KamoCRM

Edit, like and delete one post or note by its own id, never the whole stream

FixSecurityService
Shipped
September 28, 2026 at 6:33 PM UTC
Author
Kamo
Commit
ed45f19

A feed, the organization's (the Clubhouse) or a lead's notes, is ONE POST session and every post or note is a message in it, so every item the feed lists carries the session's guid. PUT, like and DELETE on /posts/{guid} therefore acted on the stream: the edit rewrote its first message, the like liked it, and a delete by whoever first opened the feed marked EVERY post or note in it removed. - PUT/DELETE **************** and POST .../notes/{noteId}/like act on that one message: reached through reachablePost (the per-lead rule, SP99-FINAL-a), the id must be a live message of that stream (else 404), and only its own author may edit or delete it (else 403). An edit is stamped (dateEdited) and drops cached translations; a delete also removes the replies under it. - The stream-level PUT, like and DELETE keep their reachability check and then answer 410. - A reply's parentId must be a live message of the same stream (else 404): any message anywhere was accepted.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing