-
-
Notifications
You must be signed in to change notification settings - Fork 0
Server Settings
This are all of the main server settings available in AstralJS
export interface ServerSettings {
port: number // The port of the server (default: 3000)
docs: boolean // If you want that the server get documented, turn it on (by default is true)
docsPath: string // Tell where the docs will be exposed (by default /api/docs)
requestLogger: boolean // If you want to log all the request to the server, turn it on (default: true)
jsonParser: boolean // To use express.json() middleware (default: true)
urlencoded: boolean // To use express.urlencoded middleware (default: true)
errorLogger(errorMessage: string): void // IMPORTANT: this file is extremely important by security reasons. At the end of this file, there is a link that explains why this function is so important and how can you configure it
responseStructure(status: number, data?: unknown, message?: string): object // Define the response structure, by default is {status, data, message} but you can adde more stuff if you want
errorResponseStructure(message: string, status: number): object // As responseStructure, you can customize this function to define your own error response structure.
ipv4Parser: boolean // This middleware parses express req.ip (ipv6) to ipv4, this is important for request logger, you can disable it if you want
xssProtection: boolean // This enables extra protection to XSS attacks. This sanitizes all of your request params and body to keep secure the server
sqlInjectionProtection: boolean // This verifies that any response contains sql queries. if it detects one query, it throws an error and responses with a 401 error code
helmet: boolean // This enables helmet middleware for extra xss and sql protection
compression: boolean // This compress all the responses for fastest and lightweight... responses!
helmetSettings?: Readonly<HelmetOptions> // You can configure here helmet if you want
compressionSettings?: CompressionOptions // Also you can configure here compression middleware if you want
static?: { // If you want static files, you can use this
path: string // The path of your static files folder
settings: ExpressStaticGzipOptions // Configure ExpressStaticGzip
}
endpoints?: EndpointType<object>[] // The endpoints of your app, dude
}To understand what the Error Logger does, consider the following:
One of the most common security vulnerabilities is the exposure of descriptive errors. When your application encounters an error, such as a database error, that error message can inadvertently reveal sensitive information, like database structure or internal details. This information can be exploited by malicious actors to gain unauthorized access or launch attacks.
The Error Logger in AstralJS plays a crucial role in mitigating this risk. Any error on AstralJS is handled. If there's an error on a response, a handler in the router catches that error, and sends a 500 Internal Server Error code. This might be a disadvantage for developers, on a development enviroment, but you can configure Error Logger to manage that error messages.
For example, you can define an error logger function like this
To look up how getEnv function works, click here
import { getEnv } from '@astralstack/astraljs'
function myErrorLogger(errorMessage: string) {
if (getEnv<string>('NODE_ENV', 'development') !== 'production') {
console.error(errorMessage)
return
}
// If you're on a production environment it is important to do this
sendErrorToAPrivateDB(errorMessage) // Send the error to a private db that ONLY YOUR BUSINESS CAN SEE
}