feat(api): validate kind on PUT /bookmarks
This commit is contained in:
@@ -78,6 +78,15 @@ func (h *Handler) Put(w http.ResponseWriter, r *http.Request) {
|
||||
return
|
||||
}
|
||||
|
||||
// Same rule as status: empty means "keep the stored value". An unknown
|
||||
// value is a client bug, not something to silently coerce to manga.
|
||||
switch b.Kind {
|
||||
case "", store.KindManga, store.KindNovel:
|
||||
default:
|
||||
writeJSON(w, http.StatusBadRequest, map[string]string{"error": "invalid kind"})
|
||||
return
|
||||
}
|
||||
|
||||
// Candidate timestamp, not a decision: Upsert keeps the stored one unless
|
||||
// reading progress actually moved. Any client value is ignored.
|
||||
b.UpdatedAt = time.Now().UnixMilli()
|
||||
|
||||
Reference in New Issue
Block a user