From 7e845df994de8afa482dea7e498a408df8294a9c Mon Sep 17 00:00:00 2001 From: zkldi Date: Sat, 24 Jul 2021 14:50:52 +0100 Subject: [PATCH] add validation for PUT endpoints --- .../games/_game/_playtype/showcase/router.ts | 28 +++++++++++++++++++ 1 file changed, 28 insertions(+) diff --git a/server/src/server/router/api/v1/users/_userID/games/_game/_playtype/showcase/router.ts b/server/src/server/router/api/v1/users/_userID/games/_game/_playtype/showcase/router.ts index 574784b22..e2269541d 100644 --- a/server/src/server/router/api/v1/users/_userID/games/_game/_playtype/showcase/router.ts +++ b/server/src/server/router/api/v1/users/_userID/games/_game/_playtype/showcase/router.ts @@ -238,6 +238,34 @@ router.put("/", RequireAuthedAsUser, RequirePermissions("customise_profile"), as description: FormatPrError(err, "Invalid stat."), }); } + + if (stat.mode === "chart") { + // eslint-disable-next-line no-await-in-loop + const chart = await db.charts[game].findOne({ chartID: stat.chartID }); + + if (!chart || chart.playtype !== playtype) { + return res.status(400).json({ + success: false, + description: `Invalid chartID - must be a chart for this game and playtype.`, + }); + } + } else if (stat.mode === "folder") { + const folderIDs = Array.isArray(stat.folderID) ? stat.folderID : [stat.folderID]; + + // eslint-disable-next-line no-await-in-loop + const folders = await db.folders.find({ folderID: { $in: folderIDs } }); + + if ( + folders.length !== folderIDs.length || + !folders.every((r) => r.game === game && r.playtype === playtype) + ) { + return res.status(400).json({ + success: false, + // this error message is kinda lazy. + description: `Invalid folderID - must be a folder for this game and playtype.`, + }); + } + } } await db["game-settings"].update(