mirror of
https://github.com/zkldi/Tachi.git
synced 2026-09-30 02:48:01 +03:00
fix bug where users could set arbitrary things on their settings
This commit is contained in:
+27
@@ -136,6 +136,33 @@ t.test("PATCH /api/v1/users/:userID/games/:game/:playtype/settings", (t) => {
|
||||
t.end();
|
||||
});
|
||||
|
||||
t.test("Should reject a arbitrary things on game specific settings.", async (t) => {
|
||||
await db["api-tokens"].insert({
|
||||
userID: 1,
|
||||
identifier: "api_token",
|
||||
permissions: {
|
||||
customise_profile: true,
|
||||
},
|
||||
token: "api_token",
|
||||
fromAPIClient: null,
|
||||
});
|
||||
|
||||
const res = await mockApi
|
||||
.patch("/api/v1/users/1/games/iidx/SP/settings")
|
||||
.set("Authorization", "Bearer api_token")
|
||||
.send({
|
||||
preferredScoreAlg: "ktRating",
|
||||
gameSpecific: {
|
||||
display2DXTra: true,
|
||||
arbitraryValue: {},
|
||||
},
|
||||
});
|
||||
|
||||
t.equal(res.statusCode, 400);
|
||||
|
||||
t.end();
|
||||
});
|
||||
|
||||
t.test("Requires the user to be authed as the requested user.", async (t) => {
|
||||
await db["api-tokens"].insert({
|
||||
userID: 2,
|
||||
|
||||
+4
-6
@@ -55,12 +55,10 @@ router.patch(
|
||||
display2DXTra: "boolean",
|
||||
};
|
||||
}
|
||||
const err = p(
|
||||
req.body,
|
||||
{ gameSpecific: p.optional(schema) },
|
||||
{},
|
||||
{ allowExcessKeys: true }
|
||||
);
|
||||
// A limitation in prudence means that validating top-level properties like this isn't
|
||||
// possible.
|
||||
// A prudence v1.0. should fix this!
|
||||
const err = p({ __: req.body.gameSpecific }, { __: p.optional(schema) }, {});
|
||||
|
||||
if (err) {
|
||||
return res.status(400).json({
|
||||
|
||||
Reference in New Issue
Block a user