import { DEFAULTED_FIELDS } from './policy-defaults' import type { DefaultedField } from './policy-defaults' const OPTIONAL_FIELDS = ['processingPurposes', 'legalBasis', 'legitimateInterests', 'storageDuration', 'dataSource', 'dataCategories'] as const const REQUIRED_FIELDS = ['title', 'processingDescription', 'recipients'] as const export type PolicyInput = Record & Partial> & { isPublic?: boolean } /** Validate untrusted request values before callers use string operations. */ export function parsePolicyInput(value: unknown): PolicyInput | null { if (!value || typeof value !== 'object' || Array.isArray(value)) return null const input = value as Record if (input.isPublic !== undefined && typeof input.isPublic !== 'boolean') return null const fields = [...REQUIRED_FIELDS, ...OPTIONAL_FIELDS, ...DEFAULTED_FIELDS] for (const field of fields) { const text = input[field] if (text !== undefined && text !== null && (typeof text !== 'string' || text.length > 100000)) return null } const text = (key: string) => typeof input[key] === 'string' ? input[key].trim() : '' return { ...Object.fromEntries([...OPTIONAL_FIELDS, ...DEFAULTED_FIELDS].map(key => [key, text(key) || null])), title: text('title'), processingDescription: text('processingDescription'), recipients: text('recipients'), ...(input.isPublic === undefined ? {} : { isPublic: input.isPublic as boolean }), } }