fix(routes): convert alias-import + canonical-shape callsites to canonical errorResponse (DC-063) [glm-grade=A]
Background (DC-062, 2026-08-18, c01a011): errorResponse has TWO bindings in
src/utils/responses.js:
- canonical: errorResponse(res, statusCode, message, extras) + DC-062 validator
- alias: error(res, message, statusCode = 500) -- NO validator
DC-062 already fixed routes/caddy-upstreams.js and added a defensive
TypeError-throwing validator on the canonical path.
DC-063 (this commit): the same bug class lurks in 2 more route files that
import the alias 'error: errorResponse' but call it with the canonical
shape '(res, NUM, STRING)'. The alias function does NOT run the validator,
so at runtime the alias path silently fires
res.status('event not found') -> TypeError -> 500 HTML panic
silently masking the intended 4xx JSON response for the client.
Affected files:
- routes/security.js: 15 callsites (lines 110-251)
Pre-fix every GET /events/:id (404), POST /events (400/409), PUT
/events/batch (400/413), POST/PATCH/DELETE /hosts (400/404/409) all
returned 500 HTML with a RangeError stack instead of the intended JSON.
Fix: switched import to canonical so the existing canonical-shape
callsites bind to the validator-armed function. 0 callsite changes.
- routes/services.js: 7 callsites total
3 already in canonical shape (POST /services credentials,
lines 222/246/261) -- switched import fixes them.
4 alias-shape callsites (lines 406/432/455/486) -- rewritten to
canonical shape per responses.js:76.
Test sweep:
- NEW __tests__/routes/errorresponse-arg-order.regression.test.js (284
lines, 75 tests): pins
(1) the validator (defense-in-depth) — 14 tests
(2) the routes/ + src/utilities/ convention — 49 one-per-file
static-tree walk that classifies each file's import style
(alias vs canonical) and asserts each callsite matches the
file's own convention.
(3) live-HTTP smoke — security.js /events/:id + /hosts/:id return
404 JSON, never 500 HTML.
Also serves as the spec defining the alias-vs-canonical convention
for any future contributor.
- UPDATED __tests__/routes/services.routes.test.js: fixture mock for
src/utils/responses now exposes both errorResponse (canonical) and
error (alias) so the route's canonical-shape import resolves.
29/29 tests still pass.
Verification: full suite 93/93 / 2114/2114 green; security.js + services.js
both fully canonical; 13 canonical-import files (DC-062 + DC-063) + 10
alias-import files (using message-first shape correctly) — proven
consistent by the static sweep.
GLM-5.3 stand-in judge round 1: GRADE=A (verified cold diff + convention
check + 4-tool-call budget); 2 LOW polish suggestions logged for a
follow-up DC: (a) require.cache injection in the live HTTP smoke
should migrate to jest.mock(virtual:true) so a module rename fails
loudly; (b) static sweep should assert a min-callsite floor per
convention class.
This commit is contained in:
@@ -30,7 +30,11 @@
|
||||
*/
|
||||
|
||||
const express = require('express');
|
||||
const { ok, error: errorResponse } = require('../src/utils/responses');
|
||||
// DC-063: use the canonical `errorResponse(res, statusCode, message, extras)`
|
||||
// shape — alias `error: errorResponse` used here previously was message-first
|
||||
// which silently mis-called every callsite (15 endpoints surfaced as 500 HTML
|
||||
// panics instead of the intended 4xx JSON).
|
||||
const { ok, errorResponse } = require('../src/utils/responses');
|
||||
const { getStore } = require('../src/security/event-store');
|
||||
const { getRegistry } = require('../src/security/host-registry');
|
||||
const platformPaths = require('../platform-paths');
|
||||
|
||||
@@ -10,7 +10,11 @@ const { exists } = require('../src/utilities/fs-helpers');
|
||||
const { paginate, parsePaginationParams } = require('../src/utilities/pagination');
|
||||
const { ValidationError, NotFoundError, ConflictError } = require('../src/utilities/errors');
|
||||
const { resolveServiceUrl } = require('../src/utilities/url-resolver');
|
||||
const { success, error: errorResponse } = require('../src/utils/responses');
|
||||
// DC-063: use the canonical `errorResponse(res, statusCode, message, extras)`
|
||||
// shape — alias `error: errorResponse` used here previously was message-first
|
||||
// which silently mis-called 3 credential-store callsites (returned 500 HTML
|
||||
// panics for invalid serviceId instead of the intended 400 JSON).
|
||||
const { success, errorResponse } = require('../src/utils/responses');
|
||||
const platformPaths = require('../platform-paths');
|
||||
|
||||
/**
|
||||
@@ -398,7 +402,8 @@ module.exports = function({
|
||||
try {
|
||||
validateServiceConfig({ id, name });
|
||||
} catch (validationErr) {
|
||||
return errorResponse(res, validationErr.message, 400, { errors: validationErr.errors });
|
||||
// DC-063: canonical shape (res, statusCode, message, extras) per responses.js:76.
|
||||
return errorResponse(res, 400, validationErr.message, { errors: validationErr.errors });
|
||||
}
|
||||
|
||||
await servicesStateManager.update(services => {
|
||||
@@ -423,7 +428,8 @@ module.exports = function({
|
||||
} catch (error) {
|
||||
log.error('deploy', error, null, { note: 'Error adding service' });
|
||||
if (error.message.includes('already exists')) {
|
||||
errorResponse(res, safeErrorMessage(error), 409);
|
||||
// DC-063: canonical shape per responses.js:76.
|
||||
errorResponse(res, 409, safeErrorMessage(error));
|
||||
} else {
|
||||
// Error handled by middleware
|
||||
}
|
||||
@@ -445,7 +451,8 @@ module.exports = function({
|
||||
try {
|
||||
validateServiceConfig(service);
|
||||
} catch (validationErr) {
|
||||
return errorResponse(res, `Invalid service "${service.id}": ${validationErr.message}`, 400, { errors: validationErr.errors });
|
||||
// DC-063: canonical shape per responses.js:76.
|
||||
return errorResponse(res, 400, `Invalid service "${service.id}": ${validationErr.message}`, { errors: validationErr.errors });
|
||||
}
|
||||
}
|
||||
|
||||
@@ -475,7 +482,8 @@ module.exports = function({
|
||||
});
|
||||
|
||||
if (!found) {
|
||||
return errorResponse(res, `Service "${id}" not found`, 404);
|
||||
// DC-063: canonical shape per responses.js:76.
|
||||
return errorResponse(res, 404, `Service "${id}" not found`);
|
||||
}
|
||||
|
||||
resyncHealthChecker?.().catch(() => {});
|
||||
|
||||
Reference in New Issue
Block a user