Bug Description
The submitQuizSchema in src/modules/quizzes/quiz.types.ts (lines 51-62) allows selectedIndex up to 20, but most quizzes have only 4-5 options. While the service validates the index against the actual question options (quiz.service.ts line 264), the schema validation is too permissive.
Location
src/modules/quizzes/quiz.types.ts lines 51-62
export const submitQuizSchema = z.object({
answers: z
.array(
z.object({
questionId: z.string().min(1).max(100),
selectedIndex: z.number().int().min(0).max(20),
})
)
.min(1, "At least one answer is required")
.max(50, "Too many answers"),
});
The Problem
selectedIndex max is 20, but MAX_QUIZ_OPTIONS is 10
- A user could submit
selectedIndex: 15 for a question with only 4 options
- The service catches this and logs a warning, but it's still accepted as a request
- This wastes processing time and clutters logs with warnings
Recommended Fix
Align the schema max with MAX_QUIZ_OPTIONS:
selectedIndex: z.number().int().min(0).max(MAX_QUIZ_OPTIONS - 1),
Or keep max(20) but document why it's higher than the typical options count.
Acceptance Criteria
- Align
selectedIndex max with MAX_QUIZ_OPTIONS (10)
- Or document why the schema allows higher values
- Reduce false-positive warnings in logs
Severity
low - Input validation improvement. The service already handles this correctly.
Bug Description
The
submitQuizSchemainsrc/modules/quizzes/quiz.types.ts(lines 51-62) allowsselectedIndexup to 20, but most quizzes have only 4-5 options. While the service validates the index against the actual question options (quiz.service.ts line 264), the schema validation is too permissive.Location
src/modules/quizzes/quiz.types.tslines 51-62The Problem
selectedIndexmax is 20, butMAX_QUIZ_OPTIONSis 10selectedIndex: 15for a question with only 4 optionsRecommended Fix
Align the schema max with
MAX_QUIZ_OPTIONS:Or keep max(20) but document why it's higher than the typical options count.
Acceptance Criteria
selectedIndexmax withMAX_QUIZ_OPTIONS(10)Severity
low - Input validation improvement. The service already handles this correctly.