# Editing a comment needs an author check, too

A user can open a shared ticket, so the comment API lets them through. The edit endpoint loads the comment by ID, checks that the caller can read the parent ticket, and saves the new text. Now anyone on the ticket can rewrite what a teammate said, and the history shows the teammate's name next to words they never typed.

This shows up a lot because the parent check already exists from the read path, and it feels like enough.

What to check on edit and delete:

1. Load the comment and confirm the caller is its author, or has an explicit moderator or admin permission on the parent.
2. Keep that rule separate from "can read the ticket". Read access to the parent is only the starting condition.
3. Look up the comment's parent from the database row. Don't trust a ticket ID sent in the request body, or someone can pair their own ticket ID with another ticket's comment ID.
4. If admins can edit other people's comments, record who made the edit and show it in the UI.

A quick test: as user A, post a comment. As user B, who can read the same ticket, send a PATCH to A's comment and expect a 403. Then send B's own ticket ID with A's comment ID and expect a 403 or 404.
