fix(graphql): errors should not result in internal error

This commit is contained in:
daedalus 2023-11-19 11:17:14 -05:00
parent 68ea256e5b
commit e51752e11c
2 changed files with 19 additions and 11 deletions

View File

@ -27,10 +27,10 @@
}, },
"dependencies": { "dependencies": {
"@sindresorhus/slugify": "1.1.0", "@sindresorhus/slugify": "1.1.0",
"lodash": "^4.17.21",
"yup": "^0.32.9",
"@strapi/strapi": "^4.14.0", "@strapi/strapi": "^4.14.0",
"@strapi/utils": "^4.14.0" "@strapi/utils": "^4.14.0",
"lodash": "^4.17.21",
"yup": "^0.32.9"
}, },
"devDependencies": { "devDependencies": {
"eslint": "^8.53.0", "eslint": "^8.53.0",

View File

@ -3,6 +3,7 @@ const { getPluginService } = require('../utils/getPluginService');
const { isValidFindSlugParams } = require('../utils/isValidFindSlugParams'); const { isValidFindSlugParams } = require('../utils/isValidFindSlugParams');
const { hasRequiredModelScopes } = require('../utils/hasRequiredModelScopes'); const { hasRequiredModelScopes } = require('../utils/hasRequiredModelScopes');
const { sanitizeOutput } = require('../utils/sanitizeOutput'); const { sanitizeOutput } = require('../utils/sanitizeOutput');
const { ForbiddenError, ValidationError } = require('@strapi/utils').errors;
const getCustomTypes = (strapi, nexus) => { const getCustomTypes = (strapi, nexus) => {
const { naming } = getPluginService('utils', 'graphql'); const { naming } = getPluginService('utils', 'graphql');
@ -54,16 +55,23 @@ const getCustomTypes = (strapi, nexus) => {
const { modelName, slug, publicationState } = args; const { modelName, slug, publicationState } = args;
const { auth } = ctx.state; const { auth } = ctx.state;
isValidFindSlugParams({ try {
modelName, isValidFindSlugParams({
slug, modelName,
modelsByName, slug,
publicationState, modelsByName,
}); publicationState,
});
} catch (error) {
throw new ValidationError(error.message);
}
const { uid, field, contentType } = modelsByName[modelName]; const { uid, field, contentType } = modelsByName[modelName];
await hasRequiredModelScopes(strapi, uid, auth); try {
await hasRequiredModelScopes(strapi, uid, auth);
} catch (error) {
throw new ForbiddenError();
}
// build query // build query
let query = { let query = {