { prefillAvatar } from "@calcom/features/auth/signup/utils/prefillAvatar";
|
|
import { validateAndGetCorrectedUsernameAndEmail } from "@calcom/features/auth/signup/utils/validateUsername";
|
|
import { getBillingProviderService } from "@calcom/features/ee/billing/di/containers/Billing";
|
|
import { sentrySpan } from "@calcom/features/watchlist/lib/telemetry";
|
|
import { checkIfEmailIsBlockedInWatchlistController } from "@calcom/features/watchlist/operations/check-if-email-in-watchlist.controller";
|
|
import { hashPassword } from "@calcom/lib/auth/hashPassword";
|
|
import { WEBAPP_URL } from "@calcom/lib/constants";
|
|
import { HttpError } from "@calcom/lib/http-error";
|
|
import logger from "@calcom/lib/logger";
|
|
import { isPrismaError } from "@calcom/lib/server/getServerErrorFromUnknown";
|
|
import type { CustomNextApiHandler } from "@calcom/lib/server/username";
|
|
import { usernameHandler } from "@calcom/lib/server/username";
|
|
import { getTrackingFromCookies } from "@calcom/lib/tracking";
|
|
import prisma from "@calcom/prisma";
|
|
import { CreationSource } from "@calcom/prisma/enums";
|
|
import { IdentityProvider } from "@calcom/prisma/enums";
|
|
import { signupSchema } from "@calcom/prisma/zod-utils";
|
|
import { buildLegacyRequest } from "@calcom/web/lib/buildLegacyCtx";
|
|
|
|
import { joinAnyChildTeamOnOrgInvite } from "@calcom/features/auth/signup/utils/organization";
|
|
import { SIGNUP_ERROR_CODES } from "@calcom/features/auth/signup/constants";
|
|
|
|
import {
|
|
findTokenByToken,
|
|
throwIfTokenExpired,
|
|
validateAndGetCorrectedUsernameForTeam,
|
|
} from "@calcom/features/auth/signup/utils/token";
|
|
|
|
const log = logger.getSubLogger({ prefix: ["signupCalcomHandler"] });
|
|
|
|
const handler: CustomNextApiHandler = async (body, usernameStatus) => {
|
|
const {
|
|
email: _email,
|
|
password,
|
|
token,
|
|
} = signupSchema
|
|
.pick({
|
|
email: true,
|
|
password: true,
|
|
token: true,
|
|
})
|
|
.parse(body);
|
|
|
|
const billingService = getBillingProviderService();
|
|
|
|
const shouldLockByDefault = await checkIfEmailIsBlockedInWatchlistController({
|
|
email: _email,
|
|
organizationId: null,
|
|
span: sentrySpan,
|
|
});
|
|
|
|
log.debug("handler", { email: _email });
|
|
|
|
let username: string | null = usernameStatus.requestedUserName;
|
|
let checkoutSessionId: string | null = null;
|
|
|
|
// Check for premium username
|
|
if (usernameStatus.statusCode === 418) {
|
|
return NextResponse.json(usernameStatus.json, { status: 418 });
|
|
}
|
|
|
|
// Validate the user
|
|
if (!username) {
|
|
throw new HttpError({
|
|
statusCode: 422,
|
|
message: "Invalid username",
|
|
});
|
|
}
|
|
|
|
const email = _email.toLowerCase();
|
|
|
|
let foundToken: { id: number; teamId: number | null; expires: Date } | null = null;
|
|
if (token) {
|
|
foundToken = await findTokenByToken({ token });
|
|
throwIfTokenExpired(foundToken?.expires);
|
|
username = await validateAndGetCorrectedUsernameForTeam({
|
|
username,
|
|
email,
|
|
teamId: foundToken?.teamId ?? null,
|
|
isSignup: true,
|
|
});
|
|
|
|
if (foundToken?.teamId) {
|
|
const existingUser = await prisma.user.findUnique({
|
|
where: { email },
|
|
select: { invitedTo: true },
|
|
});
|
|
if (existingUser && existingUser.invitedTo !== foundToken.teamId) {
|
|
return NextResponse.json({ message: SIGNUP_ERROR_CODES.USER_ALREADY_EXISTS }, { status: 409 });
|
|
}
|
|
}
|
|
} else {
|
|
const usernameAndEmailValidation = await validateAndGetCorrectedUsernameAndEmail({
|
|
username,
|
|
email,
|
|
isSignup: true,
|
|
});
|
|
if (!usernameAndEmailValidation.isValid) {
|
|
throw new HttpError({
|
|
statusCode: 409,
|
|
message: "Username or email is already taken",
|
|
});
|
|
}
|
|
|
|
if (!usernameAndEmailValidation.username) {
|
|
throw new HttpError({
|
|
statusCode: 422,
|
|
message: "Invalid username",
|
|
});
|
|
}
|
|
|
|
username = usernameAndEmailValidation.username;
|
|
}
|
|
|
|
// Create the customer in Stripe with ad tracking metadata
|
|
const cookieStore = await cookies();
|
|
const cookiesObj = Object.fromEntries(cookieStore.getAll().map((c) => [c.name, c.value]));
|
|
const tracking = getTrackingFromCookies(cookiesObj);
|
|
|
|
const customer = await billingService.createCustomer({
|
|
email,
|
|
metadata: {
|
|
email /* Stripe customer email can be changed, so we add this to keep track of which email was used to signup */,
|
|
username,
|
|
...(tracking.googleAds?.gclid && {
|
|
gclid: tracking.googleAds.gclid,
|
|
campaignId: tracking.googleAds.campaignId,
|
|
}),
|
|
...(tracking.linkedInAds?.liFatId && {
|
|
liFatId: tracking.linkedInAds.liFatId,
|
|
linkedInCampaignId: tracking.linkedInAds.campaignId,
|
|
}),
|
|
},
|
|
});
|
|
|
|
const returnUrl = `${WEBAPP_URL}/api/integrations/stripepayment/paymentCallback?checkoutSessionId={CHECKOUT_SESSION_ID}&callbackUrl=/auth/verify?sessionId={CHECKOUT_SESSION_ID}`;
|
|
|
|
// Pro username, must be purchased
|
|
if (usernameStatus.statusCode === 402) {
|
|
const checkoutSession = await billingService.createSubscriptionCheckout({
|
|
mode: "subscription",
|
|
customerId: customer.stripeCustomerId,
|
|
successUrl: returnUrl,
|
|
cancelUrl: returnUrl,
|
|
priceId: getPremiumMonthlyPlanPriceId(),
|
|
quantity: 1,
|
|
allowPromotionCodes: true,
|
|
});
|
|
|
|
/** We create a username-less user until he pays */
|
|
checkoutSessionId = checkoutSession.sessionId;
|
|
username = null;
|
|
}
|
|
|
|
// Hash the password
|
|
const hashedPassword = await hashPassword(password);
|
|
|
|
if (foundToken && foundToken?.teamId) {
|
|
const team = await prisma.team.findUnique({
|
|
where: {
|
|
id: foundToken.teamId,
|
|
},
|
|
include: {
|
|
parent: {
|
|
select: {
|
|
id: true,
|
|
slug: true,
|
|
organizationSettings: true,
|
|
},
|
|
},
|
|
organizationSettings: true,
|
|
},
|
|
});
|
|
if (team) {
|
|
const organizationId = team.isOrganization ? team.id : team.parent?.id ?? null;
|
|
|
|
if (username) {
|
|
const existingUserByUsername = await prisma.user.findFirst({
|
|
where: {
|
|
username,
|
|
organizationId,
|
|
NOT: { email },
|
|
},
|
|
select: { id: true },
|
|
});
|
|
if (existingUserByUsername) {
|
|
return NextResponse.json({ message: SIGNUP_ERROR_CODES.USER_ALREADY_EXISTS }, { status: 409 });
|
|
}
|
|
}
|
|
|
|
let user: { id: number };
|
|
try {
|
|
user = await prisma.user.upsert({
|
|
where: { email },
|
|
update: {
|
|
username,
|
|
emailVerified: new Date(Date.now()),
|
|
identityProvider: IdentityProvider.CAL,
|
|
password: {
|
|
upsert: {
|
|
create: { hash: hashedPassword },
|
|
update: { hash: hashedPassword },
|
|
},
|
|
},
|
|
organizationId,
|
|
},
|
|
create: {
|
|
username,
|
|
email,
|
|
emailVerified: new Date(Date.now()),
|
|
identityProvider: IdentityProvider.CAL,
|
|
password: { create: { hash: hashedPassword } },
|
|
organizationId,
|
|
},
|
|
select: { id: true },
|
|
});
|
|
} catch (error) {
|
|
if (isPrismaError(error) && error.code === "P2002") {
|
|
const target = String(error.meta?.target ?? "");
|
|
if (target.includes("email") || target.includes("username")) {
|
|
return NextResponse.json({ message: SIGNUP_ERROR_CODES.USER_ALREADY_EXISTS }, { status: 409 });
|
|
}
|
|
}
|
|
throw error;
|
|
}
|
|
|
|
await createOrUpdateMemberships({
|
|
user,
|
|
team,
|
|
});
|
|
|
|
// Accept any child team invites for orgs.
|
|
if (team.parent) {
|
|
await joinAnyChildTeamOnOrgInvite({
|
|
userId: user.id,
|
|
org: team.parent,
|
|
});
|
|
}
|
|
}
|
|
|
|
// Cleanup token after use
|
|
await prisma.verificationToken.delete({
|
|
where: {
|
|
id: foundToken.id,
|
|
},
|
|
});
|
|
} else {
|
|
// Create the user
|
|
try {
|
|
await prisma.user.create({
|
|
data: {
|
|
username,
|
|
email,
|
|
locked: shouldLockByDefault,
|
|
password: { create: { hash: hashedPassword } },
|
|
metadata: {
|
|
stripeCustomerId: customer.stripeCustomerId,
|
|
checkoutSessionId,
|
|
},
|
|
creationSource: CreationSource.WEBAPP,
|
|
},
|
|
});
|
|
} catch (error) {
|
|
// Fallback for race conditions where user was created between our check and create
|
|
if (isPrismaError(error) && error.code === "P2002") {
|
|
const target = String(error.meta?.target ?? "");
|
|
if (target.includes("email") || target.includes("username")) {
|
|
return NextResponse.json(
|
|
{ message: SIGNUP_ERROR_CODES.USER_ALREADY_EXISTS },
|
|
{ status: 409 }
|
|
);
|
|
}
|
|
}
|
|
throw error;
|
|
}
|
|
if (process.env.AVATARAPI_USERNAME && process.env.AVATARAPI_PASSWORD) {
|
|
await prefillAvatar({ email });
|
|
}
|
|
// Only send verification email for non-premium usernames
|
|
// Premium usernames will get a magic link after payment in paymentCallback
|
|
if (!checkoutSessionId) {
|
|
sendEmailVerification({
|
|
email,
|
|
language: await getLocaleFromRequest(buildLegacyRequest(await headers(), await cookies())),
|
|
username: username || "",
|
|
});
|
|
}
|
|
}
|
|
|
|
if (checkoutSessionId) {
|
|
console.log("Created user but missing payment", checkoutSessionId);
|
|
return NextResponse.json(
|
|
{ message: "Created user but missing payment", checkoutSessionId },
|
|
{ status: 402 }
|
|
);
|
|
}
|
|
|
|
return NextResponse.json(
|
|
{ message: "Created user", stripeCustomerId: customer.stripeCustomerId },
|
|
{ status: 201 }
|
|
);
|
|
};
|
|
|
|
export default usernameHandler(handler);
|