From f60a60618a78991ba54fbf7900ce930e8434efc1 Mon Sep 17 00:00:00 2001 From: William Oldham Date: Sat, 29 Aug 2026 17:39:06 +0100 Subject: [PATCH 1/6] chore(errors): change password error naming and add additional errors --- server/api/auth/register.post.ts | 10 +++++----- shared/errors.ts | 14 ++++++++++---- 2 files changed, 15 insertions(+), 9 deletions(-) diff --git a/server/api/auth/register.post.ts b/server/api/auth/register.post.ts index b62b6a6..c6061ec 100644 --- a/server/api/auth/register.post.ts +++ b/server/api/auth/register.post.ts @@ -21,11 +21,11 @@ const errors: Record = { 'INVALID_ARGUMENT: Two or more punctuation characters cannot be used in a row': 'USERNAME_INVALID_CHARS', 'INVALID_ARGUMENT: PNID already in use': 'USERNAME_IN_USE', 'INVALID_ARGUMENT: Mii name too long': 'MIINAME_TOO_LONG', - 'INVALID_ARGUMENT: Password must be between 6 and 16 characters long': 'INVALID_PASSWORD_INPUT', - 'INVALID_ARGUMENT: Password cannot be the same as username': 'INVALID_PASSWORD_INPUT', - 'INVALID_ARGUMENT: Password must have combination of letters, numbers, and/or punctuation characters': 'INVALID_PASSWORD_INPUT', - 'INVALID_ARGUMENT: Password may not have 3 repeating characters': 'INVALID_PASSWORD_INPUT', - 'INVALID_ARGUMENT: Passwords do not match': 'INVALID_PASSWORD_NO_MATCH' + 'INVALID_ARGUMENT: Password must be between 6 and 16 characters long': 'PASSWORD_INVALID_LENGTH', + 'INVALID_ARGUMENT: Password cannot be the same as username': 'PASSWORD_NOT_USERNAME', + 'INVALID_ARGUMENT: Password must have combination of letters, numbers, and/or punctuation characters': 'PASSWORD_NEEDS_CHARS', + 'INVALID_ARGUMENT: Password may not have 3 repeating characters': 'PASSWORD_REPEATED_CHARS', + 'INVALID_ARGUMENT: Passwords do not match': 'PASSWORDS_DO_NOT_MATCH' }; function getCutoffDateForAge(today: Date, age: number) { diff --git a/shared/errors.ts b/shared/errors.ts index bd83c98..47bb7cd 100644 --- a/shared/errors.ts +++ b/shared/errors.ts @@ -16,8 +16,11 @@ const apiErrorCodes = { USERNAME_INVALID_CHARS: 'Username contains invalid characters', USERNAME_IN_USE: 'PNID already in use', MIINAME_TOO_LONG: 'Mii name too long', - INVALID_PASSWORD_INPUT: 'Password must be between 6 and 16 characters long', - INVALID_PASSWORD_NO_MATCH: 'Passwords do not match', + PASSWORD_INVALID_LENGTH: 'Password must be between 6 and 16 characters long', + PASSWORD_NOT_USERNAME: 'Password cannot be the same as your username', + PASSWORD_NEEDS_CHARS: 'Password must have combination of letters, numbers, and/or punctuation characters', + PASSWORDS_DO_NOT_MATCH: 'Passwords do not match', + PASSWORD_REPEATED_CHARS: 'Password may not have 3 repeating characters', ACCOUNT_DELETED: 'Account has been deleted', INVALID_ACCESS_LEVEL: 'Invalid access level', BANNED: 'Account is banned', @@ -45,8 +48,11 @@ export const apiErrorCodeStatus: Record = { UNDER_THIRTEEN: 400, ACCOUNT_DELETED: 400, INVALID_EMAIL: 400, - INVALID_PASSWORD_INPUT: 400, - INVALID_PASSWORD_NO_MATCH: 400, + PASSWORD_INVALID_LENGTH: 400, + PASSWORD_NOT_USERNAME: 400, + PASSWORD_NEEDS_CHARS: 400, + PASSWORDS_DO_NOT_MATCH: 400, + PASSWORD_REPEATED_CHARS: 400, MIINAME_TOO_LONG: 400, USERNAME_IN_USE: 400, USERNAME_INVALID_CHARS: 400, From f0966e7e6b5f29cd24e91c3852b96ea6163be74d Mon Sep 17 00:00:00 2001 From: William Oldham Date: Sat, 29 Aug 2026 17:39:36 +0100 Subject: [PATCH 2/6] feat(http): add JSON parsing to httpApi data response --- server/utils/httpApi.ts | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/server/utils/httpApi.ts b/server/utils/httpApi.ts index 28f9264..e819396 100644 --- a/server/utils/httpApi.ts +++ b/server/utils/httpApi.ts @@ -27,7 +27,11 @@ export function useHttpApi(event: H3Event, token?: string): HttpApiFetch { if (response.statusCode >= 400) { const err = new Error(`Request failed with ${response.statusCode}`); try { - (err as any).data = await response.body.text(); + if (response.headers['content-type']?.includes('application/json')) { + (err as any).data = await response.body.json(); + } else { + (err as any).data = await response.body.text(); + } } catch { // It's already errored, we don't need to know the body } From 20ca7d55ffc59d83984e77b9180c5c6fc74c056f Mon Sep 17 00:00:00 2001 From: William Oldham Date: Sat, 29 Aug 2026 17:40:03 +0100 Subject: [PATCH 3/6] fix(reset-password): handle errors in http reset password api --- server/api/auth/reset-password.post.ts | 46 ++++++++++++++++++++------ 1 file changed, 36 insertions(+), 10 deletions(-) diff --git a/server/api/auth/reset-password.post.ts b/server/api/auth/reset-password.post.ts index ea77ebd..b2a6492 100644 --- a/server/api/auth/reset-password.post.ts +++ b/server/api/auth/reset-password.post.ts @@ -1,19 +1,45 @@ import { ResetPasswordSchema } from '~~/shared/api-types'; +import type { ApiErrorCodes } from '~~/shared/errors'; + +const errors: Record = { + 'Missing token': 'INVALID_INPUT', + 'Invalid token': 'INVALID_INPUT', + 'Token expired': 'INVALID_INPUT', + 'Invalid token. No user found': 'INVALID_INPUT', + 'Must enter a password': 'PASSWORD_INVALID_LENGTH', + 'Password is too long': 'PASSWORD_INVALID_LENGTH', + 'Password is too short': 'PASSWORD_INVALID_LENGTH', + 'Password cannot be the same as username': 'PASSWORD_NOT_USERNAME', + 'Password must have combination of letters, numbers, and/or punctuation characters': 'PASSWORD_NEEDS_CHARS', + 'Password may not have 3 repeating characters': 'PASSWORD_REPEATED_CHARS', + 'Passwords do not match': 'PASSWORDS_DO_NOT_MATCH' +}; export default defineEventHandler(async (event): Promise => { const body = await readZodBody(event, ResetPasswordSchema); const apiFetch = useHttpApi(event); // The GRPC version requires a login token, which the user doesnt have when resetting password, so we're using the HTTP api - await apiFetch('/v1/reset-password', { - method: 'POST', - body: JSON.stringify({ - password: body.password, - password_confirm: body.passwordConfirm, - token: body.resetToken - }), - headers: { - 'Content-type': 'application/json' + try { + await apiFetch('/v1/reset-password', { + method: 'POST', + body: JSON.stringify({ + password: body.password, + password_confirm: body.passwordConfirm, + token: body.resetToken + }), + headers: { + 'Content-type': 'application/json' + } + }); + } catch (err: any) { + const data = err?.data; + let errorCode: ApiErrorCodes = 'UNHANDLED_ERROR'; + + if (typeof data === 'object' && data?.error) { + errorCode = errors[data.error] ?? 'UNHANDLED_ERROR'; } - }); + + throw createApiError(errorCode); + } }); From b1866617c67ba890ce5b7d7065a89e891ffc01a5 Mon Sep 17 00:00:00 2001 From: William Oldham Date: Sat, 29 Aug 2026 19:14:48 +0100 Subject: [PATCH 4/6] fix(logs): don't spam the logs with 404 and add better logging for server errors --- server/plugins/log-errors.ts | 38 ++++++++++++++++++++++++++++++++++++ src/error.vue | 8 +++++--- 2 files changed, 43 insertions(+), 3 deletions(-) create mode 100644 server/plugins/log-errors.ts diff --git a/server/plugins/log-errors.ts b/server/plugins/log-errors.ts new file mode 100644 index 0000000..fb5a969 --- /dev/null +++ b/server/plugins/log-errors.ts @@ -0,0 +1,38 @@ +import type { H3Error } from 'h3'; + +/** + * Logs server-side errors in a compact, readable format. + * + * Nitro fires the `error` hook for every request error, whatever the source + * (API routes, server routes/middleware, SSR rendering). It also fires for + * expected HTTP errors like 404s, so anything below a 500 is ignored here. + */ +export default defineNitroPlugin((nitroApp) => { + nitroApp.hooks.hook('error', (err, { event }) => { + const error = err as Partial; + const statusCode = error.statusCode ?? 500; + + // Skip expected client errors (404, 401, 422, redirects, ...). + if (statusCode < 500) { + return; + } + + const where = event ? `${event.method} ${event.path}` : 'non-request'; + const tag = error.unhandled ? '[unhandled]' : ''; + + console.error(`[server error] ${tag} ${where} -> ${statusCode} ${err.message}`); + + if (error.data !== undefined) { + console.error(' data:', error.data); + } + + if (err.cause) { + console.error(' cause:', err.cause); + } + + if (err.stack) { + // Drop the first line (already printed above as the message). + console.error(err.stack.split('\n').slice(1).join('\n')); + } + }); +}); diff --git a/src/error.vue b/src/error.vue index cfb6106..f480546 100644 --- a/src/error.vue +++ b/src/error.vue @@ -3,9 +3,11 @@ import { watchImmediate } from '@vueuse/core'; import DefaultLayout from './layouts/default.vue'; const { error } = defineProps<{ error: any }>(); -watchImmediate([error], () => { - console.error(error); -}); +if (import.meta.client) { + watchImmediate([() => error], () => { + console.error(error); + }); +}