Express-validator: Define accepted fields
i am using the express-validator npm package. I looking for a way to prevent the user to send undesired fields on the body.
So, i want a validator that defines the accepted fields on the body. How can I do this with express-validator?
express-validator
add a comment |
i am using the express-validator npm package. I looking for a way to prevent the user to send undesired fields on the body.
So, i want a validator that defines the accepted fields on the body. How can I do this with express-validator?
express-validator
add a comment |
i am using the express-validator npm package. I looking for a way to prevent the user to send undesired fields on the body.
So, i want a validator that defines the accepted fields on the body. How can I do this with express-validator?
express-validator
i am using the express-validator npm package. I looking for a way to prevent the user to send undesired fields on the body.
So, i want a validator that defines the accepted fields on the body. How can I do this with express-validator?
express-validator
express-validator
asked Nov 21 '18 at 11:10
Gustavo SizílioGustavo Sizílio
311
311
add a comment |
add a comment |
2 Answers
2
active
oldest
votes
Just use matchedData from the filter API.
https://express-validator.github.io/docs/filter-api.html
add a comment |
I remember reading that it is a good idea to achieve this by taking a whitelist approach in the handler function. So, don't just incorporate all the posted variables. Specifically create a variable for each posted value you are expecting. Then If data is posted which you are not expecting it will not be incorporated into your program. Now I have written this I can see it is pretty much the same as the first answer.
add a comment |
Your Answer
StackExchange.ifUsing("editor", function () {
StackExchange.using("externalEditor", function () {
StackExchange.using("snippets", function () {
StackExchange.snippets.init();
});
});
}, "code-snippets");
StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "1"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});
function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});
}
});
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53410858%2fexpress-validator-define-accepted-fields%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
2 Answers
2
active
oldest
votes
2 Answers
2
active
oldest
votes
active
oldest
votes
active
oldest
votes
Just use matchedData from the filter API.
https://express-validator.github.io/docs/filter-api.html
add a comment |
Just use matchedData from the filter API.
https://express-validator.github.io/docs/filter-api.html
add a comment |
Just use matchedData from the filter API.
https://express-validator.github.io/docs/filter-api.html
Just use matchedData from the filter API.
https://express-validator.github.io/docs/filter-api.html
answered Nov 21 '18 at 11:21
Gustavo SizílioGustavo Sizílio
311
311
add a comment |
add a comment |
I remember reading that it is a good idea to achieve this by taking a whitelist approach in the handler function. So, don't just incorporate all the posted variables. Specifically create a variable for each posted value you are expecting. Then If data is posted which you are not expecting it will not be incorporated into your program. Now I have written this I can see it is pretty much the same as the first answer.
add a comment |
I remember reading that it is a good idea to achieve this by taking a whitelist approach in the handler function. So, don't just incorporate all the posted variables. Specifically create a variable for each posted value you are expecting. Then If data is posted which you are not expecting it will not be incorporated into your program. Now I have written this I can see it is pretty much the same as the first answer.
add a comment |
I remember reading that it is a good idea to achieve this by taking a whitelist approach in the handler function. So, don't just incorporate all the posted variables. Specifically create a variable for each posted value you are expecting. Then If data is posted which you are not expecting it will not be incorporated into your program. Now I have written this I can see it is pretty much the same as the first answer.
I remember reading that it is a good idea to achieve this by taking a whitelist approach in the handler function. So, don't just incorporate all the posted variables. Specifically create a variable for each posted value you are expecting. Then If data is posted which you are not expecting it will not be incorporated into your program. Now I have written this I can see it is pretty much the same as the first answer.
answered Nov 23 '18 at 10:25
user3425506user3425506
151113
151113
add a comment |
add a comment |
Thanks for contributing an answer to Stack Overflow!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53410858%2fexpress-validator-define-accepted-fields%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown