Threat Discussions
Each Threat has its own discussion thread. Threads are organization-scoped and inherit the same backend RBAC checks as the Threat itself.
Comments
Comments are plain text. The backend rejects empty comments and comments longer than 10,000 characters. The frontend renders comment bodies as escaped text; raw HTML is not executed.
Admin and hacker users with access to the Threat organization can create internal comments or client-visible comments. Client users can create comments only as client-visible comments; if a client submits visible_to_client=false, the backend forces the comment to remain client-visible.
Client Visibility
| Role | Can Read Internal | Can Read Client-Visible | Can Create Internal | Can Create Client-Visible |
|---|---|---|---|---|
| admin | Yes | Yes | Yes | Yes |
| hacker | Yes | Yes | Yes | Yes |
| client | No | Yes | No | Yes |
Client filtering is enforced server-side. Internal comments are never returned to client users.
Mentions
Mentions are resolved by user ID, not by raw @username text. The frontend autocomplete searches:
GET /api/v1/organizations/{org_id}/mentionable-users
For internal comments, mentionable users are admins and hackers only. For client-visible comments, clients assigned to the organization can also be mentioned. The backend rejects mention IDs that are outside the organization context or unable to read the resulting comment.
Duplicate mentions in the same comment create one mention relation. Mentioning yourself does not create a notification.
Editing
In this MVP, users can edit only their own comments. Editing updates the text, visibility flag where allowed, and resolved mentions. Existing mentions are not re-notified; only newly added mention IDs create new in-app notifications.
Comment deletion is not implemented.
Profile Notifications
When a user is mentioned in a comment they can read, hxEASM creates a self-scoped in-app notification with type:
threat_mention
Notifications appear on /profile. Clicking a Threat mention notification marks it read and opens the Threat discussion.
Mention notifications are not sent through Telegram, email, webhook, browser push, or WebSockets in this version.
Audit Log
Comment creation and update are written to the Audit Log as:
threat.comment.createdthreat.comment.updated
Audit records include safe metadata such as Threat ID, comment ID, visibility, and mentioned user IDs. Full comment bodies are not duplicated into audit rows.
Exposure Changes
Comments, mentions, and notification read state are collaboration events. They do not create Exposure Changes.