api hardening

This commit is contained in:
2026-03-16 10:46:05 +00:00
parent 598e4a6077
commit 023a8e9e6d
8 changed files with 378 additions and 24 deletions
@@ -47,8 +47,6 @@ export default async function ApiProxy(req, res) {
var queryUrl =
"incidents?$select=pinswg_environmentalstatementlocation,pinswg_caseaddress,modifiedon,description,numberofchildincidents,_accountid_value,_customerid_value,_pinswg_associatedlpa_value,_ownerid_value,pinswg_appealcasetype,statuscode,ticketnumber,title, _primarycontactid_value,pinswg_lpareference&$expand=primarycontactid($select=fullname)&$filter=(pinswg_appealcasetype eq 846040011 or pinswg_appealcasetype eq 846040002)and pinswg_publishtoweb eq true&$orderby=createdon desc&$count=true";
console.log(queryUrl);
return axios
.get(
WEBAPI_URL + queryUrl + hashAPIPath(queryUrl),
+22 -19
View File
@@ -43,6 +43,11 @@ const hashAPIPath = (queryPath) => {
export default async function ApiProxy(req, res) {
var searchString = req.query.searchString;
if (!searchString || String(searchString).trim().length === 0) {
return res.status(400).json();
}
var token = await getToken();
searchString = searchString.replace(/\'/g, "''");
@@ -54,28 +59,26 @@ export default async function ApiProxy(req, res) {
searchString +
"')) and (pinswg_appealcasetype eq 846040011 or pinswg_appealcasetype eq 846040002 ) and pinswg_publishtoweb eq true&$orderby=createdon desc&$count=true";
console.log("basic search ", queryUrl);
var apiResponse = _.isEmpty(req.query)
? res.status(400).json()
: searchString.length > 0
? axios
.get(
WEBAPI_URL + queryUrl + hashAPIPath(queryUrl),
azureHeadersPaged(token.access_token)
)
.then(({ data }) => {
var dataStr;
_.has(data, "@odata.nextLink") == true &&
((dataStr = JSON.stringify(data["@odata.nextLink"])),
(data["@odata.nextLink"] = dataStr.split("/v8.2/")[1]));
res.status(200).json(data);
})
.catch((error) => {
consoleLogger(error);
res.status(400).json(error);
})
: res.status(400).json();
? axios
.get(
WEBAPI_URL + queryUrl + hashAPIPath(queryUrl),
azureHeadersPaged(token.access_token)
)
.then(({ data }) => {
var dataStr;
_.has(data, "@odata.nextLink") == true &&
((dataStr = JSON.stringify(data["@odata.nextLink"])),
(data["@odata.nextLink"] = dataStr.split("/v8.2/")[1]));
res.status(200).json(data);
})
.catch((error) => {
consoleLogger(error);
res.status(400).json(error);
})
: res.status(400).json();
return apiResponse;
}
@@ -59,6 +59,18 @@ export default async function ApiProxy(req, res) {
var appealTypeName = req.query.appealTypeName;
var primaryIdAttribute = req.query.primaryIdAttribute;
var incidentID = req.query.incidentID;
if (
!appealTypeName ||
!primaryIdAttribute ||
!incidentID ||
String(appealTypeName).trim().length === 0 ||
String(primaryIdAttribute).trim().length === 0 ||
String(incidentID).trim().length === 0
) {
return res.status(400).json();
}
var token = await getToken();
let navigationProperty =
@@ -92,8 +104,6 @@ export default async function ApiProxy(req, res) {
? "pinswg_sipscase_value"
: primaryIdAttribute + "s_value");
console.log("query: ", queryUrl, "<<<<end query");
return axios
.get(
WEBAPI_URL + queryUrl + hashAPIPath(queryUrl),
@@ -102,7 +112,7 @@ export default async function ApiProxy(req, res) {
.then(({ data }) => {
let flattened = data.value.map((r) => ({
...r,
ticketnumber: r[navigationProperty]?.ticketnumber || null,
ticketnumber: r[navigationProperty]?.ticketnumber || null
}));
data.value = flattened;