I'm making an API with Express and Sequelize
I want my user to be able to update some entries without having a defined number of params.
For example, if I have the following "Books" database table :
| Name | Type |
|---|---|
| id | int |
| name | varchar |
| description | text |
| userId | int |
I have a post route to update the entry :
function(req, res)
{
var screenUpdate = Book.update(req.body,
{where: {id: req.body.id}})
.then(function(){
return res.status(201).json({
"data": "ok"
});
})
.catch(function(err){
return res.status(500).json({'error':"Impossible de modifier."});
});
}
In this case, the user will put in the request the params that it need, for example name, description but it doesn't prevent it to add id or userId which could break the database.
How could I forbid those parameters from being updated by that request ?
Thank you in advance.