# הזמנות שנוצרו על ידי צוות עוקפות את הדרישה של must\_approve\_users

**URL:** https://meta.discourse.org/t/staff-generated-invites-bypass-the-must-approve-users-requirement/228199
**Category:** Feature
**Tags:** invites
**Created:** [26 במאי,‏ 2022,‏ 8:37pm UTC](https://meta.discourse.org/t/staff-generated-invites-bypass-the-must-approve-users-requirement/228199 "2022-05-26T20:37:13Z")
**Posts on this page:** 10
**Page:** 2

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [2 ביוני,‏ 2022,‏ 1:07am UTC](https://meta.discourse.org/t/staff-generated-invites-bypass-the-must-approve-users-requirement/228199/23 "2022-06-02T01:07:34Z")

</div>

> [@tobiaseigen](#):
>
> Change behavior so invite links created by admins respect the approval required setting just like invites by non-admins.

This is certainly what we should do. We will get this fixed over the next few days.

---

<div class="post-metadata">

### Author: ![riking](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/riking/32/170938_2.png) [@riking](https://meta.discourse.org/u/riking)
#### Post date: [2 ביוני,‏ 2022,‏ 11:08pm UTC](https://meta.discourse.org/t/staff-generated-invites-bypass-the-must-approve-users-requirement/228199/25 "2022-06-02T23:08:59Z")

</div>

> [@tobiaseigen](#):
>
> Change behavior so invite links created by admins respect the approval required setting just like invites by non-admins.

Since the issue here was a staff member sending a _multi use_ invite to a _single_ person, you could keep the old behavior by disabling auto approve for any multiple use invites while keeping it for single use.

Additionally, the education (“this user will be approved when they accept the invitation”) (now only for single use invites) should go on the invite dialog, not the site settings page.

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [2 ביוני,‏ 2022,‏ 11:32pm UTC](https://meta.discourse.org/t/staff-generated-invites-bypass-the-must-approve-users-requirement/228199/26 "2022-06-02T23:32:32Z")

</div>

I am afraid I am making the very hard line call here that `must_approve_users` == VERY HARD LINE definition of **explicit** approval must be given.

The trouble with implicit approval (which I originally approved) is that it is full of edge cases. Edge cases breed security problems and flaws in the system. Additionally, explaining edge cases regarding implicit approval is way too complicated and not a headache we need.

If you go for `must_approve_users` we will take the absolute strictest definition and require you **explicitly** click approve on every single account regardless of invite vs not invite.

---

<div class="post-metadata">

### Author: ![Wall-E](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/wall-e/32/184438_2.png) [@Wall-E](https://meta.discourse.org/u/Wall-E)
#### Post date: [2 ביוני,‏ 2022,‏ 11:54pm UTC](https://meta.discourse.org/t/staff-generated-invites-bypass-the-must-approve-users-requirement/228199/27 "2022-06-02T23:54:05Z")

</div>

> [@riking](#):
>
> Since the issue here was a staff member sending a _multi use_ invite to a _single_ person

Just to clarify, the invite link was sent to a meeting chat room, i.e. a bunch of people that were authorized to join, and not to a single person. We set max use to the number of people in that chat room. One of them then forwarded the link to someone else belonging to an unauthorized entity, who used it faster than the people in the chat room.

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [3 ביוני,‏ 2022,‏ 5:39am UTC](https://meta.discourse.org/t/staff-generated-invites-bypass-the-must-approve-users-requirement/228199/28 "2022-06-03T05:39:32Z")

</div>

Per:

[https://github.com/discourse/discourse/commit/0fa0094531efc82d9371f90a02aa804b176d59cf](https://github.com/discourse/discourse/commit/0fa0094531efc82d9371f90a02aa804b176d59cf)

And

[https://github.com/discourse/discourse/commit/7c4e2d33fa4b922354c177ffc880a2f2701a91f9](https://github.com/discourse/discourse/commit/7c4e2d33fa4b922354c177ffc880a2f2701a91f9)

We are now done.

@Wall-E feel free to rebuild to get the latest fixes.

---

<div class="post-metadata">

### Author: ![Wall-E](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/wall-e/32/184438_2.png) [@Wall-E](https://meta.discourse.org/u/Wall-E)
#### Post date: [3 ביוני,‏ 2022,‏ 1:09pm UTC](https://meta.discourse.org/t/staff-generated-invites-bypass-the-must-approve-users-requirement/228199/29 "2022-06-03T13:09:27Z")

</div>

Great! My sys admin takes care of updating the instance. He only updates from your beta releases when a new one shows up here:

 ![Screenshot from 2022-06-03 09-07-46](https://global.discourse-cdn.com/meta/original/4X/0/9/3/0930984f7f1fed1f17299540c7b8149ee8833f92.png)

Will it make it there eventually? If so, when could that happen?

[Edit] I see a new one here:

 ![Screenshot from 2022-06-03 09-09-58](https://global.discourse-cdn.com/meta/original/4X/8/5/c/85c502ff7d008f5759142219a21e4bcfde5ecd2d.png)

Is it that one?

---

<div class="post-metadata">

### Author: ![tobiaseigen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tobiaseigen/32/539204_2.png) [@tobiaseigen](https://meta.discourse.org/u/tobiaseigen)
#### Post date: [3 ביוני,‏ 2022,‏ 2:48pm UTC](https://meta.discourse.org/t/staff-generated-invites-bypass-the-must-approve-users-requirement/228199/30 "2022-06-03T14:48:11Z")

</div>

Yes, you want to hit that one and then when it is complete return to upgrade everything else using the upgrade all button. You have to upgrade docker first, and separately, unless you are upgrading from the command line.

---

<div class="post-metadata">

### Author: ![Wall-E](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/wall-e/32/184438_2.png) [@Wall-E](https://meta.discourse.org/u/Wall-E)
#### Post date: [3 ביוני,‏ 2022,‏ 6:43pm UTC](https://meta.discourse.org/t/staff-generated-invites-bypass-the-must-approve-users-requirement/228199/31 "2022-06-03T18:43:15Z")

</div>

Sam, many thanks for addressing this issue. It will take a few days before my sys admin updates things.

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [3 ביוני,‏ 2022,‏ 9:17pm UTC](https://meta.discourse.org/t/staff-generated-invites-bypass-the-must-approve-users-requirement/228199/32 "2022-06-03T21:17:45Z")

</div>

Not probs!

All thanks should go to @tgxworld / @martin / @gerhard , it is a surprisingly complex change

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [10 ביוני,‏ 2022,‏ 5:40am UTC](https://meta.discourse.org/t/staff-generated-invites-bypass-the-must-approve-users-requirement/228199/33 "2022-06-10T05:40:44Z")

</div>

This topic was automatically closed after 7 days. New replies are no longer allowed.

[Previous page](https://meta.discourse.org/t/staff-generated-invites-bypass-the-must-approve-users-requirement/228199.md?page=1)
