From caf80f24ef8c1bba6fb6c8a564058e8b10b7c92a Mon Sep 17 00:00:00 2001 From: suricata Date: Tue, 20 Jan 2026 17:13:56 +0000 Subject: [PATCH] backend zod verification --- server/routes/login.post.ts | 24 +++++++++- server/routes/settings/changepw.post.ts | 49 +++++++++++++++++++ server/routes/settings/edit_user.post.ts | 60 ++++++++++++++++++++++++ 3 files changed, 132 insertions(+), 1 deletion(-) create mode 100644 server/routes/settings/changepw.post.ts create mode 100644 server/routes/settings/edit_user.post.ts diff --git a/server/routes/login.post.ts b/server/routes/login.post.ts index 43baa25..255841a 100644 --- a/server/routes/login.post.ts +++ b/server/routes/login.post.ts @@ -1,7 +1,27 @@ +import * as z from "zod" + export default defineEventHandler(async (event) => { const conf = useRuntimeConfig() const body = await readBody(event) + console.log(body) + + const schema = z.object({ + email: z.email('Invalid email'), + password: z.string('Password is required').min(8, 'Must be at least 8 characters'), + remember: z.boolean().optional() + }) + + let validated; + try { + validated = schema.parse(body); // throws if invalid + } catch (err: any) { + // Zod throws a ZodError + return sendError(event, createError({ + statusCode: 400, + statusMessage: err.errors?.[0]?.message || 'Invalid input' + })); + } const is_https = await getRequestProtocol(event) == "https" //console.log(is_https) @@ -35,7 +55,9 @@ export default defineEventHandler(async (event) => { secure: { user_id: body.id } - }, { + }, + { + maxAge: (body.rembember) ? 60 * 60 * 24 * 7 : undefined, cookie: { secure: is_https, sameSite: is_https ? 'none' : 'lax' diff --git a/server/routes/settings/changepw.post.ts b/server/routes/settings/changepw.post.ts new file mode 100644 index 0000000..4055772 --- /dev/null +++ b/server/routes/settings/changepw.post.ts @@ -0,0 +1,49 @@ +import * as z from "zod" + +export default defineEventHandler(async (event) => { + + const body = await readBody(event) + if (body.new_pw !== body.confirm_new_pw) + throw createError({status:400, message: "Passwords don't match!"}) + + const session = await getUserSession(event) + const config = await useRuntimeConfig(event) + + const schema = z.object({ + old_pw: z.string(), + new_pw: z.string().min(8, "Min 8 chars"), + confirm_new_pw: z.string().min(8, "Min 8 chars"), + }) + + let validated; + try { + validated = schema.parse(body); // throws if invalid + } catch (err: any) { + // Zod throws a ZodError + return sendError(event, createError({ + statusCode: 400, + statusMessage: err.errors?.[0]?.message || 'Invalid input' + })); + } + + // @ts-ignore + const userId = session.secure?.user_id; + if (userId == undefined || userId == null) + throw createError({ status: 401 }) + + const current_r = await fetch(config.fastapi_url + "/me" + '?' + + new URLSearchParams({ id: userId })) + if (!current_r.ok) + if (current_r.status == 404) + throw createError({status: 404, message: "User doesn't exist"}) + + await $fetch(config.fastapi_url + "/changepw", { + method: "POST", + body: { + user_id: userId, + old_password: body.old_pw, + password: body.new_pw + } + }) + +}) diff --git a/server/routes/settings/edit_user.post.ts b/server/routes/settings/edit_user.post.ts new file mode 100644 index 0000000..45ca5e3 --- /dev/null +++ b/server/routes/settings/edit_user.post.ts @@ -0,0 +1,60 @@ +import * as z from "zod" + +export default defineEventHandler(async (event) => { + const config = await useRuntimeConfig(event) + let body = await readBody(event) + console.log(body) + const session = await getUserSession(event) + + const schema = z.object({ + first_name: z.string(), + last_name: z.string(), + email: z.email() + }) + let validated; + try { + validated = schema.parse(body); // throws if invalid + } catch (err: any) { + // Zod throws a ZodError + return sendError(event, createError({ + statusCode: 400, + statusMessage: err.errors?.[0]?.message || 'Invalid input' + })); + } + + // @ts-ignore + const userId = session.secure?.user_id; + if (userId == undefined || userId == null) + throw createError({ status: 401 }) + + const current_r = await fetch(config.fastapi_url + "/me" + '?' + + new URLSearchParams({ id: userId })) + + if (!current_r.ok) + if (current_r.status == 404) + throw createError({ status: 404, message: "User not found"}) + + + const current_body = await current_r.json(); + try { delete current_body["id"]; } catch {} + try { delete current_body["password"]; } catch {} + try { delete current_body["created_at"] } catch {} + try { delete current_body["updated_at"]; } catch {} + + + //let differences: Record = {}; + + let a = { ...body }; + a.user_id = userId! + console.log(a) + + //console.log("Differences: " + JSON.stringify(differences)); + + await $fetch(config.fastapi_url + "/edit_user", { + method: "POST", + body: a + }) + + return + +})