mirror of
https://github.com/strapi/strapi.git
synced 2025-07-27 19:10:01 +00:00

- Remove users-permissions sanitization step in core - Move sanitization functions to users-permissions plugin utils - Add sanitizers registry to container for manage sanitizer functions in core so that we can get/add sanitizers anywhere we want
64 lines
1.9 KiB
JavaScript
64 lines
1.9 KiB
JavaScript
'use strict';
|
|
|
|
const { isArray } = require('lodash/fp');
|
|
|
|
const traverseEntity = require('../traverse-entity');
|
|
const { getNonWritableAttributes } = require('../content-types');
|
|
const pipeAsync = require('../pipe-async');
|
|
|
|
const visitors = require('./visitors');
|
|
const sanitizers = require('./sanitizers');
|
|
|
|
module.exports = {
|
|
contentAPI: {
|
|
input(data, schema, { auth } = {}) {
|
|
if (isArray(data)) {
|
|
return Promise.all(data.map(entry => this.input(entry, schema, { auth })));
|
|
}
|
|
|
|
const nonWritableAttributes = getNonWritableAttributes(schema);
|
|
|
|
const transforms = [
|
|
// Remove non writable attributes
|
|
traverseEntity(visitors.restrictedFields(nonWritableAttributes), { schema }),
|
|
];
|
|
|
|
if (auth) {
|
|
// Remove restricted relations
|
|
transforms.push(traverseEntity(visitors.removeRestrictedRelations(auth), { schema }));
|
|
}
|
|
|
|
// Apply sanitizers from registry if exists
|
|
const sanitizersRegistry = strapi.container.get('sanitizers').get('content-api.input');
|
|
if (Array.isArray(sanitizersRegistry)) {
|
|
sanitizersRegistry.forEach(sanitizer => transforms.push(sanitizer(schema)));
|
|
}
|
|
|
|
return pipeAsync(...transforms)(data);
|
|
},
|
|
|
|
output(data, schema, { auth } = {}) {
|
|
if (isArray(data)) {
|
|
return Promise.all(data.map(entry => this.output(entry, schema, { auth })));
|
|
}
|
|
|
|
const transforms = [sanitizers.defaultSanitizeOutput(schema)];
|
|
|
|
if (auth) {
|
|
transforms.push(traverseEntity(visitors.removeRestrictedRelations(auth), { schema }));
|
|
}
|
|
|
|
// Apply sanitizers from registry if exists
|
|
const sanitizersRegistry = strapi.container.get('sanitizers').get('content-api.output');
|
|
if (Array.isArray(sanitizersRegistry)) {
|
|
sanitizersRegistry.forEach(sanitizer => transforms.push(sanitizer(schema)));
|
|
}
|
|
|
|
return pipeAsync(...transforms)(data);
|
|
},
|
|
},
|
|
|
|
sanitizers,
|
|
visitors,
|
|
};
|