mirror of
https://github.com/saltbo/zpan.git
synced 2026-09-24 23:22:31 +08:00
* feat: team invitation via email and invite link - Add team invite dialog with email invite and shareable link tabs - Email invite uses better-auth organizationClient.inviteMember() with configured email service - Invite link generates a time-limited token stored in new team_invite_links table - Accept invite page at /teams/invite?token=xxx (auto-join if logged in, redirect to sign-in if not) - Pending invitations section shows all pending email invites; owners can cancel them - Add editor/viewer custom roles to better-auth organization plugin - Add sendInvitationEmail hook to send HTML invite email via configured email service - Redirect-after-login support: _authenticated layout passes current URL to sign-in - Add migration 0007_team_invite_links for new table - Only team owners see the Invite Member button and pending invitations Agent-Profile: https://agent-kanban.dev/agents/a6bb038c4226a87f * test: add integration tests for team invite service and routes Cover createInviteLink, getInviteLinkInfo, acceptInviteLink, and listPendingInvitations service functions. Add route tests for all public and authenticated team invite endpoints (invite-info, invite-link, invitations list, and join). Add team_invite_links table to test setup. Agent-Profile: https://agent-kanban.dev/agents/a6bb038c4226a87f * style: fix biome lint in team invite test files Agent-Profile: https://agent-kanban.dev/agents/a6bb038c4226a87f * fix: resolve CodeQL open-redirect and missing coverage issues - Validate redirect param in sign-in.tsx is a same-origin relative path to prevent open redirect and javascript: URI XSS (CodeQL alerts) - Spread defaultRoles (owner/admin/member) when configuring custom roles in organization plugin so built-in roles retain their permissions - Add integration tests for sendInvitationEmail callback to cover buildInvitationEmailHtml and the email dispatch path in auth.ts Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix: use URL constructor to sanitize redirect param in sign-in Replace regex check with URL constructor origin validation so CodeQL's dataflow analysis can confirm the value is same-origin before it reaches window.location.href (resolves js/xss and js/client-side-unvalidated-url-redirection alerts). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Bob <aibob@mails.agent-kanban.dev> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>