A repo-wide grep -rn "IsNotEmpty" src returns zero matches. Every required free-text field is validated with @IsString() alone, which class-validator treats as satisfied by "" or " ":
MilestonesService.create (src/milestones/milestones.service.ts) and MaintenancePoolService.create (src/maintenance-pool/maintenance-pool.service.ts) persist dto.title/dto.name verbatim with no server-side trim/empty check either. A client can POST /milestones with title: " " or POST /maintenance-pools with name: "" and get a 201 with a blank-looking, unsearchable/undisplayable resource that then holds real escrowed funds.
Fix: add @IsNotEmpty() (pair with a custom @Transform(({value}) => value?.trim()) or a @Matches(/\S/) if whitespace-only must also be rejected) to CreateMilestoneDto.title, CreatePoolDto.name, and CreateTeamDto.name.
A repo-wide
grep -rn "IsNotEmpty" srcreturns zero matches. Every required free-text field is validated with@IsString()alone, which class-validator treats as satisfied by""or" ":CreateMilestoneDto.title(src/milestones/dto/create-milestone.dto.ts) —@IsString() @MaxLength(200) title: string;CreatePoolDto.name(src/maintenance-pool/dto/create-pool.dto.ts) —@IsString() @MaxLength(100) name: string;CreateTeamDto.name(src/teams/dto/create-team.dto.ts) —@IsString() name: string;(also missing@MaxLength, tracked separately as CreateTeamDto.name has no @MaxLength, unlike every sibling free-text field the #151 fix covered #263)MilestonesService.create(src/milestones/milestones.service.ts) andMaintenancePoolService.create(src/maintenance-pool/maintenance-pool.service.ts) persistdto.title/dto.nameverbatim with no server-side trim/empty check either. A client canPOST /milestoneswithtitle: " "orPOST /maintenance-poolswithname: ""and get a 201 with a blank-looking, unsearchable/undisplayable resource that then holds real escrowed funds.Fix: add
@IsNotEmpty()(pair with a custom@Transform(({value}) => value?.trim())or a@Matches(/\S/)if whitespace-only must also be rejected) toCreateMilestoneDto.title,CreatePoolDto.name, andCreateTeamDto.name.