Compare commits

..

1 Commits

Author SHA1 Message Date
Gregor Vostrak
bf2798c0f4 fix invitations not being respected during signup when email case differs 2026-07-23 20:01:32 +02:00
2 changed files with 39 additions and 1 deletions

View File

@@ -23,6 +23,10 @@ class InvitationService
*/
public function inviteUser(Organization $organization, string $email, Role $role, User $inviter): OrganizationInvitation
{
// Normalize the email so it matches how user emails are stored (see UserService::createUser),
// otherwise a mixed-case invite silently fails to link on registration.
$email = strtolower($email);
if (app(MemberService::class)->isEmailAlreadyMember($organization, $email)) {
throw new UserIsAlreadyMemberOfOrganizationApiException;
}
@@ -55,7 +59,7 @@ class InvitationService
$organizations = new Collection;
$invitations = OrganizationInvitation::query()
->where('email', $user->email)
->whereRaw('lower(email) = ?', [strtolower($user->email)])
->whereNotNull('accepted_at')
->get();

View File

@@ -380,6 +380,40 @@ class RegistrationTest extends TestCaseWithDatabase
$this->assertSame($user->organization->id, $organizations->first()->id);
}
public function test_registration_joins_invited_organization_even_if_invitation_email_casing_differs(): void
{
// Arrange: invitation stored with a different casing than the registration email
$user = $this->createUserWithPermission();
OrganizationInvitation::factory()
->forOrganization($user->organization)
->role(Role::Employee)
->accepted()
->create([
'email' => 'Invited.User@example.com',
]);
// Act
$response = $this->post('/register', [
'name' => 'Invited User',
'email' => 'invited.user@example.com',
'password' => 'password',
'password_confirmation' => 'password',
'terms' => true,
]);
// Assert: joined the inviting organization, no extra personal organization, invitation consumed
$this->assertAuthenticated();
$response->assertRedirect(RouteServiceProvider::HOME);
$newUser = User::where('email', 'invited.user@example.com')->first();
$this->assertNotNull($newUser);
$this->assertDatabaseMissing(OrganizationInvitation::class, [
'email' => 'Invited.User@example.com',
]);
$organizations = $newUser->organizations;
$this->assertCount(1, $organizations);
$this->assertSame($user->organization->id, $organizations->first()->id);
}
public function test_registration_logs_and_skips_accepted_invitation_with_invalid_role(): void
{
// Arrange