Skip to content

Reject empty company/role in submit-application route - #1

Open
Powerworks wants to merge 1 commit into
mainfrom
pilot/20353
Open

Powerworks wants to merge 1 commit into
mainfrom
pilot/20353

Conversation

@Powerworks

Copy link
Copy Markdown
Collaborator

Summary

  • POST /applications accepted empty-string company and role values because bodySchema in src/slices/submit-application/route.ts only checked field presence, not content.
  • Added minLength: 1 to the company and role fields in bodySchema. This routes through Fastify's existing schema validation (no new error class or decider guard), which already maps validation failures to the existing 400 InvalidRequest response used for missing required fields.
  • Added a test in route.spec.ts covering an empty-string company being rejected with 400.

Why

An empty string is not a meaningful company or role name, and previously slipped past validation to create an application shell with no real identifying data.

Test plan

  • Ran the full project test suite: npm test (vitest, using testcontainers Postgres).
  • Result: 27 test files passed, 91 tests passed (includes the 3 tests in src/slices/submit-application/route.spec.ts, up from 2, covering the new empty-string rejection case).

🤖 Generated with Claude Code

POST /applications previously accepted empty-string company and role
values since bodySchema only checked presence, not content. Add
minLength: 1 to both fields so Fastify's existing schema validation
rejects empty strings the same way it already rejects missing
required fields, mapping to the existing 400 InvalidRequest response.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant