Skip to main content

sanitizeModelInput

@webda/core


Function: sanitizeModelInput()

sanitizeModelInput<T>(model, input): T

Defined in: packages/core/src/services/domainservice.service.ts:42

Sanitize client input before it reaches a model (REST, gRPC, MCP and GraphQL):

  • __-prefixed (private) keys are removed at any depth;
  • _-prefixed attributes are removed, unless the model lists them in its static getClientWritableAttributes(): by convention they are server-managed (_user, _roles, _groups, _creationDate...);
  • Behavior-typed attributes (Metadata.Relations.behaviors) are removed: behavior state can only be changed through the behavior's own actions;
  • the attributes of the model's static getProtectedAttributes() are removed, even when listed as writable;
  • the attributes the model schemas mark readOnly (@readOnly on the property) are removed: they are server-managed.

Type Parameters​

T​

T = any

Parameters​

model​

ModelClass<any>

the model class

input​

T

the client input

Returns​

T

the sanitized input