trackslash

Description

Second step of TRACK-89. Comments gain a visibility: shared (anyone who can read the issue) or members (project members only: owner, members, read-only members and admins).

  • Migration: existing comments become shared, so nothing that is visible today disappears.
  • Default for new comments: members in a help-desk project, so nothing is shared by accident. shared elsewhere, which keeps today's behaviour in public projects.
  • Setting it:
    • UI: the comment composer and the comment edit form get a visibility choice, and members-only comments carry a badge.
    • REST: create and update take visibility.
    • MCP: track_create_comment and track_update_comment take visibility, and comments return it.
  • Enforcement: a non-member reader, today a public-project viewer, never receives a members-only comment by any route:
    • comment list and get (REST, MCP, UI panel);
    • comment counts;
    • changelog entries and their previews;
    • push notifications (comment and mention categories);
    • realtime events.
  • Tests: integration tests from a public viewer's side for each route.

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

1
Bradley

Fixed in https://github.com/badbundle/track-slash-app/pull/182 (merged as c8e9538).

  • Visibility. Comments have visibility shared or members. Migration 0050 leaves existing comments shared. New comments default to members-only in a help desk and to shared elsewhere.
  • Enforcement. Non-members never receive a members-only comment:
    • REST, MCP and the issue page filter them, and a hidden comment reads as not-found.
    • Changelog entries about one carry a members_only flag that follows the comment when its visibility changes, and non-members' changelog leaves them out.
    • Push notifications about one, mentions included, are suppressed for non-members.
    • Realtime events carry members_only, and the hub delivers them only on subscriptions the authorizer granted members-only access.
  • Setting it. The composer and edit form show the choice wherever someone other than a member can read issues. Members-only comments carry a badge. REST and MCP take visibility on create and update, and an update can change the visibility alone.