No request validation on campaign/ship create/update (zod exists but unused there) #43
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
`createCampaign`/`updateCampaign`/`createShip`/`updateShip` controllers only check `name` presence and pass raw `req.body` into services. Zod schemas exist for users (`models/user.ts`) but not for campaigns/ships/characters payloads.
Consequences:
Suggested fix
Define zod schemas per entity (shared package would let the frontend reuse them) and parse bodies in controllers before calling services.
🔧 Work started — Adding zod schemas for campaign/ship payloads (
models/campaign.ts,models/ship.ts), parsing bodies in create/update controllers, returning 400 with field details.✅ Fixed & verified live (commit
7c0908e):models/campaign.ts+models/ship.ts— strict type checks on scalar fields, loose object-array validation for nested game entities, unknown keys strippeddetails: {field: [errors]}Live test:
POST /campaigns {players:not-an-array,startingResources:{throneGelt:lots}}→ 400