Skip to content

TT-015: Owners can't remove members or see and revoke pending invites #714

Description

@unjica

Severity: P2 · Area: Dashboard · Found by: QA

Summary

Organization owners can't remove members or see/revoke pending invites: there's no UI and no API route. Someone who leaves keeps read access to the org's error data indefinitely; the only mitigation is downgrading them to VIEWER. (Invites expire after 7 days; re-inviting rotates the token.)

Environment and versions

Production, API 1.17.23/1.17.24, 2026-09-26 10:12–10:14 CEST. QA org (owner = QA account), invitee = a fresh QA account.

Steps to reproduce

  1. As owner, go to Settings → Team members and invite a new email as VIEWER.
  2. Look for the pending invite and a way to revoke it.
  3. Accept the invite with the new account.
  4. As owner, look for a way to remove that member.
  5. Probe DELETE /api/meta/organizations/<org>/members/<userId>.

Expected

Pending invites are listed with a Revoke action; each member row has an owner-only "Remove" action backed by an API route.

Actual

After inviting, the UI shows the invite link but the invite isn't listed anywhere. After acceptance, the member row only has a role select (no remove/revoke/row menu). API: DELETE …/members/:userId, DELETE …/invites/:id and GET …/invites all return 404 "route not found"; only POST/PATCH exist. UI 2/2, API probes 2/2.

Acceptance criteria

  1. As owner, invite a user as VIEWER: the invite appears in a "Pending" list, and Revoke makes the invite link invalid (/api/meta/invites/preview → valid:false).
  2. Invite and accept a second user, then remove them as owner: their /api/errors for that org's project → 403, and they disappear from the members list.
  3. A VIEWER or EDITOR calling DELETE gets 403.
  4. Removing the last owner gets 400.

Fix references

None yet.


Migrated from the QA regression list on 2026-09-26. Source: QA report 2026-09-26-sweep.md (#tt-015).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    apiAPI service (apps/api)bugSomething isn't workingdashboardDashboard app (apps/dashboard)qaFound or tracked by QA regression testing (TT-xxx)

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions