ConversationsRepo (M2-005): added userId to findById, update, remove, findMessages, and addMessage so every query includes AND userId = ? in the WHERE clause — ownership enforced at the DB level.
AgentsRepo (M2-006): added ownerId to remove (required) and update (optional, omitted for admin system-agent path) so DELETE/UPDATE WHERE clause scopes to the requesting user's agents.
Controller call sites updated to pass userId/ownerId to the repo methods.
Existing resource-ownership unit test updated: findById returns undefined for cross-user access, controller raises 404.
All 134 gateway tests pass; typecheck, lint, and format:check green.
Test plan
All existing unit tests pass (134/134)
pnpm typecheck green
pnpm lint green
pnpm format:check green
Generated with Claude Code
## Summary
- ConversationsRepo (M2-005): added userId to findById, update, remove, findMessages, and addMessage so every query includes AND userId = ? in the WHERE clause — ownership enforced at the DB level.
- AgentsRepo (M2-006): added ownerId to remove (required) and update (optional, omitted for admin system-agent path) so DELETE/UPDATE WHERE clause scopes to the requesting user's agents.
- Controller call sites updated to pass userId/ownerId to the repo methods.
- Existing resource-ownership unit test updated: findById returns undefined for cross-user access, controller raises 404.
- All 134 gateway tests pass; typecheck, lint, and format:check green.
## Test plan
- All existing unit tests pass (134/134)
- pnpm typecheck green
- pnpm lint green
- pnpm format:check green
Generated with Claude Code
ConversationsRepo: add userId parameter to findById, update, remove, findMessages,
and addMessage so every query filters by conversations.userId in the WHERE clause.
This prevents cross-user data access even if the controller layer were bypassed.
AgentsRepo: add optional ownerId parameter to update (enforced for user-owned agents,
omitted for admin system-agent path) and required ownerId to remove so the DELETE
WHERE clause always scopes to the requesting user's agents.
Controller call sites updated to pass userId/ownerId to the repo methods. The
resource-ownership unit test updated to reflect that findById now returns undefined
(not a foreign-user object) when ownership is checked at the DB layer.
Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Test plan
Generated with Claude Code