feat(invites): workspace_invites schema + tRPC router + role management (Task 2, part 1/2)
Schema half of Task-workspace-invites-and-roles. Lands the table, the
invites router (create/list/revoke/accept), and the two new workspaces
procedures (updateMemberRole/removeMember). UI ships in part 2/2.
This is a stable checkpoint for Task 3 (invite-recipient-autocomplete)
to start building against — the procedure surface area is frozen and the
new identity helper from Task 1 is in the accept path.
Schema:
* workspace_invites: id, workspace_id, email (lowercased), role
(owner/admin/member), invited_by_user_id, token (base64url 32B),
expires_at (DEFAULT now() + 14d), accepted_at, revoked_at, created_at.
* Indexes: workspace_id, UNIQUE(token), and a PARTIAL UNIQUE on
(workspace_id, email) WHERE accepted_at IS NULL AND revoked_at IS NULL.
An open invite is unique per (workspace, email); closed invites
(accepted or revoked) fall out of the constraint so re-invites work.
* Drizzle relations wired: workspaceInvites.workspace,
workspaceInvites.invitedBy, workspaces.invites.
* Migration 0006_broad_lethal_legion applied to dev DB.
invites router:
* create({email, role}) on workspaceProcedure (owner/admin only).
Generates a base64url token from 32 random bytes via node:crypto.
Idempotent on (workspace, email) — if an open invite already exists,
returns it instead of inserting (the partial unique would block it
anyway). Refuses self-invite. Refuses if the email is already a
member.
* list() returns pending (non-accepted, non-revoked) invites with
inviter name/email joined for UI display.
* revoke({inviteId}) authorizes against the invite's workspace, not
the caller's input (the inviteId carries its own tenant scope).
* accept({token}) is protectedProcedure (no workspace handle). Calls
userOwnsEmail() from Task 1 — if the caller doesn't own the invited
email under any of their verified identities, throws FORBIDDEN with
a structured cause ({reason: "email_not_owned", invitedEmail}) so
the redeem page can render the "link this email" explainer. Handles
expiry, revoked, already-accepted states with clear messages.
Idempotent on existing membership — if you've already been added by
another flow, accept just closes the invite without re-inserting.
workspaces additions:
* updateMemberRole: admin/owner only. Three guards:
1. Can't change your own role (avoids accidental lockout).
2. Can't demote the only owner-role member (would leave the
membership-level ownership empty even though workspaces.owner_user_id
still points there — see ADR-pragmatic decision documented in the
Task-multi-email-identity convoy discussion).
3. Only owners can promote to owner; admins move people between
admin/member but cannot create a new owner.
* removeMember: admin/owner OR self (the leave-workspace affordance).
Same last-owner guard. Admins can't remove owners (only owners can,
via demote-then-remove).
Wired both new routers into root.ts as `invites` and `identity`
(identity was landed in Task 1; this commit just keeps the registration
visible alongside invites).
All three CI gates green: 0 lint errors, 14 unchanged warnings, 6/6
type-check, 14/14 tests (no new tests yet — apps/web vitest harness is
filed as Task-bootstrap-vitest-for-apps-web P2).
Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
parent
3a657a4aed
commit
7a55d6d1c6
8 changed files with 3321 additions and 1 deletions
|
|
@ -11,6 +11,7 @@ import { typesRouter } from "@/server/routers/types";
|
|||
import { formsRouter } from "@/server/routers/forms";
|
||||
import { favoritesRouter } from "@/server/routers/favorites";
|
||||
import { identityRouter } from "@/server/routers/identity";
|
||||
import { invitesRouter } from "@/server/routers/invites";
|
||||
|
||||
export const appRouter = router({
|
||||
health: healthRouter,
|
||||
|
|
@ -25,6 +26,7 @@ export const appRouter = router({
|
|||
forms: formsRouter,
|
||||
favorites: favoritesRouter,
|
||||
identity: identityRouter,
|
||||
invites: invitesRouter,
|
||||
});
|
||||
|
||||
export type AppRouter = typeof appRouter;
|
||||
|
|
|
|||
345
apps/web/server/routers/invites.ts
Normal file
345
apps/web/server/routers/invites.ts
Normal file
|
|
@ -0,0 +1,345 @@
|
|||
import { randomBytes } from "node:crypto";
|
||||
|
||||
import { TRPCError } from "@trpc/server";
|
||||
import { and, desc, eq, isNull } from "drizzle-orm";
|
||||
import { z } from "zod";
|
||||
|
||||
import { router, protectedProcedure, workspaceProcedure } from "@/server/trpc";
|
||||
import { userOwnsEmail } from "@/server/lib/identity";
|
||||
import {
|
||||
workspaceInvites,
|
||||
workspaceMembers,
|
||||
workspaces,
|
||||
users,
|
||||
} from "@tasks/database/schema";
|
||||
|
||||
/**
|
||||
* Workspace invites. Owners and admins create invites for an email address;
|
||||
* the recipient redeems the opaque `token` at /invite/[token].
|
||||
*
|
||||
* Security model:
|
||||
* - `create`, `list`, `revoke` are workspace-scoped and require the caller
|
||||
* to be `owner` or `admin` on the target workspace.
|
||||
* - `accept` is a *public* procedure (no workspace handle) — the token
|
||||
* itself is the capability. It does require an authenticated session
|
||||
* so we can write the `workspace_members.user_id` row, and it calls
|
||||
* `userOwnsEmail()` from Task 1 to make sure the human accepting the
|
||||
* invite actually controls the invited address under any of their
|
||||
* linked identities. Mismatch returns a structured error so the UI can
|
||||
* show the explainer instead of silently 403-ing.
|
||||
*
|
||||
* Email delivery is not in this task — `create` returns the accept URL so
|
||||
* an operator can copy/paste it. The Resend/Postmark integration is a
|
||||
* follow-up.
|
||||
*/
|
||||
|
||||
const ROLE_VALUES = ["owner", "admin", "member"] as const;
|
||||
const inviteRoleSchema = z.enum(ROLE_VALUES);
|
||||
const inviteEmailSchema = z
|
||||
.string()
|
||||
.trim()
|
||||
.toLowerCase()
|
||||
.pipe(z.string().email({ message: "Please enter a valid email address" }));
|
||||
|
||||
function assertCanManageInvites(role: string): void {
|
||||
if (role !== "owner" && role !== "admin") {
|
||||
throw new TRPCError({
|
||||
code: "FORBIDDEN",
|
||||
message: "Only owners and admins can manage invites",
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
function generateInviteToken(): string {
|
||||
// 32 random bytes -> 43-char base64url. Enough entropy that a token guess
|
||||
// is astronomically improbable; short enough to fit in a copy-paste URL.
|
||||
return randomBytes(32).toString("base64url");
|
||||
}
|
||||
|
||||
function buildAcceptUrl(token: string): string {
|
||||
// `NEXT_PUBLIC_APP_URL` is the canonical origin for invite links. Falls
|
||||
// back to a path-only URL so the procedure still works in environments
|
||||
// without it set (the UI can prefix `window.location.origin` if needed).
|
||||
const base = process.env.NEXT_PUBLIC_APP_URL?.replace(/\/$/, "");
|
||||
return base ? `${base}/invite/${token}` : `/invite/${token}`;
|
||||
}
|
||||
|
||||
export const invitesRouter = router({
|
||||
/**
|
||||
* Create or return-existing an open invite for `email` to the given
|
||||
* workspace. Idempotent on the (workspace_id, lower(email)) pair: if an
|
||||
* open invite already exists for that address, we return it instead of
|
||||
* inserting a duplicate (the partial unique constraint would block it
|
||||
* anyway).
|
||||
*/
|
||||
create: workspaceProcedure
|
||||
.input(
|
||||
z.object({
|
||||
email: inviteEmailSchema,
|
||||
role: inviteRoleSchema,
|
||||
}),
|
||||
)
|
||||
.mutation(async ({ ctx, input }) => {
|
||||
assertCanManageInvites(ctx.workspace.role);
|
||||
|
||||
const inviterId = ctx.session.user.id;
|
||||
|
||||
// Don't let inviters invite themselves — confusing failure mode.
|
||||
const [inviter] = await ctx.db
|
||||
.select({ email: users.email })
|
||||
.from(users)
|
||||
.where(eq(users.id, inviterId))
|
||||
.limit(1);
|
||||
if (inviter?.email.toLowerCase() === input.email) {
|
||||
throw new TRPCError({
|
||||
code: "BAD_REQUEST",
|
||||
message: "You can't invite yourself.",
|
||||
});
|
||||
}
|
||||
|
||||
// Already a member? Surface a clear error so the inviter knows.
|
||||
const [existingMember] = await ctx.db
|
||||
.select({ userId: workspaceMembers.userId })
|
||||
.from(workspaceMembers)
|
||||
.innerJoin(users, eq(users.id, workspaceMembers.userId))
|
||||
.where(
|
||||
and(
|
||||
eq(workspaceMembers.workspaceId, ctx.workspace.id),
|
||||
eq(users.email, input.email),
|
||||
),
|
||||
)
|
||||
.limit(1);
|
||||
if (existingMember) {
|
||||
throw new TRPCError({
|
||||
code: "CONFLICT",
|
||||
message: "This person is already a member of this workspace.",
|
||||
});
|
||||
}
|
||||
|
||||
// Reuse an open invite if one already exists for this (workspace, email).
|
||||
const [existingInvite] = await ctx.db
|
||||
.select()
|
||||
.from(workspaceInvites)
|
||||
.where(
|
||||
and(
|
||||
eq(workspaceInvites.workspaceId, ctx.workspace.id),
|
||||
eq(workspaceInvites.email, input.email),
|
||||
isNull(workspaceInvites.acceptedAt),
|
||||
isNull(workspaceInvites.revokedAt),
|
||||
),
|
||||
)
|
||||
.limit(1);
|
||||
if (existingInvite) {
|
||||
return {
|
||||
invite: existingInvite,
|
||||
acceptUrl: buildAcceptUrl(existingInvite.token),
|
||||
reused: true as const,
|
||||
};
|
||||
}
|
||||
|
||||
const token = generateInviteToken();
|
||||
const [invite] = await ctx.db
|
||||
.insert(workspaceInvites)
|
||||
.values({
|
||||
workspaceId: ctx.workspace.id,
|
||||
email: input.email,
|
||||
role: input.role,
|
||||
invitedByUserId: inviterId,
|
||||
token,
|
||||
})
|
||||
.returning();
|
||||
|
||||
return {
|
||||
invite: invite!,
|
||||
acceptUrl: buildAcceptUrl(invite!.token),
|
||||
reused: false as const,
|
||||
};
|
||||
}),
|
||||
|
||||
/** Pending (non-accepted, non-revoked) invites for the workspace. */
|
||||
list: workspaceProcedure.query(async ({ ctx }) => {
|
||||
assertCanManageInvites(ctx.workspace.role);
|
||||
|
||||
return ctx.db
|
||||
.select({
|
||||
id: workspaceInvites.id,
|
||||
email: workspaceInvites.email,
|
||||
role: workspaceInvites.role,
|
||||
token: workspaceInvites.token,
|
||||
expiresAt: workspaceInvites.expiresAt,
|
||||
createdAt: workspaceInvites.createdAt,
|
||||
invitedByUserId: workspaceInvites.invitedByUserId,
|
||||
invitedByName: users.name,
|
||||
invitedByEmail: users.email,
|
||||
})
|
||||
.from(workspaceInvites)
|
||||
.innerJoin(users, eq(users.id, workspaceInvites.invitedByUserId))
|
||||
.where(
|
||||
and(
|
||||
eq(workspaceInvites.workspaceId, ctx.workspace.id),
|
||||
isNull(workspaceInvites.acceptedAt),
|
||||
isNull(workspaceInvites.revokedAt),
|
||||
),
|
||||
)
|
||||
.orderBy(desc(workspaceInvites.createdAt));
|
||||
}),
|
||||
|
||||
/** Revoke an open invite. Caller must be owner/admin on the invite's workspace. */
|
||||
revoke: protectedProcedure
|
||||
.input(z.object({ inviteId: z.string().uuid() }))
|
||||
.mutation(async ({ ctx, input }) => {
|
||||
const [invite] = await ctx.db
|
||||
.select({
|
||||
id: workspaceInvites.id,
|
||||
workspaceId: workspaceInvites.workspaceId,
|
||||
acceptedAt: workspaceInvites.acceptedAt,
|
||||
revokedAt: workspaceInvites.revokedAt,
|
||||
})
|
||||
.from(workspaceInvites)
|
||||
.where(eq(workspaceInvites.id, input.inviteId))
|
||||
.limit(1);
|
||||
if (!invite) {
|
||||
throw new TRPCError({ code: "NOT_FOUND", message: "Invite not found" });
|
||||
}
|
||||
if (invite.acceptedAt || invite.revokedAt) {
|
||||
throw new TRPCError({
|
||||
code: "BAD_REQUEST",
|
||||
message: "This invite has already been closed.",
|
||||
});
|
||||
}
|
||||
|
||||
// Authorize against the invite's workspace, not via workspaceProcedure
|
||||
// (we don't take a workspace handle in this input; the invite tells us).
|
||||
const callerId = ctx.session.user.id;
|
||||
const [membership] = await ctx.db
|
||||
.select({ role: workspaceMembers.role })
|
||||
.from(workspaceMembers)
|
||||
.where(
|
||||
and(
|
||||
eq(workspaceMembers.workspaceId, invite.workspaceId),
|
||||
eq(workspaceMembers.userId, callerId),
|
||||
),
|
||||
)
|
||||
.limit(1);
|
||||
if (!membership) {
|
||||
throw new TRPCError({ code: "FORBIDDEN" });
|
||||
}
|
||||
assertCanManageInvites(membership.role);
|
||||
|
||||
await ctx.db
|
||||
.update(workspaceInvites)
|
||||
.set({ revokedAt: new Date() })
|
||||
.where(eq(workspaceInvites.id, invite.id));
|
||||
|
||||
return { ok: true as const };
|
||||
}),
|
||||
|
||||
/**
|
||||
* Public-by-token redemption. Caller must be authenticated AND own (under
|
||||
* any linked identity) the email the invite was sent to. On mismatch we
|
||||
* throw a `FORBIDDEN` with a structured `cause` the UI can render as the
|
||||
* "link this email first" explainer.
|
||||
*/
|
||||
accept: protectedProcedure
|
||||
.input(z.object({ token: z.string().min(8).max(128) }))
|
||||
.mutation(async ({ ctx, input }) => {
|
||||
const now = new Date();
|
||||
|
||||
const [invite] = await ctx.db
|
||||
.select({
|
||||
id: workspaceInvites.id,
|
||||
workspaceId: workspaceInvites.workspaceId,
|
||||
email: workspaceInvites.email,
|
||||
role: workspaceInvites.role,
|
||||
acceptedAt: workspaceInvites.acceptedAt,
|
||||
revokedAt: workspaceInvites.revokedAt,
|
||||
expiresAt: workspaceInvites.expiresAt,
|
||||
})
|
||||
.from(workspaceInvites)
|
||||
.where(eq(workspaceInvites.token, input.token))
|
||||
.limit(1);
|
||||
|
||||
if (!invite) {
|
||||
throw new TRPCError({
|
||||
code: "NOT_FOUND",
|
||||
message: "This invite link is not valid.",
|
||||
});
|
||||
}
|
||||
if (invite.revokedAt) {
|
||||
throw new TRPCError({
|
||||
code: "BAD_REQUEST",
|
||||
message: "This invite has been revoked.",
|
||||
});
|
||||
}
|
||||
if (invite.acceptedAt) {
|
||||
throw new TRPCError({
|
||||
code: "BAD_REQUEST",
|
||||
message: "This invite has already been accepted.",
|
||||
});
|
||||
}
|
||||
if (invite.expiresAt.getTime() < now.getTime()) {
|
||||
throw new TRPCError({
|
||||
code: "BAD_REQUEST",
|
||||
message: "This invite has expired.",
|
||||
});
|
||||
}
|
||||
|
||||
const callerId = ctx.session.user.id;
|
||||
|
||||
// Identity check: under Task 1's semantics, the caller must have a
|
||||
// verified identity row matching the invited email. We surface the
|
||||
// mismatch with a structured cause so the redeem page can render the
|
||||
// "link this email to your account first" explainer.
|
||||
const owns = await userOwnsEmail(callerId, invite.email);
|
||||
if (!owns) {
|
||||
throw new TRPCError({
|
||||
code: "FORBIDDEN",
|
||||
message: `This invite was sent to ${invite.email}. Link that email to your account from your profile, then come back to this link.`,
|
||||
cause: { reason: "email_not_owned", invitedEmail: invite.email },
|
||||
});
|
||||
}
|
||||
|
||||
// Already a member? Don't fail — just close the invite. Common when
|
||||
// someone accepts a re-invite after already being added by another flow.
|
||||
const [existingMembership] = await ctx.db
|
||||
.select({ id: workspaceMembers.id })
|
||||
.from(workspaceMembers)
|
||||
.where(
|
||||
and(
|
||||
eq(workspaceMembers.workspaceId, invite.workspaceId),
|
||||
eq(workspaceMembers.userId, callerId),
|
||||
),
|
||||
)
|
||||
.limit(1);
|
||||
if (!existingMembership) {
|
||||
await ctx.db.insert(workspaceMembers).values({
|
||||
workspaceId: invite.workspaceId,
|
||||
userId: callerId,
|
||||
role: invite.role,
|
||||
});
|
||||
}
|
||||
|
||||
await ctx.db
|
||||
.update(workspaceInvites)
|
||||
.set({ acceptedAt: now })
|
||||
.where(eq(workspaceInvites.id, invite.id));
|
||||
|
||||
const [workspace] = await ctx.db
|
||||
.select({ id: workspaces.id, slug: workspaces.slug, name: workspaces.name })
|
||||
.from(workspaces)
|
||||
.where(eq(workspaces.id, invite.workspaceId))
|
||||
.limit(1);
|
||||
|
||||
return {
|
||||
workspace: workspace!,
|
||||
role: invite.role,
|
||||
};
|
||||
}),
|
||||
});
|
||||
|
||||
export type InvitesRouter = typeof invitesRouter;
|
||||
|
||||
// Re-exports used by callers that want to share the schema (e.g. the smart
|
||||
// recipient autocomplete in Task 3).
|
||||
export const inviteRoleValues = ROLE_VALUES;
|
||||
export { inviteRoleSchema };
|
||||
|
|
@ -217,6 +217,161 @@ export const workspacesRouter = router({
|
|||
return updated;
|
||||
}),
|
||||
|
||||
/**
|
||||
* Change a member's role. Admin/owner only. Cannot demote the last owner
|
||||
* (the workspace would lose the ability to manage members).
|
||||
*/
|
||||
updateMemberRole: workspaceProcedure
|
||||
.input(
|
||||
z.object({
|
||||
userId: z.string().uuid(),
|
||||
role: z.enum(["owner", "admin", "member"]),
|
||||
}),
|
||||
)
|
||||
.mutation(async ({ ctx, input }) => {
|
||||
if (ctx.workspace.role !== "owner" && ctx.workspace.role !== "admin") {
|
||||
throw new TRPCError({
|
||||
code: "FORBIDDEN",
|
||||
message: "Only owners and admins can change member roles.",
|
||||
});
|
||||
}
|
||||
if (input.userId === ctx.session.user.id && input.role !== ctx.workspace.role) {
|
||||
throw new TRPCError({
|
||||
code: "BAD_REQUEST",
|
||||
message: "You can't change your own role. Ask another owner or admin.",
|
||||
});
|
||||
}
|
||||
|
||||
const [target] = await ctx.db
|
||||
.select({ role: workspaceMembers.role })
|
||||
.from(workspaceMembers)
|
||||
.where(
|
||||
and(
|
||||
eq(workspaceMembers.workspaceId, ctx.workspace.id),
|
||||
eq(workspaceMembers.userId, input.userId),
|
||||
),
|
||||
)
|
||||
.limit(1);
|
||||
if (!target) {
|
||||
throw new TRPCError({ code: "NOT_FOUND", message: "Member not found." });
|
||||
}
|
||||
|
||||
// Last-owner guard: demoting the only owner-role member to admin/member
|
||||
// would leave the workspace ownerless at the membership layer (even
|
||||
// though `workspaces.owner_user_id` still points at them — see the
|
||||
// ADR-pragmatic decision in Task-multi-email-identity convoy discussion).
|
||||
if (target.role === "owner" && input.role !== "owner") {
|
||||
const ownerCount = await ctx.db
|
||||
.select({ id: workspaceMembers.id })
|
||||
.from(workspaceMembers)
|
||||
.where(
|
||||
and(
|
||||
eq(workspaceMembers.workspaceId, ctx.workspace.id),
|
||||
eq(workspaceMembers.role, "owner"),
|
||||
),
|
||||
);
|
||||
if (ownerCount.length <= 1) {
|
||||
throw new TRPCError({
|
||||
code: "BAD_REQUEST",
|
||||
message: "Can't demote the only owner. Promote someone else first.",
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
// Only owners can promote anyone to owner; admins can move people
|
||||
// between admin/member but cannot create another owner.
|
||||
if (input.role === "owner" && ctx.workspace.role !== "owner") {
|
||||
throw new TRPCError({
|
||||
code: "FORBIDDEN",
|
||||
message: "Only an owner can promote someone to owner.",
|
||||
});
|
||||
}
|
||||
|
||||
await ctx.db
|
||||
.update(workspaceMembers)
|
||||
.set({ role: input.role })
|
||||
.where(
|
||||
and(
|
||||
eq(workspaceMembers.workspaceId, ctx.workspace.id),
|
||||
eq(workspaceMembers.userId, input.userId),
|
||||
),
|
||||
);
|
||||
|
||||
return { ok: true as const };
|
||||
}),
|
||||
|
||||
/**
|
||||
* Remove a member from the workspace. Admin/owner only. Cannot remove the
|
||||
* last owner (same rationale as the demote guard above). Members can
|
||||
* remove themselves — that's the "leave workspace" affordance.
|
||||
*/
|
||||
removeMember: workspaceProcedure
|
||||
.input(z.object({ userId: z.string().uuid() }))
|
||||
.mutation(async ({ ctx, input }) => {
|
||||
const isSelf = input.userId === ctx.session.user.id;
|
||||
const callerCanManage =
|
||||
ctx.workspace.role === "owner" || ctx.workspace.role === "admin";
|
||||
if (!isSelf && !callerCanManage) {
|
||||
throw new TRPCError({
|
||||
code: "FORBIDDEN",
|
||||
message: "Only owners and admins can remove other members.",
|
||||
});
|
||||
}
|
||||
|
||||
const [target] = await ctx.db
|
||||
.select({ role: workspaceMembers.role })
|
||||
.from(workspaceMembers)
|
||||
.where(
|
||||
and(
|
||||
eq(workspaceMembers.workspaceId, ctx.workspace.id),
|
||||
eq(workspaceMembers.userId, input.userId),
|
||||
),
|
||||
)
|
||||
.limit(1);
|
||||
if (!target) {
|
||||
throw new TRPCError({ code: "NOT_FOUND", message: "Member not found." });
|
||||
}
|
||||
|
||||
if (target.role === "owner") {
|
||||
const ownerCount = await ctx.db
|
||||
.select({ id: workspaceMembers.id })
|
||||
.from(workspaceMembers)
|
||||
.where(
|
||||
and(
|
||||
eq(workspaceMembers.workspaceId, ctx.workspace.id),
|
||||
eq(workspaceMembers.role, "owner"),
|
||||
),
|
||||
);
|
||||
if (ownerCount.length <= 1) {
|
||||
throw new TRPCError({
|
||||
code: "BAD_REQUEST",
|
||||
message:
|
||||
"Can't remove the only owner. Promote someone else to owner first.",
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
// Admins cannot remove owners (only owners can de-owner an owner via
|
||||
// updateMemberRole -> removeMember, in that order).
|
||||
if (target.role === "owner" && ctx.workspace.role !== "owner" && !isSelf) {
|
||||
throw new TRPCError({
|
||||
code: "FORBIDDEN",
|
||||
message: "Only an owner can remove another owner.",
|
||||
});
|
||||
}
|
||||
|
||||
await ctx.db
|
||||
.delete(workspaceMembers)
|
||||
.where(
|
||||
and(
|
||||
eq(workspaceMembers.workspaceId, ctx.workspace.id),
|
||||
eq(workspaceMembers.userId, input.userId),
|
||||
),
|
||||
);
|
||||
|
||||
return { ok: true as const };
|
||||
}),
|
||||
|
||||
/** Owner-only soft archive. */
|
||||
archive: workspaceProcedure.mutation(async ({ ctx }) => {
|
||||
if (ctx.workspace.role !== "owner") {
|
||||
|
|
|
|||
18
packages/database/migrations/0006_broad_lethal_legion.sql
Normal file
18
packages/database/migrations/0006_broad_lethal_legion.sql
Normal file
|
|
@ -0,0 +1,18 @@
|
|||
CREATE TABLE "workspace_invites" (
|
||||
"id" uuid PRIMARY KEY DEFAULT gen_random_uuid() NOT NULL,
|
||||
"workspace_id" uuid NOT NULL,
|
||||
"email" varchar(255) NOT NULL,
|
||||
"role" varchar(20) NOT NULL,
|
||||
"invited_by_user_id" uuid NOT NULL,
|
||||
"token" varchar(128) NOT NULL,
|
||||
"expires_at" timestamp with time zone DEFAULT now() + interval '14 days' NOT NULL,
|
||||
"accepted_at" timestamp with time zone,
|
||||
"revoked_at" timestamp with time zone,
|
||||
"created_at" timestamp with time zone DEFAULT now() NOT NULL
|
||||
);
|
||||
--> statement-breakpoint
|
||||
ALTER TABLE "workspace_invites" ADD CONSTRAINT "workspace_invites_workspace_id_workspaces_id_fk" FOREIGN KEY ("workspace_id") REFERENCES "public"."workspaces"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||
ALTER TABLE "workspace_invites" ADD CONSTRAINT "workspace_invites_invited_by_user_id_users_id_fk" FOREIGN KEY ("invited_by_user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||
CREATE INDEX "workspace_invites_workspace_id_idx" ON "workspace_invites" USING btree ("workspace_id");--> statement-breakpoint
|
||||
CREATE UNIQUE INDEX "workspace_invites_token_unique" ON "workspace_invites" USING btree ("token");--> statement-breakpoint
|
||||
CREATE UNIQUE INDEX "workspace_invites_open_email_unique" ON "workspace_invites" USING btree ("workspace_id","email") WHERE "workspace_invites"."accepted_at" IS NULL AND "workspace_invites"."revoked_at" IS NULL;
|
||||
2724
packages/database/migrations/meta/0006_snapshot.json
Normal file
2724
packages/database/migrations/meta/0006_snapshot.json
Normal file
File diff suppressed because it is too large
Load diff
|
|
@ -43,6 +43,13 @@
|
|||
"when": 1780412597413,
|
||||
"tag": "0005_cooing_midnight",
|
||||
"breakpoints": true
|
||||
},
|
||||
{
|
||||
"idx": 6,
|
||||
"version": "7",
|
||||
"when": 1780413875620,
|
||||
"tag": "0006_broad_lethal_legion",
|
||||
"breakpoints": true
|
||||
}
|
||||
]
|
||||
}
|
||||
|
|
@ -16,7 +16,7 @@ import { templates } from "./templates";
|
|||
import { objectTypeDefs } from "./types";
|
||||
import { markdownBacklogItems } from "./markdown_backlog";
|
||||
import { cursorSyncMappings } from "./cursor_sync";
|
||||
import { workspaces } from "./workspaces";
|
||||
import { workspaces, workspaceInvites } from "./workspaces";
|
||||
|
||||
export const objectRelations = pgTable(
|
||||
"object_relations",
|
||||
|
|
@ -65,12 +65,24 @@ export const userEmailIdentitiesRelations = relations(
|
|||
}),
|
||||
);
|
||||
|
||||
export const workspaceInvitesRelations = relations(workspaceInvites, ({ one }) => ({
|
||||
workspace: one(workspaces, {
|
||||
fields: [workspaceInvites.workspaceId],
|
||||
references: [workspaces.id],
|
||||
}),
|
||||
invitedBy: one(users, {
|
||||
fields: [workspaceInvites.invitedByUserId],
|
||||
references: [users.id],
|
||||
}),
|
||||
}));
|
||||
|
||||
export const workspacesRelations = relations(workspaces, ({ one, many }) => ({
|
||||
owner: one(users, {
|
||||
fields: [workspaces.ownerUserId],
|
||||
references: [users.id],
|
||||
}),
|
||||
members: many(workspaceMembers),
|
||||
invites: many(workspaceInvites),
|
||||
objects: many(objects),
|
||||
templates: many(templates),
|
||||
objectTypeDefs: many(objectTypeDefs),
|
||||
|
|
|
|||
|
|
@ -1,3 +1,4 @@
|
|||
import { sql } from "drizzle-orm";
|
||||
import {
|
||||
pgTable,
|
||||
uuid,
|
||||
|
|
@ -34,3 +35,59 @@ export const workspaces = pgTable(
|
|||
ownerIdx: index("workspaces_owner_user_id_idx").on(table.ownerUserId),
|
||||
}),
|
||||
);
|
||||
|
||||
/**
|
||||
* Outstanding workspace invitations. Owners and admins create rows here;
|
||||
* the recipient redeems the `token` (URL-safe, 32+ bytes) at /invite/[token]
|
||||
* to be inserted into `workspace_members`.
|
||||
*
|
||||
* State model:
|
||||
* - `accepted_at` and `revoked_at` are both null while the invite is open.
|
||||
* - Setting `accepted_at` is the success path (also inserts the
|
||||
* `workspace_members` row in the same transaction).
|
||||
* - Setting `revoked_at` is the cancel path (an owner/admin pulled the
|
||||
* invite back; the token will refuse to redeem from that point on).
|
||||
*
|
||||
* Constraint reasoning:
|
||||
* - `token` is globally unique so the redeem endpoint can be a pure
|
||||
* `where token = ?` lookup with no tenant scoping required.
|
||||
* - The partial unique index on `(workspace_id, email) WHERE both
|
||||
* accepted_at AND revoked_at are null` prevents two simultaneous open
|
||||
* invites for the same email/workspace pair. Once an invite is accepted
|
||||
* or revoked it falls out of the constraint, so a future re-invite of
|
||||
* the same email is allowed.
|
||||
* - 14-day default expiry matches the task spec; an operator who needs
|
||||
* custom expiry can override via the procedure layer (not v1).
|
||||
*/
|
||||
export const workspaceInvites = pgTable(
|
||||
"workspace_invites",
|
||||
{
|
||||
id: uuid("id").primaryKey().defaultRandom(),
|
||||
workspaceId: uuid("workspace_id")
|
||||
.notNull()
|
||||
.references(() => workspaces.id, { onDelete: "cascade" }),
|
||||
/** Stored lowercase. Inviter UI should normalize before submit. */
|
||||
email: varchar("email", { length: 255 }).notNull(),
|
||||
/** 'owner' | 'admin' | 'member'. Enforced at the procedure layer via zod. */
|
||||
role: varchar("role", { length: 20 }).notNull(),
|
||||
invitedByUserId: uuid("invited_by_user_id")
|
||||
.notNull()
|
||||
.references(() => users.id, { onDelete: "cascade" }),
|
||||
/** base64url-encoded 32-byte random. ~43 ASCII chars; varchar(128) for slack. */
|
||||
token: varchar("token", { length: 128 }).notNull(),
|
||||
expiresAt: timestamp("expires_at", { withTimezone: true })
|
||||
.notNull()
|
||||
.default(sql`now() + interval '14 days'`),
|
||||
acceptedAt: timestamp("accepted_at", { withTimezone: true }),
|
||||
revokedAt: timestamp("revoked_at", { withTimezone: true }),
|
||||
createdAt: timestamp("created_at", { withTimezone: true }).defaultNow().notNull(),
|
||||
},
|
||||
(table) => ({
|
||||
workspaceIdx: index("workspace_invites_workspace_id_idx").on(table.workspaceId),
|
||||
tokenUnique: uniqueIndex("workspace_invites_token_unique").on(table.token),
|
||||
/** At most one open invite per (workspace, email). Closed invites don't count. */
|
||||
openInviteUnique: uniqueIndex("workspace_invites_open_email_unique")
|
||||
.on(table.workspaceId, table.email)
|
||||
.where(sql`${table.acceptedAt} IS NULL AND ${table.revokedAt} IS NULL`),
|
||||
}),
|
||||
);
|
||||
|
|
|
|||
Loading…
Reference in a new issue