diff --git a/packages/cli/src/controllers/users.controller.ts b/packages/cli/src/controllers/users.controller.ts index 4f7b67934c..410de6d1ae 100644 --- a/packages/cli/src/controllers/users.controller.ts +++ b/packages/cli/src/controllers/users.controller.ts @@ -126,7 +126,9 @@ export class UsersController { const users = await this.userService.findMany(findManyOptions); const publicUsers: Array> = await Promise.all( - users.map(async (u) => this.userService.toPublic(u, { withInviteUrl: true })), + users.map(async (u) => + this.userService.toPublic(u, { withInviteUrl: true, inviterId: req.user.id }), + ), ); return listQueryOptions diff --git a/packages/cli/src/services/user.service.ts b/packages/cli/src/services/user.service.ts index c19e98eb0c..2dd4122f1a 100644 --- a/packages/cli/src/services/user.service.ts +++ b/packages/cli/src/services/user.service.ts @@ -14,7 +14,7 @@ import { createPasswordSha } from '@/auth/jwt'; import { UserManagementMailer } from '@/UserManagement/email'; import { InternalHooks } from '@/InternalHooks'; import { RoleService } from '@/services/role.service'; -import { ErrorReporterProxy as ErrorReporter } from 'n8n-workflow'; +import { ApplicationError, ErrorReporterProxy as ErrorReporter } from 'n8n-workflow'; import type { UserRequest } from '@/requests'; import { InternalServerError } from '@/errors/response-errors/internal-server.error'; @@ -123,7 +123,12 @@ export class UserService { async toPublic( user: User, - options?: { withInviteUrl?: boolean; posthog?: PostHogClient; withScopes?: boolean }, + options?: { + withInviteUrl?: boolean; + inviterId?: string; + posthog?: PostHogClient; + withScopes?: boolean; + }, ) { const { password, updatedAt, apiKey, authIdentities, mfaRecoveryCodes, mfaSecret, ...rest } = user; @@ -136,30 +141,34 @@ export class UserService { hasRecoveryCodesLeft: !!user.mfaRecoveryCodes?.length, }; - if (options?.withScopes) { - publicUser.globalScopes = user.globalScopes; + if (options?.withInviteUrl && !options?.inviterId) { + throw new ApplicationError('Inviter ID is required to generate invite URL'); } - if (options?.withInviteUrl && publicUser.isPending) { - publicUser = this.addInviteUrl(publicUser, user.id); + if (options?.withInviteUrl && options?.inviterId && publicUser.isPending) { + publicUser = this.addInviteUrl(options.inviterId, publicUser); } if (options?.posthog) { publicUser = await this.addFeatureFlags(publicUser, options.posthog); } + if (options?.withScopes) { + publicUser.globalScopes = user.globalScopes; + } + return publicUser; } - private addInviteUrl(user: PublicUser, inviterId: string) { + private addInviteUrl(inviterId: string, invitee: PublicUser) { const url = new URL(getInstanceBaseUrl()); url.pathname = '/signup'; url.searchParams.set('inviterId', inviterId); - url.searchParams.set('inviteeId', user.id); + url.searchParams.set('inviteeId', invitee.id); - user.inviteAcceptUrl = url.toString(); + invitee.inviteAcceptUrl = url.toString(); - return user; + return invitee; } private async addFeatureFlags(publicUser: PublicUser, posthog: PostHogClient) { diff --git a/packages/cli/test/unit/services/user.service.test.ts b/packages/cli/test/unit/services/user.service.test.ts index b61cd244a6..56eb26194b 100644 --- a/packages/cli/test/unit/services/user.service.test.ts +++ b/packages/cli/test/unit/services/user.service.test.ts @@ -50,22 +50,29 @@ describe('UserService', () => { }); it('should add scopes if requested', async () => { - const scopeless = await userService.toPublic(commonMockUser, { withScopes: false }); - const scoped = await userService.toPublic(commonMockUser, { withScopes: true }); + const unscoped = await userService.toPublic(commonMockUser); - expect(Array.isArray(scopeless.globalScopes)).toBe(false); - expect(Array.isArray(scoped.globalScopes)).toBe(true); + expect(scoped.globalScopes).toEqual([]); + expect(unscoped.globalScopes).toBeUndefined(); }); it('should add invite URL if requested', async () => { - const mockUser = Object.assign(new User(), { id: uuid(), isPending: true }); + const firstUser = Object.assign(new User(), { id: uuid() }); + const secondUser = Object.assign(new User(), { id: uuid(), isPending: true }); - const withUrl = await userService.toPublic(mockUser, { withInviteUrl: true }); - const withoutUrl = await userService.toPublic(mockUser, { withInviteUrl: false }); + const withoutUrl = await userService.toPublic(secondUser); + const withUrl = await userService.toPublic(secondUser, { + withInviteUrl: true, + inviterId: firstUser.id, + }); - expect(typeof withUrl.inviteAcceptUrl === 'string').toBe(true); expect(withoutUrl.inviteAcceptUrl).toBeUndefined(); + + const url = new URL(withUrl.inviteAcceptUrl ?? ''); + + expect(url.searchParams.get('inviterId')).toBe(firstUser.id); + expect(url.searchParams.get('inviteeId')).toBe(secondUser.id); }); });