mirror of
https://github.com/cpvalente/ontime.git
synced 2026-08-13 03:13:47 +00:00
972a246bb6
Adds Zod as the validation library for apps/server (in place of express-validator), scoped here to a low-risk slice rather than a full migration: - MCP tool-call arguments (apps/server/src/api-mcp) are now validated end to end. Every tool's inputSchema is generated from its Zod schema via z.toJSONSchema() instead of hand-maintained JSON Schema literals, and every handler now parses its arguments before use — previously every handler did an unchecked `args as SomeType` cast with no runtime validation at all. - A new validate.ts middleware (validateBody/validateParams) replaces the express-validator chokepoint for two reference routers, session and url-presets, demonstrating the pattern the remaining ~11 routers will follow in later PRs. - An oxlint no-restricted-imports guardrail keeps zod importable only from apps/server, so it can never leak into the apps/client bundle. The bulk of the REST router migration (automation, rundown, and the rest of api-data) is intentionally left for follow-up PRs to keep this change reviewable.
20 lines
304 B
YAML
20 lines
304 B
YAML
packages:
|
|
- apps/*
|
|
- packages/*
|
|
|
|
catalog:
|
|
'@types/node': 22.19.11
|
|
rimraf: 6.0.1
|
|
ts-essentials: 10.1.1
|
|
typescript: 7.0.2
|
|
vitest: 4.0.17
|
|
zod: 4.4.3
|
|
|
|
allowBuilds:
|
|
'@parcel/watcher': true
|
|
'@sentry/cli': false
|
|
core-js: false
|
|
electron: true
|
|
electron-winstaller: false
|
|
esbuild: true
|