Skip to content

feat: add input validation enhancements for DTOs - #362

Merged
EmmanuelOchaje merged 1 commit into
StellarTickets:mainfrom
sanmipaul:feat/validation-enhancements
Sep 26, 2026
Merged

EmmanuelOchaje merged 1 commit into
StellarTickets:mainfrom
sanmipaul:feat/validation-enhancements

Conversation

@sanmipaul

@sanmipaul sanmipaul commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Comprehensive input validation enhancements addressing issues #238, #239, #240, and #241.

Changes

#241: Add seat format validation

  • Created new @IsSeat decorator in src/common/decorators/is-seat.decorator.ts
  • Validates seat format: 1-64 characters, alphanumeric with spaces, hyphens, slashes, or periods
  • Rejects whitespace-only values
  • Applied to 4 DTOs: IssueTicketDto, PurchasePrimaryDto, ConfirmIssueTicketDto, ConfirmPurchasePrimaryDto
  • Comprehensive test suite included

#240: Add max-length validators

  • Added @MaxLength decorators to all free-text string fields across DTOs
  • Field limits:
    • name fields: 256 characters (Events, Organizations, Ticket Types, Gates, Scanner Devices, Users)
    • venue: 256 characters
    • slug: 128 characters
    • reason: 512 characters
    • events: 512 characters
    • secret: 256 characters
  • Updated docs/VALIDATION.md with comprehensive limits table

#239: Add string trimming via @Transform

  • Applied @Transform decorators to trim leading/trailing whitespace
  • Covers name, venue, reason, events, secret fields
  • Prevents whitespace-only values from bypassing validation

#238: Add ValidationPipe config test

  • Created new e2e test file: test/validation-pipe.e2e-spec.ts
  • Tests unknown field rejection (returns 400)
  • Verifies whitelist: true and forbidNonWhitelisted: true options work correctly

DTOs Modified

  • src/auth/dto/register.dto.ts
  • src/events/dto/create-event.dto.ts
  • src/events/dto/create-ticket-type.dto.ts
  • src/gates/dto/create-gate.dto.ts
  • src/organizations/dto/create-organization.dto.ts
  • src/scanner-devices/dto/register-scanner-device.dto.ts
  • src/tickets/dto/confirm-check-in.dto.ts
  • src/tickets/dto/confirm-issue-ticket.dto.ts
  • src/tickets/dto/confirm-purchase-primary.dto.ts
  • src/tickets/dto/issue-ticket.dto.ts
  • src/tickets/dto/purchase-primary.dto.ts
  • src/webhooks/dto/create-webhook-endpoint.dto.ts

Test Plan

  • New @IsSeat decorator tests verify valid/invalid seat formats
  • Global ValidationPipe config test added
  • All DTOs have been updated with proper decorators
  • Documentation updated in docs/VALIDATION.md
  • No existing tests should be broken by these changes

closes #238
closes #239
closes #240
closes #241

Addresses issues StellarTickets#238, StellarTickets#239, StellarTickets#240, StellarTickets#241:

- StellarTickets#241: Add seat format validation with @IsSeat decorator
  - Validates seat format (1-64 chars, alphanumeric + spaces/hyphens/slashes/periods)
  - Rejects whitespace-only values
  - Applied to IssueTicketDto, PurchasePrimaryDto, ConfirmIssueTicketDto, ConfirmPurchasePrimaryDto

- StellarTickets#240: Add max-length validators to free-text DTO fields
  - Added @maxlength to name fields (256 chars) in CreateEventDto, CreateOrganizationDto, CreateTicketTypeDto, CreateGateDto, RegisterScannerDeviceDto, RegisterDto
  - Added @maxlength to venue (256), slug (128), reason (512), events (512), secret (256)
  - Documented limits in docs/VALIDATION.md

- StellarTickets#239: Add @Transform trimming for string DTO fields
  - Trim leading/trailing whitespace from name, venue, reason, events, secret fields
  - Prevents whitespace-only values from passing validation

- StellarTickets#238: Add global ValidationPipe config test
  - New test file: test/validation-pipe.e2e-spec.ts
  - Tests that unknown fields return 400
  - Verifies whitelist and forbidNonWhitelisted options work correctly

All tests added for new @IsSeat decorator to cover valid/invalid seat formats.
@netlify

netlify Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for stellarticketsbackend ready!

Name Link
🔨 Latest commit 198b46a
🔍 Latest deploy log https://app.netlify.com/projects/stellarticketsbackend/deploys/6ab747d5cea8920008316f8c
😎 Deploy Preview https://deploy-preview-362--stellarticketsbackend.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@drips-wave

drips-wave Bot commented Sep 26, 2026

Copy link
Copy Markdown

@sanmipaul Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@EmmanuelOchaje
EmmanuelOchaje merged commit 2df99b8 into StellarTickets:main Sep 26, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants