fix: bypass ValidationPipe for multipart comments, auto-create uploads dir, expand client roles

- Use @Body() body: any in comment controller to skip global ValidationPipe
  which was rejecting multipart form bodies with forbidNonWhitelisted
- Auto-create uploads/ directory on startup to prevent ENOENT on file uploads
- Restrict file uploads to images only (remove pdf)
- Allow technician/collector roles to update clients (was manager-only)
This commit is contained in:
kevin-asprec
2026-05-06 18:20:14 +08:00
parent da9707f3fb
commit 85aea30730
3 changed files with 11 additions and 7 deletions

View File

@@ -54,7 +54,7 @@ export class ClientController {
}
@Patch(':id')
@Roles('manager')
@Roles('manager', 'technician', 'collector')
async update(
@CurrentUser() user: CurrentUserPayload,
@Param('id') id: string,

View File

@@ -12,7 +12,6 @@ import {
import { AuthGuard } from '@nestjs/passport';
import { FileFieldsInterceptor } from '@nestjs/platform-express';
import { CommentService } from './comment.service';
import { CreateCommentDto } from './dto/create-comment.dto';
import { Roles } from '../common/decorators/roles.decorator';
import { RolesGuard } from '../common/guards/roles.guard';
import { TenantGuard } from '../common/guards/tenant.guard';
@@ -39,10 +38,12 @@ export class CommentController {
async create(
@CurrentUser() user: CurrentUserPayload,
@Param('ticketId') ticketId: string,
@Body() body: CreateCommentDto,
@Body() body: any,
@UploadedFiles() files?: { files?: Express.Multer.File[] },
) {
const content = body.content;
let content = body?.content;
if (Array.isArray(content)) content = content[0];
if (typeof content !== 'string') content = String(content ?? '');
if (!content || content.length > 50000) {
throw new BadRequestException('Content must be between 1 and 50000 characters');
}

View File

@@ -1,12 +1,16 @@
import { MulterOptions } from '@nestjs/platform-express/multer/interfaces/multer-options.interface';
import { diskStorage } from 'multer';
import { extname } from 'path';
import { extname, resolve } from 'path';
import { existsSync, mkdirSync } from 'fs';
import { Request } from 'express';
const uploadDir = resolve('./uploads');
if (!existsSync(uploadDir)) mkdirSync(uploadDir, { recursive: true });
export const multerOptions: MulterOptions = {
storage: diskStorage({
destination: (_req: Request, _file: Express.Multer.File, cb: (error: Error | null, destination: string) => void) => {
cb(null, './uploads');
cb(null, uploadDir);
},
filename: (_req: Request, file: Express.Multer.File, cb: (error: Error | null, filename: string) => void) => {
const uniqueSuffix = Date.now() + '-' + Math.round(Math.random() * 1e9);
@@ -22,7 +26,6 @@ export const multerOptions: MulterOptions = {
'image/png',
'image/gif',
'image/webp',
'application/pdf',
];
if (allowed.includes(file.mimetype)) {
cb(null, true);