Organization settings
Organization settings
api/views/org_views.py owns the organization invitation endpoint used by the settings page.
Endpoint
POST /api/v1/org/invite/
Responsibilities
OrgInviteView:
- reads the current tenant from middleware
- re-checks that the caller can manage users in that tenant
- validates the invite body through
OrgInviteSerializer - creates an
OrgInviterow - logs the invite event
- returns a success response without sending email in the MVP
Invariants
- the tenant must be present
- the caller must be a tenant manager/admin or equivalent role with user-management rights
- the same email cannot already be an active member or a pending invite for that tenant
- the current implementation stores the invite in the database only; email delivery is a future extension point
Workflow
flowchart TD A[POST /api/v1/org/invite/] --> B[get_current_tenant] B --> C{tenant exists?} C -->|no| D[403] C -->|yes| E[check manage-users permission] E --> F{allowed?} F -->|no| G[403] F -->|yes| H[validate serializer] H --> I[create OrgInvite row] I --> J[return invite metadata]Validation
tests/integration/test_viewsets.pyfor route reachability- org-specific unit tests where invite validation is asserted
Scope boundary
This page is about invitation flow only. For membership resolution and authorization, read Tenancy.