Harden auth, payments, and frontend against review findings.
Close exploitable gaps in booking/payment flows, enforce token versioning and account checks, gate sensitive payment data, and add middleware plus input validation across admin routes. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
+23
-23
@@ -50,6 +50,29 @@ usersRouter.get('/', requireAuth(['admin']), async (c) => {
|
||||
return c.json({ users: result });
|
||||
});
|
||||
|
||||
// Get user statistics (admin) — registered before /:id so "stats" is not parsed as a user id
|
||||
usersRouter.get('/stats/overview', requireAuth(['admin']), async (c) => {
|
||||
const totalUsers = await dbGet<any>(
|
||||
(db as any)
|
||||
.select({ count: sql<number>`count(*)` })
|
||||
.from(users)
|
||||
);
|
||||
|
||||
const adminCount = await dbGet<any>(
|
||||
(db as any)
|
||||
.select({ count: sql<number>`count(*)` })
|
||||
.from(users)
|
||||
.where(eq((users as any).role, 'admin'))
|
||||
);
|
||||
|
||||
return c.json({
|
||||
stats: {
|
||||
total: totalUsers?.count || 0,
|
||||
admins: adminCount?.count || 0,
|
||||
},
|
||||
});
|
||||
});
|
||||
|
||||
// Get user by ID (admin or self)
|
||||
usersRouter.get('/:id', requireAuth(['admin', 'organizer', 'staff', 'marketing', 'user']), async (c) => {
|
||||
const id = c.req.param('id');
|
||||
@@ -286,27 +309,4 @@ usersRouter.delete('/:id', requireAuth(['admin']), async (c) => {
|
||||
}
|
||||
});
|
||||
|
||||
// Get user statistics (admin)
|
||||
usersRouter.get('/stats/overview', requireAuth(['admin']), async (c) => {
|
||||
const totalUsers = await dbGet<any>(
|
||||
(db as any)
|
||||
.select({ count: sql<number>`count(*)` })
|
||||
.from(users)
|
||||
);
|
||||
|
||||
const adminCount = await dbGet<any>(
|
||||
(db as any)
|
||||
.select({ count: sql<number>`count(*)` })
|
||||
.from(users)
|
||||
.where(eq((users as any).role, 'admin'))
|
||||
);
|
||||
|
||||
return c.json({
|
||||
stats: {
|
||||
total: totalUsers?.count || 0,
|
||||
admins: adminCount?.count || 0,
|
||||
},
|
||||
});
|
||||
});
|
||||
|
||||
export default usersRouter;
|
||||
|
||||
Reference in New Issue
Block a user