From ddeb3ec7385c921e809b6c5ad337b23ea9ce8776 Mon Sep 17 00:00:00 2001 From: Reed Garmsen Date: Tue, 7 Jul 2015 17:57:25 -0700 Subject: Added a server side check to see if members who are trying to be invited have already been invited by checking the email. Client handles it as if it was an email error. --- api/team.go | 9 +++++++++ 1 file changed, 9 insertions(+) (limited to 'api') diff --git a/api/team.go b/api/team.go index 15e4e2c17..7265b1d07 100644 --- a/api/team.go +++ b/api/team.go @@ -456,6 +456,15 @@ func inviteMembers(c *Context, w http.ResponseWriter, r *http.Request) { user = result.Data.(*model.User) } + var invNum int64 = 0 + for _, invite := range invites.Invites { + if result := <-Srv.Store.User().GetByEmail(c.Session.TeamId, invite["email"]); result.Err == nil || result.Err.Message != "We couldn't find the existing account" { + c.Err = model.NewAppError("invite_members", "This person is already on your team", strconv.FormatInt(invNum, 10)) + return + } + invNum++; + } + ia := make([]string, len(invites.Invites)) for _, invite := range invites.Invites { ia = append(ia, invite["email"]) -- cgit v1.2.3-1-g7c22 From 65dc307e685ad4a0b6df4263edd3f6b890ddd207 Mon Sep 17 00:00:00 2001 From: Reed Garmsen Date: Tue, 7 Jul 2015 18:12:53 -0700 Subject: Small tweaks and cleanup --- api/team.go | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'api') diff --git a/api/team.go b/api/team.go index 7265b1d07..c4a0ca181 100644 --- a/api/team.go +++ b/api/team.go @@ -457,12 +457,12 @@ func inviteMembers(c *Context, w http.ResponseWriter, r *http.Request) { } var invNum int64 = 0 - for _, invite := range invites.Invites { + for i, invite := range invites.Invites { if result := <-Srv.Store.User().GetByEmail(c.Session.TeamId, invite["email"]); result.Err == nil || result.Err.Message != "We couldn't find the existing account" { + invNum = int64(i) c.Err = model.NewAppError("invite_members", "This person is already on your team", strconv.FormatInt(invNum, 10)) return } - invNum++; } ia := make([]string, len(invites.Invites)) -- cgit v1.2.3-1-g7c22