Severity: P2 · Area: Dashboard · Found by: QA
Summary
Organization owners can't remove members or see/revoke pending invites: there's no UI and no API route. Someone who leaves keeps read access to the org's error data indefinitely; the only mitigation is downgrading them to VIEWER. (Invites expire after 7 days; re-inviting rotates the token.)
Environment and versions
Production, API 1.17.23/1.17.24, 2026-09-26 10:12–10:14 CEST. QA org (owner = QA account), invitee = a fresh QA account.
Steps to reproduce
- As owner, go to Settings → Team members and invite a new email as VIEWER.
- Look for the pending invite and a way to revoke it.
- Accept the invite with the new account.
- As owner, look for a way to remove that member.
- Probe
DELETE /api/meta/organizations/<org>/members/<userId>.
Expected
Pending invites are listed with a Revoke action; each member row has an owner-only "Remove" action backed by an API route.
Actual
After inviting, the UI shows the invite link but the invite isn't listed anywhere. After acceptance, the member row only has a role select (no remove/revoke/row menu). API: DELETE …/members/:userId, DELETE …/invites/:id and GET …/invites all return 404 "route not found"; only POST/PATCH exist. UI 2/2, API probes 2/2.
Acceptance criteria
- As owner, invite a user as VIEWER: the invite appears in a "Pending" list, and Revoke makes the invite link invalid (
/api/meta/invites/preview → valid:false).
- Invite and accept a second user, then remove them as owner: their
/api/errors for that org's project → 403, and they disappear from the members list.
- A VIEWER or EDITOR calling DELETE gets 403.
- Removing the last owner gets 400.
Fix references
None yet.
Migrated from the QA regression list on 2026-09-26. Source: QA report 2026-09-26-sweep.md (#tt-015).
Severity: P2 · Area: Dashboard · Found by: QA
Summary
Organization owners can't remove members or see/revoke pending invites: there's no UI and no API route. Someone who leaves keeps read access to the org's error data indefinitely; the only mitigation is downgrading them to VIEWER. (Invites expire after 7 days; re-inviting rotates the token.)
Environment and versions
Production, API 1.17.23/1.17.24, 2026-09-26 10:12–10:14 CEST. QA org (owner = QA account), invitee = a fresh QA account.
Steps to reproduce
DELETE /api/meta/organizations/<org>/members/<userId>.Expected
Pending invites are listed with a Revoke action; each member row has an owner-only "Remove" action backed by an API route.
Actual
After inviting, the UI shows the invite link but the invite isn't listed anywhere. After acceptance, the member row only has a role select (no remove/revoke/row menu). API:
DELETE …/members/:userId,DELETE …/invites/:idandGET …/invitesall return 404 "route not found"; only POST/PATCH exist. UI 2/2, API probes 2/2.Acceptance criteria
/api/meta/invites/preview→valid:false)./api/errorsfor that org's project → 403, and they disappear from the members list.Fix references
None yet.
Migrated from the QA regression list on 2026-09-26. Source: QA report
2026-09-26-sweep.md(#tt-015).