Releases: navanem/payload-comments
Release list
v0.4.1 - Maintenance & Security Update
Highlights
- Updated Payload, React, Vitest, TypeScript, and related tooling dependencies.
- Refreshed compatible transitive dependencies.
- Added hardened CI, Dependabot, contribution, security, and protected-branch configuration.
- Production dependency audit is clean; remaining GitHub alerts are development-tooling scope.
v0.4.0
Minor release: a Thread column in the comments moderation list.
Added
- Thread column in the moderation list — the
commentsadmin list now shows aThreadcolumn ("Top-level" or "↳ Reply to <author>") alongside the targetrelatedDoc, so you can tell at a glance whether a row is a reply, to whom, and which document it belongs to.
Notes
- Implemented as a
virtualfield — no database column, no migration. ItsafterReadis gated to authenticated admin reads, so the public comment-tree endpoint is unaffected (no extra query, the field is never added to the public payload).
Full changelog: https://github.com/navanem/navanem_payload_comments/blob/main/CHANGELOG.md
v0.3.0
Minor release: Markdown comment bodies and a runtime moderation toggle.
Added
- Markdown comments — comment bodies render a safe subset of Markdown (bold, italic, strikethrough, inline/block code, links, lists, blockquotes) via
react-markdown+remark-gfm. Raw HTML is never rendered (no XSS); links are hardened withrel="noopener noreferrer nofollow ugc"and open in a new tab. - Moderation toggle in Settings — the Comments Settings global gained a
requireApprovalcheckbox to turn mandatory approval on/off at runtime. The submit flow reads it live, falling back to therequireApprovaloption.
Notes
- Adds
react-markdownandremark-gfmas runtime dependencies. - Service tests updated to drive
requireApprovalthrough the settings global (its new source of truth); README and docs updated for both features.
Full changelog: https://github.com/navanem/navanem_payload_comments/blob/main/CHANGELOG.md
v0.2.0
Minor release: runtime per-collection control and an admin statistics view.
Added
- Comments Settings global (admin group "Comments") to enable or disable commenting per collection at runtime, without redeploying. The
submitandtreeendpoints consult it on every request and fail open when it has never been saved (or before its table is migrated).<Comments />renders a "closed" notice when its collection is disabled. - Comment Statistics admin view at
/admin/comments-statistics: KPIs, per-collection and per-mood breakdowns, and recent comments, filterable by collection, status and period. Queries are auth-gated server-side, so no data is rendered for anonymous requests. A nav link is registered viaafterNavLinksfor the default Nav.
Fixed
- Typed the statistics view's date filter as Payload's
Whereso the package builds cleanly undertsc.
Full changelog: https://github.com/navanem/navanem_payload_comments/blob/main/CHANGELOG.md
v0.1.1
Patch release fixing endpoint routing and SSR.
Fixed
- Moved the public endpoints from
/comments/*to/comments-api/*so they no longer collide with the comments collection's REST namespace in Payload 3.x (previouslyGET /comments/treehit the collection/:idhandler andPOST /comments/submitreturned 404). Component fetch URLs and the REST API docs were updated to match. - Guarded the browser fingerprint on
windowso the component no longer crashes during server-side rendering on runtimes that define a globalnavigator.
Full changelog: https://github.com/navanem/navanem_payload_comments/blob/main/CHANGELOG.md
v0.1.0
Initial release of @navanem/payload-comments, a comments & reactions plugin for Payload 3.x.
Added
commentsPlugin()for Payload 3.x: injectscommentsandcomment-reactionscollections plus public REST endpoints.- Anonymous comment submission with name, optional/required email and a mood emoji.
- Reactions on comments with a configurable emoji set and toggle behavior.
- Optional pre-publish moderation via
requireApproval. - Up to 3 levels of nested replies, enforced server-side.
- Built-in anti-spam: honeypot, per-IP rate limiting, length and link rules.
- Salted hashing of IPs and fingerprints (no clear-text storage).
- Ready-to-use
<Comments />React component and a documented REST API.
⚠️ Known issue: the public endpoints were registered under/comments/*, which collides with the comments collection's REST namespace in Payload 3.x (brokentree/submitroutes). Use v0.1.1 or later, which moves them to/comments-api/*.