mirror of
https://github.com/mattermost/mattermost.git
synced 2026-08-27 05:37:15 -05:00
* [MM-69895] Delete bot access tokens on permanent bot deletion App.PermanentDeleteBot removed the bot and user rows but left the bot's UserAccessToken rows (and their sessions) orphaned, since the UserAccessTokens table has no FK cascade to Users. Call UserAccessToken().DeleteAllForUser to match PermanentDeleteUser. Co-authored-by: mattermost-code <matty-code@mattermost.com> * [MM-69895] Strengthen bot access token deletion regression test Assert specific not-found errors, cover sessions for every bot token, and add a control bot to prove deletion is scoped to the deleted bot. Co-authored-by: mattermost-code <matty-code@mattermost.com> * [MM-69895] Assert not-found status on deleted bot tokens Co-authored-by: mattermost-code <matty-code@mattermost.com> * [MM-69895] Clear session cache when permanently deleting a bot Deleting the access token rows via DeleteAllForUser is plain SQL and never clears the in-memory session cache, so the bot's tokens kept authenticating after PermanentDeleteBot. Mirror PermanentDeleteUser: delete sessions, delete tokens, then clear the session cache (which also broadcasts to the cluster). --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: mattermost-code <matty-code@mattermost.com>