github / github/platform-samples

Reinviting org members thorugh API does not support reinstating privileges

Open
#388 2 comments 2 reactions 0 assignees View on GitHub
Dominant language
Shell
Stars
2.2k
Forks
1.9k
Avg merge
7d 19h
Merged PRs (30d)
1

Description

https://github.com/github/platform-samples/blob/master/api/powershell/invite_members_to_org.ps1

So through the GUI if you invite users who have been part of the org recently, you get these options to reinstate privileges which is great

![image](https://user-images.githubusercontent.com/21334768/112442021-ab3e9100-8d4b-11eb-9266-53755c41c17a.png)

I checked the network tab and it makes a POST request towards
https://github.com/orgs/equinor/invitations?invitee_id=&role=reinstate

This doesn’t seem to happen / be available when making the call through the API though
https://docs.github.com/en/rest/reference/orgs#create-an-organization-invitation

We tested removing a user, inviting them through the script. The invite works, but the privileges are not reinstated. The person had lost access to their repos + starred equinor repos (assuming this is because he lost repo access, assuming also access to Github teams etc.

Since this isn’t supported through the API call, I assume this also means that the SCIM provisioning which re-invites removed org members also makes them start fresh, which is sub-optimal for our use case.

I’ve also had reports earlier that re-instated members also have had their personal access tokens / ssh keys “lost”, which probably means they mean have been de-authortized from using SSO to the org. I have not verified if or when this happens myself.

Contributor guide

Open the contributing guide

Research direction

Start with api/powershell/invite_members_to_org.ps1 and the linked REST documentation for creating organization invitations. Compare the script/API behavior with the GUI request using role=reinstate, then verify whether reinstated members retain repository and organization access. Done means the supported API path and its effect on reinstated privileges are documented or implemented.

Written by the indexing model from the issue text.

Assessment

Tech stack
github, powershell
Domain
api, authorization
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.