Skip to content

[SEC-A05]: Validación Zod en endpoints mutables - #196

Merged
CrisNAC merged 3 commits into
devfrom
OM-556-Fix
Jun 3, 2026
Merged

CrisNAC merged 3 commits into
devfrom
OM-556-Fix

Conversation

@Andoumeda

@Andoumeda Andoumeda commented Jun 3, 2026 •

Copy link
Copy Markdown
Collaborator

Summary by CodeRabbit

Release Notes

  • Chores
    • Se mejoró la validación de datos de entrada en múltiples endpoints para garantizar la integridad de los datos.
    • Se estandarizó la estructura de respuestas de errores de validación en toda la aplicación.
    • Se actualizaron pruebas automatizadas para verificar validaciones de entrada más robustas.

@coderabbitai

coderabbitai Bot commented Jun 3, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@Andoumeda, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 17 minutes and 46 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 03d210ff-5b9c-4987-a4d0-9e8322b7fbc7

📥 Commits

Reviewing files that changed from the base of the PR and between 8b1702c and bf412d5.

📒 Files selected for processing (2)
  • src/modules/global/dtos/product-categories/admin-category.dto.js
  • src/modules/global/dtos/product-tags/admin-tag.dto.js
📝 Walkthrough

Walkthrough

Se implementa un sistema exhaustivo de validación de entrada mediante el middleware validate y esquemas Zod, aplicado a más de 30 archivos de rutas en módulos admin, commerce, delivery y usuarios. Se crean ~30 DTOs especializados por dominio y se actualizan tests para verificar la nueva estructura de respuesta de error estandarizada.

Changes

Marco de validación centralizado con DTOs Zod

Capa / Archivo(s) Resumen
DTOs base y parámetros de identificadores
src/modules/global/dtos/base/base.param.dto.js, src/modules/global/dtos/common/params.dto.js
Se define IdParamDTO y 10 DTOs adicionales (CustomerIdParamDTO, CartIdParamDTO, OrderIdParamDTO, etc.) para validar identificadores de recurso como string→número con enteros positivos y mensajes de error en español.
DTOs de banners, comercios y entregas
src/modules/global/dtos/banners/admin-banner.dto.js, src/modules/global/dtos/business-hours/business-hours.dto.js, src/modules/global/dtos/commerce/admin-store.dto.js, src/modules/global/dtos/commerce/store.request.dto.js, src/modules/global/dtos/commerce-deliveries/commerce-deliveries.dto.js
Se crean DTOs para create/update/toggle de banners (con validación de endAt >= startAt), horarios de negocio (schedules con day_of_week y times), rechazo de comercios (reason trim+min 1), status de comercios (enum ACTIVE|INACTIVE), y entregas (fk_user positivo).
DTOs de productos, categorías y tags
src/modules/global/dtos/products/admin-product.dto.js, src/modules/global/dtos/product-categories/admin-category.dto.js, src/modules/global/dtos/product-tags/admin-tag.dto.js, src/modules/global/dtos/category-requests/category-request.dto.js, src/modules/global/dtos/wishlists/wishlist.dto.js
Se definen DTOs para status de producto (enum + reason condicional), create/update/decision de categorías (con validación "al menos un campo"), create/update de tags (name 1-20 chars), create category request (name 1-100 chars), y wishlist items (cambio fk_product→productId).
DTOs de entregas, órdenes y reportes
src/modules/global/dtos/deliveries/deliveries.dto.js, src/modules/global/dtos/delivery-assignments/delivery-assignments.dto.js, src/modules/global/dtos/orders/order.dto.js, src/modules/global/dtos/product-reports/product-report.dto.js, src/modules/global/dtos/review-reports/review-report.dto.js, src/modules/global/dtos/cart/cart.dto.js
Se crean DTOs para register/status/profile de entregas (enums + refine de al menos un campo), create/respond de asignaciones, create/quote/review/status de órdenes, create/update/resolve de reportes (producto/reseña), y carrito (productId positivo, quantity ≥1).

Validación integrada en rutas administrativas

Capa / Archivo(s) Resumen
Admin banners, categorías, productos, comercios, tags
src/modules/admin/banners/admin-banners.routes.js, src/modules/admin/categories/admin-category.routes.js, src/modules/admin/products/admin-products.routes.js, src/modules/admin/stores/admin-stores.routes.js, src/modules/admin/tags/admin-tag.routes.js
POST/PUT/PATCH/DELETE routes agregan validate(DTO, "params"/"body") después de authenticate/requireRole y antes del controlador, validando entradas contra DTOs correspondientes.

Validación integrada en rutas de comercio

Capa / Archivo(s) Resumen
Direcciones, horarios, categoría requests, stores, entregas, productos
src/modules/commerce/addresses/routes/addresses.routes.js, src/modules/commerce/business-hours/routes/business-hours.routes.js, src/modules/commerce/category-requests/category-request.routes.js, src/modules/commerce/commerces/store.routes.js, src/modules/commerce/deliveries/delivery.routes.js, src/modules/commerce/products/product.routes.js
POST/PUT/PATCH/DELETE routes encadenan validate(...) con DTOs específicos para parámetros (id, id_address, etc.) y cuerpos (crear/actualizar datos) antes de invocar handlers.

Validación integrada en rutas de entrega

Capa / Archivo(s) Resumen
Delivery assignments y delivery
src/modules/delivery/delivery-assignments/delivery-assignments.routes.js, src/modules/delivery/delivery/delivery.routes.js
POST/PATCH/PUT routes validan parámetros (id, orderId) y body (create/respond/register/status/profile) con DTOs antes de ejecutar controladores.

Validación integrada en rutas de usuarios

Capa / Archivo(s) Resumen
Direcciones, carrito, órdenes, reseñas, wishlists
src/modules/users/addresses/routes/addresses.routes.js, src/modules/users/cart/cart.routes.js, src/modules/users/orders/order.routes.js, src/modules/users/product-review/product-review.routes.js, src/modules/users/wishlist/wishlist.routes.js
POST/PUT/DELETE routes aplican validate(...) para parámetros (customerId, cartId, orderId, etc.) y cuerpos (crear/actualizar/eliminar) con DTOs especializados antes de handlers.

Validación en reportes globales

Capa / Archivo(s) Resumen
Product reports y review reports
src/modules/global/reports/product/product-report.routes.js, src/modules/global/reports/review/review-report.routes.js
POST/PUT/PATCH routes validan parámetros y body con DTOs de reportes (create/update/resolve) antes de ejecutar controladores.

Tests actualizados para nueva estructura de validación

Capa / Archivo(s) Resumen
Admin, commerce, delivery tests
tests/unit/admin/admin-category.test.js, tests/unit/admin/admin-tags.test.js, tests/unit/commerce/category-request.test.js, tests/unit/commerce/delivery.test.js, tests/unit/commerce/store-status.test.js, tests/unit/delivery/delivery-complete.test.js, tests/unit/delivery/delivery-profile.test.js, tests/unit/delivery/delivery-register.test.js, tests/unit/delivery/delivery-status.test.js
Se reemplazan aserciones antiguas (res.body.error.message con regex) por validaciones estructuradas de res.body.message === "Error de validación" y res.body.errors como array con objetos { field }.

Configuración TypeScript

Capa / Archivo(s) Resumen
tsconfig.json Se agregan opciones types: ["node"] y lib: ["ES2023"] para especificar tipos de Node y librería de compilación.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related PRs

  • CrisNAC/BackendMarketplace#45: El PR introduce el middleware validate.middleware.ts que estructura la respuesta de validación como { message: "Error de validación", errors: [...] }, que es la base utilizada en este PR para todas las validaciones.
  • CrisNAC/BackendMarketplace#105: Modifica src/modules/admin/categories/admin-category.routes.js agregando validación a PUT /api/admin/categories/:id, usando los mismos DTOs introducidos en este PR.
  • CrisNAC/BackendMarketplace#165: Introduce la gestión de banners en admin-banners.routes.js, que es complementada aquí con middleware validate y DTOs para validar POST/PUT/PATCH.

Suggested reviewers

  • CrisNAC
  • leoAchu16
  • SebaKisser

Poem

🐰 Con DTOs y validación al fin,
cada request es controlado sin fin,
Zod valida, parámetros se trimean,
y los errores con estructura se ven,
¡Qué hermoso es un input bien validado! ✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed El título describe claramente la implementación principal: validación con Zod en endpoints que modifican datos (mutables).
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch OM-556-Fix

Warning

Review ran into problems

🔥 Problems

Stopped waiting for pipeline failures after 30000ms. One of your pipelines takes longer than our 30000ms fetch window to run, so review may not consider pipeline-failure results for inline comments if any failures occurred after the fetch window. Increase the timeout if you want to wait longer or run a @coderabbit review after the pipeline has finished.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 10

🧹 Nitpick comments (2)
src/modules/commerce/deliveries/delivery.routes.js (1)

244-244: ⚡ Quick win

Consolidar los dos DTO de params en uno solo.

Igual que en addresses.routes.js, se encadenan validate(IdParamDTO, "params") y validate(DeliveryIdParamDTO, "params") sobre el mismo req.params. Un DTO combinado con id y deliveryId y una sola llamada es más claro y menos dependiente del orden/implementación del middleware. Verificá también que DeliveryIdParamDTO valide la clave deliveryId que usa la ruta.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/modules/commerce/deliveries/delivery.routes.js` at line 244, La ruta que
registra el handler deleteStoreDelivery está validando req.params dos veces con
IdParamDTO y DeliveryIdParamDTO; crea un DTO combinado (por ejemplo
StoreDeliveryParamsDTO) que declare los campos id y deliveryId, reemplaza las
dos llamadas validate(IdParamDTO, "params") y validate(DeliveryIdParamDTO,
"params") por una sola validate(StoreDeliveryParamsDTO, "params") y asegúrate de
que la propiedad deliveryId del nuevo DTO coincida exactamente con el nombre
usado en la ruta; deja deleteStoreDelivery y los middlewares authenticate y
requireRole(ROLES.SELLER) sin cambios.
src/modules/commerce/addresses/routes/addresses.routes.js (1)

23-25: ⚡ Quick win

Consolidar la validación de params en un solo DTO (PUT/DELETE)

En src/modules/commerce/addresses/routes/addresses.routes.js (lín. 23-25) se ejecuta validate(..., "params") dos veces sobre req.params; el middleware hace safeParse(req[section]) y luego Object.assign(req[section], ...), así que el parse ocurre dos veces y queda redundante/frágil. Conviene un DTO único (p. ej. { id, id_address }) y una sola llamada.

AddressIdParamDTO ya valida la clave id_address, que coincide con la ruta /:id/addresses/:id_address, por lo que esa parte está OK.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/modules/commerce/addresses/routes/addresses.routes.js` around lines 23 -
25, Consolida la validación de req.params creando un único DTO que incluya { id,
id_address } (por ejemplo StoreAddressParamsDTO) y usa solo una llamada a
validate(..., "params") en las rutas PUT y DELETE; reemplaza las dos
validaciones actuales (validate(IdParamDTO, "params"),
validate(AddressIdParamDTO, "params")) por validate(StoreAddressParamsDTO,
"params"), ajusta los imports para incluir el nuevo DTO y conserva las demás
llamadas (validate(UpdateAddressDTO, "body"), authenticate) y los handlers
updateStoreAddress y deleteStoreAddress sin cambios.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/middlewares/validate.middleware.js`:
- Line 25: El problema es que Object.assign(req[section], result.data) conserva
propiedades antiguas no validadas en req[section]; cambia la lógica en el
middleware de validación para descartar las propiedades previas y quedarse solo
con result.data: en la función/middleware donde aparece
Object.assign(req[section], result.data) (validate.middleware.js) sustituye ese
comportamiento por limpiar/reescribir completamente req[section] con los valores
validados (por ejemplo asignando req[section] = result.data o borrando las
claves existentes antes de copiar), de modo que solo queden las propiedades
parseadas por result.data y no se filtren campos extra a los controladores.

In `@src/modules/global/dtos/banners/admin-banner.dto.js`:
- Around line 3-5: La validación actual de dateString usando z.string().refine
con new Date(...) acepta valores que no son fechas de calendario válidas;
reemplazá esa validación por una combinación de validadores de Zod 4: usar
z.iso.date() o z.iso.datetime() y encadenar .pipe(z.coerce.date()) para forzar y
comprobar que la cadena representa una Date válida (referenciar la constante
dateString y la expresión z.string().refine en el diff); si el resto del
DTO/rutas debe seguir recibiendo string en lugar de Date, en lugar de coerción
usá superRefine sobre dateString para validar la existencia del calendario con
z.coerce.date() internamente o convertí la salida de vuelta a string tras la
coerción, y actualizá cualquier consumidor del DTO para aceptar el tipo
resultante (Date o string) según corresponda.

In `@src/modules/global/dtos/business-hours/business-hours.dto.js`:
- Around line 8-9: The current regex for open_time and close_time allows
single-digit hours (e.g., "9:30") but the DTO message and declared format
require HH:mm; update the validator in the open_time and close_time
z.string().regex calls to enforce two-digit hours (e.g., hours 00-23) by
replacing the pattern with one that requires exactly two hour digits, and/or
update the error message to match the accepted format—ensure you change both
occurrences (open_time and close_time) so the validation and the error text are
consistent.

In `@src/modules/global/dtos/common/params.dto.js`:
- Around line 3-45: The param DTOs (IdParamDTO, CustomerIdParamDTO,
CartIdParamDTO, CartItemIdParamDTO, OrderIdParamDTO, WishlistIdParamDTO,
ProductIdParamDTO, ReportIdParamDTO, ReviewIdParamDTO, DeliveryIdParamDTO,
AddressIdParamDTO) currently use transform(Number) which accepts "1e2" or
"0x10"; restrict to strictly decimal positive integers by first validating the
string with a regex that allows only digits and no leading zero (e.g.
/^[1-9]\d*$/) and then convert to Number, keeping the existing
z.number().int().positive() pipe for type checks and error messages. Ensure the
regex validation runs on the same string field name used in each DTO before
transformation so only valid decimal digit strings are converted.

In `@src/modules/global/dtos/deliveries/deliveries.dto.js`:
- Around line 3-22: The middleware currently does Object.assign(req[section],
result.data) which leaves extra/unvalidated keys in the original req[section];
update the validate middleware so it first removes any keys from req[section]
that are not present in result.data (iterate own keys and delete those missing
in result.data) and then assign the validated keys (or copy each key from
result.data into req[section]) to preserve the original object reference; apply
this change to the validate flow used for payloads validated against DTOs like
RegisterDeliveryDTO, UpdateDeliveryStatusDTO and UpdateDeliveryProfileDTO so
extra body fields are stripped before the handler sees them.
- Around line 16-22: UpdateDeliveryProfileDTO currently allows an empty object;
require at least one updatable field by adding a Zod-level validation to
UpdateDeliveryProfileDTO that rejects an object with no keys. Locate the
UpdateDeliveryProfileDTO z.object (fields: name, phone, vehicleType) and add a
.refine or .superRefine that checks Object.keys(value).length > 0 (or
equivalent) and returns a clear error message like "Al menos un campo debe estar
presente" when validation fails.

In `@src/modules/global/dtos/product-categories/admin-category.dto.js`:
- Line 4: Replace the deprecated Zod option key "message" with the unified
"error" in the schema for the name field: locate the z.string call used for the
name property (symbol: name, expression: z.string(...)) and change the passed
option object from { message: "El nombre de la categoría no puede estar vacío" }
to { error: "El nombre de la categoría no puede estar vacío" }; also scan nearby
DTO fields for any other z.*(... { message: ... }) usages and update them
similarly to { error: ... } to be Zod v4 compliant.

In `@src/modules/global/dtos/product-tags/admin-tag.dto.js`:
- Line 4: Replace the incorrect z.string({ message: ... }) usage with the Zod v4
form using the "error" key so the custom text is applied; in
src/modules/global/dtos/product-tags/admin-tag.dto.js update the z.string()
calls (notably the one for the name field and the other z.string instance
referenced in the review) to use { error: "..." } instead of { message: "..." }
so the custom error messages are honored by Zod v4.

In `@src/modules/users/product-review/product-review.routes.js`:
- Line 9: La ruta POST registrada con router.post("/", authenticate,
validate(CreateProductReviewDTO, "body"), createProductReview) no valida
req.params.id (el :id del mount padre); agrega una validación de params para
asegurar que el id del producto sea válido antes de llegar a
createProductReview. Concreta: usa la función validate para validar los
parámetros (validate(YourIdParamDTO, "params") o un DTO existente que represente
{ id: number }) y colócala entre authenticate y createProductReview en la misma
llamada a router.post para validar req.params.id.

In `@src/modules/users/wishlist/wishlist.routes.js`:
- Line 32: El body validado por CreateWishlistItemDTO usa fk_product mientras
que addWishlistItemService espera productId, provocando que requests con {
productId, quantity } sean rechazadas; para corregirlo, unifica el nombre de
campo (recomiendo adaptar CreateWishlistItemDTO para aceptar productId en lugar
de fk_product), actualizar la validación en CreateWishlistItemDTO para exigir
productId y quantity, ajustar cualquier destructuring en addWishlistItem or
addWishlistItemService para usar productId si aún no lo hace, y actualizar la
documentación de la ruta para reflejar el campo productId consistentemente.

---

Nitpick comments:
In `@src/modules/commerce/addresses/routes/addresses.routes.js`:
- Around line 23-25: Consolida la validación de req.params creando un único DTO
que incluya { id, id_address } (por ejemplo StoreAddressParamsDTO) y usa solo
una llamada a validate(..., "params") en las rutas PUT y DELETE; reemplaza las
dos validaciones actuales (validate(IdParamDTO, "params"),
validate(AddressIdParamDTO, "params")) por validate(StoreAddressParamsDTO,
"params"), ajusta los imports para incluir el nuevo DTO y conserva las demás
llamadas (validate(UpdateAddressDTO, "body"), authenticate) y los handlers
updateStoreAddress y deleteStoreAddress sin cambios.

In `@src/modules/commerce/deliveries/delivery.routes.js`:
- Line 244: La ruta que registra el handler deleteStoreDelivery está validando
req.params dos veces con IdParamDTO y DeliveryIdParamDTO; crea un DTO combinado
(por ejemplo StoreDeliveryParamsDTO) que declare los campos id y deliveryId,
reemplaza las dos llamadas validate(IdParamDTO, "params") y
validate(DeliveryIdParamDTO, "params") por una sola
validate(StoreDeliveryParamsDTO, "params") y asegúrate de que la propiedad
deliveryId del nuevo DTO coincida exactamente con el nombre usado en la ruta;
deja deleteStoreDelivery y los middlewares authenticate y
requireRole(ROLES.SELLER) sin cambios.
🪄 Autofix (Beta)

✅ Autofix completed


ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 38abba73-df21-41c0-b4eb-612d844f9be0

📥 Commits

Reviewing files that changed from the base of the PR and between 97ad8e2 and 3e121ab.

📒 Files selected for processing (47)
  • src/middlewares/validate.middleware.js
  • src/modules/admin/banners/admin-banners.routes.js
  • src/modules/admin/categories/admin-category.routes.js
  • src/modules/admin/products/admin-products.routes.js
  • src/modules/admin/stores/admin-stores.routes.js
  • src/modules/admin/tags/admin-tag.routes.js
  • src/modules/commerce/addresses/routes/addresses.routes.js
  • src/modules/commerce/business-hours/routes/business-hours.routes.js
  • src/modules/commerce/category-requests/category-request.routes.js
  • src/modules/commerce/commerces/store.routes.js
  • src/modules/commerce/deliveries/delivery.routes.js
  • src/modules/commerce/products/product.routes.js
  • src/modules/delivery/delivery-assignments/delivery-assignments.routes.js
  • src/modules/delivery/delivery/delivery.routes.js
  • src/modules/global/dtos/banners/admin-banner.dto.js
  • src/modules/global/dtos/base/base.param.dto.js
  • src/modules/global/dtos/business-hours/business-hours.dto.js
  • src/modules/global/dtos/cart/cart.dto.js
  • src/modules/global/dtos/category-requests/category-request.dto.js
  • src/modules/global/dtos/commerce-deliveries/commerce-deliveries.dto.js
  • src/modules/global/dtos/commerce/admin-store.dto.js
  • src/modules/global/dtos/commerce/store.request.dto.js
  • src/modules/global/dtos/common/params.dto.js
  • src/modules/global/dtos/deliveries/deliveries.dto.js
  • src/modules/global/dtos/delivery-assignments/delivery-assignments.dto.js
  • src/modules/global/dtos/orders/order.dto.js
  • src/modules/global/dtos/product-categories/admin-category.dto.js
  • src/modules/global/dtos/product-reports/product-report.dto.js
  • src/modules/global/dtos/product-tags/admin-tag.dto.js
  • src/modules/global/dtos/products/admin-product.dto.js
  • src/modules/global/dtos/review-reports/review-report.dto.js
  • src/modules/global/reports/product/product-report.routes.js
  • src/modules/global/reports/review/review-report.routes.js
  • src/modules/users/addresses/routes/addresses.routes.js
  • src/modules/users/cart/cart.routes.js
  • src/modules/users/orders/order.routes.js
  • src/modules/users/product-review/product-review.routes.js
  • src/modules/users/wishlist/wishlist.routes.js
  • tests/unit/admin/admin-category.test.js
  • tests/unit/admin/admin-tags.test.js
  • tests/unit/commerce/category-request.test.js
  • tests/unit/commerce/delivery.test.js
  • tests/unit/commerce/store-status.test.js
  • tests/unit/delivery/delivery-complete.test.js
  • tests/unit/delivery/delivery-profile.test.js
  • tests/unit/delivery/delivery-register.test.js
  • tests/unit/delivery/delivery-status.test.js

Comment thread src/middlewares/validate.middleware.js Outdated
Comment thread src/modules/global/dtos/banners/admin-banner.dto.js Outdated
Comment thread src/modules/global/dtos/business-hours/business-hours.dto.js Outdated
Comment thread src/modules/global/dtos/common/params.dto.js
Comment thread src/modules/global/dtos/deliveries/deliveries.dto.js
Comment thread src/modules/global/dtos/deliveries/deliveries.dto.js
Comment thread src/modules/global/dtos/product-categories/admin-category.dto.js Outdated
Comment thread src/modules/global/dtos/product-tags/admin-tag.dto.js Outdated
Comment thread src/modules/users/product-review/product-review.routes.js Outdated
Comment thread src/modules/users/wishlist/wishlist.routes.js
@coderabbitai

coderabbitai Bot commented Jun 3, 2026 •

Copy link
Copy Markdown
Contributor

Note

Autofix is a beta feature. Expect some limitations and changes as we gather feedback and continue to improve it.

Fixes Applied Successfully

Fixed 10 file(s) based on 10 unresolved review comments.

Files modified:

  • src/middlewares/validate.middleware.js
  • src/modules/global/dtos/banners/admin-banner.dto.js
  • src/modules/global/dtos/business-hours/business-hours.dto.js
  • src/modules/global/dtos/common/params.dto.js
  • src/modules/global/dtos/deliveries/deliveries.dto.js
  • src/modules/global/dtos/product-categories/admin-category.dto.js
  • src/modules/global/dtos/product-tags/admin-tag.dto.js
  • src/modules/global/dtos/wishlists/wishlist.dto.js
  • src/modules/users/product-review/product-review.routes.js
  • tsconfig.json

Commit: 8b1702cea68d2422e031295853014f776147fb2c

The changes have been pushed to the OM-556-Fix branch.

Time taken: 5m 28s

Fixed 10 file(s) based on 10 unresolved review comments.

Co-authored-by: CodeRabbit <noreply@coderabbit.ai>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/modules/global/dtos/product-categories/admin-category.dto.js`:
- Line 4: The Zod schema for the category DTO uses z.string with errorMap which
is not supported in Zod v4; update the schema where the property name is defined
(the `name` field in admin-category.dto.js) to use the `error` option instead of
`errorMap`, e.g. replace the errorMap customization on the `name` z.string(...)
call with the appropriate `error` object so the custom message "El nombre de la
categoría no puede estar vacío" is applied correctly.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 8af6af20-69d3-4158-bdaf-29eb3cc1ca72

📥 Commits

Reviewing files that changed from the base of the PR and between 3e121ab and 8b1702c.

📒 Files selected for processing (9)
  • src/modules/global/dtos/banners/admin-banner.dto.js
  • src/modules/global/dtos/business-hours/business-hours.dto.js
  • src/modules/global/dtos/common/params.dto.js
  • src/modules/global/dtos/deliveries/deliveries.dto.js
  • src/modules/global/dtos/product-categories/admin-category.dto.js
  • src/modules/global/dtos/product-tags/admin-tag.dto.js
  • src/modules/global/dtos/wishlists/wishlist.dto.js
  • src/modules/users/product-review/product-review.routes.js
  • tsconfig.json
✅ Files skipped from review due to trivial changes (3)
  • src/modules/global/dtos/product-tags/admin-tag.dto.js
  • src/modules/global/dtos/common/params.dto.js
  • tsconfig.json
🚧 Files skipped from review as they are similar to previous changes (2)
  • src/modules/global/dtos/deliveries/deliveries.dto.js
  • src/modules/global/dtos/banners/admin-banner.dto.js

Comment thread src/modules/global/dtos/product-categories/admin-category.dto.js Outdated
@sonarqubecloud

sonarqubecloud Bot commented Jun 3, 2026

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
10.9% Duplication on New Code (required ≤ 3%)

See analysis details on SonarQube Cloud

@CrisNAC
CrisNAC merged commit 50e6983 into dev Jun 3, 2026
2 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants