Something went wrong. Try again.
[READ-ONLY] Mirror of https://github.com/openstatusHQ/openstatus. ๐ซ Status page with uptime monitoring & API monitoring as code ๐ซ openstatus.dev
bun drizzle-orm monitoring monitoring-as-code nextjs observability on-call open-source shadcn-ui status-page statuspage synthetic-monitoring tinybird turso uptime uptime-checker uptime-monitor
Something went wrong. Try again.
2.0 kB ยท 57 lines
TypeScript
12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758import { and, eq, isNull } from "@openstatus/db";import { invitation } from "@openstatus/db/src/schema";
import { emitAudit } from "../audit";import { requireScope } from "../auth";import { type ServiceContext, withTransaction } from "../context";import { DeleteInvitationInput } from "./schemas";
/** * Delete a pending invitation. Scoped to the caller's workspace; a no-op * (no error) when the row doesn't exist โ the legacy router also issues * an unconditional DELETE without a prior existence check. * * Only **pending** invitations can be deleted: the `acceptedAt IS NULL` * guard preserves the audit trail for accepted invites and prevents a * workspace owner from unilaterally wiping the "this user was invited * on date X" record after they've joined. Accepted invitations survive * as a historical breadcrumb. * * The audit row is only emitted when a row actually got deleted, so * unknown-id / wrong-workspace / already-accepted calls don't generate * misleading entries. */export async function deleteInvitation(args: { ctx: ServiceContext; input: DeleteInvitationInput;}): Promise<void> { const { ctx } = args; requireScope(ctx, "write"); const input = DeleteInvitationInput.parse(args.input);
await withTransaction(ctx, async (tx) => { // `.returning()` the full row so we don't need a separate SELECT // for the audit snapshot. `token` (email-link capability) is // stripped before emitting; everything else is safe. const [deleted] = await tx .delete(invitation) .where( and( eq(invitation.id, input.id), eq(invitation.workspaceId, ctx.workspace.id), isNull(invitation.acceptedAt), ), ) .returning();
if (!deleted) return;
const { token: _token, ...before } = deleted; await emitAudit(tx, ctx, { action: "invitation.delete", entityType: "invitation", entityId: input.id, before, }); });}