mirror of
				https://github.com/TriliumNext/Notes.git
				synced 2025-10-29 11:44:21 +08:00 
			
		
		
		
	don't allow patching relation's value in ETAPI #3998
This commit is contained in:
		
							parent
							
								
									af67cf64b1
								
							
						
					
					
						commit
						c4f69fd9cb
					
				| @ -40,19 +40,25 @@ function register(router) { | ||||
|         } | ||||
|     }); | ||||
| 
 | ||||
|     const ALLOWED_PROPERTIES_FOR_PATCH = { | ||||
|     const ALLOWED_PROPERTIES_FOR_PATCH_LABEL = { | ||||
|         'value': [v.notNull, v.isString], | ||||
|         'position': [v.notNull, v.isInteger] | ||||
|     }; | ||||
| 
 | ||||
|     const ALLOWED_PROPERTIES_FOR_PATCH_RELATION = { | ||||
|         'position': [v.notNull, v.isInteger] | ||||
|     }; | ||||
| 
 | ||||
|     eu.route(router, 'patch' ,'/etapi/attributes/:attributeId', (req, res, next) => { | ||||
|         const attribute = eu.getAndCheckAttribute(req.params.attributeId); | ||||
| 
 | ||||
|         if (attribute.type === 'relation') { | ||||
|         if (attribute.type === 'label') { | ||||
|             eu.validateAndPatch(attribute, req.body, ALLOWED_PROPERTIES_FOR_PATCH_LABEL); | ||||
|         } else if (attribute.type === 'relation') { | ||||
|             eu.getAndCheckNote(req.body.value); | ||||
|         } | ||||
| 
 | ||||
|         eu.validateAndPatch(attribute, req.body, ALLOWED_PROPERTIES_FOR_PATCH); | ||||
|             eu.validateAndPatch(attribute, req.body, ALLOWED_PROPERTIES_FOR_PATCH_RELATION); | ||||
|         } | ||||
| 
 | ||||
|         attribute.save(); | ||||
| 
 | ||||
|  | ||||
		Loading…
	
	
			
			x
			
			
		
	
		Reference in New Issue
	
	Block a user
	 zadam
						zadam