From 49eab55abe38efca8eb51a6084657b24c42f7758 Mon Sep 17 00:00:00 2001 From: Schalli Date: Sat, 27 Jun 2026 17:21:28 +0200 Subject: [PATCH] fix(07): WR-02 add @Type(Number) coercion to pagination DTO fields HTTP query params arrive as strings. Without @Type(() => Number), class-transformer never coerces page/limit before @IsInt() runs, causing HTTP 400 for any request that explicitly passes ?page or ?limit. Also adds @Max(100) on limit to bound result-set size. --- apps/api/src/dkv/dto/dkv-history.dto.ts | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/apps/api/src/dkv/dto/dkv-history.dto.ts b/apps/api/src/dkv/dto/dkv-history.dto.ts index d441f93..a693c7c 100644 --- a/apps/api/src/dkv/dto/dkv-history.dto.ts +++ b/apps/api/src/dkv/dto/dkv-history.dto.ts @@ -1,4 +1,5 @@ -import { IsInt, IsOptional, Min } from 'class-validator'; +import { Type } from 'class-transformer'; +import { IsInt, IsOptional, Max, Min } from 'class-validator'; /** * Query DTO for paginating the DKV invoice processing history. @@ -13,18 +14,25 @@ export class DkvHistoryQueryDto { /** * Page number (1-based). Defaults to 1 when omitted. * T-07-06: bounded integer prevents negative-page or non-integer injection. + * @Type(() => Number) coerces the query-string string to a number before + * validation — required because HTTP query params always arrive as strings. */ @IsOptional() @IsInt() @Min(1) + @Type(() => Number) page?: number; /** * Number of records per page. Defaults to 20 when omitted. * T-07-06: bounded integer mitigates oversized result-set DoS. + * @Type(() => Number) coerces the query-string string to a number before + * validation — required because HTTP query params always arrive as strings. */ @IsOptional() @IsInt() @Min(1) + @Max(100) + @Type(() => Number) limit?: number; }