5 ms·
The main points are 2 years old, with newer edits: https://github.com/OWASP/CheatSheetSeries/blame/master/cheatsheets/Nodejs_Security_Cheat_Sheet.md https://git
by Normal_gaussian 5y ago
The main points are 2 years old, with newer edits: https://github.com/OWASP/CheatSheetSeries/blame/master/cheatsheets/Nodejs_Security_Cheat_Sheet.md https://github.com/OWASP/CheatSheetSeries/blame/master/cheat...
Catch-log-new error-rethrow or catch-annotate-rethrow is (unfortunately) an important part of using Promises that isn't widely taught. I've also seen some Promise replacements with better debugging (often call site carry through, so more like a stack trace) - though I like to keep it vanilla.
- eyelidlessness 5y ago> Catch-log-new error-rethrow or catch-annotate-rethrow is (unfortunately) an important part of using Promises that isn't widely taught And horribly unwieldy to have to do everywhere, causes code bloat, is easy to forget. > I've also seen some Promise replacements with better debugging (often call site carry through, so more like a stack trace) - though I like to keep it vanilla. I remembered Bluebird has call stack support so I looked into that yesterday. Unfortunately it doesn’t play well with sourcemaps so it’s barely an improvement. I really think this is all a lot of trouble for very little benefit when async/await is supported basically everywhere and doesn’t have these problems. It’s not just a huge ergonomic improvement, though it’s also that.