Files
supabase/apps/studio/components/interfaces/OrganizationInvite/OrganizationInvite.tsx
Joshen LimandAlaister Young 37b072aac2 Improve UI for org invites if MFA is enforced (#47067)
## Context

When opening an invite to join an organization that's enforced MFA for
their members, if a member does not have MFA enabled yet, they'll see
this UI which is confusing as there's no clear direction on what to do
<img width="500" alt="image"
src="https://github.com/user-attachments/assets/ca2d1047-20bf-40ca-a9ea-91e81c390e40"
/>

## Changes involved
- Updating the UI to consider this error message and prompt users to set
up MFA
<img width="501" height="317" alt="image"
src="https://github.com/user-attachments/assets/d074ac6d-fd74-4fe0-9078-473fd2401045"
/>
- Small UI nudges to account security page
  - Tight copywriting to explicitly say MFA
- Opt to use Card instead of Collapsible (collapsible seems unnecessary
given that this is the only UI on this page)
  - Before:
<img width="811" height="360" alt="image"
src="https://github.com/user-attachments/assets/1412da3b-3903-4966-85ea-46e0ff443177"
/>
  - After:
<img width="817" height="370" alt="image"
src="https://github.com/user-attachments/assets/02d5a2f5-8c1f-4f78-8a20-10c7a4ff563c"
/>
- Tiny change to the user dropdown, say "account" instead of "account
preferences" + change icon
- This imo aligns better as the account page covers more than just
preferences
  - Before:
<img width="307" height="178" alt="image"
src="https://github.com/user-attachments/assets/fea43cac-9b0c-4fe4-94a3-946ed0925901"
/>
  - After:
<img width="300" height="183" alt="image"
src="https://github.com/user-attachments/assets/800357fe-222f-49b8-b52b-ce4fabff7b95"
/>

## To test
- [ ] Have an organization on paid plan with MFA enforced
- [ ] Invite a user that doesn't have MFA enabled
- [ ] Try to join the organization with that user

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Organization invites now detect and handle MFA requirements with
specific error messaging
* Redesigned Multi-factor authentication section on account security
page

* **Improvements**
  * Updated TOTP authenticator help text for clarity
  * Updated account menu navigation label

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <alaister@users.noreply.github.com>
2026-06-18 18:50:40 +08:00

202 lines
6.1 KiB
TypeScript

import { useIsLoggedIn, useParams } from 'common'
import Link from 'next/link'
import { useRouter } from 'next/router'
import type { ReactNode } from 'react'
import { toast } from 'sonner'
import { Button, Card, CardContent } from 'ui'
import { Admonition, ShimmeringLoader } from 'ui-patterns'
import {
getOrganizationInviteContent,
getOrganizationInviteStatus,
} from './OrganizationInvite.utils'
import { OrganizationInviteError } from './OrganizationInviteError'
import {
InterstitialAccountRow,
InterstitialLayout,
SupabaseLogo,
} from '@/components/layouts/InterstitialLayout'
import { useOrganizationAcceptInvitationMutation } from '@/data/organization-members/organization-invitation-accept-mutation'
import { useOrganizationInvitationTokenQuery } from '@/data/organization-members/organization-invitation-token-query'
import { useIsFeatureEnabled } from '@/hooks/misc/useIsFeatureEnabled'
import { useProfile, useProfileNameAndPicture } from '@/lib/profile'
export const OrganizationInvite = () => {
const router = useRouter()
const isLoggedIn = useIsLoggedIn()
const { profile, isLoading: isLoadingProfile } = useProfile()
const { username, avatarUrl, primaryEmail } = useProfileNameAndPicture()
const { slug, token } = useParams()
const isSignUpEnabled = useIsFeatureEnabled('dashboard_auth:sign_up')
const {
data,
error,
isSuccess: isSuccessInvitation,
isError: isErrorInvitation,
isPending: isLoadingInvitation,
} = useOrganizationInvitationTokenQuery(
{ slug, token },
{
retry: false,
refetchOnWindowFocus: false,
enabled: !!profile && !!slug && !!token,
}
)
const inviteStatus = getOrganizationInviteStatus({
data,
error,
isErrorInvitation,
isLoadingInvitation,
isLoadingProfile,
isLoggedIn,
isRouterReady: router.isReady,
isSuccessInvitation,
profileExists: !!profile,
})
const isSignedOut = inviteStatus === 'signed-out'
const isInvitationLoading = inviteStatus === 'loading'
const inviteContent = getOrganizationInviteContent({
data,
error,
isSignUpEnabled,
status: inviteStatus,
})
const hasError = ['wrong-account', 'expired', 'invalid', 'error'].includes(inviteStatus)
const loginRedirectLink = `/sign-in?returnTo=${encodeURIComponent(`/join?token=${token}&slug=${slug}`)}`
const signupRedirectLink = `/sign-up?returnTo=${encodeURIComponent(`/join?token=${token}&slug=${slug}`)}`
const mfaRequiredError = error?.message.includes('MFA required')
const { mutate: joinOrganization, isPending: isJoining } =
useOrganizationAcceptInvitationMutation({
onSuccess: () => {
router.push('/organizations')
},
onError: (error) => {
toast.error(`Failed to join organization: ${error.message}`)
},
})
async function handleJoinOrganization() {
if (!slug) return console.error('Slug is required')
if (!token) return console.error('Token is required')
joinOrganization({ slug, token })
}
const withLayout = (children: ReactNode) => (
<InterstitialLayout
logo={<SupabaseLogo />}
titleClassName="text-xl"
title={
isInvitationLoading ? (
<ShimmeringLoader className="mx-auto h-7 w-36 max-w-full py-0" />
) : (
inviteContent.title
)
}
description={
isInvitationLoading ? (
<ShimmeringLoader className="mx-auto h-4 w-48 max-w-full py-0" />
) : (
inviteContent.description
)
}
>
<div className="px-6 pb-6">{children}</div>
</InterstitialLayout>
)
if (isSignedOut) {
return withLayout(
<div className="flex flex-col gap-2">
<Button asChild variant="primary" block>
<Link href={loginRedirectLink}>Sign in</Link>
</Button>
{isSignUpEnabled && (
<Button asChild variant="default" block>
<Link href={signupRedirectLink}>Create an account</Link>
</Button>
)}
</div>
)
}
if (isInvitationLoading) {
return withLayout(
<div className="flex flex-col gap-6">
<Card className="shadow-none">
<CardContent className="flex items-center gap-3 border-none px-4 py-3">
<ShimmeringLoader className="size-8 flex-shrink-0 rounded-full py-0" />
<div className="min-w-0 flex-1 space-y-2">
<ShimmeringLoader className="h-3 w-20 py-0" />
<ShimmeringLoader className="h-4 w-40 max-w-full py-0" />
</div>
</CardContent>
</Card>
<div className="flex flex-col gap-2">
<ShimmeringLoader className="h-10 w-full py-0" />
<ShimmeringLoader className="h-10 w-full py-0" />
</div>
</div>
)
}
if (inviteStatus === 'no-longer-valid') {
return withLayout(
<div className="flex flex-col gap-3">
<Admonition
type="warning"
description="This invite has already been accepted or declined."
/>
<Button variant="default" block asChild>
<Link href="/">Back to dashboard</Link>
</Button>
</div>
)
}
if (mfaRequiredError) {
return withLayout(
<div className="flex flex-col gap-3">
<Button variant="default" block asChild>
<Link href="/account/security">Go to account settings</Link>
</Button>
</div>
)
}
if (hasError) {
return withLayout(
<OrganizationInviteError
data={data}
error={error}
isError={isErrorInvitation}
isInvalidInvite={inviteStatus === 'invalid'}
/>
)
}
return withLayout(
<div className="flex flex-col gap-6">
<InterstitialAccountRow avatarUrl={avatarUrl} displayName={primaryEmail ?? username ?? ''} />
<div className="flex flex-col gap-2">
<Button
variant="primary"
block
loading={isJoining}
disabled={isJoining}
onClick={handleJoinOrganization}
>
Accept invite
</Button>
<Button asChild variant="text" block>
<Link href="/projects">Decline</Link>
</Button>
</div>
</div>
)
}