Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 11 additions & 1 deletion apps/docs/content/docs/integrations/calcom.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -1136,11 +1136,21 @@ Trigger workflow on any Cal.com webhook event (configure event types in Cal.com)

## OAuth Scopes

Sim requests no OAuth scopes for Cal.com. On a self-hosted deployment, register your own app with the provider using the settings below. See [Integrations & OAuth](/platform/self-hosting/integrations-oauth) for the full setup.
Sim requests these scopes when someone connects a Cal.com account. On a self-hosted deployment, register your own app with the provider using the settings below. See [Integrations & OAuth](/platform/self-hosting/integrations-oauth) for the full setup.

| Setting | Value |
| ------- | ----- |
| Redirect URI | `<NEXT_PUBLIC_APP_URL>/api/auth/oauth2/callback/calcom` |
| Environment variables | `CALCOM_CLIENT_ID` |

| Scope | Description |
| ----- | ----------- |
| `PROFILE_READ` | View your Cal.com profile |
| `BOOKING_READ` | View bookings |
| `BOOKING_WRITE` | Create, edit, and delete bookings |
| `EVENT_TYPE_READ` | View event types |
| `EVENT_TYPE_WRITE` | Create, edit, and delete event types |
| `SCHEDULE_READ` | View availability schedules |
| `SCHEDULE_WRITE` | Create, edit, and delete availability schedules |


1 change: 1 addition & 0 deletions apps/docs/content/docs/integrations/google_groups.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -434,5 +434,6 @@ Sim requests these scopes when someone connects a Google Groups account. On a se
| `https://www.googleapis.com/auth/userinfo.profile` | View basic profile info |
| `https://www.googleapis.com/auth/admin.directory.group` | Manage Google Workspace groups |
| `https://www.googleapis.com/auth/admin.directory.group.member` | Manage Google Workspace group memberships |
| `https://www.googleapis.com/auth/apps.groups.settings` | View and manage Google Workspace group settings |


6 changes: 0 additions & 6 deletions apps/docs/content/docs/integrations/jira.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -2241,13 +2241,7 @@ Sim requests these scopes when someone connects a Jira account. On a self-hosted
| `write:jira-work` | Create, edit, and delete Jira issues, comments, and worklogs |
| `read:me` | Read profile information |
| `offline_access` | Access account when not using the application |
| `read:issue.vote:jira` | Read Jira issue votes |
| `read:user:jira` | View Jira users |
| `delete:issue:jira` | Delete Jira issues |
| `delete:comment:jira` | Delete comments from Jira issues |
| `delete:attachment:jira` | Delete attachments from Jira issues |
| `delete:issue-worklog:jira` | Delete worklog entries from Jira issues |
| `delete:issue-link:jira` | Delete links between Jira issues |
| `read:servicedesk-request` | View service desk requests |
| `write:servicedesk-request` | Create and update service desk requests |
| `manage:servicedesk-customer` | Manage service desk customers and organizations |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1562,13 +1562,7 @@ Sim requests these scopes when someone connects a Jira account. On a self-hosted
| `write:jira-work` | Create, edit, and delete Jira issues, comments, and worklogs |
| `read:me` | Read profile information |
| `offline_access` | Access account when not using the application |
| `read:issue.vote:jira` | Read Jira issue votes |
| `read:user:jira` | View Jira users |
| `delete:issue:jira` | Delete Jira issues |
| `delete:comment:jira` | Delete comments from Jira issues |
| `delete:attachment:jira` | Delete attachments from Jira issues |
| `delete:issue-worklog:jira` | Delete worklog entries from Jira issues |
| `delete:issue-link:jira` | Delete links between Jira issues |
| `read:servicedesk-request` | View service desk requests |
| `write:servicedesk-request` | Create and update service desk requests |
| `manage:servicedesk-customer` | Manage service desk customers and organizations |
Expand Down
8 changes: 4 additions & 4 deletions apps/docs/content/docs/integrations/linear.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -828,7 +828,7 @@ Update an existing label in Linear

### Linear Archive Label

Archive a label in Linear
Archive (retire) a label in Linear. Retired labels stay on existing issues but cannot be applied to new ones.

#### Input

Expand Down Expand Up @@ -2128,19 +2128,19 @@ Update a project status in Linear

### Linear Delete Project Status

Delete a project status in Linear
Archive a project status in Linear. The status must have no active projects and must not be the last status of its type.

#### Input

| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `statusId` | string | Yes | Project status ID to delete |
| `statusId` | string | Yes | Project status ID to archive |

#### Output

| Parameter | Type | Description |
| --------- | ---- | ----------- |
| `success` | boolean | Whether the deletion was successful |
| `success` | boolean | Whether the archive operation was successful |

### Linear List Project Statuses

Expand Down
3 changes: 3 additions & 0 deletions apps/docs/content/docs/integrations/microsoft_excel.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -231,6 +231,9 @@ Sim requests these scopes when someone connects a Microsoft Excel account. On a
| `email` | Access email address |
| `Files.Read` | Read OneDrive files |
| `Files.ReadWrite` | Read and write OneDrive files |
| `Files.Read.All` | Read all files you can access, including SharePoint libraries |
| `Files.ReadWrite.All` | Read and write files you have access to, including SharePoint libraries |
| `Sites.Read.All` | Read documents and list items in all SharePoint sites |
| `offline_access` | Access account when not using the application |


2 changes: 0 additions & 2 deletions apps/docs/content/docs/integrations/microsoft_planner.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -428,8 +428,6 @@ Sim requests these scopes when someone connects a Microsoft Planner account. On
| `openid` | Standard authentication |
| `profile` | Access profile information |
| `email` | Access email address |
| `Group.ReadWrite.All` | Read and write all groups |
| `Group.Read.All` | Read all groups, memberships, and group content |
| `Tasks.ReadWrite` | Read and manage Planner tasks |
| `offline_access` | Access account when not using the application |

Expand Down
3 changes: 1 addition & 2 deletions apps/docs/content/docs/integrations/microsoft_teams.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -526,12 +526,11 @@ Sim requests these scopes when someone connects a Microsoft Teams account. On a
| `ChannelMessage.Read.All` | Read channel messages |
| `ChannelMessage.ReadWrite` | Read and write channel messages |
| `ChannelMember.Read.All` | Read team channel members |
| `Group.Read.All` | Read all groups, memberships, and group content |
| `Group.ReadWrite.All` | Read and write all groups |
| `Team.ReadBasic.All` | Read team names and descriptions |
| `TeamMember.Read.All` | Read team members |
| `offline_access` | Access account when not using the application |
| `Files.Read` | Read OneDrive files |
| `Files.ReadWrite` | Read and write OneDrive files |
| `Sites.Read.All` | Read documents and list items in all SharePoint sites |


4 changes: 0 additions & 4 deletions apps/docs/content/docs/integrations/reddit.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -998,12 +998,8 @@ Sim requests these scopes when someone connects a Reddit account. On a self-host
| `subscribe` | Subscribe and unsubscribe from subreddits |
| `history` | View your voting history and saved or hidden posts |
| `privatemessages` | Access inbox and send private messages |
| `account` | Update account preferences and settings |
| `mysubreddits` | Access subscribed and moderated subreddits |
| `flair` | Select your user flair and change flair on your posts |
| `report` | Report content and hide or show posts |
| `modposts` | Approve, remove, and moderate posts in moderated subreddits |
| `modflair` | Manage flair in moderated subreddits |
| `modmail` | Access and respond to moderator mail |


Original file line number Diff line number Diff line change
Expand Up @@ -80,6 +80,7 @@ meeting:read:list_past_participants:admin
cloud_recording:read:list_user_recordings:admin
cloud_recording:read:list_recording_files:admin
cloud_recording:delete:recording_file:admin
cloud_recording:delete:meeting_recording:admin
```

<Callout type="info">
Expand Down
1 change: 1 addition & 0 deletions apps/docs/content/docs/integrations/zoom.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -631,5 +631,6 @@ Sim requests these scopes when someone connects a Zoom account. On a self-hosted
| `cloud_recording:read:list_user_recordings` | List Zoom cloud recordings |
| `cloud_recording:read:list_recording_files` | View recording files |
| `cloud_recording:delete:recording_file` | Delete individual cloud recording files |
| `cloud_recording:delete:meeting_recording` | Delete all cloud recordings of a meeting |


Original file line number Diff line number Diff line change
Expand Up @@ -271,9 +271,9 @@ Some providers need more setup than a client ID, secret, and redirect URI:
|---|---|
| Asana | Sim requests the `default` scope. Enable **Full permissions** under the app's OAuth settings, or Asana rejects the authorization. |
| Attio | Enable the scopes listed on the [Attio page](/integrations/attio#oauth-scopes) in the app's Developer console; Attio grants scopes from the app, not the authorization request. |
| Cal.com | Sim does not send a `scope` parameter, so connecting works only with a legacy Cal.com OAuth client: one with no scopes configured, or only `READ_BOOKING` and `READ_PROFILE`. Cal.com requires at least one scope on new clients and rejects their authorization without a `scope` parameter. |
| Cal.com | Enable the scopes listed on the [Cal.com page](/integrations/calcom#oauth-scopes) on the OAuth client. Cal.com rejects an authorization that requests a scope the client does not have. |
| DocuSign | `DOCUSIGN_AUTH_HOST` defaults to the demo host `account-d.docusign.com`. Set it to `account.docusign.com` for production accounts. |
| Microsoft | Azure AD, Teams, and Planner request permissions that need tenant admin consent. For Dataverse and Dynamics 365, add the **Dynamics CRM** API's delegated `user_impersonation` permission. |
| Microsoft | Azure AD and Teams request permissions that need tenant admin consent. For Dataverse and Dynamics 365, add the **Dynamics CRM** API's delegated `user_impersonation` permission. |
| Notion | Enable the integration's **Read content**, **Update content**, **Insert content**, **Read comments**, **Insert comments**, and **User information with email addresses** capabilities. |
| Zoho Desk and ManageEngine | Both use one Zoho client. Register both `zoho-desk` and `manageengine-sdp` redirect URIs on it if you use both. |

Expand Down
4 changes: 2 additions & 2 deletions apps/sim/blocks/blocks/linear.ts
Original file line number Diff line number Diff line change
Expand Up @@ -319,7 +319,7 @@ export const LinearBlock: BlockConfig<LinearResponse> = {
{ text: 'Update project status', field: 'projectStatusId', core: true },
],
linear_delete_project_status: [
{ text: 'Delete project status', field: 'projectStatusId', core: true },
{ text: 'Archive project status', field: 'projectStatusId', core: true },
],
linear_list_project_statuses: [
'List project statuses',
Expand Down Expand Up @@ -431,7 +431,7 @@ export const LinearBlock: BlockConfig<LinearResponse> = {
// Project Status Operations
{ label: 'Create Project Status', id: 'linear_create_project_status' },
{ label: 'Update Project Status', id: 'linear_update_project_status' },
{ label: 'Delete Project Status', id: 'linear_delete_project_status' },
{ label: 'Archive Project Status', id: 'linear_delete_project_status' },
{ label: 'List Project Statuses', id: 'linear_list_project_statuses' },
],
value: () => 'linear_read_issues',
Expand Down
2 changes: 1 addition & 1 deletion apps/sim/lib/auth/connectors/managed-oauth.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -291,7 +291,7 @@ describe('userinfo-backed managed OAuth connectors', () => {
})
})

it.each(['notion', 'clickup', 'calcom'])(
it.each(['notion', 'clickup'])(
'declares %s scopeless so an empty scope policy is not read as a misconfiguration',
(providerId) => {
expect(policyFor(providerId).scopeless).toBe(true)
Expand Down
4 changes: 1 addition & 3 deletions apps/sim/lib/auth/connectors/managed-oauth.ts
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,7 @@ export interface ManagedOAuthConnectorConfig {
requiresRefreshToken: boolean
pkce: boolean
/**
* Set when the provider takes no scopes at all (Notion, ClickUp, Cal.com all authorize with an
* Set when the provider takes no scopes at all (Notion and ClickUp both authorize with an
* empty scope list). Without it the empty scope policy is indistinguishable from a
* misconfigured connector, which is what the policy guard exists to catch.
*/
Expand Down Expand Up @@ -940,8 +940,6 @@ const USER_INFO_MANAGED_OAUTH_CONNECTORS = new Map<string, () => ManagedOAuthCon
() =>
createUserInfoManagedOAuthConnector({
providerId: 'calcom',
/** Cal.com's OAuth app authorizes without a scope list. */
scopeless: true,
pkce: true,
requiresRefreshToken: true,
scopes: { from: 'token_response' },
Expand Down
2 changes: 1 addition & 1 deletion apps/sim/lib/auth/connectors/providers.ts
Original file line number Diff line number Diff line change
Expand Up @@ -2798,7 +2798,7 @@ export function buildConnectorProviders(): GenericOAuthConfig[] {
providerId: 'calcom',
clientId: env.CALCOM_CLIENT_ID as string,
authorizationUrl: 'https://app.cal.com/auth/oauth2/authorize',
tokenUrl: 'https://app.cal.com/api/auth/oauth/token',
tokenUrl: 'https://api.cal.com/v2/auth/oauth2/token',
scopes: getCanonicalScopesForProvider('calcom'),
responseType: 'code',
pkce: true,
Expand Down
8 changes: 4 additions & 4 deletions apps/sim/lib/oauth/oauth.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -388,7 +388,7 @@ describe('OAuth Token Refresh', () => {
expect(bodyParams.get('client_id')).toBeNull()
})

it.concurrent('should preserve Cal.com bearer refresh authentication', async () => {
it.concurrent('should send the Cal.com refresh token in the v2 request body', async () => {
const mockFetch = createMockFetch(defaultOAuthResponse)
const refreshToken = 'test_refresh_token'

Expand All @@ -400,12 +400,12 @@ describe('OAuth Token Refresh', () => {
]
const bodyParams = new URLSearchParams(requestOptions.body)

expect(endpoint).toBe('https://app.cal.com/api/auth/oauth/refreshToken')
expect(requestOptions.headers.Authorization).toBe(`Bearer ${refreshToken}`)
expect(endpoint).toBe('https://api.cal.com/v2/auth/oauth2/token')
expect(requestOptions.headers.Authorization).toBeUndefined()
expect(bodyParams.get('grant_type')).toBe('refresh_token')
expect(bodyParams.get('client_id')).toBe('calcom_client_id')
expect(bodyParams.get('client_secret')).toBeNull()
expect(bodyParams.get('refresh_token')).toBeNull()
expect(bodyParams.get('refresh_token')).toBe(refreshToken)
})

it.concurrent('should send Notion request with Basic Auth header and JSON body', async () => {
Expand Down
Loading
Loading