fix: bypass ValidationPipe for multipart comments, auto-create uploads dir, expand client roles
- Use @Body() body: any in comment controller to skip global ValidationPipe which was rejecting multipart form bodies with forbidNonWhitelisted - Auto-create uploads/ directory on startup to prevent ENOENT on file uploads - Restrict file uploads to images only (remove pdf) - Allow technician/collector roles to update clients (was manager-only)
This commit is contained in:
@@ -54,7 +54,7 @@ export class ClientController {
|
|||||||
}
|
}
|
||||||
|
|
||||||
@Patch(':id')
|
@Patch(':id')
|
||||||
@Roles('manager')
|
@Roles('manager', 'technician', 'collector')
|
||||||
async update(
|
async update(
|
||||||
@CurrentUser() user: CurrentUserPayload,
|
@CurrentUser() user: CurrentUserPayload,
|
||||||
@Param('id') id: string,
|
@Param('id') id: string,
|
||||||
|
|||||||
@@ -12,7 +12,6 @@ import {
|
|||||||
import { AuthGuard } from '@nestjs/passport';
|
import { AuthGuard } from '@nestjs/passport';
|
||||||
import { FileFieldsInterceptor } from '@nestjs/platform-express';
|
import { FileFieldsInterceptor } from '@nestjs/platform-express';
|
||||||
import { CommentService } from './comment.service';
|
import { CommentService } from './comment.service';
|
||||||
import { CreateCommentDto } from './dto/create-comment.dto';
|
|
||||||
import { Roles } from '../common/decorators/roles.decorator';
|
import { Roles } from '../common/decorators/roles.decorator';
|
||||||
import { RolesGuard } from '../common/guards/roles.guard';
|
import { RolesGuard } from '../common/guards/roles.guard';
|
||||||
import { TenantGuard } from '../common/guards/tenant.guard';
|
import { TenantGuard } from '../common/guards/tenant.guard';
|
||||||
@@ -39,10 +38,12 @@ export class CommentController {
|
|||||||
async create(
|
async create(
|
||||||
@CurrentUser() user: CurrentUserPayload,
|
@CurrentUser() user: CurrentUserPayload,
|
||||||
@Param('ticketId') ticketId: string,
|
@Param('ticketId') ticketId: string,
|
||||||
@Body() body: CreateCommentDto,
|
@Body() body: any,
|
||||||
@UploadedFiles() files?: { files?: Express.Multer.File[] },
|
@UploadedFiles() files?: { files?: Express.Multer.File[] },
|
||||||
) {
|
) {
|
||||||
const content = body.content;
|
let content = body?.content;
|
||||||
|
if (Array.isArray(content)) content = content[0];
|
||||||
|
if (typeof content !== 'string') content = String(content ?? '');
|
||||||
if (!content || content.length > 50000) {
|
if (!content || content.length > 50000) {
|
||||||
throw new BadRequestException('Content must be between 1 and 50000 characters');
|
throw new BadRequestException('Content must be between 1 and 50000 characters');
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,12 +1,16 @@
|
|||||||
import { MulterOptions } from '@nestjs/platform-express/multer/interfaces/multer-options.interface';
|
import { MulterOptions } from '@nestjs/platform-express/multer/interfaces/multer-options.interface';
|
||||||
import { diskStorage } from 'multer';
|
import { diskStorage } from 'multer';
|
||||||
import { extname } from 'path';
|
import { extname, resolve } from 'path';
|
||||||
|
import { existsSync, mkdirSync } from 'fs';
|
||||||
import { Request } from 'express';
|
import { Request } from 'express';
|
||||||
|
|
||||||
|
const uploadDir = resolve('./uploads');
|
||||||
|
if (!existsSync(uploadDir)) mkdirSync(uploadDir, { recursive: true });
|
||||||
|
|
||||||
export const multerOptions: MulterOptions = {
|
export const multerOptions: MulterOptions = {
|
||||||
storage: diskStorage({
|
storage: diskStorage({
|
||||||
destination: (_req: Request, _file: Express.Multer.File, cb: (error: Error | null, destination: string) => void) => {
|
destination: (_req: Request, _file: Express.Multer.File, cb: (error: Error | null, destination: string) => void) => {
|
||||||
cb(null, './uploads');
|
cb(null, uploadDir);
|
||||||
},
|
},
|
||||||
filename: (_req: Request, file: Express.Multer.File, cb: (error: Error | null, filename: string) => void) => {
|
filename: (_req: Request, file: Express.Multer.File, cb: (error: Error | null, filename: string) => void) => {
|
||||||
const uniqueSuffix = Date.now() + '-' + Math.round(Math.random() * 1e9);
|
const uniqueSuffix = Date.now() + '-' + Math.round(Math.random() * 1e9);
|
||||||
@@ -22,7 +26,6 @@ export const multerOptions: MulterOptions = {
|
|||||||
'image/png',
|
'image/png',
|
||||||
'image/gif',
|
'image/gif',
|
||||||
'image/webp',
|
'image/webp',
|
||||||
'application/pdf',
|
|
||||||
];
|
];
|
||||||
if (allowed.includes(file.mimetype)) {
|
if (allowed.includes(file.mimetype)) {
|
||||||
cb(null, true);
|
cb(null, true);
|
||||||
|
|||||||
Reference in New Issue
Block a user