Skip to content

Fix private comment and reply visibility - #10348

Open
ruibaby wants to merge 4 commits into
halo-dev:mainfrom
ruibaby:fix/comment-reply-privacy
Open

ruibaby wants to merge 4 commits into
halo-dev:mainfrom
ruibaby:fix/comment-reply-privacy

Conversation

@ruibaby

@ruibaby ruibaby commented Sep 25, 2026

Copy link
Copy Markdown
Member

What type of PR is this?

  • Feature
  • Bug fix
  • Improvement
  • Cleanup
  • Documentation

What this PR does / why we need it:

A requested private reply was overwritten by its parent comment's visibility during creation. The Console also lacked controls to change comment and reply privacy, and public reply lists could expose replies beneath an unapproved parent comment.

This PR preserves the requested private state while inheriting privacy from a parent comment or quoted reply. It adds private reply controls, privacy labels and toggle actions in the Console, and applies parent visibility checks to public reply queries. The original comment author can view approved private replies after signing in.

Before the fix, create an approved public comment and submit a Console reply with hidden: true: the saved reply has hidden: false. An anonymous request for replies beneath an unapproved comment could also return an approved child reply. After the fix, the private reply remains hidden, and anonymous reply lists, direct lookup, and comment trees exclude content they cannot view.

Which issue(s) this PR fixes:

N/A

Special notes for your reviewer:

  • Coverage includes mixed public, private, and pending replies; pagination; comment authors and unrelated users; moderators; parent visibility changes; and anonymous access to public, Console, and raw extension APIs.
  • This PR was prepared with LLM assistance. The changed code was reviewed and verified with automated tests and a running Halo instance.
  • Validation: :application:test (2,059 passed), :application:spotlessJavaCheck, pnpm -C ui test:unit, pnpm -C ui typecheck, pnpm -C ui build, pnpm -C ui lint, and git diff --check. Console privacy toggling and anonymous API responses were also checked against a local service.

Does this PR introduce a user-facing change?

评论管理支持将评论和回复设为私密,并可在创建回复时选择私密回复。私密回复不会向公众显示。

@codecov

codecov Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 94.66667% with 4 lines in your changes missing coverage. Please review.
✅ Project coverage is 67.31%. Comparing base (42c374d) to head (5f1fd64).
⚠️ Report is 809 commits behind head on main.

Files with missing lines Patch % Lines
...nt/comment/CommentNotificationReasonPublisher.java 89.47% 0 Missing and 2 partials ⚠️
...run/halo/app/content/comment/ReplyServiceImpl.java 80.00% 0 Missing and 1 partial ⚠️
...me/finders/impl/CommentPublicQueryServiceImpl.java 97.82% 0 Missing and 1 partial ⚠️
Additional details and impacted files
@@             Coverage Diff              @@
##               main   #10348      +/-   ##
============================================
+ Coverage     59.55%   67.31%   +7.75%     
- Complexity     3812     5431    +1619     
============================================
  Files           677      769      +92     
  Lines         23248    27298    +4050     
  Branches       1500     1935     +435     
============================================
+ Hits          13846    18376    +4530     
+ Misses         8764     8001     -763     
- Partials        638      921     +283     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Comment thread application/src/main/java/run/halo/app/extension/index/query/QueryVisitor.java Outdated
@sonarqubecloud

Copy link
Copy Markdown

@ruibaby
ruibaby requested a review from JohnNiang September 29, 2026 10:05

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants