Only required query params

This commit is contained in:
Raul Ochoa
2015-03-26 17:19:16 +01:00
parent 4be0a70362
commit d210643d63
+5 -12
View File
@@ -10,13 +10,11 @@ var assert = require('assert');
// Whitelist query parameters and attach format
var REQUEST_QUERY_PARAMS_WHITELIST = [
'user',
'callback',
'config',
'map_key',
'api_key',
'auth_token',
'config',
'scale_factor'
'callback'
];
module.exports = function(redisPool) {
@@ -495,7 +493,7 @@ module.exports = function(redisPool) {
lzma,
function(result) {
if (req.profiler) {
req.profiler.done('LZMA decompress');
req.profiler.done('lzma');
}
try {
delete req.query.lzma;
@@ -504,18 +502,13 @@ module.exports = function(redisPool) {
} catch (err) {
callback(new Error('Error parsing lzma as JSON: ' + err));
}
},
function(/*percent*/) { // progress
//console.log("LZMA decompression " + percent + "%");
}
);
return;
}
var bad_query = _.difference(_.keys(req.query), REQUEST_QUERY_PARAMS_WHITELIST);
_.each(bad_query, function(key){ delete req.query[key]; });
req.params = _.extend({}, req.params); // shuffle things as request is a strange array/object
req.query = _.pick(req.query, REQUEST_QUERY_PARAMS_WHITELIST);
req.params = _.extend({}, req.params); // shuffle things as request is a strange array/object
var user = cdbRequest.userByReq(req);