Tencent/WeKnora · error

member limit cannot be lower than current member count

Error message

member limit cannot be lower than current member count

What it means

Sentinel ErrOrgMemberLimitTooLow returned by org update when the new MemberLimit is smaller than the current member count — shrinking the cap below existing membership is rejected. The handler surfaces it as a validation error (400).

Source

Thrown at internal/application/service/organization.go:37

const DefaultInviteCodeValidityDays = 7

// DefaultMemberLimit is the default max tenant-members per organization (0 = unlimited)
const DefaultMemberLimit = 200

// ValidInviteCodeValidityDays are the allowed values for invite_code_validity_days
var ValidInviteCodeValidityDays = map[int]bool{0: true, 1: true, 7: true, 30: true}

var (
	ErrOrgNotFound           = errors.New("organization not found")
	ErrOrgPermissionDenied   = errors.New("permission denied for this organization")
	ErrCannotRemoveOwner     = errors.New("cannot remove organization owner tenant")
	ErrCannotChangeOwnerRole = errors.New("cannot change organization owner tenant role")
	ErrTenantNotInOrg        = errors.New("tenant is not a member of this organization")
	ErrInvalidRole           = errors.New("invalid role")
	ErrInviteCodeExpired     = errors.New("invite code has expired")
	ErrInvalidValidityDays   = errors.New("invite_code_validity_days must be 0, 1, 7, or 30")
	ErrOrgMemberLimitReached = errors.New("organization member limit reached")
	ErrOrgMemberLimitTooLow  = errors.New("member limit cannot be lower than current member count")
)

// organizationService implements OrganizationService.
//
// Plan 3 of #1303: a "member" of an org is a tenant, identified by
// (org_id, tenant_id). The user_id of the requester is recorded only as
// the representative for UI/audit; permission decisions ride on the
// tenant's role inside the org.
type organizationService struct {
	orgRepo        interfaces.OrganizationRepository
	userRepo       interfaces.UserRepository
	shareRepo      interfaces.KBShareRepository
	agentShareRepo interfaces.AgentShareRepository
}

// NewOrganizationService creates a new organization service
func NewOrganizationService(
	orgRepo interfaces.OrganizationRepository,

View on GitHub (pinned to 988cbb0330)

Solutions

  1. Set MemberLimit to at least the current member count
  2. Remove members first if a lower limit is genuinely required
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at internal/application/service/organization.go:37 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of Tencent/WeKnora@988cbb0330 (2026-09-02). Data as JSON: /api/errors/16c621b9b8d38d7a. Report an issue: GitHub.