fix: finalize share API responses and permissions

This commit is contained in:
2026-08-16 01:06:38 +07:00 Unverified
parent c5357795bb
commit 5c8ab1c9bf
2 changed files with 16 additions and 11 deletions
+11 -9
View File
@@ -132,17 +132,19 @@ export async function deleteCommentAction(
try {
const author = await requireShareAuthor();
const isAdmin = getAdminDiscordIds().includes(author.discordId);
const deleted = await db
.delete(shareComments)
.where(
and(
const ownership = isAdmin
? and(
eq(shareComments.id, commentId),
eq(shareComments.shareId, shareId)
)
: and(
eq(shareComments.id, commentId),
eq(shareComments.shareId, shareId),
isAdmin
? eq(shareComments.shareId, shareId)
: eq(shareComments.authorDiscordId, author.discordId)
)
)
eq(shareComments.authorDiscordId, author.discordId)
);
const deleted = await db
.delete(shareComments)
.where(ownership)
.returning({ id: shareComments.id });
if (deleted.length === 0) {
throw new ShareHttpError("Comment not found or forbidden", 404);
+5 -2
View File
@@ -36,6 +36,7 @@ export async function POST(request: Request) {
if (!hasValidBearerToken(request)) {
throw new ShareHttpError("Unauthorized", 401);
}
const baseUrl = getCanonicalUrl();
await enforceShareRateLimit({
key: "bot:global",
@@ -93,7 +94,7 @@ export async function POST(request: Request) {
avatarUrl: profile.avatarUrl,
},
});
const url = `${getCanonicalUrl()}/share/${share.id}`;
const url = `${baseUrl}/share/${share.id}`;
return Response.json(
{
@@ -105,7 +106,9 @@ export async function POST(request: Request) {
displayName,
avatarUrl: profile.avatarUrl,
},
imageUrl: cdnUrl(share.imageCdnId) || null,
imageUrl: share.imageCdnId
? `${baseUrl}${cdnUrl(share.imageCdnId)}`
: null,
createdAt: share.createdAt.toISOString(),
},
},