feat(backend): Zod request validation middleware across routes - #695
Open
woahwhattheheck wants to merge 13 commits into
Open
woahwhattheheck wants to merge 13 commits into
woahwhattheheck wants to merge 13 commits into
Conversation
The boundary middleware validates coerced numbers but passes the original request text onward. Employee and schedule controllers use parseInt for IDs; asset audit-log pagination uses parseInt too. Exponent notation such as 1e3 therefore passes the existing check as 1000 and reaches these controllers as 1. Require decimal digit strings before the existing positive-integer coercion in the employee ID, schedule ID and asset page/limit schemas. Keep optional pagination, the limit100 cap, request objects, tenant/authentication middleware and other schemas unchanged. Each modified file includes a dated Apache modification notice. Benefits and tax controllers use Number, while freeze pagination parses its full schema again; those inspected paths already agree with their validators and are preserved. Source: existing PR695 / issue532; validateRequest.ts ab17f16, employeeController.ts c63bb47, scheduleController.ts 7eb70fc, assetController.ts c43203e. Zod coercion/pipes: https://zod.dev/api . Integer parsing: https://tc39.es/ecma262/multipage/global-object.html#sec-parseint-string-radix . Validation is source-only: full preimages, complete line deltas and postimage identities were checked. No HTTP request, TypeScript build, Zod execution, tests, workflow or database operation ran. This correction does not establish complete issue532 coverage, upstream acceptance or deployment.
Complete the audit route boundary in the existing request-validation contribution. Validate all three transaction-hash routes, including POST, before controller dispatch. Preserve the list controller's pagination limits, filters, defaults and raw request types while returning the shared validation error envelope. Add five focused route cases using the real Express router, Zod schemas and validation middleware with controller doubles. No service, database, Horizon or transaction-submission behavior changes. Runtime results are recorded separately after execution.
Add co-located query schemas to the four cash-flow routes and three certificate routes in the existing request-validation contribution. Keep the controllers' omitted-window defaults and raw string inputs, bound forecast and alert windows to 365 days and history to 24 months, and reject partial integer parses before calculations. Validate hashes and supplied certificate IDs before lookup while retaining generation's absent-ID auto-detection and verification's required IDs. Preserve authentication and tenant middleware ordering, controllers, services, database behavior and transaction execution. Six focused Express/Zod/middleware cases isolate these query boundaries from external services; runtime evidence is recorded separately.
Repair GitHub Actions workflow validation for fleet branches. Preserve job definitions, event filters, permissions, artifact retention inputs, and all application files.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #532.
What
validateRequestmiddleware and per-route Zod schemas across asset, auth, benefits, employee, freeze, multisig, schedule, and audit routes.Validation
Exact source head:
9b575def29c6aeb6fc576cd9703b78c82e7e6df6.Focused audit-route acceptance ran successfully in GitHub Actions run
37359554506(job111930425846): 5 HTTP cases passed using real Express/Zod/middleware with controller doubles. This is focused boundary validation only; no database, Horizon, live transaction, or full-suite pass is claimed.