2021-12-21 00:59:06 +00:00
|
|
|
import { MembershipRole } from "@prisma/client";
|
2021-09-22 19:52:38 +00:00
|
|
|
import { randomBytes } from "crypto";
|
2021-08-19 12:27:01 +00:00
|
|
|
import type { NextApiRequest, NextApiResponse } from "next";
|
2021-09-22 19:52:38 +00:00
|
|
|
|
2022-06-06 17:49:56 +00:00
|
|
|
import { sendTeamInviteEmail } from "@calcom/emails";
|
|
|
|
|
2021-09-03 20:51:21 +00:00
|
|
|
import { getSession } from "@lib/auth";
|
2021-11-26 11:03:43 +00:00
|
|
|
import { BASE_URL } from "@lib/config/constants";
|
2021-10-25 13:05:21 +00:00
|
|
|
import prisma from "@lib/prisma";
|
2021-12-21 00:59:06 +00:00
|
|
|
import slugify from "@lib/slugify";
|
2021-09-22 19:52:38 +00:00
|
|
|
|
2021-10-25 13:05:21 +00:00
|
|
|
import { getTranslation } from "@server/lib/i18n";
|
2021-06-05 22:53:33 +00:00
|
|
|
|
|
|
|
export default async function handler(req: NextApiRequest, res: NextApiResponse) {
|
2021-10-25 13:05:21 +00:00
|
|
|
const t = await getTranslation(req.body.language ?? "en", "common");
|
|
|
|
|
2021-06-05 22:53:33 +00:00
|
|
|
if (req.method !== "POST") {
|
|
|
|
return res.status(400).json({ message: "Bad request" });
|
|
|
|
}
|
|
|
|
|
2021-12-21 00:59:06 +00:00
|
|
|
const session = await getSession({ req });
|
2021-06-05 22:53:33 +00:00
|
|
|
if (!session) {
|
2021-08-19 12:27:01 +00:00
|
|
|
return res.status(401).json({ message: "Not authenticated" });
|
2021-06-05 22:53:33 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
const team = await prisma.team.findFirst({
|
|
|
|
where: {
|
2021-10-25 13:05:21 +00:00
|
|
|
id: parseInt(req.query.team as string),
|
2021-08-19 12:27:01 +00:00
|
|
|
},
|
2021-06-05 22:53:33 +00:00
|
|
|
});
|
|
|
|
|
|
|
|
if (!team) {
|
2021-08-19 12:27:01 +00:00
|
|
|
return res.status(404).json({ message: "Invalid team" });
|
2021-06-05 22:53:33 +00:00
|
|
|
}
|
|
|
|
|
2021-12-21 00:59:06 +00:00
|
|
|
const reqBody = req.body as {
|
|
|
|
usernameOrEmail: string;
|
|
|
|
role: MembershipRole;
|
|
|
|
sendEmailInvitation: boolean;
|
|
|
|
};
|
|
|
|
const { role, sendEmailInvitation } = reqBody;
|
|
|
|
// liberal email match
|
|
|
|
const isEmail = (str: string) => /^[^\s@]+@[^\s@]+\.[^\s@]+$/.test(str);
|
|
|
|
const usernameOrEmail = isEmail(reqBody.usernameOrEmail)
|
|
|
|
? reqBody.usernameOrEmail.toLowerCase()
|
|
|
|
: slugify(reqBody.usernameOrEmail);
|
|
|
|
|
2021-06-05 22:53:33 +00:00
|
|
|
const invitee = await prisma.user.findFirst({
|
|
|
|
where: {
|
2021-12-21 00:59:06 +00:00
|
|
|
OR: [{ username: usernameOrEmail }, { email: usernameOrEmail }],
|
2021-08-19 12:27:01 +00:00
|
|
|
},
|
2021-06-05 22:53:33 +00:00
|
|
|
});
|
|
|
|
|
|
|
|
if (!invitee) {
|
2022-01-26 15:51:15 +00:00
|
|
|
const email = isEmail(usernameOrEmail) ? usernameOrEmail : undefined;
|
|
|
|
if (!email) {
|
2021-06-09 21:29:31 +00:00
|
|
|
return res.status(400).json({
|
2021-12-21 00:59:06 +00:00
|
|
|
message: `Invite failed because there is no corresponding user for ${usernameOrEmail}`,
|
2021-06-09 21:29:31 +00:00
|
|
|
});
|
|
|
|
}
|
2021-12-21 00:59:06 +00:00
|
|
|
await prisma.user.create({
|
|
|
|
data: {
|
2022-01-26 15:51:15 +00:00
|
|
|
email,
|
2021-12-21 00:59:06 +00:00
|
|
|
teams: {
|
|
|
|
create: {
|
|
|
|
team: {
|
|
|
|
connect: {
|
|
|
|
id: parseInt(req.query.team as string),
|
|
|
|
},
|
|
|
|
},
|
|
|
|
role,
|
2021-06-09 21:29:31 +00:00
|
|
|
},
|
2021-12-21 00:59:06 +00:00
|
|
|
},
|
|
|
|
},
|
|
|
|
});
|
2021-06-09 21:29:31 +00:00
|
|
|
|
|
|
|
const token: string = randomBytes(32).toString("hex");
|
|
|
|
|
2022-04-21 20:32:25 +00:00
|
|
|
await prisma.verificationToken.create({
|
2021-06-09 21:29:31 +00:00
|
|
|
data: {
|
2021-12-21 00:59:06 +00:00
|
|
|
identifier: usernameOrEmail,
|
2021-06-09 21:29:31 +00:00
|
|
|
token,
|
2021-08-19 12:27:01 +00:00
|
|
|
expires: new Date(new Date().setHours(168)), // +1 week
|
|
|
|
},
|
2021-06-09 21:29:31 +00:00
|
|
|
});
|
|
|
|
|
2021-10-25 13:05:21 +00:00
|
|
|
if (session?.user?.name && team?.name) {
|
2022-06-06 18:59:57 +00:00
|
|
|
await sendTeamInviteEmail({
|
2021-10-25 13:05:21 +00:00
|
|
|
language: t,
|
|
|
|
from: session.user.name,
|
2021-12-21 00:59:06 +00:00
|
|
|
to: usernameOrEmail,
|
2021-10-25 13:05:21 +00:00
|
|
|
teamName: team.name,
|
2022-06-06 08:37:53 +00:00
|
|
|
joinLink: `${BASE_URL}/auth/signup?token=${token}&callbackUrl=/settings/teams}`,
|
2022-06-06 18:59:57 +00:00
|
|
|
});
|
2021-10-25 13:05:21 +00:00
|
|
|
}
|
2021-06-09 21:29:31 +00:00
|
|
|
|
|
|
|
return res.status(201).json({});
|
2021-06-05 22:53:33 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// create provisional membership
|
2021-06-07 15:12:00 +00:00
|
|
|
try {
|
2021-08-19 12:27:01 +00:00
|
|
|
await prisma.membership.create({
|
2021-06-07 15:12:00 +00:00
|
|
|
data: {
|
2021-08-19 12:27:01 +00:00
|
|
|
teamId: parseInt(req.query.team as string),
|
2021-06-07 15:12:00 +00:00
|
|
|
userId: invitee.id,
|
2021-12-21 00:59:06 +00:00
|
|
|
role,
|
2021-06-07 15:12:00 +00:00
|
|
|
},
|
|
|
|
});
|
2021-10-25 13:05:21 +00:00
|
|
|
} catch (err: any) {
|
2021-08-19 12:27:01 +00:00
|
|
|
if (err.code === "P2002") {
|
|
|
|
// unique constraint violation
|
2021-06-07 15:12:00 +00:00
|
|
|
return res.status(409).json({
|
2021-08-19 12:27:01 +00:00
|
|
|
message: "This user is a member of this team / has a pending invitation.",
|
2021-06-07 15:12:00 +00:00
|
|
|
});
|
|
|
|
} else {
|
|
|
|
throw err; // rethrow
|
|
|
|
}
|
2021-08-19 12:27:01 +00:00
|
|
|
}
|
2021-06-05 22:53:33 +00:00
|
|
|
|
|
|
|
// inform user of membership by email
|
2021-12-21 00:59:06 +00:00
|
|
|
if (sendEmailInvitation && session?.user?.name && team?.name) {
|
2022-06-06 18:59:57 +00:00
|
|
|
await sendTeamInviteEmail({
|
2021-10-25 13:05:21 +00:00
|
|
|
language: t,
|
2021-06-05 22:53:33 +00:00
|
|
|
from: session.user.name,
|
2021-12-21 00:59:06 +00:00
|
|
|
to: usernameOrEmail,
|
2021-08-19 12:27:01 +00:00
|
|
|
teamName: team.name,
|
2021-11-26 11:03:43 +00:00
|
|
|
joinLink: BASE_URL + "/settings/teams",
|
2022-06-06 18:59:57 +00:00
|
|
|
});
|
2021-06-05 22:53:33 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
res.status(201).json({});
|
|
|
|
}
|