What — When user-facing invitations are enabled, an invite token should be claimed and finalized at signup even if public signup is open.
Why — Today the server never claims/finalizes an invite token while public signup is open (#3833 guard), so on deployments with open signup the referral loop can never convert — invitations go out, rewards never land.
Scope
Refs: #3945 (user-facing abilities), #3833 (guards stay).
Scope: validated 2026-07-24
Created via /dev:issue
What — When user-facing invitations are enabled, an invite token should be claimed and finalized at signup even if public signup is open.
Why — Today the server never claims/finalizes an invite token while public signup is open (#3833 guard), so on deployments with open signup the referral loop can never convert — invitations go out, rewards never land.
Scope
invitations.userFacing === true: the signup flow accepts an invite token (email-pinned, single-use, expiry, self-referral guard 🔒 GATE for referral phase (#5): /api/invitations must be invitedBy-scoped for non-admins (+ self-referral guard, open-signup note) #3833 all stay enforced) and finalizes the invitation —invitation.accepted+invitation_redeemed+ referral reward fire as in closed-signup mode.userFacing: false(default) keeps today's behavior unchanged.invitations.userFacinginGET /api/auth/config(same pattern assign.upand billing flags) so the frontend can gate referral UI on it.Refs: #3945 (user-facing abilities), #3833 (guards stay).
Scope: validated 2026-07-24
Created via /dev:issue