From 45331948c1800cfe67f5a66e65269873d0ba9384 Mon Sep 17 00:00:00 2001 From: Thanakorn Date: Mon, 14 Sep 2026 17:18:42 +0700 Subject: [PATCH] Use absolute URLs in invitation emails --- app/setting/api/engine/manage_users.php | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/app/setting/api/engine/manage_users.php b/app/setting/api/engine/manage_users.php index 34abb3b..606303f 100644 --- a/app/setting/api/engine/manage_users.php +++ b/app/setting/api/engine/manage_users.php @@ -31,7 +31,11 @@ $result = $um->inviteUser($email, $role, $app_access); // Both new and existing users require explicit acceptance via email - $invite_url = rtrim($server_url, '/') . ($result['new_user'] + // Absolute URL: the link is opened from a mail client, where a bare + // /app/... path goes nowhere. Same construction as register.php. + $invite_url = (isset($_SERVER['HTTPS']) && $_SERVER['HTTPS'] === 'on' ? 'https' : 'http') + . '://' . $_SERVER['HTTP_HOST'] + . rtrim($server_url, '/') . ($result['new_user'] ? '/login/invited_onboarding.php?token=' . $result['token'] : '/login/accept_invite.php?token=' . $result['token']); @@ -89,7 +93,11 @@ $map_id = (int)($data['map_id'] ?? 0); $result = $um->resendInvite($map_id); - $invite_url = rtrim($server_url, '/') . ($result['is_new_user'] + // Absolute URL: the link is opened from a mail client, where a bare + // /app/... path goes nowhere. Same construction as register.php. + $invite_url = (isset($_SERVER['HTTPS']) && $_SERVER['HTTPS'] === 'on' ? 'https' : 'http') + . '://' . $_SERVER['HTTP_HOST'] + . rtrim($server_url, '/') . ($result['is_new_user'] ? '/login/invited_onboarding.php?token=' . $result['token'] : '/login/accept_invite.php?token=' . $result['token']);