feat(search): wire sort to DocumentList; validate sort param allowlist
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -13,7 +13,12 @@ export async function load({ url, fetch }) {
|
|||||||
const senderId = url.searchParams.get('senderId') || '';
|
const senderId = url.searchParams.get('senderId') || '';
|
||||||
const receiverId = url.searchParams.get('receiverId') || '';
|
const receiverId = url.searchParams.get('receiverId') || '';
|
||||||
const tags = url.searchParams.getAll('tag');
|
const tags = url.searchParams.getAll('tag');
|
||||||
const sort = url.searchParams.get('sort') || 'DATE';
|
const VALID_SORTS = ['DATE', 'TITLE', 'SENDER', 'RECEIVER', 'UPLOAD_DATE'] as const;
|
||||||
|
type ValidSort = (typeof VALID_SORTS)[number];
|
||||||
|
const rawSort = url.searchParams.get('sort') ?? 'DATE';
|
||||||
|
const sort: ValidSort = (VALID_SORTS as readonly string[]).includes(rawSort)
|
||||||
|
? (rawSort as ValidSort)
|
||||||
|
: 'DATE';
|
||||||
const dir = url.searchParams.get('dir') || 'desc';
|
const dir = url.searchParams.get('dir') || 'desc';
|
||||||
const tagQ = url.searchParams.get('tagQ') || '';
|
const tagQ = url.searchParams.get('tagQ') || '';
|
||||||
|
|
||||||
@@ -35,7 +40,7 @@ export async function load({ url, fetch }) {
|
|||||||
receiverId: receiverId || undefined,
|
receiverId: receiverId || undefined,
|
||||||
tag: tags.length ? tags : undefined,
|
tag: tags.length ? tags : undefined,
|
||||||
tagQ: tagQ || undefined,
|
tagQ: tagQ || undefined,
|
||||||
sort: sort as 'DATE' | 'TITLE' | 'SENDER' | 'RECEIVER' | 'UPLOAD_DATE',
|
sort,
|
||||||
dir: dir || undefined
|
dir: dir || undefined
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -139,6 +139,7 @@ const showRightColumn = $derived(data.canWrite || (data.incompleteDocs?.length ?
|
|||||||
error={data.error}
|
error={data.error}
|
||||||
total={data.total ?? 0}
|
total={data.total ?? 0}
|
||||||
q={q}
|
q={q}
|
||||||
|
sort={sort}
|
||||||
/>
|
/>
|
||||||
{/if}
|
{/if}
|
||||||
</main>
|
</main>
|
||||||
|
|||||||
Reference in New Issue
Block a user