Fix logic bugs found in third multi-agent review
Security / PHP Security (semgrep) (push) Failing after 2m44s
Lint / Deploy (push) Successful in 8s
Lint / Notify on failure (push) Has been skipped
Lint / PHP (phpcs PSR-12) (push) Successful in 18s
Lint / JS (eslint) (push) Successful in 8s
Lint / PHP requirements (version + extensions) (push) Successful in 21s
Security / PHP Security (semgrep) (push) Failing after 2m44s
Lint / Deploy (push) Successful in 8s
Lint / Notify on failure (push) Has been skipped
Lint / PHP (phpcs PSR-12) (push) Successful in 18s
Lint / JS (eslint) (push) Successful in 8s
Lint / PHP requirements (version + extensions) (push) Successful in 21s
Medium:
- create_ticket_api.php: environment tags were parsed with explode('][') which
left brackets on the first/last tag so the whitelist never matched, dropping
the env tag from the dedup hash — a [production] and [staging] issue with
otherwise-identical components could collide onto one ticket. Use a
bracket-aware regex.
- CommentModel::getThreadedCommentsPaged only fetched DIRECT children of root
comments, so when pagination is active, nested replies at depth 2-3 vanished
from the thread. Expand replies level-by-level (bounded to depth 3).
- StatsModel::getTicketsByAssignee ignored the visibility filter the rest of the
stats apply, so a non-admin's "by assignee" widget counted (leaked) confidential
tickets. Thread the same filter through.
- watch_ticket.php GET path returned watch state / watcher names / count for any
ticket with no access check (the POST path checks it) — added canUserAccessTicket.
- dashboard.js kanban: every card rendered as P4 because the [class*="lt-p"]
selector never matched the lt-badge-p1 class and the fallback didn't strip "P".
Extract the digit directly.
Low:
- audit_log.php CSV: "Log ID" column was always blank ($log['log_id'] vs the real
audit_id column). Use audit_id.
- check_duplicates.php: the graceful-degradation try/catch only covered the throw
path; guard the false-return (non-exception mysqli) path too.
- notifications.php: owner-who-is-also-@mentioned got two notifications for one
comment; drop the duplicate comment row when a mention covers the same comment.
- dashboard.js hover preview rendered "PP1" (doubled prefix); strip the leading P.
- markdown.js: code/inline-code restore used string replace, so $&, $$, $`, $' in
user code were treated as replacement patterns; use a function replacer. Also
removed an unused loop var.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
+34
-20
@@ -176,27 +176,41 @@ class CommentModel
|
||||
return [];
|
||||
}
|
||||
|
||||
// All replies for these root comments (up to 3 levels deep)
|
||||
$placeholders = implode(',', array_fill(0, count($rootIds), '?'));
|
||||
$replySql = "SELECT tc.*, u.display_name, u.username
|
||||
FROM ticket_comments tc
|
||||
LEFT JOIN users u ON tc.user_id = u.user_id
|
||||
WHERE tc.ticket_id = ?
|
||||
AND tc.parent_comment_id IN ($placeholders)
|
||||
AND tc.parent_comment_id IS NOT NULL
|
||||
ORDER BY tc.created_at ASC";
|
||||
$replyStmt = $this->conn->prepare($replySql);
|
||||
$types = 'i' . str_repeat('i', count($rootIds));
|
||||
$replyStmt->bind_param($types, $ticketId, ...$rootIds);
|
||||
$replyStmt->execute();
|
||||
$replyResult = $replyStmt->get_result();
|
||||
$replyStmt->close();
|
||||
// Load replies level-by-level under this page's roots. A single
|
||||
// "parent_comment_id IN (rootIds)" only fetches DIRECT children, so
|
||||
// grandchildren/great-grandchildren (addComment allows up to depth 3)
|
||||
// would be missing from the map and dropped by buildCommentThread.
|
||||
// Expand iteratively until no new replies (bounded by max depth 3).
|
||||
$parentIds = $rootIds;
|
||||
$depth = 0;
|
||||
while (!empty($parentIds) && $depth < 3) {
|
||||
$placeholders = implode(',', array_fill(0, count($parentIds), '?'));
|
||||
$replySql = "SELECT tc.*, u.display_name, u.username
|
||||
FROM ticket_comments tc
|
||||
LEFT JOIN users u ON tc.user_id = u.user_id
|
||||
WHERE tc.ticket_id = ?
|
||||
AND tc.parent_comment_id IN ($placeholders)
|
||||
ORDER BY tc.created_at ASC";
|
||||
$replyStmt = $this->conn->prepare($replySql);
|
||||
$types = 'i' . str_repeat('i', count($parentIds));
|
||||
$replyStmt->bind_param($types, $ticketId, ...$parentIds);
|
||||
$replyStmt->execute();
|
||||
$replyResult = $replyStmt->get_result();
|
||||
$replyStmt->close();
|
||||
|
||||
while ($row = $replyResult->fetch_assoc()) {
|
||||
$row['display_name_formatted'] = $row['display_name'] ?: ($row['user_name'] ?? 'Unknown User');
|
||||
$row['replies'] = [];
|
||||
$row['thread_depth'] = $row['thread_depth'] ?? 1;
|
||||
$commentMap[$row['comment_id']] = $row;
|
||||
$nextParentIds = [];
|
||||
while ($row = $replyResult->fetch_assoc()) {
|
||||
if (isset($commentMap[$row['comment_id']])) {
|
||||
continue; // guard against cycles / duplicates
|
||||
}
|
||||
$row['display_name_formatted'] = $row['display_name'] ?: ($row['user_name'] ?? 'Unknown User');
|
||||
$row['replies'] = [];
|
||||
$row['thread_depth'] = $depth + 1;
|
||||
$commentMap[$row['comment_id']] = $row;
|
||||
$nextParentIds[] = $row['comment_id'];
|
||||
}
|
||||
$parentIds = $nextParentIds;
|
||||
$depth++;
|
||||
}
|
||||
|
||||
$rootComments = [];
|
||||
|
||||
Reference in New Issue
Block a user