fix: finalize share API responses and permissions
This commit is contained in:
+11
-9
@@ -132,17 +132,19 @@ export async function deleteCommentAction(
|
||||
try {
|
||||
const author = await requireShareAuthor();
|
||||
const isAdmin = getAdminDiscordIds().includes(author.discordId);
|
||||
const deleted = await db
|
||||
.delete(shareComments)
|
||||
.where(
|
||||
and(
|
||||
const ownership = isAdmin
|
||||
? and(
|
||||
eq(shareComments.id, commentId),
|
||||
eq(shareComments.shareId, shareId)
|
||||
)
|
||||
: and(
|
||||
eq(shareComments.id, commentId),
|
||||
eq(shareComments.shareId, shareId),
|
||||
isAdmin
|
||||
? eq(shareComments.shareId, shareId)
|
||||
: eq(shareComments.authorDiscordId, author.discordId)
|
||||
)
|
||||
)
|
||||
eq(shareComments.authorDiscordId, author.discordId)
|
||||
);
|
||||
const deleted = await db
|
||||
.delete(shareComments)
|
||||
.where(ownership)
|
||||
.returning({ id: shareComments.id });
|
||||
if (deleted.length === 0) {
|
||||
throw new ShareHttpError("Comment not found or forbidden", 404);
|
||||
|
||||
Reference in New Issue
Block a user