rajput-hemant/infinitunes

0 errors, 36 warningsmaster

No critical or high-risk findings. 33 worth a look.

36 warnings in the paths between 43 routes and 3 tables.

Every file was read, but 1 place in them could not be parsed — listed at the end of this report.

ROUTE FINDINGS34 of 43 · 12/12 rules
ROUTES
43
TABLES
3
FILES READ
214/214
RULES RUN
12/12

36 findings

33 medium3 low

  • Mediumlow confidenceServer Action getPlaylistDetails (src/lib/db/queries.ts) has no validator or rate limiter attached.

    Server Action getPlaylistDetails (src/lib/db/queries.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getPlaylistDetails(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action addSongsToPlaylist (src/lib/db/queries.ts) has no validator or rate limiter attached.

    Server Action addSongsToPlaylist (src/lib/db/queries.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function addSongsToPlaylist(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getHomeData (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getHomeData (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getHomeData(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getSongDetails (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getSongDetails (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getSongDetails(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getSongRecommendations (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getSongRecommendations (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getSongRecommendations(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getAlbumDetails (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getAlbumDetails (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getAlbumDetails(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getAlbumRecommendations (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getAlbumRecommendations (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getAlbumRecommendations(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getAlbumFromSameYear (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getAlbumFromSameYear (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getAlbumFromSameYear(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getPlaylistDetails (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getPlaylistDetails (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getPlaylistDetails(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getPlaylistRecommendations (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getPlaylistRecommendations (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getPlaylistRecommendations(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getArtistDetails (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getArtistDetails (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getArtistDetails(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getArtistsSongs (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getArtistsSongs (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getArtistsSongs(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getArtistsAlbums (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getArtistsAlbums (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getArtistsAlbums(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getArtistTopSongs (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getArtistTopSongs (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getArtistTopSongs(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getShowDetails (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getShowDetails (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getShowDetails(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getShowEpisodes (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getShowEpisodes (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getShowEpisodes(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getEpisodeDetails (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getEpisodeDetails (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getEpisodeDetails(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getTopSearches (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getTopSearches (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getTopSearches(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action searchAll (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action searchAll (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function searchAll(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action search (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action search (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function search(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getTrending (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getTrending (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getTrending(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getTopAlbums (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getTopAlbums (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getTopAlbums(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getCharts (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getCharts (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getCharts(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getFeaturedPlaylists (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getFeaturedPlaylists (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getFeaturedPlaylists(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getTopArtists (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getTopArtists (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getTopArtists(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getTopShows (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getTopShows (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getTopShows(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getFeaturedRadioStations (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getFeaturedRadioStations (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getFeaturedRadioStations(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getActorsTopSongs (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getActorsTopSongs (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getActorsTopSongs(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getLyrics (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getLyrics (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getLyrics(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getLabelDetails (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getLabelDetails (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getLabelDetails(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getMixDetails (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getMixDetails (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getMixDetails(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getMegaMenu (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getMegaMenu (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getMegaMenu(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceServer Action getFooterDetails (src/lib/jiosaavn-api.ts) has no validator or rate limiter attached.

    Server Action getFooterDetails (src/lib/jiosaavn-api.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.

    Missing
    Schema validation of the action's arguments, and a rate limit.
    Confidence
    Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    const Input = z.object({ title: z.string().min(1).max(200) });
    
    export async function getFooterDetails(formData: FormData) {
      const parsed = Input.safeParse(Object.fromEntries(formData));
      if (!parsed.success) return { error: parsed.error.flatten() };
      // ...use parsed.data, never formData directly
    }

    Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowhigh confidenceaccount is not connected to anything.

    account is connected to nothing: dead weight, or a route that was meant to use it and does not.

    Missing
    A route that uses it, or its removal.
    Confidence
    Nothing is wired to it in the design.

    Intended? If it is used by a job or another service, accept it as known debt: run wyro-check --update-baseline and commit the ledger. It stays visible and CI fails only on new findings.

    no-orphan-datastore

  • Lowhigh confidenceverificationToken is not connected to anything.

    verificationToken is connected to nothing: dead weight, or a route that was meant to use it and does not.

    Missing
    A route that uses it, or its removal.
    Confidence
    Nothing is wired to it in the design.

    Intended? If it is used by a job or another service, accept it as known debt: run wyro-check --update-baseline and commit the ledger. It stays visible and CI fails only on new findings.

    no-orphan-datastore

  • Lowlow confidenceGET /api/og has no validator or rate limiter attached.

    GET /api/og can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    // 60 requests per IP per minute.
    app.get("/api/og", rateLimit({ windowMs: 60_000, limit: 60 }), handler);

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

1 place could not be parsed, so any route or table declared there is missing from this report:

  • src/app/api/auth/[...nextauth]/route.ts — Next route file exports no recognised method handler

Free account, no card. The repository opens as an editable graph.

Add this check to the README

wyro architecture badge
[![wyro architecture](https://wyro.in/api/badge/rajput-hemant/infinitunes)](https://wyro.in/scan/rajput-hemant/infinitunes)

It updates itself whenever the repository changes and links back to this report.

What this is

Wyro reads the repository’s routes and data models and checks the paths between them: whether a route can reach a table without passing a guard, whether a datastore holding personal data is exposed to a public read, whether an endpoint that issues credentials requires the credentials it issues.

It is rule-based, not a model. The same commit produces the same result every time, and it does not guess at business rules it cannot see. A rule with nothing to look at is reported as not having run — never as a pass.

This check runs on public source through GitHub’s own API and needs no account. A free account adds the editable architecture canvas, private repositories on paid plans, and a CI gate. No card required.

Maintain this repository? You can have this report removed, and a real vulnerability is disclosed to you privately before it is published. How public reports are handled.