[Customer Portal][BE] Add endpoints to create comments on cases - #122
Conversation
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughAdds comment and attachment creation: new enums and payload/response types, two public entity functions ( Changes
Sequence Diagram(s)sequenceDiagram
participant Client as Client
participant Service as Service
participant Entity as Entity
participant External as ExternalAPI
Client->>Service: POST /cases/{id}/comments (payload)
activate Service
Service->>Service: extract user token, validate id
Service->>Entity: createComment(idToken, payload)
activate Entity
Entity->>External: POST /comments (payload + headers)
activate External
External-->>Entity: CommentCreateResponse
deactivate External
Entity-->>Service: CommentCreateResponse
deactivate Entity
Service-->>Client: CreatedComment (200)
deactivate Service
sequenceDiagram
participant Client as Client
participant Service as Service
participant Entity as Entity
participant External as ExternalAPI
Client->>Service: POST /cases/{id}/attachments (payload)
activate Service
Service->>Service: extract user token, validate id
Service->>Entity: createAttachment(idToken, payload)
activate Entity
Entity->>External: POST /attachments (payload + headers)
activate External
External-->>Entity: AttachmentCreateResponse
deactivate External
Entity-->>Service: AttachmentCreateResponse
deactivate Entity
Service-->>Client: CreatedAttachment (200)
deactivate Service
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Possibly related PRs
Suggested labels
Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 2 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (2 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Fix all issues with AI agents
In `@apps/customer-portal/backend/modules/entity/entity.bal`:
- Around line 137-143: The createAttachment function currently ignores the case
ID and sends an empty payload; update it to accept the case identifier and
attachment payload from the API handler and forward them to
csEntityClient->/attachments.post (instead of posting {}), e.g., add parameters
for the case id and attachment metadata/file content to public isolated function
createAttachment(string idToken, string caseId, AttachmentPayload payload) and
include caseId (and payload fields) in the POST body, ensuring the API endpoint
that extracts the path `id` passes that id into entity:createAttachment and that
generateHeaders(idToken) remains used for auth.
In `@apps/customer-portal/backend/modules/entity/types.bal`:
- Around line 545-553: AttachmentCreateResponse currently lacks the permissive
rest field used elsewhere (e.g., CommentCreateResponse) so extra fields from the
upstream API will break deserialization; update the AttachmentCreateResponse
record type to include the open rest field (json...;) so the record tolerates
additional JSON properties, matching the pattern used by CommentCreateResponse.
In `@apps/customer-portal/backend/service.bal`:
- Around line 1046-1097: The post cases/[string id]/attachments resource
validates the path parameter id but calls entity:createAttachment only with
userInfo.idToken, so the attachment won’t be linked to the case; change the call
to entity:createAttachment to forward the case id (e.g., pass id as a second
argument or as referenceId) so the entity layer receives both userInfo.idToken
and the case id (update the entity:createAttachment usage/signature accordingly
if needed), mirroring how the comment endpoint forwards id as referenceId.
🧹 Nitpick comments (2)
apps/customer-portal/backend/types.bal (1)
289-298: Consider adding@constraintvalidation oncontent.The
contentfield has no length constraints, unlikeCaseCreatePayloadwhich validatestitle(maxLength: 500) anddescription(maxLength: 65000). An empty or excessively large comment payload could reach the downstream entity API unchecked.💡 Proposed constraint addition
# Payload for creating a comment. public type CommentCreatePayload record {| # Reference type entity:ReferenceType referenceType; # Comment content + `@constraint`:String { + minLength: 1, + maxLength: 65000 + } string content; # Comment type entity:CommentType 'type; |};apps/customer-portal/backend/service.bal (1)
983-1040: Missing case access verification before creating the comment.The
GET cases/[id]/commentsendpoint (Line 867) verifies case access by callingentity:getCasebefore fetching comments. ThePOSTendpoint skips this step, relying solely on the downstream entity API for authorization. If the entity API doesn't enforce case-level access control on comment creation, a user could comment on a case they don't have access to.Consider adding the same case access verification pattern used in the GET endpoint for consistency and defense-in-depth.
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Fix all issues with AI agents
In `@apps/customer-portal/backend/types.bal`:
- Around line 301-313: AttachmentPayload currently exposes a client-sent
referenceId that gets ignored by the attachment endpoint (payload.referenceId is
overridden by the path param id), causing confusion; remove the unused field
from the public type AttachmentPayload to match CommentCreatePayload's pattern,
update any compile-time references/usages to stop expecting payload.referenceId,
and ensure the service handler continues to use the path parameter id as the
authoritative reference; alternatively, if you prefer to accept client-provided
IDs, remove the override in the attachment handler and document the behavior
consistently—pick one approach and update API docs/tests accordingly.
🧹 Nitpick comments (2)
apps/customer-portal/backend/service.bal (2)
1003-1039: Misleading variable namecreatedCaseResponsefor a comment creation result.The variable at Line 1003 is named
createdCaseResponsebut holds aCommentCreateResponse. This appears to be a copy-paste artifact from the case creation endpoint. Rename it for clarity.Proposed rename
- entity:CommentCreateResponse|error createdCaseResponse = entity:createComment(userInfo.idToken, + entity:CommentCreateResponse|error createdCommentResponse = entity:createComment(userInfo.idToken, { referenceId: id, referenceType: payload.referenceType, content: payload.content, 'type: payload.'type }); - if createdCaseResponse is error { - if getStatusCode(createdCaseResponse) == http:STATUS_UNAUTHORIZED { + if createdCommentResponse is error { + if getStatusCode(createdCommentResponse) == http:STATUS_UNAUTHORIZED { log:printWarn(string `User: ${userInfo.userId} is not authorized to access the customer portal!`); return <http:Unauthorized>{ body: { message: ERR_MSG_UNAUTHORIZED_ACCESS } }; } - if getStatusCode(createdCaseResponse) == http:STATUS_FORBIDDEN { + if getStatusCode(createdCommentResponse) == http:STATUS_FORBIDDEN { log:printWarn(string `User: ${userInfo.userId} is forbidden to comment on case with ID: ${id}!`); return <http:Forbidden>{ body: { message: "You're not authorized to comment on the requested case. " + "Please check your access permissions or contact support." } }; } string customError = "Failed to create a new comment."; - log:printError(customError, createdCaseResponse); + log:printError(customError, createdCommentResponse); return <http:InternalServerError>{ body: { message: customError } }; } - return createdCaseResponse.comment; + return createdCommentResponse.comment;
1042-1047: Doc comment is missing thepayloadparameter description.Line 1042–1045: the doc comment for the attachment endpoint documents
idbut omitspayload.Proposed fix
# Create a new attachment for a specific case. # # + id - ID of the case + # + payload - Attachment creation payload # + return - Created attachment or error response
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Fix all issues with AI agents
In `@apps/customer-portal/backend/service.bal`:
- Around line 978-1040: The POST resource function post cases/[string
id]/comments currently returns entity:CreatedComment (from entity:createComment)
directly, risking exposure of sensitive fields like referenceId; update this to
map the createdCaseResponse.comment into a public DTO before returning—either
define a public CreatedComment type (omitting referenceId) and construct/convert
the entity:CommentCreateResponse.comment into that type, or reuse the existing
mapCommentsResponse pattern to filter fields; ensure the mapping happens after
successful entity:createComment and return the mapped public comment instead of
createdCaseResponse.comment.
🧹 Nitpick comments (2)
apps/customer-portal/backend/types.bal (1)
301-311:AttachmentPayloadlacks input validation onnameandcontent.Unlike
CommentCreatePayloadwhich constrainscontent,AttachmentPayloadaccepts arbitrary strings fornameandcontentwith no length or format validation. An empty file name or an unbounded base64contentstring could cause issues downstream or allow excessively large payloads.Consider adding constraints — at minimum a
minLength: 1onnameand amaxLengthoncontentto bound upload size.Suggested constraints
public type AttachmentPayload record {| # Reference type entity:ReferenceType referenceType; # File name + `@constraint`:String {minLength: 1, maxLength: 255} string name; # MIME type of the file + `@constraint`:String {minLength: 1} string 'type; # Base 64 encoded content + `@constraint`:String {minLength: 1} string content; |};apps/customer-portal/backend/service.bal (1)
1042-1045: Missing+ payloadparameter in doc comment.The doc comment documents
idbut omits thepayloadparameter, unlike the comment endpoint above which documents both.Suggested fix
# Create a new attachment for a specific case. # # + id - ID of the case +# + payload - Attachment creation payload # + return - Created attachment or error response
…tone-1-case-attachment
f4b8dd1
into
wso2-open-operations:customer-portal-milestone-1
Description
This PR adds a new API endpoint to allow users to create comments on cases.
Changes
Reason
Cases currently lack an API for adding comments, limiting collaboration and tracking. This change enables proper discussion and documentation within cases.
Testing
Related Issues
Related PRs
Summary by CodeRabbit