mirror of
https://github.com/ever-co/ever-gauzy.git
synced 2026-10-02 01:54:50 +08:00
fix: security in relations
This commit is contained in:
@@ -0,0 +1,35 @@
|
||||
---
|
||||
description: how to do comprehensive file search on Windows
|
||||
---
|
||||
|
||||
# Comprehensive File Search on Windows
|
||||
|
||||
The built-in `grep_search` tool can **silently miss files** on Windows, returning no results even for files that clearly contain the search term. This may be related to workspace paths with spaces, long paths, or other Windows-specific issues.
|
||||
|
||||
## Steps
|
||||
|
||||
// turbo-all
|
||||
|
||||
1. Use `findstr /S /N` for comprehensive recursive search across all directories:
|
||||
|
||||
```powershell
|
||||
findstr /S /N "searchTerm" packages\*.ts
|
||||
```
|
||||
|
||||
2. For case-insensitive search, add `/I`:
|
||||
|
||||
```powershell
|
||||
findstr /S /N /I "searchterm" packages\*.ts
|
||||
```
|
||||
|
||||
3. To search multiple file types or directories:
|
||||
|
||||
```powershell
|
||||
findstr /S /N "searchTerm" packages\*.ts apps\*.ts
|
||||
```
|
||||
|
||||
## When to Use
|
||||
|
||||
- **Always** use `findstr /S /N` when searching for function/class usage references, because plugins and other gitignored code may reference them
|
||||
- **Always** use `findstr /S /N` when auditing for security-related patterns across the entire codebase
|
||||
- Use `grep_search` only for quick searches where completeness is not critical
|
||||
@@ -12,3 +12,30 @@
|
||||
- For Nx plugin best practices, check `node_modules/@nx/<plugin>/PLUGIN.md`. Not all plugins have this file - proceed without it if unavailable.
|
||||
|
||||
<!-- nx configuration end-->
|
||||
|
||||
# File Search on Windows
|
||||
|
||||
> **IMPORTANT**: The built-in `grep_search` tool (ripgrep) can **silently miss files** on Windows, returning no results even for files that clearly contain the search term. This may be related to workspace paths with spaces, long paths, or other Windows-specific issues. Always verify critical searches with `findstr /S`.
|
||||
|
||||
## Recommended Approach
|
||||
|
||||
Always use `findstr /S` for comprehensive code searches to ensure **all** files are covered:
|
||||
|
||||
```powershell
|
||||
# Search recursively in all .ts files under packages/
|
||||
findstr /S /N "searchTerm" packages\*.ts
|
||||
|
||||
# Search with case-insensitivity
|
||||
findstr /S /N /I "searchterm" packages\*.ts
|
||||
|
||||
# Search across all source files
|
||||
findstr /S /N "searchTerm" packages\*.ts apps\*.ts
|
||||
```
|
||||
|
||||
## When to Use Each Tool
|
||||
|
||||
| Tool | Use When |
|
||||
| --------------- | ------------------------------------------------------------------ |
|
||||
| `grep_search` | Quick searches — but always verify critical results with `findstr` |
|
||||
| `findstr /S /N` | **Comprehensive searches** where completeness is essential |
|
||||
| `find_by_name` | Finding files by name/pattern |
|
||||
|
||||
@@ -1,10 +1,24 @@
|
||||
import { IEstimateEmailFindInput } from "@gauzy/contracts";
|
||||
import { ApiProperty } from "@nestjs/swagger";
|
||||
import { IsEmail, IsNotEmpty, IsString } from "class-validator";
|
||||
import { RelationsQueryDTO } from "./../../shared/dto";
|
||||
import { IEstimateEmailFindInput } from '@gauzy/contracts';
|
||||
import { ApiProperty, ApiPropertyOptional } from '@nestjs/swagger';
|
||||
import { Transform, TransformFnParams } from 'class-transformer';
|
||||
import { IsEmail, IsEnum, IsNotEmpty, IsOptional, IsString } from 'class-validator';
|
||||
|
||||
export class FindEstimateEmailQueryDTO extends RelationsQueryDTO implements IEstimateEmailFindInput {
|
||||
/**
|
||||
* Allowed relations for the estimate-email validation endpoint.
|
||||
*
|
||||
* Only relations whose columns are explicitly constrained by the service's
|
||||
* `select` clause are permitted. Any relation not in this enum will be
|
||||
* rejected by class-validator.
|
||||
*/
|
||||
export enum EstimateEmailRelationEnum {
|
||||
'tenant' = 'tenant',
|
||||
'organization' = 'organization'
|
||||
}
|
||||
|
||||
/**
|
||||
* Find estimate email request DTO validation
|
||||
*/
|
||||
export class FindEstimateEmailQueryDTO implements IEstimateEmailFindInput {
|
||||
@ApiProperty({ type: () => String, readOnly: true })
|
||||
@IsNotEmpty()
|
||||
@IsEmail()
|
||||
@@ -14,4 +28,10 @@ export class FindEstimateEmailQueryDTO extends RelationsQueryDTO implements IEst
|
||||
@IsNotEmpty()
|
||||
@IsString()
|
||||
readonly token: string;
|
||||
|
||||
@ApiPropertyOptional({ type: () => String, enum: EstimateEmailRelationEnum })
|
||||
@IsOptional()
|
||||
@Transform(({ value }: TransformFnParams) => (value ? value.map((element: string) => element.trim()) : []))
|
||||
@IsEnum(EstimateEmailRelationEnum, { each: true })
|
||||
readonly relations: string[] = [];
|
||||
}
|
||||
@@ -1,3 +1,35 @@
|
||||
import { RelationsQueryDTO } from "./../../../shared/dto";
|
||||
import { ApiPropertyOptional } from '@nestjs/swagger';
|
||||
import { Transform, TransformFnParams } from 'class-transformer';
|
||||
import { IsEnum, IsOptional } from 'class-validator';
|
||||
|
||||
export class PublicInvoiceQueryDTO extends RelationsQueryDTO {}
|
||||
/**
|
||||
* Allowed relations for the public invoice endpoint.
|
||||
*
|
||||
* Only relations whose columns are explicitly constrained by the service's
|
||||
* `select` clause are permitted. Any relation not in this enum will be
|
||||
* rejected by class-validator.
|
||||
*/
|
||||
export enum PublicInvoiceRelationEnum {
|
||||
'tenant' = 'tenant',
|
||||
'organization' = 'organization',
|
||||
'fromOrganization' = 'fromOrganization',
|
||||
'toContact' = 'toContact',
|
||||
'invoiceItems' = 'invoiceItems',
|
||||
'invoiceItems.employee' = 'invoiceItems.employee',
|
||||
'invoiceItems.employee.user' = 'invoiceItems.employee.user',
|
||||
'invoiceItems.project' = 'invoiceItems.project',
|
||||
'invoiceItems.product' = 'invoiceItems.product',
|
||||
'invoiceItems.expense' = 'invoiceItems.expense',
|
||||
'invoiceItems.task' = 'invoiceItems.task'
|
||||
}
|
||||
|
||||
/**
|
||||
* Get public invoice request DTO validation
|
||||
*/
|
||||
export class PublicInvoiceQueryDTO {
|
||||
@ApiPropertyOptional({ type: () => String, enum: PublicInvoiceRelationEnum })
|
||||
@IsOptional()
|
||||
@Transform(({ value }: TransformFnParams) => (value ? value.map((element: string) => element.trim()) : []))
|
||||
@IsEnum(PublicInvoiceRelationEnum, { each: true })
|
||||
readonly relations: string[] = [];
|
||||
}
|
||||
@@ -72,6 +72,11 @@ export class PublicInvoiceService {
|
||||
description: true
|
||||
},
|
||||
productId: true,
|
||||
product: {
|
||||
id: true,
|
||||
code: true,
|
||||
imageUrl: true
|
||||
},
|
||||
expenseId: true,
|
||||
expense: {
|
||||
id: true,
|
||||
|
||||
Reference in New Issue
Block a user