Skip to content

Issue codes

Every issue has one of six codes. invalid_body, unsafe_key, unknown_field, forbidden_field and invalid_type come from mongoose-guard’s own checks. invalid_value comes from your Mongoose schema’s validators, and carries a rule field naming which one failed. Codes are stable, so branch on them in code. Messages are for people and may be reworded.

The body as a whole can’t be validated. path is "", except for the depth limit below.

MessageCauseFix
Expected a JSON objectThe body is an array, string, number, null or missing.Send a JSON object. In Express, add app.use(express.json()) before the guard.
Request body must be valid JSONWeb adapter only: the body isn’t valid JSON, or it’s empty.Send valid JSON.
Value is nested too deeplyA value inside a Mixed field is nested more than 32 levels deep. path points at the deep value.Flatten the data, or give the field a real schema.

A key that’s never accepted, anywhere in the body.

MessageExample key
Key "__proto__" is reserved__proto__, also constructor and prototype
Keys starting with $ are not allowed$where, $gt, $set
Keys containing a dot are not allowed"address.city" used as a key

Reported in strip mode too. See Security.

Message: Unknown field

The key doesn’t exist in the schema at this position. Usually a typo (nmae) or a field from another model. Removed silently in strip mode.

Message: Field is not allowed

The key exists in the schema but isn’t in this route’s allow list. This is the mass-assignment check. Removed silently in strip mode.

Message: Expected <type>, received <actual>

The value has the wrong JavaScript type. <actual> is one of string, number, boolean, object, array, null, date, bigint or undefined.

<type>For schema type
stringString
numberNumber, Double
32-bit integerInt32
integerBigInt
booleanBoolean
ISO 8601 dateDate
ObjectIdObjectId
decimalDecimal128
UUIDUUID
string or binary dataBuffer
objectnested objects, sub-schemas, Maps, elements of document arrays
arrayarrays

invalid_type can also come from Mongoose, if a custom SchemaType fails to cast. In that case the message is Mongoose’s and rule is set.

Message: whatever the Mongoose validator says, including custom messages from your schema.

rule tells you which validator failed. It’s Mongoose’s validator kind:

ruleSchema option
requiredrequired
min, maxmin, max on numbers and dates
minlength, maxlengthminLength, maxLength on strings
enumenum
regexpmatch
user defineda custom validate function

Real example:

{
"code": "invalid_value",
"path": "password",
"message": "Path `password` (`123`, length 3) is shorter than the minimum allowed length (8).",
"rule": "minlength"
}

Issues from mongoose-guard’s own checks are listed in the order their keys appear in the body. If any of those exist, Mongoose validation doesn’t run, so you never get invalid_value issues mixed in with structural ones. invalid_value issues come in the order Mongoose reports them.