Skip to content

feat: Implement Purchases and Expense modules, including their API ro… - #44

Merged
JahnaviVeera merged 1 commit into
spotmies:masterfrom
JahnaviVeera:Jahnavi_Dev
Mar 9, 2026
Merged

JahnaviVeera merged 1 commit into
spotmies:masterfrom
JahnaviVeera:Jahnavi_Dev

Conversation

@JahnaviVeera

Copy link
Copy Markdown
Collaborator

…utes, services, controllers, and database schema, and add a new project service.

…utes, services, controllers, and database schema, and add a new project service.
@JahnaviVeera
JahnaviVeera merged commit 75fc8e5 into spotmies:master Mar 9, 2026
1 check passed
@github-actions

github-actions Bot commented Mar 9, 2026

Copy link
Copy Markdown

🤖 AI Code Review

🤖 AI Code Review

📌 Summary

  • The code introduces a new Purchase model and integrates it into the application.
  • Enhancements to the Expense module include file upload handling and receipt URL storage.
  • Minor improvements to the Project module for better data consistency.
  • Overall, the changes are functional and align with the application's structure, but there are areas for improvement in validation, error handling, and maintainability.

💬 Inline Comments (File-wise)

prisma/schema.prisma

  • Line 372: The receiptUrl field is added to the Expense model. However, there is no validation in the application to ensure that the URL is valid.
    • ✅ Suggestion: Add validation logic in the service layer to ensure receiptUrl is a valid URL format.
  • Line 508: The Purchase model uses Decimal for the price field, which is appropriate for monetary values. However, ensure that the database supports the precision defined (12, 2) to avoid runtime issues.

src/app.ts

  • Line 85: The purchasesRoutes are added. Ensure that the corresponding routes are tested for proper integration with the application.

src/modules/expense/expense.controller.ts

  • Line 15: The MulterRequest interface is introduced to handle file uploads. This is a good addition, but the file property should be explicitly checked for null or undefined before accessing it.
    • ✅ Suggestion: Add a null/undefined check for req.file to avoid potential runtime errors.
  • Line 25: The category field is parsed from a string. This could fail silently if the input is malformed.
    • ✅ Suggestion: Add more robust error handling or validation for the category field to ensure it meets expected requirements.
  • Line 33: The fileUploadService is used to upload receipts. Consider adding a retry mechanism or logging for failed uploads to improve reliability.

src/modules/expense/expense.routes.ts

  • Line 42: The upload.single("receipt") middleware is added. Ensure that the file size and type are validated in the multer configuration to prevent malicious uploads.
    • ✅ Suggestion: Update the multer configuration to include file size and MIME type validation.

src/modules/expense/expense.services.ts

  • Line 24: The amount field is parsed as a float. Ensure that the input is sanitized to prevent injection attacks or unexpected behavior.
    • ✅ Suggestion: Use a library like validator to sanitize and validate numeric inputs.
  • Line 44: The receiptUrl is stored directly without validation.
    • ✅ Suggestion: Validate the URL format before saving it to the database.

src/modules/project/project.services.ts

  • Line 132: Clearing customer notes when upgrading their status is a good addition. However, ensure that this behavior is documented and communicated to the team to avoid confusion.

src/modules/purchases/purchases.controller.ts

  • Line 8: The price field is converted to a number without validation. This could lead to unexpected behavior if the input is not a valid number.
    • ✅ Suggestion: Validate the price field to ensure it is a positive number before proceeding.
  • Line 22: The response wraps the newPurchase object in an array. Ensure this format is consistent across the application to avoid confusion.

src/modules/purchases/purchases.routes.ts

  • Line 12: The authenticate middleware is added, but there is no role-based authorization for purchase routes.
    • ✅ Suggestion: Add role-based authorization to restrict access to purchase routes as needed.

src/modules/purchases/purchases.services.ts

  • Line 6: The createPurchase function does not validate the projectId or materialName fields for length or format.
    • ✅ Suggestion: Add validation for projectId (e.g., UUID format) and materialName (e.g., max length) to ensure data integrity.
  • Line 26: The getAllPurchases function formats the response. Consider centralizing response formatting logic to improve maintainability.

⚠️ High-Risk Issues

  1. File Upload Security:

    • The multer configuration does not validate file size or type, which could allow malicious files to be uploaded.
    • ✅ Suggestion: Update the multer configuration to restrict file uploads to specific MIME types (e.g., images or PDFs) and enforce a maximum file size.
  2. Input Validation:

    • Several fields (e.g., price, projectId, receiptUrl) lack proper validation, which could lead to data integrity issues or runtime errors.
    • ✅ Suggestion: Use a validation library like Joi or Zod to enforce input constraints across the application.
  3. Error Handling:

    • Error messages in the controllers are generic and may not provide enough context for debugging.
    • ✅ Suggestion: Include more detailed error messages and log errors for better traceability.

Final Notes

The changes are well-structured and align with the application's architecture. However, addressing the highlighted issues will improve the security, reliability, and maintainability of the code. Let me know if you need further clarification or assistance!


Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

2 participants