fix: Ensure bot can only read messages from rooms it is a member of

Added explicit RecordNotFound handling to return 404 when a bot tries to
read messages from a room it's not a member of. This matches the security
model used by the create action.

Added tests to verify:
- Bot gets 404 when trying to read from room it's not a member of
- Bot can successfully read from room it IS a member of

Co-authored-by: openhands <openhands@all-hands.dev>
This commit is contained in:
John-Mason Shackelford
2026-04-08 13:56:02 -04:00
parent d4a56784e0
commit 5340f3da01
2 changed files with 16 additions and 0 deletions
@@ -5,6 +5,8 @@ class Messages::ByBotsController < MessagesController
set_room
@messages = find_paged_messages
render json: messages_as_json(@messages)
rescue ActiveRecord::RecordNotFound
head :not_found
end
def create