fix bug where users could set arbitrary things on their settings

This commit is contained in:
zkldi
2022-01-21 14:56:38 +00:00
parent 92b1cebd0c
commit cf27bb2e60
2 changed files with 31 additions and 6 deletions
@@ -136,6 +136,33 @@ t.test("PATCH /api/v1/users/:userID/games/:game/:playtype/settings", (t) => {
t.end();
});
t.test("Should reject a arbitrary things on game specific settings.", async (t) => {
await db["api-tokens"].insert({
userID: 1,
identifier: "api_token",
permissions: {
customise_profile: true,
},
token: "api_token",
fromAPIClient: null,
});
const res = await mockApi
.patch("/api/v1/users/1/games/iidx/SP/settings")
.set("Authorization", "Bearer api_token")
.send({
preferredScoreAlg: "ktRating",
gameSpecific: {
display2DXTra: true,
arbitraryValue: {},
},
});
t.equal(res.statusCode, 400);
t.end();
});
t.test("Requires the user to be authed as the requested user.", async (t) => {
await db["api-tokens"].insert({
userID: 2,
@@ -55,12 +55,10 @@ router.patch(
display2DXTra: "boolean",
};
}
const err = p(
req.body,
{ gameSpecific: p.optional(schema) },
{},
{ allowExcessKeys: true }
);
// A limitation in prudence means that validating top-level properties like this isn't
// possible.
// A prudence v1.0. should fix this!
const err = p({ __: req.body.gameSpecific }, { __: p.optional(schema) }, {});
if (err) {
return res.status(400).json({