Skip to content

Api runtime input validation - #625

Open
bperel wants to merge 20 commits into
masterfrom
api-runtime-input-validation
Open

bperel wants to merge 20 commits into
masterfrom
api-runtime-input-validation

Conversation

@bperel

@bperel bperel commented Sep 16, 2026

Copy link
Copy Markdown
Collaborator

No description provided.

Comment thread apps/duck-estimator/scrapes/bedetheque/check-missing.ts Fixed
Comment thread apps/duck-estimator/scrapes/bedetheque/check-missing.ts Fixed
Comment thread packages/api/services/auth/index.ts Dismissed

This comment was marked as outdated.

bperel and others added 4 commits September 21, 2026 16:59
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

This comment was marked as outdated.

This comment was marked as outdated.

This comment was marked as outdated.

This comment was marked as outdated.

This comment was marked as outdated.

This comment was marked as outdated.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Some validation paths lose established error messages, and release-date validation still accepts invalid calendar dates.

Review effort: Balanced
Findings: 3 Medium severity

Open (3)
Resolved since last review (8)
Files not reviewed (11)
  • apps/duckguessr/api/pnpm-lock.yaml: Generated file
  • apps/duckguessr/pnpm-lock.yaml: Generated file
  • apps/dumili/api/pnpm-lock.yaml: Generated file
  • apps/dumili/pnpm-lock.yaml: Generated file
  • apps/edgecreator/api/pnpm-lock.yaml: Generated file
  • apps/edgecreator/pnpm-lock.yaml: Generated file
  • apps/inducksql/pnpm-lock.yaml: Generated file
  • apps/web/pnpm-lock.yaml: Generated file
  • apps/whattheduck/pnpm-lock.yaml: Generated file
  • packages/api/pnpm-lock.yaml: Generated file
  • packages/prisma-schemas/pnpm-lock.yaml: Generated file

Comment on lines +1150 to +1153
v.check(
({ releaseDate }) =>
!releaseDate || !Number.isNaN(new Date(releaseDate).getTime()),
"Invalid release date" as const,
Comment on lines +38 to +42
getIssueDetails: ev(
v.config(v.pipe(v.string(), v.nonEmpty()), {
message: "Invalid issuecode",
}),
)(async (issuecode) => {
Comment on lines +28 to +32
sendNewEdgePhotoEmail: ev(
v.config(v.pipe(v.string(), v.nonEmpty()), {
message: "Invalid issuecode",
}),
)(async (issuecode: string) => {

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants