Skip to content

fix(invitations): let Chat invite teammates through the workspace invitations command - #8834

Merged
waleedlatif1 merged 2 commits into
stagingfrom
fix/chat-workspace-invitations
Oct 9, 2026
Merged

waleedlatif1 merged 2 commits into
stagingfrom
fix/chat-workspace-invitations

Conversation

@waleedlatif1

Copy link
Copy Markdown
Collaborator

Summary

  • workspaces invitations create bound a use case with no delegated admission, so every Chat call got 403 This operation is unavailable through Mothership, even though Chat could already send the same invitation through settings workspace … teammates invite
  • The v2 route now binds sendWorkspaceInvitationBatch, the use case the settings tool already uses, through a single workspaceInvitationOperations.sendBatch operation (session, personal key, OAuth api:write and Copilot delegation)
  • Chat runs as the user: workspace admin role, invitations.send permission-group capability, invite policy and delegated-workspace target pinning are the same checks the settings path applies. Workspace API keys stay denied
  • Personal key and OAuth callers keep every check they had, including the per-email locked-transaction rechecks. Session callers on the internal batch route are untouched
  • The teammates settings hint now names workspaces invitations create alongside workspaces members
  • The OpenAPI x-sim-operation id changes to workspace_invitations.send_batch. The CLI contract is unchanged
  • Organization invitation, member and permission-group v2 routes stay direct-caller only. Chat reaches those through settings organization. No v2 workspace route exists yet for adding, removing or updating members, or for cancelling or resending invitations; Chat does those through the settings teammates operations

Type of Change

  • Bug fix

Testing

  • New lib/invitations/__integration__/copilot-workspace-invitations.integration.ts (real Postgres, Chat's in-process CLI transport, real route and domain): a workspace admin invites a new teammate; an email with a pending organization invitation gets the workspace grant added to that invitation, with no second invitation; a member without admin is refused with INSUFFICIENT_WORKSPACE_ROLE. Before the fix both admitted cases returned 403; after it, 3/3 pass
  • send-invitation-batch.test.ts: the personal-key and OAuth admission cases (workspace key denial, read-only OAuth, role, disabled personal keys, permission-group withdrawal mid-batch, locked-transaction rechecks, plan policy) now run against both use cases. New delegated cases cover inviting as the delegating user and a permission group that disables invitations. With the operation's capability removed, that case fails
  • Copilot route inventory snapshot updated
  • bun run lint, bun run type-check, bun run check:audits, root bun run test, docs-manifest:check, block-registry check

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

…itations command

The public `workspaces invitations create` command bound a use case with no
delegated admission, so every Chat call was refused before authorization even
though Chat could already send the same invitation through workspace settings.

The v2 route now binds the workspace invitation use case the settings tool
already uses. Direct callers keep their checks, and a Chat caller passes the
same workspace admin role, permission-group and invite-policy checks as the
user it acts for.
@vercel

vercel Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 9, 2026 3:26am UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 11 files

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/app/api/v2/workspaces/[workspaceId]/invitations/route.ts
@greptile-apps

greptile-apps Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Medium impact] The PR appears safe to merge; no new blocking issue was found.

Summary

Chat can invite teammates through workspaces invitations create, using the workspace invitation use case shared with settings.

  • The operation keeps workspace admin, invitation permission, and caller checks.
  • This revision records the calling operation in invitation audit rows and checks the saved Chat actor in the integration test.
  • The previous mock-argument assertion was removed, addressing the resolved thread.
  • No new actionable issues were found. Tests were not run during this review.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart LR
  Chat[Chat CLI] --> Route[Workspace invitations route]
  API[Personal key or OAuth] --> Route
  Route --> UseCase[sendWorkspaceInvitationBatch]
  Settings[Workspace settings] --> UseCase
  UseCase --> Checks[Check workspace role and invitation permission]
  Checks --> Invite[Create invitation or add workspace grant]
  Invite --> Audit[Save user and operation in audit row]
Loading

Reviews (2) · Last reviewed commit: "fix(invitations): record the invoked ope..." · Reviewed by Greptile

Comment thread apps/sim/lib/invitations/application/send-invitation-batch.test.ts Outdated
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 11 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit 0488311 into staging Oct 9, 2026
47 checks passed
@waleedlatif1
waleedlatif1 deleted the fix/chat-workspace-invitations branch October 9, 2026 03:40

This branch was previously deployed

1 inactive deployment
Preview — 4b58c40f Deployed Oct 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant