Adds Zod as the validation library for apps/server (in place of
express-validator), scoped here to a low-risk slice rather than a
full migration:
- MCP tool-call arguments (apps/server/src/api-mcp) are now validated
end to end. Every tool's inputSchema is generated from its Zod
schema via z.toJSONSchema() instead of hand-maintained JSON Schema
literals, and every handler now parses its arguments before use —
previously every handler did an unchecked `args as SomeType` cast
with no runtime validation at all.
- A new validate.ts middleware (validateBody/validateParams) replaces
the express-validator chokepoint for two reference routers, session
and url-presets, demonstrating the pattern the remaining ~11 routers
will follow in later PRs.
- An oxlint no-restricted-imports guardrail keeps zod importable only
from apps/server, so it can never leak into the apps/client bundle.
The bulk of the REST router migration (automation, rundown, and the
rest of api-data) is intentionally left for follow-up PRs to keep this
change reviewable.
* chore: migrate eslint to oxlint
* chore: migrate prettier to oxfmt
* chore: migrate typescript
* chore: toThrow should have a expected value
* chore: cast test value as Day
* chore: small title fix
* chore: mocks should be hoisted
* chore: incorrect async useage
* chore: test should be inside description
* chore: test sohuld include an expeced
* chore: oxfmt
---------
Co-authored-by: alex-Arc <omnivox@LAPTOP-RC5SNBVV.localdomain>
* upgrade expressjs
* migration
* reenable test
* extend timeout on download test
* fixup! migration
* move empty body test from controller to validator
* enusre not empty
* extract validation function
* fixup! reenable test
* remove thin controllers
* disable e2e test of project file download