feat(api): validate kind on PUT /bookmarks

This commit is contained in:
2026-08-06 03:05:14 +07:00
parent dcec12ae72
commit d9d7a1c00d
2 changed files with 82 additions and 0 deletions
+9
View File
@@ -78,6 +78,15 @@ func (h *Handler) Put(w http.ResponseWriter, r *http.Request) {
return
}
// Same rule as status: empty means "keep the stored value". An unknown
// value is a client bug, not something to silently coerce to manga.
switch b.Kind {
case "", store.KindManga, store.KindNovel:
default:
writeJSON(w, http.StatusBadRequest, map[string]string{"error": "invalid kind"})
return
}
// Candidate timestamp, not a decision: Upsert keeps the stored one unless
// reading progress actually moved. Any client value is ignored.
b.UpdatedAt = time.Now().UnixMilli()