From 92b1cebd0cf4b00ec970f22d5298f55586f50fe9 Mon Sep 17 00:00:00 2001 From: zkldi <20380519+zkldi@users.noreply.github.com> Date: Fri, 14 Jan 2022 13:32:54 +0000 Subject: [PATCH 1/2] Enable 0.8.4 as a valid lr2oraja client. --- .../import-types/ir/beatoraja/parser.ts | 24 ------------------- 1 file changed, 24 deletions(-) diff --git a/server/src/lib/score-import/import-types/ir/beatoraja/parser.ts b/server/src/lib/score-import/import-types/ir/beatoraja/parser.ts index 2729c3de3..18ba11bfa 100644 --- a/server/src/lib/score-import/import-types/ir/beatoraja/parser.ts +++ b/server/src/lib/score-import/import-types/ir/beatoraja/parser.ts @@ -63,30 +63,6 @@ const PR_BeatorajaChart = { hasRandom: "boolean", }; -const SUPPORTED_BMS_CLIENTS = [ - "LR2oraja 0.8.4", - "LR2oraja 0.8.3", - "LR2oraja 0.8.2", - "LR2oraja 0.8.1", - "LR2oraja 0.8.0", - // LITONE9 comes with its own fork of lr2oraja with a different name - "LR2oraja 0.8.4c", - // Rekidai maintains a custom fork of lr2oraja too... - "LR2oraja(rekidai.info) 0.8.4", - "LR2oraja(rekidai.info) 0.8.3", - "LR2oraja(rekidai.info) 0.8.2", - "LR2oraja(rekidai.info) 0.8.1", - "LR2oraja(rekidai.info) 0.8.0", -]; - -const SUPPORTED_PMS_CLIENTS = [ - "beatoraja 0.8.4", - "beatoraja 0.8.3", - "beatoraja 0.8.2", - "beatoraja 0.8.1", - "beatoraja 0.8.0", -]; - export function ParseBeatorajaSingle( body: Record, userID: integer, From cf27bb2e604dbf637d0f9ede78f5ec0f080a37f9 Mon Sep 17 00:00:00 2001 From: zkldi <20380519+zkldi@users.noreply.github.com> Date: Fri, 21 Jan 2022 14:53:24 +0000 Subject: [PATCH 2/2] fix bug where users could set arbitrary things on their settings --- .../_game/_playtype/settings/router.test.ts | 27 +++++++++++++++++++ .../games/_game/_playtype/settings/router.ts | 10 +++---- 2 files changed, 31 insertions(+), 6 deletions(-) diff --git a/server/src/server/router/api/v1/users/_userID/games/_game/_playtype/settings/router.test.ts b/server/src/server/router/api/v1/users/_userID/games/_game/_playtype/settings/router.test.ts index 19c14ed5b..49e994f48 100644 --- a/server/src/server/router/api/v1/users/_userID/games/_game/_playtype/settings/router.test.ts +++ b/server/src/server/router/api/v1/users/_userID/games/_game/_playtype/settings/router.test.ts @@ -136,6 +136,33 @@ t.test("PATCH /api/v1/users/:userID/games/:game/:playtype/settings", (t) => { t.end(); }); + t.test("Should reject a arbitrary things on game specific settings.", async (t) => { + await db["api-tokens"].insert({ + userID: 1, + identifier: "api_token", + permissions: { + customise_profile: true, + }, + token: "api_token", + fromAPIClient: null, + }); + + const res = await mockApi + .patch("/api/v1/users/1/games/iidx/SP/settings") + .set("Authorization", "Bearer api_token") + .send({ + preferredScoreAlg: "ktRating", + gameSpecific: { + display2DXTra: true, + arbitraryValue: {}, + }, + }); + + t.equal(res.statusCode, 400); + + t.end(); + }); + t.test("Requires the user to be authed as the requested user.", async (t) => { await db["api-tokens"].insert({ userID: 2, diff --git a/server/src/server/router/api/v1/users/_userID/games/_game/_playtype/settings/router.ts b/server/src/server/router/api/v1/users/_userID/games/_game/_playtype/settings/router.ts index ed865c379..e78e707fe 100644 --- a/server/src/server/router/api/v1/users/_userID/games/_game/_playtype/settings/router.ts +++ b/server/src/server/router/api/v1/users/_userID/games/_game/_playtype/settings/router.ts @@ -55,12 +55,10 @@ router.patch( display2DXTra: "boolean", }; } - const err = p( - req.body, - { gameSpecific: p.optional(schema) }, - {}, - { allowExcessKeys: true } - ); + // A limitation in prudence means that validating top-level properties like this isn't + // possible. + // A prudence v1.0. should fix this! + const err = p({ __: req.body.gameSpecific }, { __: p.optional(schema) }, {}); if (err) { return res.status(400).json({