feat(security): pengerasan keamanan API internify-be (CORS, Rate Limiting, Helmet, Multer, Cookie)
This commit is contained in:
@@ -15,7 +15,8 @@ const storage = multer.diskStorage({
|
||||
destination: (_req, _file, cb) => cb(null, uploadDir),
|
||||
filename: (_req, file, cb) => {
|
||||
const uniqueSuffix = Date.now() + '-' + Math.round(Math.random() * 1E9);
|
||||
cb(null, uniqueSuffix + path.extname(file.originalname));
|
||||
const safeExt = path.extname(file.originalname).replace(/[^a-zA-Z0-9.]/g, '').toLowerCase();
|
||||
cb(null, `${uniqueSuffix}${safeExt}`);
|
||||
},
|
||||
});
|
||||
|
||||
@@ -39,6 +40,10 @@ const fileFilter = (req, file, cb) => {
|
||||
const upload = multer({
|
||||
storage: storage,
|
||||
fileFilter: fileFilter,
|
||||
limits: {
|
||||
fileSize: 5 * 1024 * 1024, // 5MB Makss
|
||||
files: 5,
|
||||
},
|
||||
});
|
||||
|
||||
// middleware untuk ngechek ukuran file
|
||||
@@ -88,6 +93,15 @@ const checkFileSizes = (req, res, next) => {
|
||||
// middleware untuk error multer
|
||||
const multerErrorHandler = (err, req, res, next) => {
|
||||
if (err instanceof multer.MulterError) {
|
||||
if (err.code === 'LIMIT_FILE_SIZE') {
|
||||
return res.status(413).json({
|
||||
status: false,
|
||||
data: null,
|
||||
message: 'Ukuran file terlalu besar. Maksimal 5MB',
|
||||
code: 413,
|
||||
});
|
||||
}
|
||||
|
||||
if (err.code === 'LIMIT_UNEXPECTED_FILE') {
|
||||
return res.status(400).json({
|
||||
status: false,
|
||||
|
||||
Reference in New Issue
Block a user