Module: utilities/formValidation

Shared express-validator support for server-rendered forms.

Controllers define their own field rules and messages. This module adds the checks common to every management form (action and record ID) and handles the redirect back to the form when validation fails.

Source:

Members

(static, constant) management

Builds the validation middleware for a create, update and delete form.

Runs the shared action and ID checks, then the controller's field rules for create and update only (delete needs just a valid ID), then rejectInvalidForm.

Source:
Example
static formValidation = management("/activities", ["name"], [
  body("name").isString().withMessage("Name must be text."),
]);

(static, constant) rejectInvalidForm

Creates middleware that stops invalid submissions before the controller runs.

When validation has failed, the first error per field and the listed values are saved in req.session.formFeedback, keyed by the form page URL. The user is then redirected (303) to that page, where the formFeedback middleware displays them once. Valid requests continue to the next handler.

Source:

(inner, constant) maxId

Largest value for a signed MySQL INT ID column.

Source:

Methods

(inner) feedbackPath(req, base) → {string}

Works out the GET page to return to after a failed submission. Keeps a valid record ID and the query string so the user returns to the same record, filters and page; anything else falls back to the base path.

Parameters:
Name Type Description
req express.Request

Incoming request.

base string

Base form path, such as "/activities".

Source:
Throws:

When the request URL is not under the base path.

Type
Error
Returns:

Path and query string of the form page.

Type
string

(inner) isScalar(value) → {boolean}

Rejects arrays and objects that the urlencoded parser can produce from repeated or bracketed field names.

Parameters:
Name Type Description
value unknown

Submitted value.

Source:
Returns:

True for a string or safe integer.

Type
boolean

(inner) isWrite(req) → {boolean}

Checks whether the submitted action writes field data.

Parameters:
Name Type Description
req express.Request

Incoming request.

Source:
Returns:

True for create and update actions.

Type
boolean

(inner) managementFields() → {Array.<ValidationChain>}

Builds the action and record ID checks shared by management forms. The ID is required for update and delete, and checked whenever it is in the URL.

Source:
Returns:

Validation chains.

Type
Array.<ValidationChain>

Type Definitions

FormFeedback

Feedback stored in the session for one form page until it is displayed.

Type:
  • object
Properties:
Name Type Description
errors Record.<string, string>

First error message for each invalid field.

values Record.<string, string>

Submitted values to refill the form with.

action "create" | "update" | "delete"

Action that was submitted.

Source: