Prevent expired invitations from silently failing and blocking future re-invites - #805
Merged
JoseSzycho merged 4 commits intoSep 25, 2026
Conversation
…ecks to allow re-invites
…te regression scenarios
4 tasks
…nvitation in race condition
JoseSzycho
enabled auto-merge
September 24, 2026 16:28
Contributor
Author
|
up! |
…n-blocks-the-person-forever
Contributor
Author
|
@mattdjenkinson I see you updated the branch against main. The e2e tests are green ! 🚀 |
mattdjenkinson
approved these changes
Sep 25, 2026
JoseSzycho
deleted the
802-an-expired-invitation-silently-fails-then-blocks-the-person-forever
branch
September 25, 2026 15:03
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this changes
When someone lets a join invitation to an organization lapse, two things used to go wrong — and both could leave a person stuck in a situation they couldn't fix on their own:
Accepting a late invitation looked like it worked, but did nothing. If a person tried to accept an invitation after it had expired, the system recorded the acceptance without ever making them a member, and didn't tell them anything was wrong. They believed they had joined the organization, but they hadn't. The invitation just sat there as a dead record.
A dead invitation could block future invitations forever. Because any existing invitation — expired, declined, or otherwise finished — counted as a duplicate, an organization that wanted to invite the same person again was told "Duplicate value" and couldn't. One lapsed invitation could block a re-invite for good.
Why the bugs were there
Both symptoms came from the invite flow trusting an invitation's recorded state and never double-checking whether the invitation was still actually valid at the moment it was used:
On acceptance, the system recorded the state without confirming the invitation was still live. When the invitation had already lapsed, the acceptance was recorded but the membership was never granted — silently.
On re-invite, the duplicate check treated any existing invitation as a conflict, whether or not it was still live and pending. A rule meant to stop someone from being double-invited at the same time was also blocking legitimate fresh invitations once an older one had finished its life.
What we changed
What else we improved
Outcome
No scenario leaves a person unable to join an organization. If an invitation lapses, the person gets a clear reason and the organization can simply invite them again. If an invitation is live, the person can accept it and become a member, exactly as they expect.
Closes #802