Introduces zod-based validation schemas for Minecraft and Mojang API endpoints. Refactors texture route to support hash-based file serving and removes the old static texture route. Updates database schema for player properties and adds an event to clean expired certificates. Improves ValidationError formatting, adjusts skin/cape URL construction, and adds SSRF protection for skin uploads.
24 lines
826 B
JavaScript
24 lines
826 B
JavaScript
const z = require("zod")
|
|
|
|
module.exports = {
|
|
POST: {
|
|
headers: z.object({
|
|
"content-type": z.string()
|
|
.regex(/application\/json/i, { message: "Content-Type must be application/json" }),
|
|
"authorization": z.string().min(1, { message: "Authorization header is required." })
|
|
}),
|
|
body: z.object({
|
|
variant: z.enum(["classic", "slim"], {
|
|
errorMap: () => ({ message: "Variant must be 'classic' or 'slim'." })
|
|
}),
|
|
url: z.string()
|
|
.url({ message: "Invalid URL format." })
|
|
.max(2048, { message: "URL is too long." })
|
|
}),
|
|
error: {
|
|
code: 400,
|
|
message: "Invalid skin URL or variant.",
|
|
error: "IllegalArgumentException"
|
|
}
|
|
}
|
|
} |