Commit f71612e
committed
fix: let VALIDATION_ERROR messages reach the client in production
The errorHandler middleware was unconditionally rewriting every
VALIDATION_ERROR to the generic 'Invalid request' string in production,
which silently neutralized the whole field-aware validation work from
the previous commit. Live curl showed "Invalid request" on the wire
even after the controllers were wired to formatZodError.
Added PASS_THROUGH_CODES — a small allow-list of error codes whose real
message is safe to expose. VALIDATION_ERROR is the only entry: its
messages are written by formatZodError and contain only the field name,
expected format, and the shape (not content) of what the client just
submitted. Nothing the client doesn't already know; no internal state
leaked.
All other codes keep the existing sanitize-in-production behavior
(generic message from the map, or 'An error occurred' for unknown
codes). 2 new middleware tests lock both sides in: VALIDATION_ERROR
propagates verbatim in production, NOT_FOUND still masks.1 parent dc600f4 commit f71612e
2 files changed
Lines changed: 71 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
8 | 12 | | |
9 | 13 | | |
10 | 14 | | |
| |||
13 | 17 | | |
14 | 18 | | |
15 | 19 | | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
16 | 26 | | |
17 | 27 | | |
18 | | - | |
| 28 | + | |
| 29 | + | |
19 | 30 | | |
20 | 31 | | |
21 | 32 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
165 | 165 | | |
166 | 166 | | |
167 | 167 | | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
168 | 227 | | |
169 | 228 | | |
170 | 229 | | |
| |||
0 commit comments