diff --git a/src/routes/todos.ts b/src/routes/todos.ts index 4e65551..250e0aa 100644 --- a/src/routes/todos.ts +++ b/src/routes/todos.ts @@ -29,13 +29,24 @@ router.get("/:id", (req: Request, res: Response) => { }); // POST /todos - Create a new todo -// NOTE: No input validation! Title could be empty, null, or wrong type router.post("/", (req: Request, res: Response) => { const body = req.body as CreateTodoRequest; + // Validate that title exists and is not empty + if (!body.title || typeof body.title !== "string") { + res.status(400).json({ error: "Title is required and must be a string" }); + return; + } + + const trimmedTitle = body.title.trim(); + if (trimmedTitle.length === 0) { + res.status(400).json({ error: "Title cannot be empty" }); + return; + } + const newTodo: Todo = { id: nextId++, - title: body.title, // Could be undefined or empty! + title: trimmedTitle, completed: false, createdAt: new Date(), };