Improve invite flow by replacing user listing with email existence check (#229)

* Improve invite flow by replacing user listing with email existence check

* Refactor invite logic to redirect users based on account status and enhance email existence check permissions
This commit is contained in:
Mattsson
2026-04-13 16:15:20 +02:00
committed by GitHub
parent 7bf7565852
commit 4644642f8a
3 changed files with 34 additions and 9 deletions
@@ -0,0 +1,19 @@
-- Efficient email existence check for invite flow.
-- Replaces the previous approach of listing all auth users (which only
-- returned the first page and broke for instances with >50 users).
CREATE OR REPLACE FUNCTION public.check_email_exists(email_to_check text)
RETURNS boolean
LANGUAGE sql
SECURITY DEFINER
SET search_path = ''
AS $$
SELECT EXISTS (
SELECT 1 FROM auth.users WHERE lower(email) = lower(email_to_check)
);
$$;
-- Only callable by service role — prevents email enumeration via PostgREST.
-- Must revoke from PUBLIC first (PostgreSQL grants EXECUTE to PUBLIC by default),
-- then grant explicitly to service_role.
REVOKE EXECUTE ON FUNCTION public.check_email_exists(text) FROM PUBLIC;
GRANT EXECUTE ON FUNCTION public.check_email_exists(text) TO service_role;