Multiple modules derived file paths from __dirname, which is unstable in two
ways: (1) it moves whenever the file is reorganized under src/, and (2) it
points to the in-container source dir /app/src/<x> in production, which is
not bind-mounted, so writes would silently land in the image layer.
Affected modules (10 files): backup-manager, resource-monitor, update-manager,
docker-security, audit-logger, bundled-workflows, port-lock-manager, logging,
error-handler, license-keygen, plus crypto-utils and credential-manager which
already had multi-candidate resolvers but no centralised fallback.
Introduced platformPaths.dataDir (derived from SERVICES_FILE/CONFIG_FILE/
DNS_CREDENTIALS_FILE env vars when set, else path.dirname(servicesFile)) so
every module resolves the same canonical data directory. Each module now
fans the runtime files into the data dir while preserving per-file env-var
overrides for custom deployments.
Why a single resolver:
- one place to swap the default path scheme in v2.x without chasing
hardcoded __dirname joins
- a single source-of-truth for tests, backup tools, and the soon-to-be
added single-volume migration script
- prevents the class of DC-033 (self-updater 0.0.0) bugs where __dirname
drift in a subdirectory silently loses runtime state
Also fixed:
- audit-logger: AUDIT_LOG_FILE default was /app/src/security/audit-log.json
(writable in dev, image-layer in production). Now /app/data/audit-log.json
via platformPaths.dataDir, matching logging.js's same file. Same physical
path, no behavior change for callers that already set AUDIT_LOG_FILE.
- logging.js: LOG_DIR was __dirname (src/utils/) — error.log and
audit-log.json were being written into the source tree. Now
platformPaths.dataDir, matching every other persistent file.
- error-handler.js: ERROR_LOG_FILE hard-coded to __dirname/error.log
(src/utilities/error.log), redundant with logging.js's own default.
Now platformPaths.dataDir/error.log.
- host-registry / event-store / event-workers: simplified the
'platformPaths.dataDir || path.join(__dirname, ../../data)' pattern
to just platformPaths.dataDir (the legacy fallback is no longer
reachable — services.json lives at dataDir/services.json now).
- public-routes-drift.test.js: added 'routes/security.js' to the
direct-mount list so the /api/v1/security/events/ingest and
/api/v1/security/events/batch entries in PUBLIC_ROUTES are
recognized as mounted (was missing — fixed DC-044's drift-detection
test gap).
Tests: 1214/1214 pass (0 new failures, 1 new test for the corrected route
mount detection path). ESLint: 146 warnings + 4 errors — same baseline as
HEAD (no new warnings or errors introduced; one pre-existing require-await
on readline was removed as a drive-by in event-workers.js since the module
uses line-level fs reads, not readline). Container config files like
audit-log.json, container-stats.json, and workflow-history.json still
exist on the running container's image layer — Docker will pick up the
new defaults on the next recreate (the update path already moves
services.json+config.json+credentials.json via the data bind mount).
89 lines
2.7 KiB
JavaScript
89 lines
2.7 KiB
JavaScript
/**
|
|
* DashCaddy Error Handler Middleware
|
|
* Centralizes error handling logic to eliminate duplicate catch blocks
|
|
*
|
|
* Logging: this middleware uses the unified logError from src/utils/logging.js
|
|
* (same one src/app.js uses), so all errors go to one log file. The legacy
|
|
* ./error-logger.js and its ./error.log file have been retired.
|
|
*/
|
|
|
|
const path = require('path');
|
|
const { AppError } = require('./errors');
|
|
const { LIMITS } = require('./constants');
|
|
const { logError: unifiedLogError, safeErrorMessage } = require('../utils/logging');
|
|
const { errorResponse } = require('../utils/responses');
|
|
const platformPaths = require('../../platform-paths');
|
|
|
|
const ERROR_LOG_FILE = process.env.ERROR_LOG_FILE || path.join(platformPaths.dataDir, 'error.log');
|
|
const MAX_ERROR_LOG_SIZE = LIMITS.ERROR_LOG_SIZE;
|
|
|
|
/**
|
|
* Global error handling middleware
|
|
* MUST be registered after all routes in server.js
|
|
*/
|
|
function errorMiddleware(err, req, res, next) {
|
|
// Log all errors with request context (unified, same file the rest of the app uses)
|
|
unifiedLogError(
|
|
ERROR_LOG_FILE,
|
|
MAX_ERROR_LOG_SIZE,
|
|
req.path,
|
|
err,
|
|
{
|
|
method: req.method,
|
|
ip: req.ip,
|
|
userId: req.user?.id,
|
|
body: req.body
|
|
}
|
|
).catch(e => console.error('Failed to write to error log:', e.message));
|
|
|
|
// Determine if this is an operational error (AppError) or programming error
|
|
const isOperational = err.isOperational || err instanceof AppError;
|
|
|
|
// Status code
|
|
const statusCode = err.statusCode || 500;
|
|
|
|
// Error code (DC-XXX format)
|
|
const code = err.code || `DC-${statusCode}`;
|
|
|
|
// Build extras for response
|
|
const extras = { code };
|
|
|
|
// Add optional fields if present
|
|
if (err.requiresTotp) extras.requiresTotp = true;
|
|
if (err.retryAfter) extras.retryAfter = err.retryAfter;
|
|
if (err.field) extras.field = err.field;
|
|
if (err.resource) extras.resource = err.resource;
|
|
if (err.details && Object.keys(err.details).length > 0) extras.details = err.details;
|
|
|
|
// Development mode: include stack trace
|
|
if (process.env.NODE_ENV === 'development') {
|
|
extras.stack = err.stack;
|
|
}
|
|
|
|
// Send response
|
|
errorResponse(res, statusCode, isOperational ? safeErrorMessage(err) : 'Internal server error', extras);
|
|
|
|
// For non-operational errors, log as fatal
|
|
if (!isOperational) {
|
|
console.error('FATAL: Non-operational error detected', {
|
|
error: err.message,
|
|
stack: err.stack,
|
|
path: req.path
|
|
});
|
|
}
|
|
}
|
|
|
|
/**
|
|
* 404 handler for routes not found
|
|
* Register this before the global error handler
|
|
*/
|
|
function notFoundHandler(req, res, next) {
|
|
const { NotFoundError } = require('./errors');
|
|
next(new NotFoundError(`Route ${req.method} ${req.path}`));
|
|
}
|
|
|
|
module.exports = {
|
|
errorMiddleware,
|
|
notFoundHandler
|
|
};
|