From f8df71508b085a167d212c95412758dadce397ad Mon Sep 17 00:00:00 2001 From: Jackson Harper Date: Wed, 10 May 2023 23:09:31 +0800 Subject: [PATCH] Enforce max lengths on signup credentials --- packages/api/src/routers/auth/auth_router.ts | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/packages/api/src/routers/auth/auth_router.ts b/packages/api/src/routers/auth/auth_router.ts index 0b4b5266c..8022d1caa 100644 --- a/packages/api/src/routers/auth/auth_router.ts +++ b/packages/api/src/routers/auth/auth_router.ts @@ -74,13 +74,17 @@ const cookieParams = { export const isValidSignupRequest = (obj: any): obj is SignupRequest => { return ( 'email' in obj && - obj.email.trim().length > 0 && // email must not be empty + obj.email.trim().length > 0 && + obj.email.trim().length < 512 && // email must not be empty 'password' in obj && - obj.password.length >= 8 && // password must be at least 8 characters + obj.password.length >= 8 && + obj.password.trim().length < 512 && // password must be at least 8 characters 'name' in obj && - obj.name.trim().length > 0 && // name must not be empty + obj.name.trim().length > 0 && + obj.name.trim().length < 512 && // name must not be empty 'username' in obj && - obj.username.trim().length > 0 // username must not be empty + obj.username.trim().length > 0 && + obj.username.trim().length < 512 // username must not be empty ) }