Repository navigation
fix(api): enforce password length and upload content validation - #84
Conversation
Follow-up to a validation audit of the interface-adapters layer. Two concrete, highest-value gaps: Password length was only enforced on the reset-password flow (PASSWORD_MIN_LENGTH), not on register or change-password, so a user could set a 1-character password through either of those paths. Extracted the check into use-cases/auth/passwordValidation.ts (mirrors the existing use-cases/jobs/bulkValidation.ts pattern — a plain same-layer helper, not a new port) and wired it into all three password-writing use cases. The document-upload flow validated authorization but not content: mimeType wasn't checked against any allow-list at requestUploadUrl or confirmDocument, and confirmDocument's sizeBytes accepted negative or unbounded values. Added use-cases/documents/documentValidation.ts with an allow-list (ALLOWED_DOCUMENT_MIME_TYPES) and a size cap (MAX_DOCUMENT_SIZE_BYTES, 10MB) in constants.ts, enforced in both use cases. All validation stays in the use-cases layer, consistent with Clean Architecture — interface-adapters (resolvers) and infrastructure (Prisma repos) are untouched; only business-rule checks were added where business logic already lives.
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (13)
WalkthroughThe change centralises password and document validation, applies checks before repository operations, and adds tests for invalid passwords, MIME types, and file sizes. ChangesInput validation
Estimated code review effort: 3 (Moderate) | ~20 minutes Possibly related PRs
Poem
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
Follow-up to a validation audit of
apps/api's interface-adapters layer. The audit found validation was thin and inconsistent across the API — this PR fixes the two highest-value, lowest-risk gaps that were flagged:ResetPasswordUseCaseenforcedPASSWORD_MIN_LENGTH(8 chars), butRegisterUseCaseandUpdatePasswordUseCasedidn't check length at all — a user could register or change their password to a single character. Extracted the check intouse-cases/auth/passwordValidation.ts(a plain same-layer helper, mirroring the existinguse-cases/jobs/bulkValidation.tspattern — not a new port/abstraction) and wired it into all three password-writing use cases.requestUploadUrlandconfirmDocumentnever checkedmimeTypeagainst an allow-list, andconfirmDocument'ssizeBytesaccepted negative or unbounded values. Addeduse-cases/documents/documentValidation.tswithALLOWED_DOCUMENT_MIME_TYPES(pdf/doc/docx/txt/png/jpeg, matching the document types the web app's upload UI actually offers) andMAX_DOCUMENT_SIZE_BYTES(10MB) inconstants.ts, enforced in both use cases.Clean Architecture: all new validation logic lives in the use-cases layer, next to the business logic it guards — no interface-adapters (resolvers) or infrastructure (Prisma repos) files were touched. The new helper modules are plain functions imported by sibling use-cases within the same layer, not new port interfaces, since they don't need to cross a layer boundary.
Deliberately out of scope (from the same audit, not part of this fix): email format validation,
documentTypeenum-ification, free-text length caps, date-string validation, and MCP tool parameter validation — larger/lower-priority items not requested for this pass.Test plan
pnpm --filter @job-finder/api test— 667 tests passing (7 new, covering the new validation paths)pnpm --filter @job-finder/api typecheck— cleanpnpm --filter @job-finder/api lint— cleanNote: one pre-existing, unrelated flaky test (
PrismaDocumentRepository— SQLite millisecond-resolution timestamp ordering) was observed during verification; not touched by this PR.🤖 Generated with Claude Code
Summary by CodeRabbit
New Features
Tests