fix: 修正 getProjects 响应解析 — 后端返回 {items:[...]} 而非裸数组
- BackendProjectResponse 对齐后端 ProjectResponse(仅 id/name/description) - getProjects 改为 response.data.items 解析 - 修复代码审计 PR#94 审查发现的 P0 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -6,32 +6,32 @@ import apiClient from './client';
|
||||
|
||||
export interface ProjectItem {
|
||||
id: string;
|
||||
owner_user_id: string;
|
||||
name: string;
|
||||
description: string;
|
||||
shared_users: string[];
|
||||
}
|
||||
|
||||
/** 后端 ProjectResponse 只返回 id, name, description */
|
||||
interface BackendProjectResponse {
|
||||
id: string;
|
||||
owner_user_id: string;
|
||||
name: string;
|
||||
description: string;
|
||||
shared_users: string[];
|
||||
}
|
||||
|
||||
/** 后端 ListProjectsResponse 返回 { items: [...] } */
|
||||
interface BackendListProjectsResponse {
|
||||
items: BackendProjectResponse[];
|
||||
}
|
||||
|
||||
const toProjectItem = (item: BackendProjectResponse): ProjectItem => ({
|
||||
id: item.id,
|
||||
owner_user_id: item.owner_user_id,
|
||||
name: item.name,
|
||||
description: item.description,
|
||||
shared_users: item.shared_users || [],
|
||||
});
|
||||
|
||||
/** 获取当前用户的项目列表 */
|
||||
export const getProjects = async (): Promise<ProjectItem[]> => {
|
||||
const response = await apiClient.get<BackendProjectResponse[]>('/projects');
|
||||
return (response.data || []).map(toProjectItem);
|
||||
const response = await apiClient.get<BackendListProjectsResponse>('/projects');
|
||||
return (response.data.items || []).map(toProjectItem);
|
||||
};
|
||||
|
||||
/** 创建项目 */
|
||||
|
||||
Reference in New Issue
Block a user