Invites in user page queries database without checking table emptiness

Hi,

My instance is a new one so no one invited anyone to anything, and I checked the ‘invites’ table in postgresql database, it is empty.

Then if I open ‘/users’, visit a user’s page and select ‘invites’, it will create a critical error in the error log.

Because:

UserController (app/controllers/user_controller.rb) > invites_count calls app/models/invite.rb, ‘find_all_invites_from’ function didn’t check if invites.email or invites.user_id exists there.

Please reproduce and correct me

:kissing_heart:

Can you paste the actual backtrace of the error?

1 Like

@zogstrip

    ActiveRecord::StatementInvalid (PG::InvalidColumnReference: ERROR:  for SELECT DISTINCT, ORDER BY expressions must appear in select list
    LINE 1: ... NOT NULL) AND (invites.user_id IS NULL) ORDER BY CASE WHEN ...
                                                         ^
    SELECT COUNT(*) FROM (SELECT DISTINCT "invites".* FROM "invites" LEFT OUTER JOIN "users" ON "users"."id" = "invites"."user_id" LEFT OUTER JOIN "user_stats" ON "user_stats"."user_id" = "users"."id" WHERE ("invites"."deleted_at" IS NULL) AND "invites"."invited_by_id" = 1 AND (invites.email IS NOT NULL) AND (invites.user_id IS NULL) ORDER BY CASE WHEN invites.user_id IS NOT NULL THEN 0 ELSE 1 END, user_stats.time_read DESC, invites.redeemed_at DESC OFFSET 0) subquery_for_count)
    /usr/lib64/ruby/gems/2.4.0/gems/rack-mini-profiler-0.10.5/lib/patches/db/pg.rb:90:in `async_exec'

backtrace:

    /usr/lib64/ruby/gems/2.4.0/gems/rack-mini-profiler-0.10.5/lib/patches/db/pg.rb:90:in `async_exec'
    /usr/lib64/ruby/gems/2.4.0/gems/rack-mini-profiler-0.10.5/lib/patches/db/pg.rb:90:in `async_exec'
    /usr/lib64/ruby/gems/2.4.0/gems/activerecord-5.1.4/lib/active_record/connection_adapters/postgresql_adapter.rb:614:in `block (2 levels) in exec_no_cache'
    /usr/lib64/ruby/gems/2.4.0/gems/activesupport-5.1.4/lib/active_support/dependencies/interlock.rb:46:in `block in permit_concurrent_loads'
    /usr/lib64/ruby/gems/2.4.0/gems/activesupport-5.1.4/lib/active_support/concurrency/share_lock.rb:185:in `yield_shares'
    /usr/lib64/ruby/gems/2.4.0/gems/activesupport-5.1.4/lib/active_support/dependencies/interlock.rb:45:in `permit_concurrent_loads'
    /usr/lib64/ruby/gems/2.4.0/gems/activerecord-5.1.4/lib/active_record/connection_adapters/postgresql_adapter.rb:613:in `block in exec_no_cache'
    /usr/lib64/ruby/gems/2.4.0/gems/activerecord-5.1.4/lib/active_record/connection_adapters/abstract_adapter.rb:612:in `block (2 levels) in log'
    /usr/lib64/ruby/2.4.0/monitor.rb:214:in `mon_synchronize'
    /usr/lib64/ruby/gems/2.4.0/gems/activerecord-5.1.4/lib/active_record/connection_adapters/abstract_adapter.rb:611:in `block in log'
    /usr/lib64/ruby/gems/2.4.0/gems/activesupport-5.1.4/lib/active_support/notifications/instrumenter.rb:21:in `instrument'
    /usr/lib64/ruby/gems/2.4.0/gems/activerecord-5.1.4/lib/active_record/connection_adapters/abstract_adapter.rb:603:in `log'
     /usr/lib64/ruby/gems/2.4.0/gems/activerecord-5.1.4/lib/active_record/connection_adapters/postgresql_adapter.rb:612:in `exec_no_cache'
    /usr/lib64/ruby/gems/2.4.0/gems/activerecord-5.1.4/lib/active_record/connection_adapters/postgresql_adapter.rb:599:in `execute_and_clear'
    /usr/lib64/ruby/gems/2.4.0/gems/activerecord-5.1.4/lib/active_record/connection_adapters/postgresql/database_statements.rb:79:in `exec_query'
    /usr/lib64/ruby/gems/2.4.0/gems/activerecord-5.1.4/lib/active_record/connection_adapters/abstract/database_statements.rb:371:in `select'
    /usr/lib64/ruby/gems/2.4.0/gems/activerecord-5.1.4/lib/active_record/connection_adapters/abstract/database_statements.rb:42:in `select_all'
    /usr/lib64/ruby/gems/2.4.0/gems/activerecord-5.1.4/lib/active_record/connection_adapters/abstract/query_cache.rb:95:in `block in select_all'
    /usr/lib64/ruby/gems/2.4.0/gems/activerecord-5.1.4/lib/active_record/connection_adapters/abstract/query_cache.rb:117:in `block in cache_sql'
    /usr/lib64/ruby/2.4.0/monitor.rb:214:in `mon_synchronize'
    /usr/lib64/ruby/gems/2.4.0/gems/activerecord-5.1.4/lib/active_record/connection_adapters/abstract/query_cache.rb:104:in `cache_sql'
    /usr/lib64/ruby/gems/2.4.0/gems/activerecord-5.1.4/lib/active_record/connection_adapters/abstract/query_cache.rb:95:in `select_all'
    /usr/lib64/ruby/gems/2.4.0/gems/activerecord-5.1.4/lib/active_record/relation/calculations.rb:253:in `execute_simple_calculation'
    /usr/lib64/ruby/gems/2.4.0/gems/activerecord-5.1.4/lib/active_record/relation/calculations.rb:209:in `perform_calculation'
    /usr/lib64/ruby/gems/2.4.0/gems/activerecord-5.1.4/lib/active_record/relation/calculations.rb:118:in `calculate'
    /usr/lib64/ruby/gems/2.4.0/gems/activerecord-5.1.4/lib/active_record/relation/calculations.rb:116:in `calculate'
    /usr/lib64/ruby/gems/2.4.0/gems/activerecord-5.1.4/lib/active_record/relation/calculations.rb:41:in `count'
    /srv/www/vhosts/discourse/app/models/invite.rb:186:in `find_pending_invites_count'
    /srv/www/vhosts/discourse/app/controllers/users_controller.rb:225:in `invited_count'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/action_controller/metal/basic_implicit_render.rb:4:in `send_action'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/abstract_controller/base.rb:186:in `process_action'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/action_controller/metal/rendering.rb:30:in `process_action'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/abstract_controller/callbacks.rb:20:in `block in process_action'
    /usr/lib64/ruby/gems/2.4.0/gems/activesupport-5.1.4/lib/active_support/callbacks.rb:131:in `run_callbacks'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/abstract_controller/callbacks.rb:19:in `process_action'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/action_controller/metal/rescue.rb:20:in `process_action'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/action_controller/metal/instrumentation.rb:32:in `block in process_action'
    /usr/lib64/ruby/gems/2.4.0/gems/activesupport-5.1.4/lib/active_support/notifications.rb:166:in `block in instrument'
    /usr/lib64/ruby/gems/2.4.0/gems/activesupport-5.1.4/lib/active_support/notifications/instrumenter.rb:21:in `instrument'
    /usr/lib64/ruby/gems/2.4.0/gems/activesupport-5.1.4/lib/active_support/notifications.rb:166:in `instrument'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/action_controller/metal/instrumentation.rb:30:in `process_action'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/action_controller/metal/params_wrapper.rb:252:in `process_action'
    /usr/lib64/ruby/gems/2.4.0/gems/activerecord-5.1.4/lib/active_record/railties/controller_runtime.rb:22:in `process_action'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/abstract_controller/base.rb:124:in `process'
    /usr/lib64/ruby/gems/2.4.0/gems/actionview-5.1.4/lib/action_view/rendering.rb:30:in `process'
    /usr/lib64/ruby/gems/2.4.0/gems/rack-mini-profiler-0.10.5/lib/mini_profiler/profiling_methods.rb:76:in `block in profile_method'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/action_controller/metal.rb:189:in `dispatch'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/action_controller/metal.rb:253:in `dispatch'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/action_dispatch/routing/route_set.rb:49:in `dispatch'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/action_dispatch/routing/route_set.rb:31:in `serve'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/action_dispatch/journey/router.rb:50:in `block in serve'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/action_dispatch/journey/router.rb:33:in `each'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/action_dispatch/journey/router.rb:33:in `serve'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/action_dispatch/routing/route_set.rb:834:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/rack-protection-2.0.0/lib/rack/protection/frame_options.rb:31:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/omniauth-1.6.1/lib/omniauth/strategy.rb:189:in `call!'
    /usr/lib64/ruby/gems/2.4.0/gems/omniauth-1.6.1/lib/omniauth/strategy.rb:167:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/omniauth-1.6.1/lib/omniauth/strategy.rb:189:in `call!'
    /usr/lib64/ruby/gems/2.4.0/gems/omniauth-1.6.1/lib/omniauth/strategy.rb:167:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/omniauth-1.6.1/lib/omniauth/strategy.rb:189:in `call!'
    /usr/lib64/ruby/gems/2.4.0/gems/omniauth-1.6.1/lib/omniauth/strategy.rb:167:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/omniauth-1.6.1/lib/omniauth/strategy.rb:189:in `call!'
     /usr/lib64/ruby/gems/2.4.0/gems/omniauth-1.6.1/lib/omniauth/strategy.rb:167:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/omniauth-1.6.1/lib/omniauth/strategy.rb:189:in `call!'
    /usr/lib64/ruby/gems/2.4.0/gems/omniauth-1.6.1/lib/omniauth/strategy.rb:167:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/omniauth-1.6.1/lib/omniauth/strategy.rb:189:in `call!'
    /usr/lib64/ruby/gems/2.4.0/gems/omniauth-1.6.1/lib/omniauth/strategy.rb:167:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/omniauth-1.6.1/lib/omniauth/builder.rb:63:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/rack-2.0.3/lib/rack/conditional_get.rb:25:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/rack-2.0.3/lib/rack/head.rb:12:in `call'
    /srv/www/vhosts/discourse/lib/middleware/anonymous_cache.rb:149:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/rack-2.0.3/lib/rack/session/abstract/id.rb:232:in `context'
    /usr/lib64/ruby/gems/2.4.0/gems/rack-2.0.3/lib/rack/session/abstract/id.rb:226:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/action_dispatch/middleware/cookies.rb:613:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/action_dispatch/middleware/callbacks.rb:26:in `block in call'
    /usr/lib64/ruby/gems/2.4.0/gems/activesupport-5.1.4/lib/active_support/callbacks.rb:97:in `run_callbacks'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/action_dispatch/middleware/callbacks.rb:24:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/action_dispatch/middleware/debug_exceptions.rb:59:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/action_dispatch/middleware/show_exceptions.rb:31:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/logster-1.2.8/lib/logster/middleware/reporter.rb:31:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/railties-5.1.4/lib/rails/rack/logger.rb:36:in `call_app'
    /usr/lib64/ruby/gems/2.4.0/gems/railties-5.1.4/lib/rails/rack/logger.rb:26:in `call'
    /srv/www/vhosts/discourse/config/initializers/100-quiet_logger.rb:16:in `call'
    /srv/www/vhosts/discourse/config/initializers/100-silence_logger.rb:29:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/action_dispatch/middleware/remote_ip.rb:79:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/action_dispatch/middleware/request_id.rb:25:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/rack-2.0.3/lib/rack/method_override.rb:22:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/rack-2.0.3/lib/rack/runtime.rb:22:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/actionpack-5.1.4/lib/action_dispatch/middleware/executor.rb:12:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/rack-2.0.3/lib/rack/sendfile.rb:111:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/rack-mini-profiler-0.10.5/lib/mini_profiler/profiler.rb:171:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/message_bus-2.0.8/lib/message_bus/rack/middleware.rb:63:in `call'
    /srv/www/vhosts/discourse/lib/middleware/request_tracker.rb:110:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/railties-5.1.4/lib/rails/engine.rb:522:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/railties-5.1.4/lib/rails/railtie.rb:185:in `public_send'
    /usr/lib64/ruby/gems/2.4.0/gems/railties-5.1.4/lib/rails/railtie.rb:185:in `method_missing'
    /usr/lib64/ruby/gems/2.4.0/gems/rack-2.0.3/lib/rack/urlmap.rb:68:in `block in call'
    /usr/lib64/ruby/gems/2.4.0/gems/rack-2.0.3/lib/rack/urlmap.rb:53:in `each'
    /usr/lib64/ruby/gems/2.4.0/gems/rack-2.0.3/lib/rack/urlmap.rb:53:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/puma-3.10.0/lib/puma/configuration.rb:225:in `call'
    /usr/lib64/ruby/gems/2.4.0/gems/puma-3.10.0/lib/puma/server.rb:605:in `handle_request'
    /usr/lib64/ruby/gems/2.4.0/gems/puma-3.10.0/lib/puma/server.rb:437:in `process_client'
    /usr/lib64/ruby/gems/2.4.0/gems/puma-3.10.0/lib/puma/server.rb:301:in `block in run'
    /usr/lib64/ruby/gems/2.4.0/gems/puma-3.10.0/lib/puma/thread_pool.rb:120:in `block in spawn_thread'
2 Likes

I fixed that bug a few days ago. Please make sure your Discourse is up-to-date in order to get the bugfix.

https://github.com/discourse/discourse/commit/4be8f17e66d95e786edd91cdade334ff5da8ee04

6 Likes

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.