From 3d7be239d6a3b3dbcbd3c9602768cfba42e3d237 Mon Sep 17 00:00:00 2001 From: Chris Smith Date: Wed, 30 Sep 2026 09:44:23 -0400 Subject: [PATCH] Add auth.middleware and Pool to category router --- api/src/category.router.ts | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/api/src/category.router.ts b/api/src/category.router.ts index 2ce2dfe..6981e9b 100644 --- a/api/src/category.router.ts +++ b/api/src/category.router.ts @@ -1,18 +1,23 @@ import { Router, Request, Response } from 'express'; import { CategoryRepository } from './category.repository.ts'; import { buildCategoryTree } from './tree.utility.ts'; +import { createAuthMiddleware } from './auth.middleware.ts'; +import { Pool } from 'pg'; // Clean regex pattern matching valid Postgres ltree structures const LTREE_REGEX = /^[A-Za-z0-9_]+(\.[A-Za-z0-9_]+)*$/; -export function createCategoryRouter(repository: CategoryRepository): Router { +export function createCategoryRouter(repository: CategoryRepository, db: Pool): Router { const router = Router(); + const auth = createAuthMiddleware(db); - router.get('/tree{/:path}', async (req: Request, res: Response): Promise => { + router.get('/tree{/:path}', auth, async (req: Request, res: Response): Promise => { try { const rawPath = req.params.path; const parentPath = Array.isArray(rawPath) ? rawPath[0] : (rawPath || 'Top'); + const userId = (req as any).userId; + // 1. INPUT VALIDATION: Stop malicious or broken ltree strings early if (!LTREE_REGEX.test(parentPath)) { res.status(400).json({ @@ -22,7 +27,7 @@ export function createCategoryRouter(repository: CategoryRepository): Router { return; // Break execution early } - const flatRows = await repository.findAllDescendants(parentPath); + const flatRows = await repository.findAllDescendants(parentPath, userId); const nestedTree = flatRows.length > 0 ? buildCategoryTree(flatRows) : []; res.json({ success: true, data: nestedTree });