Skip to content

basalt / drives/src / DriveHostNotAllowedError

Class: DriveHostNotAllowedError ​

Defined in: drives/src/errors.ts:128

A URL the framework refused to open — because the host is not on the provider's declared allowlist, because the address it resolves to failed SSRF validation, or because it could not be parsed at all. The primary SSRF control, because provider responses (a @microsoft.graph.downloadUrl, a redirect target) are attacker-influenced data, not trusted configuration.

It names the host and a fixed reason, never the URL. That is not fastidiousness. On this package's hottest path the URL being refused is a pre-signed download URL, which is itself a bearer credential for the file, and this message is forwarded verbatim into drive:sync_failed, an app's logger and @basaltkit/audit. @basaltkit/webhooks' guard quotes the URL it refused — correct for an endpoint an operator configured, wrong for one a provider handed us — so createDriveFetch re-raises it as this.

Extends ​

Constructors ​

Constructor ​

> new DriveHostNotAllowedError(host, provider, reason?): DriveHostNotAllowedError

Defined in: drives/src/errors.ts:136

Parameters ​

host ​

string

provider ​

string

reason? ​

string = 'it is not on its allowed-hosts list'

Returns ​

DriveHostNotAllowedError

Overrides ​

BasaltError.constructor

Properties ​

code ​

> readonly code: string

Defined in: core/src/errors.ts:25

Inherited from ​

BasaltError.code


details? ​

> readonly optional details?: Record<string, unknown>

Defined in: core/src/errors.ts:28

Structured payload passed to the constructor, exactly as given (never sanitised here).

Inherited from ​

BasaltError.details


expose ​

> readonly expose: false = false

Defined in: drives/src/errors.ts:135

The host and reason stay in the message and details for the log, the drive:sync_failed event and the audit trail; an HTTP client only gets the code — naming an internal host it was refused is an SSRF oracle.


status ​

> readonly status: 502 = 502

Defined in: drives/src/errors.ts:129

Released under the MIT License.