Build the PATCH allowlist
Construct a safe request DTO for a PATCH endpoint to prevent object property authorization failures.
PATCH /users/me needs to update profile fields without letting users write privileged fields. Domain model is not input model: define client-editable fields, validate them, apply them intentionally. Blocklists feel fast but fail when new sensitive fields are added or when attackers guess internal names. Name allowed fields For PATCH /users/me, allow only displayName, timezone, and marketingOptIn. The list comes from the feature requirement, not from the current database columns. Create a DTO/schema Define UpdateProfileRequest with those fields, types, lengths, enums, and additionalProperties:false. The schema rejects role, tenantId, isAdmin, and future fields unless deliberately added. Map intentionally Apply each allowed field…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in