fix: scope comment endpoints to workspace and skip trashed pages

This commit is contained in:
Philipinho
2026-08-24 20:19:43 +01:00
parent dae22d5a42
commit ff28a38c88
@@ -54,7 +54,7 @@ export class CommentController {
@AuthWorkspace() workspace: Workspace,
) {
const page = await this.pageRepo.findById(createCommentDto.pageId);
if (!page || page.deletedAt) {
if (!page || page.workspaceId !== workspace.id || page.deletedAt) {
throw new NotFoundException('Page not found');
}
@@ -89,9 +89,10 @@ export class CommentController {
@Body()
pagination: PaginationOptions,
@AuthUser() user: User,
@AuthWorkspace() workspace: Workspace,
) {
const page = await this.pageRepo.findById(input.pageId);
if (!page) {
if (!page || page.workspaceId !== workspace.id || page.deletedAt) {
throw new NotFoundException('Page not found');
}
@@ -102,14 +103,18 @@ export class CommentController {
@HttpCode(HttpStatus.OK)
@Post('info')
async findOne(@Body() input: CommentIdDto, @AuthUser() user: User) {
async findOne(
@Body() input: CommentIdDto,
@AuthUser() user: User,
@AuthWorkspace() workspace: Workspace,
) {
const comment = await this.commentRepo.findById(input.commentId);
if (!comment) {
throw new NotFoundException('Comment not found');
}
const page = await this.pageRepo.findById(comment.pageId);
if (!page) {
if (!page || page.workspaceId !== workspace.id || page.deletedAt) {
throw new NotFoundException('Page not found');
}
@@ -130,7 +135,7 @@ export class CommentController {
}
const page = await this.pageRepo.findById(comment.pageId);
if (!page) {
if (!page || page.workspaceId !== workspace.id || page.deletedAt) {
throw new NotFoundException('Page not found');
}
@@ -148,7 +153,7 @@ export class CommentController {
}
const page = await this.pageRepo.findById(comment.pageId);
if (!page) {
if (!page || page.workspaceId !== workspace.id || page.deletedAt) {
throw new NotFoundException('Page not found');
}