Every AJAX request should be nonced. We also need to make sure that the user has permission to access or update the thread.