Skip to content

Better authorize comment actions - #361

Merged
Cannonb4ll merged 2 commits into
ploi:mainfrom
stayallive:feature/fix-auth-bypass
Sep 28, 2026
Merged

Cannonb4ll merged 2 commits into
ploi:mainfrom
stayallive:feature/fix-auth-bypass

Conversation

@stayallive

Copy link
Copy Markdown
Contributor

There are some issues with comment authorizations.

Fixes #340.

stayallive and others added 2 commits September 28, 2026 11:56
Main moved replies to an inline editor that uses the server-bound comment and item,
so the argument-based reply lookup is no longer needed. The edit action still takes
a client-supplied comment id, so it keeps the ownership check and profanity rule.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Cannonb4ll
Cannonb4ll merged commit 03f8ca7 into ploi:main Sep 28, 2026
3 checks passed
@stayallive
stayallive deleted the feature/fix-auth-bypass branch September 28, 2026 10:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Authorization bypass: replyAction() in Comment Livewire component bypasses item visibility

2 participants