Skip to content

Server Settings

Cesar Blender edited this page Sep 13, 2023 · 1 revision

This are all of the main server settings available in AstralJS

export interface ServerSettings {
    port: number // The port of the server (default: 3000)
    docs: boolean // If you want that the server get documented, turn it on (by default is true)
    docsPath: string // Tell where the docs will be exposed (by default /api/docs)
    requestLogger: boolean // If you want to log all the request to the server, turn it on (default: true)
    jsonParser: boolean // To use express.json() middleware (default: true)
    urlencoded: boolean // To use express.urlencoded middleware (default: true)
    errorLogger(errorMessage: string): void // IMPORTANT: this file is extremely important by security reasons. At the end of this file, there is a link that explains why this function is so important and how can you configure it
    responseStructure(status: number, data?: unknown, message?: string): object // Define the response structure, by default is {status, data, message} but you can adde more stuff if you want
    errorResponseStructure(message: string, status: number): object // As responseStructure, you can customize this function to define your own error response structure.
    ipv4Parser: boolean // This middleware parses express req.ip (ipv6) to ipv4, this is important for request logger, you can disable it if you want
    xssProtection: boolean // This enables extra protection to XSS attacks. This sanitizes all of your request params and body to keep secure the server
    sqlInjectionProtection: boolean // This verifies that any response contains sql queries. if it detects one query, it throws an error and responses with a 401 error code
    helmet: boolean // This enables helmet middleware for extra xss and sql protection
    compression: boolean // This compress all the responses for fastest and lightweight... responses!
    helmetSettings?: Readonly<HelmetOptions> // You can configure here helmet if you want
    compressionSettings?: CompressionOptions // Also you can configure here compression middleware if you want
    static?: { // If you want static files, you can use this
        path: string // The path of your static files folder
        settings: ExpressStaticGzipOptions // Configure ExpressStaticGzip
    }
    endpoints?: EndpointType<object>[] // The endpoints of your app, dude
}

Error Logger

To understand what the Error Logger does, consider the following:

One of the most common security vulnerabilities is the exposure of descriptive errors. When your application encounters an error, such as a database error, that error message can inadvertently reveal sensitive information, like database structure or internal details. This information can be exploited by malicious actors to gain unauthorized access or launch attacks.

The Error Logger in AstralJS plays a crucial role in mitigating this risk. Any error on AstralJS is handled. If there's an error on a response, a handler in the router catches that error, and sends a 500 Internal Server Error code. This might be a disadvantage for developers, on a development enviroment, but you can configure Error Logger to manage that error messages.

For example, you can define an error logger function like this

To look up how getEnv function works, click here

import { getEnv } from '@astralstack/astraljs'

function myErrorLogger(errorMessage: string) {
    if (getEnv<string>('NODE_ENV', 'development') !== 'production') {
        console.error(errorMessage)
        return
    }

    // If you're on a production environment it is important to do this
    sendErrorToAPrivateDB(errorMessage) // Send the error to a private db that ONLY YOUR BUSINESS CAN SEE
}

Clone this wiki locally