fix(news): enforce shared comment publication and moderation rules
This commit is contained in:
1 parent
8aefb415b6
commit
fe34d4ac93
7 files changed
+554
-126
No files matched your search
@@ -28,4 +28,4 @@ The additional `withNitroStaff` code and its tests mentioned in the supplied por
|
||||
|
||||
## Follow-up identified during verification
|
||||
|
||||
The article-comment REST endpoint needs a separate review of publication visibility and moderation parity with the website form. This was discovered while enumerating bearer consumers; it is not silently treated as covered by the supplied review.
|
||||
The separate comment review is now implemented: both the website form and REST API use one submission service, require a published article whose publication time is due, apply the same moderation, and share a five-attempt/30-second per-user quota. The publication check locks the current article in the insertion transaction. Regression tests cover both entrypoints; real MariaDB/Redis coverage includes publication eligibility, word filtering and alternating submissions. Moderation retains its existing fail-open behavior on service outages. Form input beyond 255 characters is now rejected instead of truncated, and temporary API storage failures return 503. Real integration execution remains a required CI check.
|
||||
Reference in new issue
Block a user