PartyStream / projectPS

API for the Party Stream app
www.partystreamapp.com
1 stars 0 forks source link

no parameter validation on create pictures function #43

Open hebime opened 11 years ago

hebime commented 11 years ago

I was able to still run the function without passing in the userId or eventId. The queries still worked which might also mean that foreign keys aren't. I think we're missing one from picture_events.eventId to events.id. Fixed this by adding NOT NULL to both columns in the picture_events table;

Still need to add parameter validation.

iToto commented 11 years ago

hmm, yeah I was thinking about a nice way to do validation. I want to see there's a nice way to do before and after filters with express. That way we can write a universal validate function and call it before we route.