如何捕获Parse-Server中无效会话令牌请求的请求头?
Great question! I've run into a similar issue with Parse Server before, and the key here is to target only the invalid session token errors (instead of validating every request) using either Express's error-handling middleware or Parse Server's built-in event system. Here are two reliable, efficient approaches:
Option 1: Use Express Error-Handling Middleware
Since Parse Server runs on top of Express, you can add an error-handling middleware after mounting the Parse Server instance. This middleware will catch errors thrown during request processing—including invalid session token errors—and let you extract the request headers you need without impacting valid requests.
// First, initialize your Parse Server instance const parseServer = new ParseServer({ // Your Parse Server config (databaseURI, appId, masterKey, etc.) }); // Mount Parse Server to your Express app app.use('/parse', parseServer); // Add this error-handling middleware AFTER mounting Parse Server app.use((err, req, res, next) => { // Check if this is an invalid session token error (Parse's official error code 101) if (err.code === 101 && err.message.includes('invalid session token')) { // Extract the problematic session token from request headers const invalidSessionToken = req.headers['x-parse-session-token']; // Log the details you need (customize this for your logging system or monitoring tool) console.log('=== Invalid Session Token Request ==='); console.log('Token:', invalidSessionToken); console.log('Full Request Headers:', req.headers); console.log('Request Path:', req.path); } // Pass the error along so Parse Server can send its default error response to the client next(err); });
Why this works:
- It only triggers when an invalid session token error occurs, so there's no extra overhead for valid requests.
- Parse Server uses error code
101exclusively for invalid session tokens, making the check precise and reliable.
Option 2: Listen to Parse Server's beforeError Event
Parse Server emits events during request processing, including a beforeError event that lets you intercept errors before they're sent to the client. This is a more Parse-native approach:
const parseServer = new ParseServer({ // Your Parse Server config }); // Listen for the beforeError event to catch invalid token errors parseServer.on('beforeError', (req, res, err) => { if (err.code === 101) { const invalidToken = req.headers['x-parse-session-token']; console.log('Invalid session token detected:', invalidToken); // Log additional request headers or request details here as needed } }); // Mount the Parse Server to your Express app app.use('/parse', parseServer);
Notes:
- The
beforeErrorevent is available in most recent Parse Server versions. If you're on an older version, stick with the Express middleware approach for broader compatibility.
Either method will let you capture the x-parse-session-token and full request headers for invalid token requests without wasting resources on valid traffic.
内容的提问来源于stack exchange,提问作者Jake T.

