Forbidden class represents an HTTP error response with status code 403. It is used to standardize "Forbidden" error responses, typically when the user is authenticated but lacks permission to access the requested resource.ts
import { Forbidden } from "@arkyn/server/forbidden";
message (required): A descriptive message explaining the reason for access denial.cause (optional): Additional information about the error cause, which can be any serializable data.toResponse() - Converts the instance into a Response object with JSON body and Content-Type: application/json header.toJson() - Alternative method using Response.json() for generating the JSON error response.typescript
import { Forbidden } from "@arkyn/server/forbidden";// Basic usage - throw the errorthrow new Forbidden("You don't have permission to access this resource");// With cause informationthrow new Forbidden("Admin access required", {requiredRole: "admin",userRole: "member",});// Convert to Response objectconst error = new Forbidden("Access denied to this feature");return error.toResponse();// Using toJson alternativereturn error.toJson();
json
{"name": "Forbidden","message": "You don't have permission to access this resource"}
403, set on the Response object itself, the status code is not part of the JSON body.cause is passed to the constructor, it is included in the body as well:json
{"name": "Forbidden","message": "Admin access required","cause": "{\"requiredRole\":\"admin\",\"userRole\":\"member\"}"}
cause parameter, when provided, is serialized with JSON.stringify() and included in the response body under the cause key, it is sent to clients, not just kept for server-side debugging. Because it's stringified, cause appears in the JSON body as a JSON-encoded string rather than a nested object.Forbidden (403) when the user is authenticated but lacks permission. Use Unauthorized (401) when the user is not authenticated at all.