diff --git a/server/channels/api4/user_test.go b/server/channels/api4/user_test.go index 356d966d98..2b8146b0dd 100644 --- a/server/channels/api4/user_test.go +++ b/server/channels/api4/user_test.go @@ -6601,6 +6601,25 @@ func TestConvertUserToBot(t *testing.T) { require.NoError(t, err) require.NotNil(t, bot) }) + + t.Run("user cannot login after being converted to bot", func(t *testing.T) { + // Create a new user + user := th.CreateUser() + + // Login as the new user to verify login works initially + _, _, err := th.Client.Login(context.Background(), user.Email, user.Password) + require.NoError(t, err) + + // Convert user to bot + _, _, err = th.SystemAdminClient.ConvertUserToBot(context.Background(), user.Id) + require.NoError(t, err) + + // Try to login again - should fail + _, resp, err := th.Client.Login(context.Background(), user.Email, user.Password) + require.Error(t, err) + CheckErrorID(t, err, "api.user.login.bot_login_forbidden.app_error") + CheckUnauthorizedStatus(t, resp) + }) } func TestGetChannelMembersWithTeamData(t *testing.T) { diff --git a/server/channels/app/bot.go b/server/channels/app/bot.go index abecb70f09..27b5e6ce0c 100644 --- a/server/channels/app/bot.go +++ b/server/channels/app/bot.go @@ -617,6 +617,7 @@ func (a *App) ConvertUserToBot(rctx request.CTX, user *model.User) (*model.Bot, if err := a.RevokeAllSessions(rctx, user.Id); err != nil { return nil, err } + a.InvalidateCacheForUser(user.Id) return bot, nil }