This commit is contained in:
@@ -5,11 +5,13 @@ const { requireAuth } = require("../middleware/auth");
|
||||
const router = express.Router();
|
||||
|
||||
const EMAIL_RE = /^[^\s@]+@[^\s@]+\.[^\s@]+$/;
|
||||
const HEX_COLOR_RE = /^#[0-9a-fA-F]{6}$/;
|
||||
|
||||
// POST /api/hibolia/orders — public order submission
|
||||
router.post("/orders", async (req, res) => {
|
||||
try {
|
||||
const { name, surname, email, message, color, shipping } = req.body || {};
|
||||
const { name, surname, email, message, color, customColor, shipping } =
|
||||
req.body || {};
|
||||
if (!name || !surname || !email || !message || !color || !shipping) {
|
||||
return res
|
||||
.status(400)
|
||||
@@ -18,6 +20,9 @@ router.post("/orders", async (req, res) => {
|
||||
if (!HiboliaOrder.COLORS.includes(color)) {
|
||||
return res.status(400).json({ error: "invalid color" });
|
||||
}
|
||||
if (color === "custom" && !HEX_COLOR_RE.test(String(customColor || ""))) {
|
||||
return res.status(400).json({ error: "invalid custom color" });
|
||||
}
|
||||
if (!EMAIL_RE.test(String(email))) {
|
||||
return res.status(400).json({ error: "invalid email" });
|
||||
}
|
||||
@@ -27,6 +32,7 @@ router.post("/orders", async (req, res) => {
|
||||
email,
|
||||
message,
|
||||
color,
|
||||
customColor: color === "custom" ? String(customColor).toLowerCase() : undefined,
|
||||
shipping,
|
||||
});
|
||||
res.status(201).json({ id: order._id });
|
||||
|
||||
@@ -12,9 +12,19 @@ const COLORS = [
|
||||
"black",
|
||||
"white",
|
||||
"pink",
|
||||
"turquoise",
|
||||
"teal",
|
||||
"navy",
|
||||
"lavender",
|
||||
"magenta",
|
||||
"lime",
|
||||
"coral",
|
||||
"custom",
|
||||
"none",
|
||||
];
|
||||
|
||||
const HEX_COLOR_RE = /^#[0-9a-f]{6}$/;
|
||||
|
||||
const hiboliaOrderSchema = new mongoose.Schema(
|
||||
{
|
||||
name: { type: String, required: true, trim: true, maxlength: 100 },
|
||||
@@ -22,6 +32,18 @@ const hiboliaOrderSchema = new mongoose.Schema(
|
||||
email: { type: String, required: true, trim: true, lowercase: true },
|
||||
message: { type: String, required: true, trim: true, maxlength: 2000 },
|
||||
color: { type: String, required: true, enum: COLORS },
|
||||
customColor: {
|
||||
type: String,
|
||||
trim: true,
|
||||
lowercase: true,
|
||||
required: [
|
||||
function () {
|
||||
return this.color === "custom";
|
||||
},
|
||||
"customColor is required when color is custom",
|
||||
],
|
||||
match: [HEX_COLOR_RE, "invalid custom color"],
|
||||
},
|
||||
shipping: { type: String, required: true, trim: true, maxlength: 2000 },
|
||||
},
|
||||
{ timestamps: true }
|
||||
|
||||
Reference in New Issue
Block a user