From 801980e8f599c28c5059657a9d85dd03e3827992 Mon Sep 17 00:00:00 2001 From: Michael Bromley Date: Wed, 18 Sep 2024 14:27:50 +0200 Subject: [PATCH] fix(asset-server-plugin): Do not return raw error message on error https://github.com/vendure-ecommerce/vendure/security/code-scanning/15 --- packages/asset-server-plugin/src/plugin.ts | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/packages/asset-server-plugin/src/plugin.ts b/packages/asset-server-plugin/src/plugin.ts index 18a58e8bac..ba47653e93 100644 --- a/packages/asset-server-plugin/src/plugin.ts +++ b/packages/asset-server-plugin/src/plugin.ts @@ -310,8 +310,8 @@ export class AssetServerPlugin implements NestModule, OnApplicationBootstrap { res.send(imageBuffer); return; } catch (e: any) { - Logger.error(e, loggerCtx, e.stack); - res.status(500).send(e.message); + Logger.error(e.message, loggerCtx, e.stack); + res.status(500).send('An error occurred when generating the image'); return; } }