From cb4ae52ece21ce879d6d169992558a55bf349a0f Mon Sep 17 00:00:00 2001 From: Bjarn Bronsveld Date: Fri, 2 Oct 2026 18:28:39 +0200 Subject: [PATCH 1/2] Authorize private note creation --- app/Livewire/Item/Comments.php | 2 ++ tests/Feature/Livewire/Item/CommentsTest.php | 31 ++++++++++++++++++++ 2 files changed, 33 insertions(+) diff --git a/app/Livewire/Item/Comments.php b/app/Livewire/Item/Comments.php index 36ac7772..eeffc45e 100644 --- a/app/Livewire/Item/Comments.php +++ b/app/Livewire/Item/Comments.php @@ -49,6 +49,8 @@ public function submit() ]); if (filled($this->private_content)) { + abort_unless(auth()->user()->hasAdminAccess(), 403); + $formState['content'] = $this->private_content; $formState['private'] = true; } diff --git a/tests/Feature/Livewire/Item/CommentsTest.php b/tests/Feature/Livewire/Item/CommentsTest.php index 67a20d8a..2e658dbc 100644 --- a/tests/Feature/Livewire/Item/CommentsTest.php +++ b/tests/Feature/Livewire/Item/CommentsTest.php @@ -41,3 +41,34 @@ function addVotedCommentThread(Item $item): void expect(countQueriesRenderingComments($item))->toBe($queriesForOneThread); }); + +test('a normal user cannot create a private note through component state', function () { + $user = User::factory()->create(); + $item = Item::factory()->create(); + + $this->actingAs($user); + + Livewire::test(Comments::class, ['item' => $item]) + ->set('content', 'Valid public content') + ->set('private_content', 'Forged private note') + ->call('submit') + ->assertForbidden(); + + expect($item->comments()->where('private', true)->exists())->toBeFalse(); +}); + +test('an administrator can create a private note', function () { + $admin = User::factory()->admin()->create(); + $item = Item::factory()->create(); + + $this->actingAs($admin); + + Livewire::test(Comments::class, ['item' => $item]) + ->set('private_content', 'Authorized private note') + ->call('submit'); + + expect($item->comments() + ->where('content', 'Authorized private note') + ->where('private', true) + ->exists())->toBeTrue(); +}); From 8a93218f51aac4842b5ae28e9c09994fab491ed9 Mon Sep 17 00:00:00 2001 From: Bjarn Bronsveld Date: Fri, 2 Oct 2026 18:38:03 +0200 Subject: [PATCH 2/2] Test private notes for staff roles --- tests/Feature/Livewire/Item/CommentsTest.php | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/tests/Feature/Livewire/Item/CommentsTest.php b/tests/Feature/Livewire/Item/CommentsTest.php index 2e658dbc..329387f7 100644 --- a/tests/Feature/Livewire/Item/CommentsTest.php +++ b/tests/Feature/Livewire/Item/CommentsTest.php @@ -3,6 +3,7 @@ use App\Models\Item; use App\Models\User; use Livewire\Livewire; +use App\Enums\UserRole; use App\Models\Comment; use App\Livewire\Item\Comments; use Illuminate\Support\Facades\DB; @@ -57,11 +58,11 @@ function addVotedCommentThread(Item $item): void expect($item->comments()->where('private', true)->exists())->toBeFalse(); }); -test('an administrator can create a private note', function () { - $admin = User::factory()->admin()->create(); +test('staff can create a private note', function (UserRole $role) { + $staff = User::factory()->create(['role' => $role]); $item = Item::factory()->create(); - $this->actingAs($admin); + $this->actingAs($staff); Livewire::test(Comments::class, ['item' => $item]) ->set('private_content', 'Authorized private note') @@ -71,4 +72,7 @@ function addVotedCommentThread(Item $item): void ->where('content', 'Authorized private note') ->where('private', true) ->exists())->toBeTrue(); -}); +})->with([ + UserRole::Admin, + UserRole::Employee, +]);