Improve invite flow by replacing user listing with email existence check (#229)
* Improve invite flow by replacing user listing with email existence check * Refactor invite logic to redirect users based on account status and enhance email existence check permissions
This commit is contained in:
@@ -0,0 +1,19 @@
|
||||
-- Efficient email existence check for invite flow.
|
||||
-- Replaces the previous approach of listing all auth users (which only
|
||||
-- returned the first page and broke for instances with >50 users).
|
||||
CREATE OR REPLACE FUNCTION public.check_email_exists(email_to_check text)
|
||||
RETURNS boolean
|
||||
LANGUAGE sql
|
||||
SECURITY DEFINER
|
||||
SET search_path = ''
|
||||
AS $$
|
||||
SELECT EXISTS (
|
||||
SELECT 1 FROM auth.users WHERE lower(email) = lower(email_to_check)
|
||||
);
|
||||
$$;
|
||||
|
||||
-- Only callable by service role — prevents email enumeration via PostgREST.
|
||||
-- Must revoke from PUBLIC first (PostgreSQL grants EXECUTE to PUBLIC by default),
|
||||
-- then grant explicitly to service_role.
|
||||
REVOKE EXECUTE ON FUNCTION public.check_email_exists(text) FROM PUBLIC;
|
||||
GRANT EXECUTE ON FUNCTION public.check_email_exists(text) TO service_role;
|
||||
Reference in New Issue
Block a user