Skip to content

Article review comments: only the author or a Super Admin deletes one, and the delete is logged (D617) #1314

Description

@guillaumelauzier

S1: Any admin can silently delete any review comment on an article. Decision D617. No migration. Found by #1165's audit (area 7, comment deletion).

What is true on main

  • The route. DELETE /api/admin/articles/comments/:cid (cloudflare-worker/src/routes/admin_articles.ts) checks only requireAdmin, hard-deletes the row, and always answers {ok: true}, even for an id that does not exist.
  • Who loses it. Authors see these comments (routes/articles.ts), so a delete removes the feedback from their view too. Nothing logs it.
  • The alternative. Resolving a comment is the non-destructive path, and it already exists.

The work

  1. Who may delete: the comment's author (author_id), or a Super Admin. Anyone else gets 403 not_your_comment.
  2. An unknown id gets a 404 comment_not_found, never {ok: true}.
  3. Each delete is logged through logAdminAction as article_comment_deleted, with the article and comment ids. The comment's text is not logged.
  4. D617 records the rule.

Files this task owns

  • cloudflare-worker/src/routes/admin_articles.ts (the comment delete only)
  • new Worker tests
  • documentation/architecture/decisions/D617.md

Do not add a Delete control to the review page. Its design is requested on #1165 (area 7, item 4).

Done when

  • Tests cover:
    • the author deletes;
    • a Super Admin deletes;
    • another admin is refused with 403;
    • an unknown id gets a 404;
    • one audit row per delete, without the text.
  • Every new assertion is mutation-checked.

Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    slot:S16Work queue of slot S16state:readyReady for its slot to claim

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions