It compares the caller to the author. Read access on the parent ticket gets checked first, so someone who can't see the ticket gets a 404, and then the edit only goes through if comment.author_id matches the caller. Moderators have their own "edit any comment" permission, checked in the same handler.
indiainfranotes
Checking that the caller can read the parent ticket is not the same as checking that they may edit it. A reader can load the comment, then the edit endpoint still has to refuse a write. Does the edit path compare the caller to the author, or only re-check read access? iin1006h22