Is there an existing issue for this?
Current behavior
POST /api/workspaces//projects/<project_id>/invitations/ (ProjectInvitationsViewset.create in apps/api/plane/app/views/project/invite.py) returns 500 for every non-empty request, so no project invitation email can ever be sent.
Two separate crashes:
Workspace-role check (lines 65–67):
workspace_role = WorkspaceMember.objects.filter(
workspace__slug=slug, member__email=email.get("email"), is_active=True
).role
.filter() returns a QuerySet, which has no .role, so this raises AttributeError before anything is saved. It was introduced in #5588 (Sep 2024).
Email dispatch (line 108):
project_invitations = ProjectMemberInvite.objects.bulk_create(...)
for invitation in project_invitations:
project_invitations.delay(...)
project_invitations is the list returned by bulk_create. The project_invitation Celery task (plane/bgtasks/project_invitation_task.py) is never imported, and nothing else in the codebase calls it. If crash 1 were fixed, the invites would be saved and the request would still 500 with no email sent. This line has been wrong since #2762 (Nov 2023).
Also, when the role check rejects a request, it returns the error body with status 200 (no status= is passed).
Expected: invites are saved, one project_invitation email task is queued per invite, and the endpoint returns 200. A role mismatch should return 400.
The web app adds project members through a different endpoint, which is probably why this went unnoticed. The endpoint is still registered and reachable by API clients.
Steps to reproduce
Be a project admin in workspace , project <project_id>.
Send:
curl -X POST "https:///api/workspaces//projects/<project_id>/invitations/"
-H "Content-Type: application/json" -H "Cookie: "
-d '{"emails": [{"email": "someone@example.com", "role": 15}]}'
Response: 500 Internal Server Error. Server log: AttributeError: 'QuerySet' object has no attribute 'role'.
With the role line patched, the same request still returns 500 (AttributeError: 'list' object has no attribute 'delay'). The ProjectMemberInvite row is created, but no email is sent.
Reproduced on preview @ d616636 with a contract test: case 1 gave 500 with 0 invites saved; case 2 gave 500 with 1 invite saved and no email.
Environment
Production
Browser
Google Chrome
Edition
Community
Version
v1.4.2 / preview @ d616636
Is there an existing issue for this?
Current behavior
POST /api/workspaces//projects/<project_id>/invitations/ (ProjectInvitationsViewset.create in apps/api/plane/app/views/project/invite.py) returns 500 for every non-empty request, so no project invitation email can ever be sent.
Two separate crashes:
Workspace-role check (lines 65–67):
workspace_role = WorkspaceMember.objects.filter(
workspace__slug=slug, member__email=email.get("email"), is_active=True
).role
.filter() returns a QuerySet, which has no .role, so this raises AttributeError before anything is saved. It was introduced in #5588 (Sep 2024).
Email dispatch (line 108):
project_invitations = ProjectMemberInvite.objects.bulk_create(...)
for invitation in project_invitations:
project_invitations.delay(...)
project_invitations is the list returned by bulk_create. The project_invitation Celery task (plane/bgtasks/project_invitation_task.py) is never imported, and nothing else in the codebase calls it. If crash 1 were fixed, the invites would be saved and the request would still 500 with no email sent. This line has been wrong since #2762 (Nov 2023).
Also, when the role check rejects a request, it returns the error body with status 200 (no status= is passed).
Expected: invites are saved, one project_invitation email task is queued per invite, and the endpoint returns 200. A role mismatch should return 400.
The web app adds project members through a different endpoint, which is probably why this went unnoticed. The endpoint is still registered and reachable by API clients.
Steps to reproduce
Be a project admin in workspace , project <project_id>.
Send:
curl -X POST "https:///api/workspaces//projects/<project_id>/invitations/"
-H "Content-Type: application/json" -H "Cookie: "
-d '{"emails": [{"email": "someone@example.com", "role": 15}]}'
Response: 500 Internal Server Error. Server log: AttributeError: 'QuerySet' object has no attribute 'role'.
With the role line patched, the same request still returns 500 (AttributeError: 'list' object has no attribute 'delay'). The ProjectMemberInvite row is created, but no email is sent.
Reproduced on preview @ d616636 with a contract test: case 1 gave 500 with 0 invites saved; case 2 gave 500 with 1 invite saved and no email.
Environment
Production
Browser
Google Chrome
Edition
Community
Version
v1.4.2 / preview @ d616636