Skip to content

Add field validation in updateProfile service method #534

Description

@DeFiVC

Bug Description

The updateProfile method in src/modules/users/user.service.ts (lines 82-112) directly spreads the request body into the database update without validating field constraints. While Zod schemas validate at the route level, the service method itself doesn't enforce limits.

Location

src/modules/users/user.service.ts lines 86-90

async updateProfile(
    userId: string,
    data: UpdateProfileBody,
): Promise<UserProfile> {
    const [updated] = await db
        .update(users)
        .set({ ...data, updatedAt: new Date() })
        .where(eq(users.id, userId))
        .returning();

The Problem

The method spreads data directly into the update. If the Zod schema is bypassed (e.g., by calling the service method directly from another service), the database could receive:

  1. displayName longer than 100 characters (column limit)
  2. pace longer than 20 characters
  3. language longer than 10 characters
  4. Null values for fields that should be strings

While the database will reject values exceeding column limits with an error, it's better to validate at the service level for:

  • Clearer error messages
  • Defense in depth
  • Consistent validation regardless of call site

Recommended Fix

Add explicit validation in the service method:

async updateProfile(
    userId: string,
    data: UpdateProfileBody,
): Promise<UserProfile> {
    // Validate field lengths
    if (data.displayName && data.displayName.length > 100) {
        throw new ValidationError({ displayName: ["Display name must be 100 characters or less"] });
    }
    if (data.pace && data.pace.length > 20) {
        throw new ValidationError({ pace: ["Pace must be 20 characters or less"] });
    }
    // ... etc

    const [updated] = await db
        .update(users)
        .set({ ...data, updatedAt: new Date() })
        .where(eq(users.id, userId))
        .returning();

Acceptance Criteria

  • Add field length validation in the service method
  • Return clear validation errors for oversized fields
  • Consider using a shared validation utility

Severity

low - Defense in depth. The Zod schema at the route level should catch these, but the service should be self-contained.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions