basalt / drives/src / DriveHostNotAllowedError
Class: DriveHostNotAllowedError
Defined in: drives/src/errors.ts:128
A URL the framework refused to open — because the host is not on the provider's declared allowlist, because the address it resolves to failed SSRF validation, or because it could not be parsed at all. The primary SSRF control, because provider responses (a @microsoft.graph.downloadUrl, a redirect target) are attacker-influenced data, not trusted configuration.
It names the host and a fixed reason, never the URL. That is not fastidiousness. On this package's hottest path the URL being refused is a pre-signed download URL, which is itself a bearer credential for the file, and this message is forwarded verbatim into drive:sync_failed, an app's logger and @basaltkit/audit. @basaltkit/webhooks' guard quotes the URL it refused — correct for an endpoint an operator configured, wrong for one a provider handed us — so createDriveFetch re-raises it as this.
Extends
Constructors
Constructor
> new DriveHostNotAllowedError(host, provider, reason?): DriveHostNotAllowedError
Defined in: drives/src/errors.ts:136
Parameters
host
string
provider
string
reason?
string = 'it is not on its allowed-hosts list'
Returns
DriveHostNotAllowedError
Overrides
Properties
code
> readonly code: string
Defined in: core/src/errors.ts:25
Inherited from
details?
> readonly optional details?: Record<string, unknown>
Defined in: core/src/errors.ts:28
Structured payload passed to the constructor, exactly as given (never sanitised here).
Inherited from
expose
> readonly expose: false = false
Defined in: drives/src/errors.ts:135
The host and reason stay in the message and details for the log, the drive:sync_failed event and the audit trail; an HTTP client only gets the code — naming an internal host it was refused is an SSRF oracle.
status
> readonly status: 502 = 502
Defined in: drives/src/errors.ts:129