feat(08-03): FavoriteLink schema + FavoritesModule (CRUD + SSRF icon discovery)
- Add FavoriteLink Prisma model (userId/tenantId/widgetId scope, iconUrl nullable, position) - IconDiscoveryService: port SSRF-protected icon discovery with redirect: 'manual', private IP / blocked-hostname checks, 4000ms timeout, 200k HTML cap (T-08-05) - FavoritesService: list/create/update/remove all scoped by userId (T-08-06 / Pitfall 3) - FavoritesController: GET /favorites?widgetId, POST, PATCH :id, DELETE :id - FavoritesModule registered in AppModule - tsc --noEmit passes for @tessera/api
This commit is contained in:
@@ -0,0 +1,20 @@
|
||||
import { Module } from '@nestjs/common';
|
||||
import { FavoritesController } from './favorites.controller';
|
||||
import { FavoritesService } from './favorites.service';
|
||||
import { IconDiscoveryService } from './icon-discovery.service';
|
||||
|
||||
/**
|
||||
* NestJS module for per-user favorite link management.
|
||||
*
|
||||
* Provides:
|
||||
* - FavoritesController: REST API under /favorites (CRUD scoped by user + widget)
|
||||
* - FavoritesService: Business logic with userId-scoped queries (T-08-06)
|
||||
* - IconDiscoveryService: Server-side icon/favicon discovery with SSRF protection (T-08-05)
|
||||
*
|
||||
* PrismaModule is global — no need to re-import here.
|
||||
*/
|
||||
@Module({
|
||||
controllers: [FavoritesController],
|
||||
providers: [FavoritesService, IconDiscoveryService],
|
||||
})
|
||||
export class FavoritesModule {}
|
||||
Reference in New Issue
Block a user