Skip to content

Organization settings

Organization settings

api/views/org_views.py owns the organization invitation endpoint used by the settings page.

Endpoint

  • POST /api/v1/org/invite/

Responsibilities

OrgInviteView:

  • reads the current tenant from middleware
  • re-checks that the caller can manage users in that tenant
  • validates the invite body through OrgInviteSerializer
  • creates an OrgInvite row
  • logs the invite event
  • returns a success response without sending email in the MVP

Invariants

  • the tenant must be present
  • the caller must be a tenant manager/admin or equivalent role with user-management rights
  • the same email cannot already be an active member or a pending invite for that tenant
  • the current implementation stores the invite in the database only; email delivery is a future extension point

Workflow

flowchart TD
A[POST /api/v1/org/invite/] --> B[get_current_tenant]
B --> C{tenant exists?}
C -->|no| D[403]
C -->|yes| E[check manage-users permission]
E --> F{allowed?}
F -->|no| G[403]
F -->|yes| H[validate serializer]
H --> I[create OrgInvite row]
I --> J[return invite metadata]

Validation

  • tests/integration/test_viewsets.py for route reachability
  • org-specific unit tests where invite validation is asserted

Scope boundary

This page is about invitation flow only. For membership resolution and authorization, read Tenancy.