Files
directus/api/src/utils/validate-snapshot.ts
Rijk van Zanten ca3e7f521f Upgrade previous "Extensions" system to new "Errors" model (#18797)
* Typecheck across packages that are built with esbuild

* Boilerplate new Errors package

* No need, tsup checks with --dts

* Switch to tsup

* Setup dev script

* Add readme

* More boilerplaty things

* Finish createError function

* Install @directus/random

* Downgrade node types

* Add utility function to check if an error is a DirectusError

* Use new is-error check

* Install errors package

* Add failed validation common error

* Export common errors

* Move joi convertion to utils

* Export failed validation

* Use new failed validation error in validate-batch

* Enhance typing output of createError

* Remove outdir (handled by tsup now)

* Replace Exception with Error

* Replace exception in test

* Remove exceptions from app

* Remove exceptions from app

* Remove failed validation exception from users service

* Remove old failed validation exception from shared

* Remove exceptions package in favor of errors

* Uninstall exceptions

* Replace baseexception check

* Migrate content too large error

* Critical detail

* Replace ForbiddenException

* WIP remove exceptions

* Add ForbiddenError to errors

* HitRateLimitError

* Move validation related error/helper to new validation package

* Add index

* Add docs

* Install random

* Convert TokenExpired

* Convert user-suspended

* Convert invalid-credentials

* Move UnsupportedMediaType

* Replace wrong imports for forbidden

* Convert invalid-ip

* Move invalid provider

* Move InvalidOtp

* Convert InvalidToken

* Move MethodNotAllowed

* Convert range not satisfiable

* Move unexpect response

* Move UnprocessableContent

* Move IllegalAssetTransformation

* Move RouteNotFound

* Finalize not found

* Various db errors

* Move value too long

* Move not null

* Move record-not-unique

* Move value out of range

* Finish db errors

* Service unavailable

* GQL errors

* Update packages/validation/src/errors/failed-validation.ts

Co-authored-by: Azri Kahar <42867097+azrikahar@users.noreply.github.com>

* Update packages/validation/src/errors/failed-validation.ts

Co-authored-by: Azri Kahar <42867097+azrikahar@users.noreply.github.com>

* InvalidQuery

* Add test for invalid query message constructor

* Invalid Payload

* Finalize exceptions move

* Improve type of isDirectusError

* Various fixes

* Fix build in api

* Update websocket exceptions use

* Allow optional reason for invalid config

* Update errors usage in utils

* Remove unused package from errors

* Update lockfile

* Update api/src/auth/drivers/ldap.ts

Co-authored-by: Azri Kahar <42867097+azrikahar@users.noreply.github.com>

* Update packages/validation/src/utils/joi-to-error-extensions.ts

Co-authored-by: Azri Kahar <42867097+azrikahar@users.noreply.github.com>

* Put error codes in shared enum

* Replace instanceof checks in api

* Fix tests I think

* Tweak override names

* Fix linter warnings

* Set snapshots

* Start fixing BB tests

* Fix blackbox tests

* Add changeset

* Update changeset

* Update extension docs to use new createError abstraction

* 🙄

* Fix graphql validation error name

* 🥳

* use ErrorCode.Forbidden

* fix blackbox auth login test

* Add license files

* Rename preMutationException to preMutationError

* Remove unused ms dep & sort package.json

* Remove periods from error messages for consistency

Co-authored-by: Azri Kahar <42867097+azrikahar@users.noreply.github.com>

* Add optional code check

* Use updated error code checker

* Rename InvalidConfigError to InvalidProviderConfigError

---------

Co-authored-by: Azri Kahar <42867097+azrikahar@users.noreply.github.com>
Co-authored-by: Pascal Jufer <pascal-jufer@bluewin.ch>
Co-authored-by: ian <licitdev@gmail.com>
2023-06-27 17:22:26 -04:00

84 lines
2.4 KiB
TypeScript

import { TYPES } from '@directus/constants';
import Joi from 'joi';
import { ALIAS_TYPES } from '../constants.js';
import { getDatabaseClient } from '../database/index.js';
import { InvalidPayloadError } from '../errors/index.js';
import type { Snapshot } from '../types/index.js';
import { DatabaseClients } from '../types/index.js';
import { version as currentDirectusVersion } from './package.js';
const snapshotJoiSchema = Joi.object({
version: Joi.number().valid(1).required(),
directus: Joi.string().required(),
vendor: Joi.string()
.valid(...DatabaseClients)
.optional(),
collections: Joi.array().items(
Joi.object({
collection: Joi.string(),
meta: Joi.any(),
schema: Joi.object({
name: Joi.string(),
}),
})
),
fields: Joi.array().items(
Joi.object({
collection: Joi.string(),
field: Joi.string(),
meta: Joi.any(),
schema: Joi.object({
default_value: Joi.any(),
max_length: [Joi.number(), Joi.string(), Joi.valid(null)],
is_nullable: Joi.bool(),
})
.unknown()
.allow(null),
type: Joi.string()
.valid(...TYPES, ...ALIAS_TYPES)
.allow(null),
})
),
relations: Joi.array().items(
Joi.object({
collection: Joi.string(),
field: Joi.string(),
meta: Joi.any(),
related_collection: Joi.any(),
schema: Joi.any(),
})
),
});
/**
* Validates the snapshot against the current instance.
**/
export function validateSnapshot(snapshot: Snapshot, force = false) {
const { error } = snapshotJoiSchema.validate(snapshot);
if (error) throw new InvalidPayloadError({ reason: error.message });
// Bypass checks when "force" option is enabled
if (force) return;
if (snapshot.directus !== currentDirectusVersion) {
throw new InvalidPayloadError({
reason: `Provided snapshot's directus version ${snapshot.directus} does not match the current instance's version ${currentDirectusVersion}. You can bypass this check by passing the "force" query parameter`,
});
}
if (!snapshot.vendor) {
throw new InvalidPayloadError({
reason:
'Provided snapshot does not contain the "vendor" property. You can bypass this check by passing the "force" query parameter',
});
}
const currentVendor = getDatabaseClient();
if (snapshot.vendor !== currentVendor) {
throw new InvalidPayloadError({
reason: `Provided snapshot's vendor ${snapshot.vendor} does not match the current instance's vendor ${currentVendor}. You can bypass this check by passing the "force" query parameter`,
});
}
}