fix(07): WR-02 add @Type(Number) coercion to pagination DTO fields
HTTP query params arrive as strings. Without @Type(() => Number), class-transformer never coerces page/limit before @IsInt() runs, causing HTTP 400 for any request that explicitly passes ?page or ?limit. Also adds @Max(100) on limit to bound result-set size.
This commit is contained in:
@@ -1,4 +1,5 @@
|
||||
import { IsInt, IsOptional, Min } from 'class-validator';
|
||||
import { Type } from 'class-transformer';
|
||||
import { IsInt, IsOptional, Max, Min } from 'class-validator';
|
||||
|
||||
/**
|
||||
* Query DTO for paginating the DKV invoice processing history.
|
||||
@@ -13,18 +14,25 @@ export class DkvHistoryQueryDto {
|
||||
/**
|
||||
* Page number (1-based). Defaults to 1 when omitted.
|
||||
* T-07-06: bounded integer prevents negative-page or non-integer injection.
|
||||
* @Type(() => Number) coerces the query-string string to a number before
|
||||
* validation — required because HTTP query params always arrive as strings.
|
||||
*/
|
||||
@IsOptional()
|
||||
@IsInt()
|
||||
@Min(1)
|
||||
@Type(() => Number)
|
||||
page?: number;
|
||||
|
||||
/**
|
||||
* Number of records per page. Defaults to 20 when omitted.
|
||||
* T-07-06: bounded integer mitigates oversized result-set DoS.
|
||||
* @Type(() => Number) coerces the query-string string to a number before
|
||||
* validation — required because HTTP query params always arrive as strings.
|
||||
*/
|
||||
@IsOptional()
|
||||
@IsInt()
|
||||
@Min(1)
|
||||
@Max(100)
|
||||
@Type(() => Number)
|
||||
limit?: number;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user