Skip to content

Debug API Endpoints ​

Overview ​

Debug endpoints for development and troubleshooting. These endpoints should be removed or disabled in production environments.

Debug Endpoints ​

Get Debug Info (auth/debug.get.ts) ​

Debug endpoint to check cookie status and authentication state.

Endpoint: GET /api/auth/debug

Purpose:

  • Check if authentication cookies are present
  • Verify cookie values
  • Debug authentication issues during development

Response:

typescript
{
  hasAuthToken: boolean        // Whether auth_token cookie exists
  authTokenLength: number      // Length of auth token (if present)
  hasAuthUser: boolean         // Whether auth_user cookie exists
  cookieHeader: string         // First 100 characters of cookie header
  allCookieNames: string[]     // Array of all cookie names
}

Security Note:

  • Development Only: This endpoint should be removed in production
  • Exposes cookie information for debugging purposes
  • Use only in development/staging environments

File Path: server/api/auth/debug.get.ts

Usage:

typescript
// Development only
const response = await $api('/api/auth/debug')
console.log('Auth cookies:', response)

Post Debug Info (auth/debug-post.post.ts) ​

Debug endpoint to test POST body handling and token validation.

Endpoint: POST /api/auth/debug-post

Purpose:

  • Test POST request body handling
  • Verify token presence in request body
  • Debug request size and structure

Request Body:

typescript
{
  token?: string              // Optional auth token
  user?: object               // Optional user data
  [key: string]: any          // Any additional data
}

Response:

typescript
{
  success: boolean            // Request processing success
  bodySizeKB: string          // Request body size in KB (formatted)
  hasToken: boolean           // Whether token is present
  tokenLength: number         // Token length (if present)
  hasUser: boolean            // Whether user data is present
  userKeys: string[]          // Keys in user object (if present)
  timestamp: string            // ISO timestamp of request
}

Error Response:

typescript
{
  success: false
  error: string               // Error message
  timestamp: string           // ISO timestamp
}

Security Note:

  • Development Only: This endpoint should be removed in production
  • Accepts any POST body for testing
  • Use only in development/staging environments

File Path: server/api/auth/debug-post.post.ts

Usage:

typescript
// Development only
const response = await $api('/api/auth/debug-post', {
  method: 'POST',
  body: {
    token: 'test-token',
    user: { id: 1, name: 'Test User' }
  }
})
console.log('Debug info:', response)

Best Practices ​

  1. Remove in Production: Always remove or disable debug endpoints before deploying to production
  2. Environment Checks: Add environment checks to disable in production:
    typescript
    if (process.env.NODE_ENV === 'production') {
      throw createError({ statusCode: 404 })
    }
  3. Logging: Use debug endpoints to troubleshoot authentication issues during development
  4. Security: Never expose sensitive data through debug endpoints
  5. Documentation: Clearly mark debug endpoints in code comments