diff --git a/app/controllers/api/notes_controller.rb b/app/controllers/api/notes_controller.rb
index 20a24ce99..fc9167eb3 100644
--- a/app/controllers/api/notes_controller.rb
+++ b/app/controllers/api/notes_controller.rb
@@ -4,7 +4,7 @@ module Api
before_action :check_api_readable
before_action :setup_user_auth, :only => [:create, :comment, :show]
- before_action :authorize, :only => [:close, :reopen, :destroy]
+ before_action :authorize, :only => [:close, :reopen, :destroy, :comment]
authorize_resource
diff --git a/app/views/browse/note.html.erb b/app/views/browse/note.html.erb
index c7989d789..f68dfbe2e 100644
--- a/app/views/browse/note.html.erb
+++ b/app/views/browse/note.html.erb
@@ -41,18 +41,18 @@
<% end %>
<% if @note.status == "open" %>
-
+ <% end -%>
<% else %>