Skip to content
Back to skills

Error Handling

ASecurity

Global Exception Filters and standard error formats.

  • 8 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 8, 2026
ai-agentsnodeexpressapisecurity

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned September 8, 2026

npx -y skills add ngxtm/devkit --skill error-handling --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Error Handling?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Error Handling
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/ngxtm-error-handling-devkit/badge)](https://www.skillsdirectory.com/skills/ngxtm-error-handling-devkit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: NestJS Error Handling
description: Global Exception Filters and standard error formats.
metadata:
  labels: [nestjs, errors, filters]
  triggers:
    files: ['**/*.filter.ts', 'main.ts']
    keywords: [ExceptionFilter, Catch, HttpException]
---

# NestJS Error Handling Standards

## Global Exception Filter

- **Requirement**: Centralize error formatting.
- **Platform Agnostic**: Do **not** import `Request`/`Response` from Express/Fastify types directly.
  - **Use**: `HttpAdapterHost` to access the underlying platform response methods.
  - `const { httpAdapter } = this.httpAdapterHost;`
- **Structure**:
  - Implement strictly typed error responses.
  - Refer to **[API Standards](../api-standards/SKILL.md)** for `ApiErrorResponse`.

  ```json
  {
    "statusCode": 400,
    "message": "Validation failed",
    "error": "Bad Request",
    "timestamp": "ISO...",
    "path": "/users"
  }
  ```

## Error Flow

1. **Service**: Throws specific or generic errors (e.g., `EntityNotFoundError`).
2. **Interceptor**: Maps low-level errors to HTTP Exceptions (e.g., `catchError(err => throw new NotFoundException())`).
   - _Why_: Keeps Exception Filters focused on formatting, not business logic interpretation.
3. **Global Filter**: Formats the final JSON response.

## Built-in Exceptions

- **Use**: Throw `NotFoundException`, `ForbiddenException`, `BadRequestException`.
- **Custom**: Extend `HttpException` only for domain-specific failures that need specific status codes.

## Logging

- **Context**: Always pass `MyClass.name` to the `Logger` constructor.
- **Levels**:
  - `error`: 500s (Stack trace required).
  - `warn`: 400s (Client errors).

## Security (Information Leakage)

- **Production**: **NEVER** expose stack traces in HTTP responses (`process.env.NODE_ENV === 'production'`).
- **Sanitization**: Ensure `ApiException` payloads do not leak internal file paths or raw variable dumps.

Files in this skill

  • SKILL.md1.9 KB
  • references/REFERENCE.md361 B
  • references/exception-filters.md3.6 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…