Skip to content

Redirect instead of a 500 when the waiting-list entry is already gone - #2998

Open
mroderick wants to merge 1 commit into
codebar:masterfrom
mroderick:fix/waiting-list-destroy-missing-entry
Open

mroderick wants to merge 1 commit into
codebar:masterfrom
mroderick:fix/waiting-list-destroy-missing-entry

Conversation

@mroderick

@mroderick mroderick commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Removing a waiting-list entry that no longer exists rendered a 500. This PR guards the lookup in WaitingListsController#destroy and redirects with a notice instead.

One of five small PRs from the same pre-existing-gap audit against this flow. Heads are reviewed independently; if a sibling merges first expect a trivial rebase, the branches touch different regions of the same spec files.

Detail

WaitingListsController#destroy calls .destroy on WaitingList.find_by(invitation_id: @invitation.id), which is nil when the entry is already gone — reachable by replaying a "Remove from the waiting list" link (double-click, or a bookmarked token URL after the entry was consumed by a promotion). A consumed entry is more likely after the promotion fix lands, since promotions destroy the next entry in the reject flow.

Now: no entry means redirect to the invitation page with notice "You are not on the waiting list", and no waiting_list.left activity recorded.

Review notes
  • The notice text is a literal, matching this controller's existing style ("You have been removed from the waiting list").
  • Param name is invitation_id, which carries the invitation token: the token is still the only credential, unchanged.

Sibling PRs:

WaitingListsController#destroy calls destroy on
WaitingList.find_by(invitation_id: @invitation.id), which is nil when the
entry no longer exists. The case is reachable by replaying a stale
Remove-from-the-waiting-list link (double-click, or a bookmarked token
URL after the entry was consumed), and currently renders a 500.

Guard the lookup: redirect with a notice when the entry is gone, and
record no waiting_list.left activity.
@mroderick
mroderick force-pushed the fix/waiting-list-destroy-missing-entry branch from d1fbd40 to 2834634 Compare October 9, 2026 06:55
@mroderick
mroderick marked this pull request as ready for review October 9, 2026 06:58

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant