Skip to content

fix: don't serialize error stack traces to the client in production - #2241

Merged
birkskyum merged 2 commits into
solidjs:mainfrom
birkskyum:fix-issue-1967
Jul 26, 2026
Merged

fix: don't serialize error stack traces to the client in production#2241
birkskyum merged 2 commits into
solidjs:mainfrom
birkskyum:fix-issue-1967

Conversation

@birkskyum

Copy link
Copy Markdown
Member

When a server function throws, the error is serialized with seroval and rethrown on the client. Seroval includes Error.prototype.stack unless the ErrorPrototypeStack feature is disabled, and serialization.ts only disabled Feature.RegExp, so production builds ship server file paths and internal function names to anyone who can trigger a throw (CWE-209).

Disables the feature on the two serializer paths when import.meta.env.PROD. Development is unchanged, so the stack is still there when it's useful. The parse side keeps the original feature set, so a payload that does carry a stack still deserializes.

Note serializeToJSStream passed no disabledFeatures at all, so it leaked regardless of the JSON path's settings. It gets its own constant rather than reusing the JSON one, to avoid picking up the Feature.RegExp downgrade it never had.

@changeset-bot

changeset-bot Bot commented Jul 26, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: b3b674e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@solidjs/start Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@netlify

netlify Bot commented Jul 26, 2026

Copy link
Copy Markdown

Deploy Preview for solid-start-landing-page ready!

Name Link
🔨 Latest commit b3b674e
🔍 Latest deploy log https://app.netlify.com/projects/solid-start-landing-page/deploys/6a655e46e59d09000787bbde
😎 Deploy Preview https://deploy-preview-2241--solid-start-landing-page.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@birkskyum
birkskyum requested a review from lxsmnsyc July 26, 2026 00:33
@pkg-pr-new

pkg-pr-new Bot commented Jul 26, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@solidjs/start@2241

commit: b3b674e

@brenelz brenelz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM but might want Alexis to make sure

@birkskyum
birkskyum enabled auto-merge (squash) July 26, 2026 01:10
@birkskyum
birkskyum merged commit d3c2af2 into solidjs:main Jul 26, 2026
10 checks passed
brenelz added a commit that referenced this pull request Jul 29, 2026
Brings the v2 rc line (through 2.0.0-rc.6) into the Solid 2 branch.

Ported main features onto the Solid 2 architecture:
- Server-function error handler (#2262): wired through
  handleServerFunctionRequest's transformResult hook and the
  solid-start:server-fn-error-handler virtual module.
- Custom seroval plugins (#2250): serialization.plugins now feeds the
  @solidjs/web codec on both the client transport and the server handler.
- ~ alias fix for workspace packages (#2239): adopted appRootAlias in
  place of the global resolve.alias entry.
- Dev toolbar (#2049, replaces the dev overlay): ported to Solid 2
  (Errored/Loading, onSettled, two-arg createEffect, draft-mutation
  stores, terracotta 2 subpath imports, @solidjs/web Portal/Dynamic/JSX,
  createMemo(async) instead of createResource). Protocol-specific pieces
  (SerovalChunkReader, body-format markers) moved local to the toolbar.
- Deferred stream response via h3 iterable() (#2231), StartHandler type
  (#2234), routerLoad restore (#2228), nonce on streaming redirect
  script (#2252), ResizeObserver-loop filter (#2240) all kept.

Kept deleted (superseded by vite-plugin-solid / @solidjs/web /
@solidjs/router server-function integration): fs-routes tree-shake,
manifest.ts, directives, fns serialization/registration/shared and their
specs. Fixes main landed in those files (#2249, #2238, #2243, #2245,
#2241, #2261) live upstream now and are tracked for porting there.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug?]: [security] Server stack trace sent to client on error in server action

3 participants