fix(orders): forward only the checkout's fields on an order update

PUT /api/orders/:uuid forwarded the browser's body to the CMS unchanged. It
now forwards { data } with only the seven fields of the checkout's steps:
email, acceptedTermsAndConditionsAt, invoiceAddress, deliveryAddress,
invoiceAddressStructured, deliveryAddressStructured and delivery. Any other
field, a field beside data, or a body of another shape is answered 400
"Invalid order update" with the CMS's error format, without calling the
CMS. The values are left to the CMS, which checks them and stays the
authority; this is defence in depth.

pickCustomerUpdate (server/utils/customerUpdate.ts) is pure and tested with
the exact payloads of steps 1 and 2 and with every server-only attribute of
the order.

Refs libretech/mp#71
This commit is contained in:
2026-10-09 02:32:20 +02:00
parent 5c773a99e6
commit bfcbbfac39
3 changed files with 254 additions and 2 deletions
+7 -2
View File
@@ -1,4 +1,5 @@
import { forwardToCms } from "~/server/utils/cmsApi";
import { invalidOrderUpdate, pickCustomerUpdate } from "~/server/utils/customerUpdate";
export default defineEventHandler(async (event) => {
const uuid = getRouterParam(event, "uuid");
@@ -6,10 +7,14 @@ export default defineEventHandler(async (event) => {
throw createError({ statusCode: 400, statusMessage: "Missing order UUID" });
}
const body = await readBody(event);
// Only the fields of the checkout's steps reach the CMS, which checks their values. Any other field is answered 400 here.
const update = pickCustomerUpdate(await readBody(event));
if (update.ok === false) {
throw createError(invalidOrderUpdate(update.errors));
}
return await forwardToCms(`/orders/${uuid}/cart`, {
method: "PUT",
body
body: { data: update.data }
});
});