Skip to content

fix(api): enforce the listing price rule on update - #3

Merged
Denver-sn merged 1 commit into
Code-for-Senegal:mainfrom
SKonteye:fix/listing-price-on-update
Sep 7, 2026
Merged

Denver-sn merged 1 commit into
Code-for-Senegal:mainfrom
SKonteye:fix/listing-price-on-update

Conversation

@SKonteye

@SKonteye SKonteye commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

What

  • ListingsService.update now applies the same price rule as create, based on the stored listing type (the type cannot change after publication):
    • a sale rejects price: null with 400 A price is required for a sale;
    • a donation, barter or request ignores price, as create already does.
  • assertOwnership returns the listing type so the rule needs no extra query.
  • New unit spec listings.service.spec.ts (ownership check, price rule on a sale, price ignored on a donation).
  • Two end-to-end cases in listings.e2e-spec.ts for the same rule over HTTP.

Why

create enforces the rule, update did not. @IsOptional() in UpdateListingDto lets an explicit null through validation, so PATCH /listings/:id with { "price": null } turned a sale into a listing with no price, and { "price": 3000 } on a donation was persisted and shown publicly. This is one of the money-adjacent rules CONTRIBUTING asks to cover with tests.

Testing

  • pnpm lint
  • pnpm typecheck
  • pnpm test (11 unit tests, 4 new)
  • pnpm --filter @wantere/api test:e2e against the docker Postgres and Redis (11 tests, 2 new)
  • pnpm build
  • The two new end-to-end cases fail on main without the service change and pass with it.

No API surface change, so pnpm api:generate was not needed.

Screenshots

N/A, API only.

https://claude.ai/code/session_01TwmkH7BorySLrvJkMGGo3G

`create` refuses a sale without a price and never stores a price for a
donation, barter or request. `update` skipped that rule: `IsOptional` lets an
explicit `price: null` through validation, so a seller could strip the price
from a sale, and a price sent for a donation was persisted as-is.

The stored type now decides, since the type cannot change after publication:
a sale rejects `null` with 400, anything else ignores the field, exactly as
`create` does.

Claude-Session: https://claude.ai/code/session_01TwmkH7BorySLrvJkMGGo3G
@SKonteye
SKonteye marked this pull request as ready for review September 6, 2026 23:37
@Denver-sn
Denver-sn self-requested a review September 7, 2026 00:20

@Denver-sn Denver-sn left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

La règle de prix est maintenant appliquée sur la mise à jour en s'appuyant sur le type stocké après contrôle de propriété : les ventes conservent leur prix si le champ est absent, refusent null et acceptent une nouvelle valeur ; les autres types ignorent price. Les tests unitaires et E2E couvrent ces chemins, ainsi que l'autorisation. Aucun finding introduit par ce diff.

Vérification locale non exécutée : pnpm/corepack n'est pas disponible dans l'environnement de revue ; les checks GitHub affichés ne contiennent aucun résultat.

@Denver-sn
Denver-sn merged commit 2bb4e03 into Code-for-Senegal:main Sep 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants