Repository navigation
fix(api): enforce the listing price rule on update - #3
Merged
Denver-sn merged 1 commit intoSep 7, 2026
Merged
Conversation
`create` refuses a sale without a price and never stores a price for a donation, barter or request. `update` skipped that rule: `IsOptional` lets an explicit `price: null` through validation, so a seller could strip the price from a sale, and a price sent for a donation was persisted as-is. The stored type now decides, since the type cannot change after publication: a sale rejects `null` with 400, anything else ignores the field, exactly as `create` does. Claude-Session: https://claude.ai/code/session_01TwmkH7BorySLrvJkMGGo3G
SKonteye
marked this pull request as ready for review
September 6, 2026 23:37
Denver-sn
self-requested a review
September 7, 2026 00:20
Denver-sn
approved these changes
Sep 7, 2026
Denver-sn
left a comment
Collaborator
There was a problem hiding this comment.
La règle de prix est maintenant appliquée sur la mise à jour en s'appuyant sur le type stocké après contrôle de propriété : les ventes conservent leur prix si le champ est absent, refusent null et acceptent une nouvelle valeur ; les autres types ignorent price. Les tests unitaires et E2E couvrent ces chemins, ainsi que l'autorisation. Aucun finding introduit par ce diff.
Vérification locale non exécutée : pnpm/corepack n'est pas disponible dans l'environnement de revue ; les checks GitHub affichés ne contiennent aucun résultat.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
ListingsService.updatenow applies the same price rule ascreate, based on the stored listing type (the type cannot change after publication):price: nullwith400 A price is required for a sale;price, ascreatealready does.assertOwnershipreturns the listing type so the rule needs no extra query.listings.service.spec.ts(ownership check, price rule on a sale, price ignored on a donation).listings.e2e-spec.tsfor the same rule over HTTP.Why
createenforces the rule,updatedid not.@IsOptional()inUpdateListingDtolets an explicitnullthrough validation, soPATCH /listings/:idwith{ "price": null }turned a sale into a listing with no price, and{ "price": 3000 }on a donation was persisted and shown publicly. This is one of the money-adjacent rules CONTRIBUTING asks to cover with tests.Testing
pnpm lintpnpm typecheckpnpm test(11 unit tests, 4 new)pnpm --filter @wantere/api test:e2eagainst the docker Postgres and Redis (11 tests, 2 new)pnpm buildmainwithout the service change and pass with it.No API surface change, so
pnpm api:generatewas not needed.Screenshots
N/A, API only.
https://claude.ai/code/session_01TwmkH7BorySLrvJkMGGo3G