Node.js Practical — Authorization/RBAC — Security Bug

Node.js Published Updated 0 Views Verified
Node.js Practical Debugging — Authorization/RBAC (Security Bug). The implementation works but accepts unsafe input or exposes sensitive data. Correct it with validation, parameter binding, safe output and proper authorization. The specific area is role exists but permission check fails. Assume a real Express/Node.js project where the developer needs a reliable, maintainable fix. Explain why the buggy version can fail, then provide corrected code and the expected behavior. Do not hide the root cause behind a generic 'restart the server' answer. BUGGY/PROBLEM CODE: app.get('/profile', (req, res) => { const token = req.headers.authorization; const payload = jwt.verify(token, process.env.JWT_SECRET); res.json(payload); }); TASK: Find the exact problem and write the production-safe correction.
Looking for the latest Sarkari Result 2026 updates? Check the latest government exam results, merit lists and result updates on Sarkari Resultess.
Sarkari Resultess
Questions & Answers

Answer & Explanation

4 Answers
Verified

Possible but Incorrect Code

app.get('/profile', (req, res, next) => { try { var header = req.headers.authorization || ''; const token = header.startsWith('Bearer ') ? header.slice(7) : null; if (!token) return res.status(401).json({success:false, message:'Token required'}); const payload = jwt.verify(token, process.env.JWT_SECRET); return res.json({success:true, data:payload}); } catch (error) { return res.status(401).json({success:false, message:'Invalid or expired token'}); } });
Additional Explanation
यह option जानबूझकर एक common bug/unsafe approach दिखाता है। इसे production solution के रूप में इस्तेमाल करने से पहले variable scope, async flow, module path, validation, error handling और security checks verify करें। ऊपर दिए गए correct option से exact difference compare करें.
Sarkari Resultess
Editorial Answer 1
Verified Correct Answer

Correct Code / Solution

app.get('/profile', (req, res, next) => { try { const header = req.headers.authorization || ''; const token = header.startsWith('Bearer ') ? header.slice(7) : null; if (!token) return res.status(401).json({success:false, message:'Token required'}); const payload = jwt.verify(token, process.env.JWT_SECRET); return res.json({success:true, data:payload}); } catch (error) { return res.status(401).json({success:false, message:'Invalid or expired token'}); } });
Additional Explanation
Root cause: role exists but permission check fails. The important debugging step is to verify the exact runtime value, module path, middleware order, environment variable, database/model export, or asynchronous result before changing unrelated code. The corrected version adds explicit validation/error handling where appropriate. Expected behavior: the code should either complete the requested operation or return/log a controlled error instead of failing silently, returning undefined unexpectedly, or crashing the process.
Sarkari Resultess
Editorial Answer 2
Verified

Possible but Incorrect Code

app.get('/profile', (req, res) => { const token = req.headers.authorization; const payload = jwt.verify(token, process.env.JWT_SECRET); res.json(payload); });
Additional Explanation
यह option जानबूझकर एक common bug/unsafe approach दिखाता है। इसे production solution के रूप में इस्तेमाल करने से पहले variable scope, async flow, module path, validation, error handling और security checks verify करें। ऊपर दिए गए correct option से exact difference compare करें.
Sarkari Resultess
Editorial Answer 3
Verified

Possible but Incorrect Code

app.get('/profile', (req, res, next) => { try { /* missing error handling */ const header = req.headers.authorization || ''; const token = header.startsWith('Bearer ') ? header.slice(7) : null; if (!token) return res.status(401).json({success:false, message:'Token required'}); const payload = jwt.verify(token, process.env.JWT_SECRET); return res.json({success:true, data:payload}); } catch (error) { return res.status(401).json({success:false, message:'Invalid or expired token'}); } });
Additional Explanation
यह option जानबूझकर एक common bug/unsafe approach दिखाता है। इसे production solution के रूप में इस्तेमाल करने से पहले variable scope, async flow, module path, validation, error handling और security checks verify करें। ऊपर दिए गए correct option से exact difference compare करें.
Sarkari Resultess
Editorial Answer 4