Add auth.middleware and Pool to category router

This commit is contained in:
chris committed 2026-09-30 09:44:23 -04:00
1 parent f27d87531c
commit 3d7be239d6
1 file changed
+8 -3
+8 -3
View File
@@ -1,18 +1,23 @@
import { Router, Request, Response } from 'express';
import { CategoryRepository } from './category.repository.ts';
import { buildCategoryTree } from './tree.utility.ts';
import { createAuthMiddleware } from './auth.middleware.ts';
import { Pool } from 'pg';
// Clean regex pattern matching valid Postgres ltree structures
const LTREE_REGEX = /^[A-Za-z0-9_]+(\.[A-Za-z0-9_]+)*$/;
export function createCategoryRouter(repository: CategoryRepository): Router {
export function createCategoryRouter(repository: CategoryRepository, db: Pool): Router {
const router = Router();
const auth = createAuthMiddleware(db);
router.get('/tree{/:path}', async (req: Request, res: Response): Promise<void> => {
router.get('/tree{/:path}', auth, async (req: Request, res: Response): Promise<void> => {
try {
const rawPath = req.params.path;
const parentPath = Array.isArray(rawPath) ? rawPath[0] : (rawPath || 'Top');
const userId = (req as any).userId;
// 1. INPUT VALIDATION: Stop malicious or broken ltree strings early
if (!LTREE_REGEX.test(parentPath)) {
res.status(400).json({
@@ -22,7 +27,7 @@ export function createCategoryRouter(repository: CategoryRepository): Router {
return; // Break execution early
}
const flatRows = await repository.findAllDescendants(parentPath);
const flatRows = await repository.findAllDescendants(parentPath, userId);
const nestedTree = flatRows.length > 0 ? buildCategoryTree(flatRows) : [];
res.json({ success: true, data: nestedTree });