github / github/platform-samples

Reinviting org members thorugh API does not support reinstating privileges

Ouverte
#388 2 commentaires 2 réactions 0 personnes assignées Voir sur GitHub
Langage dominant
Shell
Étoiles
2.2k
Forks
1.9k
Merge moyen
7 j 19 h
PR mergées (30 j)
1

Description

https://github.com/github/platform-samples/blob/master/api/powershell/invite_members_to_org.ps1

So through the GUI if you invite users who have been part of the org recently, you get these options to reinstate privileges which is great

![image](https://user-images.githubusercontent.com/21334768/112442021-ab3e9100-8d4b-11eb-9266-53755c41c17a.png)

I checked the network tab and it makes a POST request towards
https://github.com/orgs/equinor/invitations?invitee_id=&role=reinstate

This doesn’t seem to happen / be available when making the call through the API though
https://docs.github.com/en/rest/reference/orgs#create-an-organization-invitation

We tested removing a user, inviting them through the script. The invite works, but the privileges are not reinstated. The person had lost access to their repos + starred equinor repos (assuming this is because he lost repo access, assuming also access to Github teams etc.

Since this isn’t supported through the API call, I assume this also means that the SCIM provisioning which re-invites removed org members also makes them start fresh, which is sub-optimal for our use case.

I’ve also had reports earlier that re-instated members also have had their personal access tokens / ssh keys “lost”, which probably means they mean have been de-authortized from using SSO to the org. I have not verified if or when this happens myself.

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Start with api/powershell/invite_members_to_org.ps1 and the linked REST documentation for creating organization invitations. Compare the script/API behavior with the GUI request using role=reinstate, then verify whether reinstated members retain repository and organization access. Done means the supported API path and its effect on reinstated privileges are documented or implemented.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
github, powershell
Domaine
api, authorization
Type d'issue
Fonctionnalité
Difficulté
5/5
Temps estimé
Plus d'une semaine
Activité
À l'abandon
Clarté
À clarifier
Accessibilité débutants
25/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.