Repository navigation
feat(tenancy): complete tenant onboarding and invitation flows - #212
Merged
Merged
Conversation
rrrodzilla
marked this pull request as ready for review
October 6, 2026 19:01
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Tenant creators previously received no membership, tenanted open OAuth signups could not finish login, and tenant owners needed direct user creation permission to invite. This change adds atomic creator membership across all shipping backends, scoped membership roles, an existing default tenant for open signup, and an independent Cedar InviteUser action.
Invitation responses expose delivery outcomes and shareable acceptance links. Link mode skips SMTP; a stored invitation whose SMTP delivery fails returns a recoverable typed 502. The generated invitation form supports Invite-only owners and link sharing.
Existing non-platform inviters must explicitly grant InviteUser. Enabled open OAuth signup with tenancy now requires a valid existing default tenant. Configuration and migration examples are in the tenancy and invitations references.
Validation covers backend rollback and PostgreSQL create-receipt reconciliation, root create/refresh/read, scoped role isolation and stream revocation, OAuth default membership and invitation precedence, and Invite-only authorization and delivery recovery. Local validation passed: 1,987 runtime/schema tests, 402 CLI tests, all-target clippy with zero warnings, live PostgreSQL atomic creation and receipt retries, live SQL Server 2019 and 2022 suites, and the generated site build, lint, and 17 invitation, session, client-error, and relation-label Playwright cases. Required CI passed for the final commit, including all shipping backends, Windows, generated-site smoke tests, scalar proofs, feature checks, and zero-warning lints.
Release: v0.49.0.
Fixes #208