mirror of
https://github.com/yusufipk/OpenFrame.git
synced 2026-09-11 09:36:08 +00:00
feat(projects): add validation for name and description in PATCH request to ensure they are non-empty strings within specified length limits
This commit is contained in:
@@ -112,6 +112,23 @@ export async function PATCH(request: NextRequest, { params }: RouteParams) {
|
|||||||
const body = await request.json();
|
const body = await request.json();
|
||||||
const { name, description, visibility } = body;
|
const { name, description, visibility } = body;
|
||||||
|
|
||||||
|
if (name !== undefined) {
|
||||||
|
if (typeof name !== 'string' || name.trim().length === 0) {
|
||||||
|
return apiErrors.badRequest('Name must be a non-empty string');
|
||||||
|
}
|
||||||
|
if (name.trim().length > 100) {
|
||||||
|
return apiErrors.badRequest('Name must be 100 characters or fewer');
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if (description !== undefined && description !== null) {
|
||||||
|
if (typeof description !== 'string') {
|
||||||
|
return apiErrors.badRequest('Description must be a string');
|
||||||
|
}
|
||||||
|
if (description.trim().length > 1000) {
|
||||||
|
return apiErrors.badRequest('Description must be 1000 characters or fewer');
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
const VALID_VISIBILITY = ['PRIVATE', 'INVITE', 'PUBLIC'] as const;
|
const VALID_VISIBILITY = ['PRIVATE', 'INVITE', 'PUBLIC'] as const;
|
||||||
if (visibility !== undefined && !VALID_VISIBILITY.includes(visibility)) {
|
if (visibility !== undefined && !VALID_VISIBILITY.includes(visibility)) {
|
||||||
return apiErrors.badRequest('Invalid visibility value');
|
return apiErrors.badRequest('Invalid visibility value');
|
||||||
|
|||||||
@@ -94,6 +94,15 @@ export async function POST(request: NextRequest, { params }: RouteParams) {
|
|||||||
return apiErrors.badRequest('Video URL is required');
|
return apiErrors.badRequest('Video URL is required');
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (versionLabel !== undefined && versionLabel !== null) {
|
||||||
|
if (typeof versionLabel !== 'string') {
|
||||||
|
return apiErrors.badRequest('Version label must be a string');
|
||||||
|
}
|
||||||
|
if (versionLabel.trim().length > 100) {
|
||||||
|
return apiErrors.badRequest('Version label must be 100 characters or fewer');
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// Validate URLs use safe schemes (http/https only)
|
// Validate URLs use safe schemes (http/https only)
|
||||||
const videoUrlError = validateUrl(videoUrl, 'Video URL');
|
const videoUrlError = validateUrl(videoUrl, 'Video URL');
|
||||||
if (videoUrlError) {
|
if (videoUrlError) {
|
||||||
|
|||||||
@@ -108,6 +108,23 @@ export async function PATCH(request: NextRequest, { params }: RouteParams) {
|
|||||||
const body = await request.json();
|
const body = await request.json();
|
||||||
const { name, description } = body;
|
const { name, description } = body;
|
||||||
|
|
||||||
|
if (name !== undefined) {
|
||||||
|
if (typeof name !== 'string' || name.trim().length === 0) {
|
||||||
|
return apiErrors.badRequest('Name must be a non-empty string');
|
||||||
|
}
|
||||||
|
if (name.trim().length > 100) {
|
||||||
|
return apiErrors.badRequest('Name must be 100 characters or fewer');
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if (description !== undefined && description !== null) {
|
||||||
|
if (typeof description !== 'string') {
|
||||||
|
return apiErrors.badRequest('Description must be a string');
|
||||||
|
}
|
||||||
|
if (description.trim().length > 1000) {
|
||||||
|
return apiErrors.badRequest('Description must be 1000 characters or fewer');
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
const updateData: Record<string, unknown> = {};
|
const updateData: Record<string, unknown> = {};
|
||||||
if (name !== undefined) updateData.name = name.trim();
|
if (name !== undefined) updateData.name = name.trim();
|
||||||
if (description !== undefined) updateData.description = description?.trim() || null;
|
if (description !== undefined) updateData.description = description?.trim() || null;
|
||||||
|
|||||||
Reference in New Issue
Block a user