Skip to content

fix(users): validate profile updates at service boundary - #541

Closed
blackmore-technology-group wants to merge 1 commit into
ChainLearnOfficial:mainfrom
blackmore-technology-group:fix/534-profile-service-validation
Closed

blackmore-technology-group wants to merge 1 commit into
ChainLearnOfficial:mainfrom
blackmore-technology-group:fix/534-profile-service-validation

Conversation

@blackmore-technology-group

Copy link
Copy Markdown

Summary

Fixes #534.

UserService.updateProfile now validates at the service boundary instead of assuming every caller passed through the HTTP/Zod layer. It reuses the existing updateProfileSchema, so direct/internal callers get the same field limits, enum/type checks, and text sanitization without duplicating validation constants.

Validation failures are translated to the project's existing ValidationError shape before any database update occurs.

Tests

  • Added service-level regression coverage for an over-length displayName.
  • Added service-level regression coverage for null supplied to a string field by a direct/internal caller.
  • Both cases verify that db.update is never reached.
  • Targeted Vitest: 2/2 passed.
  • ESLint on the changed service and test: passed.

Repository baseline note

npm run typecheck is not currently a usable repo-wide gate on current main: it reports pre-existing syntax errors in unrelated files including src/config/index.ts, admin/credentials/quizzes/rewards services, and src/stellar/client.ts. This PR does not touch those files.

The scoped regression and lint gates for this change are green.

@DeFiVC DeFiVC closed this Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add field validation in updateProfile service method

2 participants