diff --git a/app/actions/share.ts b/app/actions/share.ts index eed8f39..a378f44 100644 --- a/app/actions/share.ts +++ b/app/actions/share.ts @@ -132,17 +132,19 @@ export async function deleteCommentAction( try { const author = await requireShareAuthor(); const isAdmin = getAdminDiscordIds().includes(author.discordId); - const deleted = await db - .delete(shareComments) - .where( - and( + const ownership = isAdmin + ? and( + eq(shareComments.id, commentId), + eq(shareComments.shareId, shareId) + ) + : and( eq(shareComments.id, commentId), eq(shareComments.shareId, shareId), - isAdmin - ? eq(shareComments.shareId, shareId) - : eq(shareComments.authorDiscordId, author.discordId) - ) - ) + eq(shareComments.authorDiscordId, author.discordId) + ); + const deleted = await db + .delete(shareComments) + .where(ownership) .returning({ id: shareComments.id }); if (deleted.length === 0) { throw new ShareHttpError("Comment not found or forbidden", 404); diff --git a/app/api/share/route.ts b/app/api/share/route.ts index 39c1435..a0b33fc 100644 --- a/app/api/share/route.ts +++ b/app/api/share/route.ts @@ -36,6 +36,7 @@ export async function POST(request: Request) { if (!hasValidBearerToken(request)) { throw new ShareHttpError("Unauthorized", 401); } + const baseUrl = getCanonicalUrl(); await enforceShareRateLimit({ key: "bot:global", @@ -93,7 +94,7 @@ export async function POST(request: Request) { avatarUrl: profile.avatarUrl, }, }); - const url = `${getCanonicalUrl()}/share/${share.id}`; + const url = `${baseUrl}/share/${share.id}`; return Response.json( { @@ -105,7 +106,9 @@ export async function POST(request: Request) { displayName, avatarUrl: profile.avatarUrl, }, - imageUrl: cdnUrl(share.imageCdnId) || null, + imageUrl: share.imageCdnId + ? `${baseUrl}${cdnUrl(share.imageCdnId)}` + : null, createdAt: share.createdAt.toISOString(), }, },