backend zod verification
This commit is contained in:
60
server/routes/settings/edit_user.post.ts
Normal file
60
server/routes/settings/edit_user.post.ts
Normal file
@@ -0,0 +1,60 @@
|
||||
import * as z from "zod"
|
||||
|
||||
export default defineEventHandler(async (event) => {
|
||||
const config = await useRuntimeConfig(event)
|
||||
let body = await readBody(event)
|
||||
console.log(body)
|
||||
const session = await getUserSession(event)
|
||||
|
||||
const schema = z.object({
|
||||
first_name: z.string(),
|
||||
last_name: z.string(),
|
||||
email: z.email()
|
||||
})
|
||||
let validated;
|
||||
try {
|
||||
validated = schema.parse(body); // throws if invalid
|
||||
} catch (err: any) {
|
||||
// Zod throws a ZodError
|
||||
return sendError(event, createError({
|
||||
statusCode: 400,
|
||||
statusMessage: err.errors?.[0]?.message || 'Invalid input'
|
||||
}));
|
||||
}
|
||||
|
||||
// @ts-ignore
|
||||
const userId = session.secure?.user_id;
|
||||
if (userId == undefined || userId == null)
|
||||
throw createError({ status: 401 })
|
||||
|
||||
const current_r = await fetch(config.fastapi_url + "/me" + '?' +
|
||||
new URLSearchParams({ id: userId }))
|
||||
|
||||
if (!current_r.ok)
|
||||
if (current_r.status == 404)
|
||||
throw createError({ status: 404, message: "User not found"})
|
||||
|
||||
|
||||
const current_body = await current_r.json();
|
||||
try { delete current_body["id"]; } catch {}
|
||||
try { delete current_body["password"]; } catch {}
|
||||
try { delete current_body["created_at"] } catch {}
|
||||
try { delete current_body["updated_at"]; } catch {}
|
||||
|
||||
|
||||
//let differences: Record<string, any> = {};
|
||||
|
||||
let a = { ...body };
|
||||
a.user_id = userId!
|
||||
console.log(a)
|
||||
|
||||
//console.log("Differences: " + JSON.stringify(differences));
|
||||
|
||||
await $fetch(config.fastapi_url + "/edit_user", {
|
||||
method: "POST",
|
||||
body: a
|
||||
})
|
||||
|
||||
return
|
||||
|
||||
})
|
||||
Reference in New Issue
Block a user