fix(news): enforce shared comment publication and moderation rules
CI / check (push) Failing after 1m46s
CI / deploy (push) Skipped
CI / publish-container (push) Skipped

This commit is contained in:
Simo committed 2026-09-13 20:14:32 +02:00
1 parent 8aefb415b6
commit fe34d4ac93
7 files changed
+554 -126

No files matched your search

+39 -75
View File
@@ -1,15 +1,11 @@
"use server";
import { eq } from "drizzle-orm";
import { revalidatePath } from "next/cache";
import { redirect } from "next/navigation";
import { auth } from "@/lib/auth";
import { db, WebsiteArticleComments, WebsiteArticles } from "@/lib/db";
import { clientIp, rateLimit } from "@/lib/rate-limit";
import { isAllowed } from "@/lib/services/moderation";
// website_article_comments.comment is VARCHAR(255); keep the write within bounds.
const COMMENT_MAX = 255;
import { sessionUserId } from "@/lib/auth/session-user";
import { logger } from "@/lib/logger";
import { submitArticleComment } from "@/lib/services/article-comment-submission";
type CommentOutcome =
| "posted"
@@ -31,86 +27,54 @@ function isNextRedirect(e: unknown): boolean {
!!e &&
typeof e === "object" &&
"digest" in e &&
typeof (e as { digest?: unknown }).digest === "string" &&
(e as { digest: string }).digest.startsWith("NEXT_REDIRECT")
typeof e.digest === "string" &&
e.digest.startsWith("NEXT_REDIRECT")
);
}
/**
* Post a comment on a news article as the SIGNED-IN user. The author id is read
* from the session (re-fetched via auth()), never from the submitted FormData,
* so a crafted form cannot post as another account. The articleId comes from the
* form and is validated as a BigInt (website_articles.id is UNSIGNED BIGINT).
*
* Errors redirect back with a machine-readable ?error= code; success redirects
* with ?comment=posted.
*/
/** The signed-in session determines ownership; form-supplied author IDs are ignored. */
export async function postComment(formData: FormData): Promise<void> {
const slugHint = String(formData.get("slug") ?? "")
let slug = String(formData.get("slug") ?? "")
.normalize("NFC")
.trim();
let outcome: CommentOutcome = "error";
let slug = slugHint;
try {
const session = await auth();
if (!session?.user?.id) {
redirect("/login");
}
const userId = Number(session.user.id);
if (!Number.isFinite(userId) || userId <= 0) {
redirect("/login");
}
await clientIp();
if (!(await rateLimit(`comment:${userId}`, 5, 30_000)).ok) {
outcome = "ratelimit";
} else {
const comment = String(formData.get("comment") ?? "")
.normalize("NFC")
.trim()
.slice(0, COMMENT_MAX);
if (!comment) {
outcome = "empty";
} else if (!(await isAllowed(comment)).ok) {
outcome = "moderated";
} else {
const articleIdRaw = String(formData.get("articleId") ?? "")
const userId = sessionUserId(session?.user?.id);
if (!userId) redirect("/login");
const result = await submitArticleComment({
userId,
target: {
id: String(formData.get("articleId") ?? "")
.normalize("NFC")
.trim();
if (!/^\d+$/.test(articleIdRaw)) {
outcome = "invalid";
} else {
const articleId = BigInt(articleIdRaw);
const [article] = await db
.select({ slug: WebsiteArticles.slug })
.from(WebsiteArticles)
.where(eq(WebsiteArticles.id, articleId))
.limit(1);
if (!article) {
outcome = "not_found";
} else {
slug = article.slug;
const now = new Date();
await db.insert(WebsiteArticleComments).values({
articleId,
userId,
comment,
createdAt: now,
updatedAt: now,
});
outcome = "posted";
}
}
}
.trim(),
},
comment: formData.get("comment"),
});
if (result.ok) {
slug = result.slug;
outcome = "posted";
} else {
outcome = result.reason === "too_long" ? "invalid" : result.reason;
}
} catch (e) {
if (isNextRedirect(e)) throw e;
outcome = "error";
} catch (error) {
if (isNextRedirect(error)) throw error;
// Driver errors can include SQL and comment text: retain only safe context.
logger.error("Article comment submission failed", {
module: "article-comments",
channel: "site",
});
}
if (slug) revalidatePath(`/news/${slug}`);
if (outcome === "posted") {
try {
revalidatePath(`/news/${slug}`);
} catch {
logger.error("Article comment refresh failed", {
module: "article-comments",
channel: "site",
});
}
}
commentRedirect(slug, outcome);
}