backend zod verification

This commit is contained in:
2026-01-20 17:13:56 +00:00
parent c0a1a0b944
commit caf80f24ef
3 changed files with 132 additions and 1 deletions

View File

@@ -1,7 +1,27 @@
import * as z from "zod"
export default defineEventHandler(async (event) => {
const conf = useRuntimeConfig()
const body = await readBody(event)
console.log(body)
const schema = z.object({
email: z.email('Invalid email'),
password: z.string('Password is required').min(8, 'Must be at least 8 characters'),
remember: z.boolean().optional()
})
let validated;
try {
validated = schema.parse(body); // throws if invalid
} catch (err: any) {
// Zod throws a ZodError
return sendError(event, createError({
statusCode: 400,
statusMessage: err.errors?.[0]?.message || 'Invalid input'
}));
}
const is_https = await getRequestProtocol(event) == "https"
//console.log(is_https)
@@ -35,7 +55,9 @@ export default defineEventHandler(async (event) => {
secure: {
user_id: body.id
}
}, {
},
{
maxAge: (body.rembember) ? 60 * 60 * 24 * 7 : undefined,
cookie: {
secure: is_https,
sameSite: is_https ? 'none' : 'lax'