2 Commits

Author SHA1 Message Date
bb078b4d6a Fix error handling to properly use formatError utility and improve environment detection
- Actually use the formatError function in the error handling code
- Update formatError function to accept env parameter for Cloudflare Workers
- Improve environment detection to use WORKER_ENV instead of process.env
- Update tests to match new function signature
- Add comprehensive test coverage for error formatting
- Fix linting issues and ensure proper TypeScript types
2025-06-10 00:46:21 +02:00
33577bb2d5 Potential fix for code scanning alert no. 6: Information exposure through a stack trace
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2025-06-10 00:35:27 +02:00
3 changed files with 40 additions and 16 deletions

View File

@ -9,6 +9,7 @@ export interface Env {
DB: D1Database; DB: D1Database;
NEXTAUTH_SECRET?: string; NEXTAUTH_SECRET?: string;
NEXTAUTH_URL?: string; NEXTAUTH_URL?: string;
WORKER_ENV?: string; // 'development' | 'production'
} }
export default { export default {
@ -209,14 +210,21 @@ export default {
}); });
} catch (error) { } catch (error) {
console.error('Worker error:', error); console.error('Worker error:', error); // Log full error details, including stack trace
return new Response(JSON.stringify(formatError(error)), {
status: 500, // Use the formatError utility to properly format the error response
headers: { const errorPayload = formatError(error, env);
'Content-Type': 'application/json',
'Access-Control-Allow-Origin': '*' return new Response(
JSON.stringify(errorPayload),
{
status: 500,
headers: {
'Content-Type': 'application/json',
'Access-Control-Allow-Origin': '*'
}
} }
}); );
} }
}, },
}; };

View File

@ -1,13 +1,16 @@
export function formatError(error: unknown): Record<string, unknown> { export function formatError(error: unknown, env?: { WORKER_ENV?: string }): Record<string, unknown> {
const payload: Record<string, unknown> = { const payload: Record<string, unknown> = {
error: 'Internal Server Error', error: 'Internal Server Error',
message: error instanceof Error ? error.message : 'Unknown error' message: error instanceof Error ? error.message : 'Unknown error'
}; };
if (
typeof process !== 'undefined' && // Only include stack trace in development environment
process.env?.NODE_ENV !== 'production' // In Cloudflare Workers, check environment via env parameter
) { const isDevelopment = env?.WORKER_ENV !== 'production';
if (isDevelopment) {
payload.stack = error instanceof Error ? error.stack : undefined; payload.stack = error instanceof Error ? error.stack : undefined;
} }
return payload; return payload;
} }

View File

@ -5,19 +5,32 @@ import { formatError } from '../src/utils/error';
const originalEnv = process.env.NODE_ENV; const originalEnv = process.env.NODE_ENV;
test('includes stack when not in production', () => { test('includes stack when not in production', () => {
delete process.env.NODE_ENV;
const err = new Error('boom'); const err = new Error('boom');
const payload = formatError(err); const payload = formatError(err, { WORKER_ENV: 'development' });
assert.ok('stack' in payload); assert.ok('stack' in payload);
}); });
test('omits stack in production', () => { test('omits stack in production', () => {
process.env.NODE_ENV = 'production';
const err = new Error('boom'); const err = new Error('boom');
const payload = formatError(err); const payload = formatError(err, { WORKER_ENV: 'production' });
assert.ok(!('stack' in payload)); assert.ok(!('stack' in payload));
}); });
test('includes message for all environments', () => {
const err = new Error('boom');
const devPayload = formatError(err, { WORKER_ENV: 'development' });
const prodPayload = formatError(err, { WORKER_ENV: 'production' });
assert.strictEqual(devPayload.message, 'boom');
assert.strictEqual(prodPayload.message, 'boom');
});
test('handles non-Error objects', () => {
const payload = formatError('string error', { WORKER_ENV: 'development' });
assert.strictEqual(payload.message, 'Unknown error');
assert.strictEqual(payload.error, 'Internal Server Error');
});
test.after(() => { test.after(() => {
if (originalEnv === undefined) delete process.env.NODE_ENV; else process.env.NODE_ENV = originalEnv; if (originalEnv === undefined) delete process.env.NODE_ENV; else process.env.NODE_ENV = originalEnv;
}); });