Objective
Reject malformed input at the edge and keep responses matching the documented contract.
Target area
api/routes, api/middleware
Context
Express routes validate input by hand or not at all. Schema validation stops injection-style bugs, gives consistent 400 errors, and can generate the OpenAPI spec.
Acceptance criteria
- Every route declares request schemas (params, query, body) and response schemas with a single library (e.g. zod).
- Validation errors return a consistent problem+json shape.
- OpenAPI documents are generated from the schemas, so the spec and implementation can't drift.
- Tests cover valid, boundary and malformed payloads for each route.
- Automated tests cover the primary flow, at least one boundary case, and at least one failure case.
- User-facing documentation or developer guidance is updated, including compatibility, security, or migration notes where applicable.
Pull request requirements
- All continuous integration checks must pass before a pull request may be merged.
- The branch must be free of merge conflicts with the target branch at the time of merge.
- Do not request merge with failing workflows, skipped required checks, or unresolved conflicts.
Objective
Reject malformed input at the edge and keep responses matching the documented contract.
Target area
api/routes, api/middlewareContext
Express routes validate input by hand or not at all. Schema validation stops injection-style bugs, gives consistent 400 errors, and can generate the OpenAPI spec.
Acceptance criteria
Pull request requirements