Skip to content

Commit bcd00a9

Browse files
Prevent submission of empty HTML comments (e.g. <p></p>)
Agent-Logs-Url: https://github.com/kirschbaum-development/commentions/sessions/33ccb0f6-9921-40e0-a10b-729ba43a5a94 Co-authored-by: luisdalmolin <403446+luisdalmolin@users.noreply.github.com>
1 parent 4c23d35 commit bcd00a9

4 files changed

Lines changed: 72 additions & 6 deletions

File tree

‎src/Livewire/Comment.php‎

Lines changed: 16 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -24,9 +24,20 @@ class Comment extends Component
2424

2525
public ?string $tipTapCssClasses = null;
2626

27-
protected $rules = [
28-
'commentBody' => 'required|string',
29-
];
27+
protected function rules(): array
28+
{
29+
return [
30+
'commentBody' => [
31+
'required',
32+
'string',
33+
function ($attribute, $value, $fail) {
34+
if (trim(strip_tags($value)) === '') {
35+
$fail(__('validation.required', ['attribute' => 'comment body']));
36+
}
37+
},
38+
],
39+
];
40+
}
3041

3142
#[On('comment:reaction:toggled')]
3243
public function handleReactionToggledEvent(string $reaction, int $commentId): void
@@ -93,6 +104,8 @@ public function updateComment()
93104
return;
94105
}
95106

107+
$this->validate();
108+
96109
$this->comment->update([
97110
'body' => $this->commentBody,
98111
]);

‎src/Livewire/Comments.php‎

Lines changed: 14 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -26,9 +26,20 @@ class Comments extends Component
2626

2727
public ?string $tipTapCssClasses = null;
2828

29-
protected $rules = [
30-
'commentBody' => 'required|string',
31-
];
29+
protected function rules(): array
30+
{
31+
return [
32+
'commentBody' => [
33+
'required',
34+
'string',
35+
function ($attribute, $value, $fail) {
36+
if (trim(strip_tags($value)) === '') {
37+
$fail(__('validation.required', ['attribute' => 'comment body']));
38+
}
39+
},
40+
],
41+
];
42+
}
3243

3344
#[Renderless]
3445
public function save()

‎tests/Livewire/CommentTest.php‎

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -97,6 +97,28 @@
9797
]);
9898
});
9999

100+
test('updating comment is rejected when body contains only empty html tags', function () {
101+
$user = User::factory()->create();
102+
actingAs($user);
103+
104+
$post = Post::factory()->create();
105+
$comment = CommentModel::factory()->author($user)->commentable($post)->create([
106+
'body' => 'Test comment body',
107+
]);
108+
109+
livewire(CommentComponent::class, [
110+
'comment' => $comment,
111+
])
112+
->set('commentBody', '<p></p>')
113+
->call('updateComment')
114+
->assertHasErrors(['commentBody']);
115+
116+
test()->assertDatabaseHas('comments', [
117+
'id' => $comment->id,
118+
'body' => 'Test comment body',
119+
]);
120+
});
121+
100122
test('other users cannot update a comment by default', function () {
101123
$user = User::factory()->create();
102124
actingAs($user);

‎tests/Livewire/CommentsTest.php‎

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -63,6 +63,26 @@
6363
]);
6464
});
6565

66+
test('comment creation is rejected when body contains only empty html tags', function () {
67+
/** @var User $user */
68+
$user = User::factory()->create();
69+
actingAs($user);
70+
71+
$post = Post::factory()->create();
72+
73+
livewire(Comments::class, [
74+
'record' => $post,
75+
])
76+
->set('commentBody', '<p></p>')
77+
->call('save')
78+
->assertHasErrors(['commentBody']);
79+
80+
$this->assertDatabaseMissing('comments', [
81+
'commentable_id' => $post->id,
82+
'commentable_type' => Post::class,
83+
]);
84+
});
85+
6686
test('guests cannot create comments', function () {
6787
Event::fake();
6888

0 commit comments

Comments
 (0)