Defaults to the ambiguous wording, which is correct for every READ denial. Pass message
only through a named factory such as FieldSecurityError.WriteDenial, so the choice
of wording is always a deliberate, reviewable decision rather than an inline string.
Optionalmessage: stringOptionalcauseOptionalstackStatic ReadonlyErrorStaticstackThe Error.stackTraceLimit property specifies the number of stack frames
collected by a stack trace (whether generated by new Error().stack or
Error.captureStackTrace(obj)).
The default value is 10 but may be set to any valid JavaScript number. Changes
will affect any stack trace captured after the value has been changed.
If set to a non-number value, or set to a negative number, stack traces will not capture any frames.
StaticcaptureCreates a .stack property on targetObject, which when accessed returns
a string representing the location in the code at which
Error.captureStackTrace() was called.
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack; // Similar to `new Error().stack`
The first line of the trace will be prefixed with
${myObject.name}: ${myObject.message}.
The optional constructorOpt argument accepts a function. If given, all frames
above constructorOpt, including constructorOpt, will be omitted from the
generated stack trace.
The constructorOpt argument is useful for hiding implementation
details of error generation from the user. For instance:
function a() {
b();
}
function b() {
c();
}
function c() {
// Create an error without stack trace to avoid calculating the stack trace twice.
const { stackTraceLimit } = Error;
Error.stackTraceLimit = 0;
const error = new Error();
Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b
Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
throw error;
}
a();
OptionalconstructorOpt: FunctionStaticprepareStaticWriteA write refusal on a field the caller CAN read — names the missing permission instead of hiding behind "or it does not exist", which would be actively misleading about a field whose values they are looking at. Callers must confirm readability first; see FieldSecurityWriteDenialMessage.
The error thrown when field-level security refuses a request — a caller-authored predicate naming an unreadable field, a typed accessor touching one, or a save modifying a field the caller may not write.
A DISTINCT class because its message is the one security rejection that is deliberately safe to show a caller: both FieldSecurityDenialMessage and FieldSecurityWriteDenialMessage were designed for exactly that surface and disclose nothing (see their docs). Transport layers that rightly swallow arbitrary resolver errors (whose messages can carry SQL text or internal state) recognize this one and let it through, so the intended wording reaches the wire instead of degenerating into a generic transport error.
Recognize it by
name === FieldSecurityError.ErrorNamerather thaninstanceofwhere bundling might duplicate the class.