From c4c4caa0955ea5d08334a2b6288c9d2a8bec3536 Mon Sep 17 00:00:00 2001 From: Bjarn Bronsveld Date: Fri, 2 Oct 2026 18:28:39 +0200 Subject: [PATCH] Enforce board comment restrictions --- app/Livewire/Item/Comments.php | 2 ++ tests/Feature/Livewire/Item/CommentsTest.php | 21 ++++++++++++++++++++ 2 files changed, 23 insertions(+) diff --git a/app/Livewire/Item/Comments.php b/app/Livewire/Item/Comments.php index 36ac7772..9480d878 100644 --- a/app/Livewire/Item/Comments.php +++ b/app/Livewire/Item/Comments.php @@ -36,6 +36,8 @@ public function submit() return redirect()->route('login'); } + abort_if($this->item->board?->block_comments, 403); + if (app(GeneralSettings::class)->users_must_verify_email && !auth()->user()->hasVerifiedEmail()) { Notification::make() ->title('Reply') diff --git a/tests/Feature/Livewire/Item/CommentsTest.php b/tests/Feature/Livewire/Item/CommentsTest.php index 67a20d8a..2c740290 100644 --- a/tests/Feature/Livewire/Item/CommentsTest.php +++ b/tests/Feature/Livewire/Item/CommentsTest.php @@ -2,8 +2,10 @@ use App\Models\Item; use App\Models\User; +use App\Models\Board; use Livewire\Livewire; use App\Models\Comment; +use App\Models\Project; use App\Livewire\Item\Comments; use Illuminate\Support\Facades\DB; @@ -41,3 +43,22 @@ function addVotedCommentThread(Item $item): void expect(countQueriesRenderingComments($item))->toBe($queriesForOneThread); }); + +test('a user cannot comment when the board blocks comments', function () { + $user = User::factory()->create(); + $project = Project::factory()->create(); + $board = Board::factory()->for($project)->create(['block_comments' => true]); + $item = Item::factory()->create([ + 'project_id' => $project->id, + 'board_id' => $board->id, + ]); + + $this->actingAs($user); + + Livewire::test(Comments::class, ['item' => $item]) + ->set('content', 'Blocked comment') + ->call('submit') + ->assertForbidden(); + + expect($item->comments()->where('content', 'Blocked comment')->exists())->toBeFalse(); +});