travel, import API: Verify that payload is a hash

This commit is contained in:
Daniel Friesel 2019-12-17 20:41:36 +01:00
parent 934a9ac21a
commit c8695ecb1c

View file

@ -170,13 +170,24 @@ sub travel_v1 {
my ($self) = @_; my ($self) = @_;
my $payload = $self->req->json; my $payload = $self->req->json;
if ( not $payload or ref($payload) ne 'HASH' ) {
$self->render(
json => {
success => \0,
error => 'Malformed JSON',
},
);
return;
}
my $api_token = $payload->{token} // ''; my $api_token = $payload->{token} // '';
if ( $api_token !~ qr{ ^ (?<id> \d+ ) - (?<token> .* ) $ }x ) { if ( $api_token !~ qr{ ^ (?<id> \d+ ) - (?<token> .* ) $ }x ) {
$self->render( $self->render(
json => { json => {
success => \0, success => \0,
error => 'Malformed JSON or malformed token', error => 'Malformed token',
}, },
); );
return; return;
@ -339,13 +350,24 @@ sub import_v1 {
my ($self) = @_; my ($self) = @_;
my $payload = $self->req->json; my $payload = $self->req->json;
if ( not $payload or ref($payload) ne 'HASH' ) {
$self->render(
json => {
success => \0,
error => 'Malformed JSON',
},
);
return;
}
my $api_token = $payload->{token} // ''; my $api_token = $payload->{token} // '';
if ( $api_token !~ qr{ ^ (?<id> \d+ ) - (?<token> .* ) $ }x ) { if ( $api_token !~ qr{ ^ (?<id> \d+ ) - (?<token> .* ) $ }x ) {
$self->render( $self->render(
json => { json => {
success => \0, success => \0,
error => 'Malformed JSON or malformed token', error => 'Malformed token',
}, },
); );
return; return;