ogrechkoandClaude Sonnet 5 681f89000f Make internal notes admin-only, close a direct-URL ticket access gap
Internal notes ("Внутренняя заметка") were visible to any agent who
opened the ticket — the compose toggle and the SSE-delivered live
updates had no role check. Agents now never see the internal/public
toggle (they only ever reply publicly) and internal messages are
filtered out of both the initial server-rendered load and live SSE
message.created events.

Fixing that surfaced a bigger gap: the ticket detail page and every
per-ticket API route (GET/PATCH /api/tickets/[id], POST .../messages,
POST .../attachments, PUT .../tags) had no ownership check at all — an
agent could open, reply to, tag, reassign, or read the full message
history of *any* ticket by URL/API, not just their own, regardless of
the dashboard-level filtering added earlier. All five now reuse
isTicketVisibleTo() to 404/redirect for tickets an agent doesn't own.

Verified live: an agent opening a ticket assigned to them sees public
messages but not an admin's internal note or the note-vs-reply toggle;
opening a ticket assigned to someone else redirects to /dashboard on
the page and returns 404 from the API. Test accounts/data removed after.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012o9j9RezxbZVKQMrB7oRLY
2026-08-05 18:22:46 +00:00

top-tickets

Хелпдеск-система: тикеты, дашборд по статусам, канал Telegram, realtime-обновления без перезагрузки страницы, отдельный клиентский портал. MVP-1 — см. /root/.claude/plans/refactored-discovering-corbato.md за архитектурой и тем, что отложено на MVP-2 (email, встраиваемый виджет).

Запуск в Docker

cp .env.example .env
npm run generate-key   # вставить результат в CREDENTIALS_ENCRYPTION_KEY
# заполнить ADMIN_BOOTSTRAP_EMAIL / ADMIN_BOOTSTRAP_PASSWORD / TELEGRAM_BOT_TOKEN в .env

docker compose up --build -d

Приложение слушает :8081 (уже проброшено внешним nginx на help.top-sysops.ru). При первом старте контейнер сам применяет миграции и создаёт админ-аккаунт из .env.

Локальная разработка

npm install
cp .env.example .env   # + generate-key, как выше
npm run db:migrate
npm run bootstrap-admin
npm run dev

Telegram

Подключается через Настройки → Telegram в интерфейсе (или через TELEGRAM_BOT_TOKEN в .env — сработает только при первом старте, если бот ещё не настроен). Чтобы бот видел все сообщения в группе, а не только с упоминанием — @BotFather → /setprivacy → Disable.

Токен, который прислали в чат Claude Code, стоит перевыпустить (@BotFather → /revoke) — он засветился в истории сессии.

S
Description
No description provided
Readme
1.1 MiB
0 Stars 1 Watchers 0 Forks
Languages
TypeScript 95.9%
CSS 2.3%
JavaScript 1.2%
Dockerfile 0.6%