mirror of
https://github.com/zkldi/Tachi.git
synced 2026-10-02 03:48:14 +03:00
fix bug where users could set arbitrary things on their settings
This commit is contained in:
+1
-1
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "tachi-server",
|
||||
"version": "2.0.33",
|
||||
"version": "2.0.34",
|
||||
"description": "A score tracking server.",
|
||||
"main": "js/index.js",
|
||||
"private": true,
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
|
||||
const MAJOR = 2;
|
||||
const MINOR = 0;
|
||||
const PATCH = 33;
|
||||
const PATCH = 34;
|
||||
|
||||
// As is with all front-facing zkldi projects, the version names for tachi-server
|
||||
// are from an album I like. In this case, the album is Portishead - Dummy.
|
||||
|
||||
+27
@@ -136,6 +136,33 @@ t.test("PATCH /api/v1/users/:userID/games/:game/:playtype/settings", (t) => {
|
||||
t.end();
|
||||
});
|
||||
|
||||
t.test("Should reject a arbitrary things on game specific settings.", async (t) => {
|
||||
await db["api-tokens"].insert({
|
||||
userID: 1,
|
||||
identifier: "api_token",
|
||||
permissions: {
|
||||
customise_profile: true,
|
||||
},
|
||||
token: "api_token",
|
||||
fromAPIClient: null,
|
||||
});
|
||||
|
||||
const res = await mockApi
|
||||
.patch("/api/v1/users/1/games/iidx/SP/settings")
|
||||
.set("Authorization", "Bearer api_token")
|
||||
.send({
|
||||
preferredScoreAlg: "ktRating",
|
||||
gameSpecific: {
|
||||
display2DXTra: true,
|
||||
arbitraryValue: {},
|
||||
},
|
||||
});
|
||||
|
||||
t.equal(res.statusCode, 400);
|
||||
|
||||
t.end();
|
||||
});
|
||||
|
||||
t.test("Requires the user to be authed as the requested user.", async (t) => {
|
||||
await db["api-tokens"].insert({
|
||||
userID: 2,
|
||||
|
||||
+4
-6
@@ -55,12 +55,10 @@ router.patch(
|
||||
display2DXTra: "boolean",
|
||||
};
|
||||
}
|
||||
const err = p(
|
||||
req.body,
|
||||
{ gameSpecific: p.optional(schema) },
|
||||
{},
|
||||
{ allowExcessKeys: true }
|
||||
);
|
||||
// A limitation in prudence means that validating top-level properties like this isn't
|
||||
// possible.
|
||||
// A prudence v1.0. should fix this!
|
||||
const err = p({ __: req.body.gameSpecific }, { __: p.optional(schema) }, {});
|
||||
|
||||
if (err) {
|
||||
return res.status(400).json({
|
||||
|
||||
Reference in New Issue
Block a user