Skip to content

basalt / auth/src / WeakJwtSecretError

Class: WeakJwtSecretError ​

Defined in: auth/src/auth.ts:48

Thrown at construction when the JWT signing secret is missing or too weak. A short/low-entropy HS256 key can be brute-forced offline, letting an attacker forge access tokens for any account — so this fails closed rather than boot with a guessable key. Use @basaltkit/env's secret({ minLength: 32 }).

Extends ​

Constructors ​

Constructor ​

> new WeakJwtSecretError(reason): WeakJwtSecretError

Defined in: auth/src/auth.ts:49

Parameters ​

reason ​

string

Returns ​

WeakJwtSecretError

Overrides ​

BasaltError.constructor

Properties ​

code ​

> readonly code: string

Defined in: core/src/errors.ts:25

Inherited from ​

BasaltError.code


details? ​

> readonly optional details?: Record<string, unknown>

Defined in: core/src/errors.ts:28

Structured payload passed to the constructor, exactly as given (never sanitised here).

Inherited from ​

BasaltError.details

Released under the MIT License.