## Context #4765 Following investigations ([#5083](https://github.com/twentyhq/twenty/issues/5083)) we decided to restrict updates of server from which zero tables have been synchronized only ## How was it tested Locally with /metadata 1. Updating a database that already has synchronized tables <img width="1072" alt="Capture d’écran 2024-04-24 à 16 16 05" src="https://github.com/twentyhq/twenty/assets/51697796/f9a84c34-2dcd-4f3c-b0bc-b710abae5021"> 2. Updating a database that has no synchronized tables <img width="843" alt="Capture d’écran 2024-04-24 à 16 17 28" src="https://github.com/twentyhq/twenty/assets/51697796/f320fe03-a6bc-4724-bcd0-4e89d3ac31f5"> + tested that the connection works well
27 lines
676 B
TypeScript
27 lines
676 B
TypeScript
import { BadRequestException } from '@nestjs/common';
|
|
|
|
import { isDefined } from 'class-validator';
|
|
|
|
const INPUT_REGEX = /^([A-Za-z0-9\-_.@]+)$/;
|
|
|
|
export const validateObjectAgainstInjections = (input: object) => {
|
|
for (const [key, value] of Object.entries(input)) {
|
|
// Password are encrypted so we don't need to validate them
|
|
if (key === 'password') {
|
|
continue;
|
|
}
|
|
|
|
if (!isDefined(value)) {
|
|
continue;
|
|
}
|
|
|
|
validateStringAgainstInjections(value.toString());
|
|
}
|
|
};
|
|
|
|
export const validateStringAgainstInjections = (input: string) => {
|
|
if (!INPUT_REGEX.test(input)) {
|
|
throw new BadRequestException('Invalid remote server input');
|
|
}
|
|
};
|