Security News
New Python Packaging Proposal Aims to Solve Phantom Dependency Problem with SBOMs
PEP 770 proposes adding SBOM support to Python packages to improve transparency and catch hidden non-Python dependencies that security tools often miss.
ganomede-errors
Advanced tools
Ganomede's extended restify errors
The way to distinguish our app's logic-level errors from others.
(Like socket hang up
vs user already exists
.)
The idea is to create error classes like UserNotFoundError extends GanomedeError
,
define appropriate statusCode
and message
on it with optional params,
and return those from lower-level places.
//
// Database.js
//
class Db {
getDocument (id, callback) {
this.redis.get(id, (err, reply) => {
// Propagate "fundamental" errors.
if (err)
return callback(err);
// Wrap app-level errors into more meaningful objects.
if (reply === null)
return callback(new Db.DocumentNotFoundError({id}));
callback(null, reply);
});
}
}
Db.DocumentNotFoundError = class DocumentNotFoundError extends GanomedeError {
constructor (query) {
super('No documents matching `%j`', query);
this.severity = 'info';
this.statusCode = 404;
}
};
In app-code, make use of more meaningful errors and act accordingly.
//
// app.js
//
app.get('/users/:id', (req, res) => {
db.getDocument(`users:${req.params.id}`, (err, user) => {
if (err instanceof Db.DocumentNotFoundError) {
// This will:
// - call `logger[err.severity]` with approprite message;
// - call `next(toRestError(err))`.
//
// Resulting in HTTP response will have appropriate status code (`err.statusCode`)
// and contain JSON body:
//
// { // `error.name` (default is `error.constructor.name`)
// "restCode": "DocumentNotFoundError",
//
// // `error.statusCode`,
// "statusCode": 404,
//
// // `error.message`
// "message": "No documents matching `{\"id\": \"users:4\"}`"
// }
return sendHttpError(logger, next, err);
}
else if (err) {
// Same as above, except log level is "error"
// and `next` will receive restify.InternalServerError instance
// (which `next` already knows how to upcast to `RestError`).
return sendHttpError(logger, next, new restify.InternalServerError());
}
res.json(user);
});
});
It can also be sometimes useful to have more granular error classes.
//
// Orm.js
//
const findUser = (userId, callback) => {
new Db().getDocument(userId, (err, json) => {
if (err instanceof Db.DocumentNotFoundError) {
// here we now what missing document means
// (and DB knows how to distinguish missing document errors
// from, say, "cannot connect to hostname")
return callback(new UserNotFoundError(userId));
}
else if (err)
return callback(err);
callback(null, json);
});
};
Some situations are quite common, so error classes for them with appropriate severity levels, status codes and names are already included.
Class Name (as exported) | HTTP Status | Rest Code | Message | Severity |
---|---|---|---|---|
InvalidAuthTokenError | 401 | 'InvalidAuthTokenError' | Invalid auth token | severity.info |
InvalidCredentialsError | 401 | 'InvalidCredentialsError' | Invalid credentials | severity.info |
RequestValidationError | 400 | First argument passed to constructor | Rest of constructor arguments | severity.info |
if (!req.params.token)
return sendHttpError(logger, next, new InvalidAuthTokenError());
if (req.headers['Authorization'] !== 'Bearer 0xdeadbeef')
return sendHttpError(logger, next, new InvalidCredentialsError());
if (typeof req.body.message !== 'string')
return sendHttpError(logger, next, new RequestValidationError(
'BadMessage',
'Message must be a string, got `%s`', typeof req.body.message
));
FAQs
Errors and handler functions for Ganomede services
The npm package ganomede-errors receives a total of 0 weekly downloads. As such, ganomede-errors popularity was classified as not popular.
We found that ganomede-errors demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
PEP 770 proposes adding SBOM support to Python packages to improve transparency and catch hidden non-Python dependencies that security tools often miss.
Security News
Socket CEO Feross Aboukhadijeh discusses open source security challenges, including zero-day attacks and supply chain risks, on the Cyber Security Council podcast.
Security News
Research
Socket researchers uncover how threat actors weaponize Out-of-Band Application Security Testing (OAST) techniques across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.