diff --git a/app/Livewire/Item/Comments.php b/app/Livewire/Item/Comments.php index 9480d878..b75642a5 100644 --- a/app/Livewire/Item/Comments.php +++ b/app/Livewire/Item/Comments.php @@ -51,6 +51,8 @@ public function submit() ]); if (filled($this->private_content)) { + abort_unless(auth()->user()->hasAdminAccess(), 403); + $formState['content'] = $this->private_content; $formState['private'] = true; } diff --git a/tests/Feature/Livewire/Item/CommentsTest.php b/tests/Feature/Livewire/Item/CommentsTest.php index 2c740290..6c4c82ae 100644 --- a/tests/Feature/Livewire/Item/CommentsTest.php +++ b/tests/Feature/Livewire/Item/CommentsTest.php @@ -4,6 +4,7 @@ use App\Models\User; use App\Models\Board; use Livewire\Livewire; +use App\Enums\UserRole; use App\Models\Comment; use App\Models\Project; use App\Livewire\Item\Comments; @@ -62,3 +63,37 @@ function addVotedCommentThread(Item $item): void expect($item->comments()->where('content', 'Blocked comment')->exists())->toBeFalse(); }); + +test('a normal user cannot create a private note through component state', function () { + $user = User::factory()->create(); + $item = Item::factory()->create(); + + $this->actingAs($user); + + Livewire::test(Comments::class, ['item' => $item]) + ->set('content', 'Valid public content') + ->set('private_content', 'Forged private note') + ->call('submit') + ->assertForbidden(); + + expect($item->comments()->where('private', true)->exists())->toBeFalse(); +}); + +test('staff can create a private note', function (UserRole $role) { + $staff = User::factory()->create(['role' => $role]); + $item = Item::factory()->create(); + + $this->actingAs($staff); + + Livewire::test(Comments::class, ['item' => $item]) + ->set('private_content', 'Authorized private note') + ->call('submit'); + + expect($item->comments() + ->where('content', 'Authorized private note') + ->where('private', true) + ->exists())->toBeTrue(); +})->with([ + UserRole::Admin, + UserRole::Employee, +]);